WordPress Vulnerability Report

WordPress Vulnerability Report — June 11, 2025

Since last week, 306 new vulnerabilities emerged in the WordPress ecosystem, including 271 plugins and 35 themes. 172 of the vulnerable plugins and themes remain unpatched, but Solid Security Pro users are protected by virtual patching from Patchstack.

Avatar photo
Sarah Ulmer

In this report, 306 vulnerabilities have been publicly disclosed. Security patches for 134 of these plugins and themes are available now, so run those updates as soon as possible. If you’re a Solid Security Pro user, the version management tool may have already warned you and updated these plugins, depending on your settings.

Additionally, there are 172 plugin and theme vulnerabilities, and no patch has been available yet. If you’re a Solid Security Pro user, those vulnerabilities are already protected by the Solid Security firewall. Virtual patches from Patchstack will be applied when a vulnerability is considered high or medium risk. If no patch is forthcoming from the vendor or the vulnerable software has been marked “closed” and dropped from the official WordPress repositories, you should deactivate it soon and look for alternative solutions.

Along with poor user account security, vulnerable plugins and themes are among the top reasons why WordPress websites get hacked. Unfortunately, cyberattacks are increasing in volume and sophistication. They’re also increasingly aimed at small to mid-sized businesses.

Our WordPress Vulnerability Report covers the latest emerging WordPress plugin, theme, and core vulnerabilities. Each vulnerability will have a severity rating of LowMediumHigh, or Critical. Responsible disclosure of vulnerabilities is essential to keeping the WordPress community safe. Please share this report to help spread the word and make WordPress — and the web — more secure.

WordPress Core

WordPress 6.8.1 was released on April 30, 2025. This maintenance release includes fixes for 15 bugs throughout Core and the Block Editor, addressing issues affecting multiple areas of WordPress, including the block editor, multisite, and REST API. For a full list, refer to the release candidate announcement.

No new core vulnerabilities were disclosed this week.

WordPress Plugins — 120 Patched / 151 Unpatched

Widget Logic

Plugin Slug:
widget-logic
Installations
100,000+
Vulnerability:
Remote Code Execution (RCE)
Patched in Version:
No Fix
Severity Score:
Critical
The vulnerability has not been patched. You should deactivate the plugin.

CubeWP – All-in-One Dynamic Content Framework

Plugin Slug:
cubewp-framework
Installations
5,000+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

PayU CommercePro Plugin

Plugin Slug:
payu-india
Installations
5,000+
Vulnerability:
Broken Authentication
Patched in Version:
No Fix
Severity Score:
Critical
The vulnerability has not been patched. You should deactivate the plugin.

WP Shopify

Plugin:
WP Shopify
Plugin Slug:
wp-shopify
Installations
4,000+
Vulnerability:
Local File Inclusion
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Easy Mega Menu Plugin for WordPress – ThemeHunk

Plugin Slug:
themehunk-megamenu-plus
Installations
3,000+
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Widgetize Pages Light

Plugin Slug:
widgetize-pages-light
Installations
3,000+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Premium Packages – Sell Digital Products Securely

Plugin Slug:
wpdm-premium-packages
Installations
3,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Category Icon

Plugin Slug:
category-icon
Installations
2,000+
Vulnerability:
XML External Entity (XXE)
Patched in Version:
No Fix
Severity Score:
Critical
The vulnerability has not been patched. You should deactivate the plugin.

Post Grid Master – Custom Post Types, Taxonomies & Ajax Filter Everything with Infinite Scroll, Load More, Pagination & Shortcode Builder

Plugin Slug:
ajax-filter-posts
Installations
1,000+
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Booqable Rental Plugin

Plugin Slug:
booqable-rental-reservations
Installations
1,000+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Activity Plus Reloaded for BuddyPress

Plugin Slug:
bp-activity-plus-reloaded
Installations
1,000+
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

onOffice for WP-Websites

Plugin Slug:
onoffice-for-wp-websites
Installations
1,000+
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.
Plugin Slug:
simple-keyword-to-link
Installations
1,000+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

All Currencies for WooCommerce

Plugin Slug:
woocommerce-all-currencies
Installations
1,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

WP Compress for MainWP

Plugin Slug:
wp-compress-mainwp
Installations
900+
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

???????????????

Plugin Slug:
os-diagnosis-generator
Installations
800+
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Spice Blocks

Plugin Slug:
spice-blocks
Installations
800+
Vulnerability:
Arbitrary File Download
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

ACF: Yandex Maps Field

Plugin Slug:
acf-yandex-maps-field
Installations
700+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Broadly for WordPress

Plugin Slug:
broadly
Installations
700+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Bitly URL Shortener

Plugin Slug:
codehaveli-bitly-url-shortener
Installations
700+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

«?????????» ?? DaData.ru

Plugin Slug:
dadata-ru
Installations
700+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

IFrame Widget

Plugin Slug:
iframe-widget
Installations
700+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Melipayamak

Plugin Slug:
melipayamak
Installations
700+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Accessibility Suite by Ability, Inc

Plugin Slug:
online-accessibility
Installations
700+
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Pinterest Verify Meta Tag

Plugin Slug:
pinterest-verify-meta-tag
Installations
700+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Responsify WP

Plugin Slug:
responsify-wp
Installations
700+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Wordapp

Plugin:
Wordapp
Plugin Slug:
wordapp
Installations
700+
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Spreadsheet Price Changer for WooCommerce and WP E-commerce – Light

Plugin Slug:
excel-like-price-change-for-woocommerce-and-wp-e-commerce-light
Installations
600+
Vulnerability:
SQL Injection
Patched in Version:
No Fix
Severity Score:
Critical
The vulnerability has not been patched. You should deactivate the plugin.

WordLift – AI powered SEO – Schema

Plugin Slug:
wordlift
Installations
600+
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Behance Portfolio Manager

Plugin Slug:
portfolio-manager-powered-by-behance
Installations
500+
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Wishlist

Plugin:
Wishlist
Plugin Slug:
wishlist
Installations
500+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

HR Management Lite

Plugin Slug:
hr-management-lite
Installations
400+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Multi CryptoCurrency Payments

Plugin Slug:
multi-crypto-currency-payment
Installations
400+
Vulnerability:
SQL Injection
Patched in Version:
No Fix
Severity Score:
Critical
The vulnerability has not been patched. You should deactivate the plugin.

WP AutoKeyword

Plugin Slug:
wp-autokeyword
Installations
400+
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

GPP Slideshow

Plugin Slug:
gpp-slideshow
Installations
300+
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Viral Loops WP Integration

Plugin Slug:
viral-loops-wp-integration
Installations
300+
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Viral Loops WP Integration

Plugin Slug:
viral-loops-wp-integration
Installations
300+
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Elastic Email Subscribe Form

Plugin Slug:
elastic-email-subscribe-form
Installations
200+
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Epicwin Plugin

Plugin Slug:
epicwin-subscribers
Installations
200+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Read More Login

Plugin Slug:
read-more-login
Installations
200+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Subscription Renewal Reminders for WooCommerce

Plugin Slug:
subscriptions-renewal-reminders
Installations
200+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Pay with Contact Form 7

Plugin Slug:
pay-with-contact-form-7
Installations
100+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Quick Event Calendar

Plugin Slug:
quick-event-calendar
Installations
100+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Recover abandoned cart for WooCommerce

Plugin Slug:
recover-wc-abandoned-cart
Installations
100+
Vulnerability:
SQL Injection
Patched in Version:
No Fix
Severity Score:
Critical
The vulnerability has not been patched. You should deactivate the plugin.

WP Media File Type Manager

Plugin Slug:
wp-media-file-type-manager
Installations
100+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

TicketBAI Facturas para WooCommerce

Plugin Slug:
wp-ticketbai
Installations
80+
Vulnerability:
SQL Injection
Patched in Version:
No Fix
Severity Score:
Critical
The vulnerability has not been patched. You should deactivate the plugin.

TicketBAI Facturas para WooCommerce

Plugin Slug:
wp-ticketbai
Installations
80+
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

One-Login

Plugin:
One-Login
Plugin Slug:
one-login
Installations
70+
Vulnerability:
Privilege Escalation
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Next Event Calendar

Plugin Slug:
next-event-calendar
Installations
60+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

WP Post Corrector

Plugin Slug:
wp-post-corrector
Installations
60+
Vulnerability:
SQL Injection
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

6Storage Rentals

Plugin Slug:
6storage-rentals
Installations
50+
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Bang tinh vay

Plugin Slug:
bang-tinh-lai-suat
Installations
50+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Sola Support Tickets

Plugin Slug:
sola-support-tickets
Installations
50+
Vulnerability:
Arbitrary Content Deletion
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Interactive Regional Map of Africa

Plugin Slug:
interactive-map-of-africa
Installations
30+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

SEPA Girocode

Plugin Slug:
sepa-girocode
Installations
30+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Admin Notes

Plugin Slug:
admin-note
Installations
20+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Interactive UK Regional Map

Plugin Slug:
interactive-uk-regional-map
Installations
20+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Bacon Ipsum

Plugin Slug:
bacon-ipsum
Installations
10+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Interactive Regional Map of Florida

Plugin Slug:
interactive-map-of-florida
Installations
10+
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Team Builder

Plugin:
Team Builder
Plugin Slug:
a-team-showcase
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Abbie Expander

Plugin:
Abbie Expander
Plugin Slug:
abbie-expander
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Advanced Post List

Plugin:
Advanced Post List
Plugin Slug:
advanced-post-list
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

AI Mortgage Calculator

Plugin:
AI Mortgage Calculator
Plugin Slug:
ai-mortgage-calculator
Vulnerability:
Local File Inclusion
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

AppBanners

Plugin:
AppBanners
Plugin Slug:
appbanners
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Atelier Create CV

Plugin Slug:
atelier-create-cv
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Backwp

Plugin:
Backwp
Plugin Slug:
backwp
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

bbPress API

Plugin:
bbPress API
Plugin Slug:
bbp-api
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Bg Orthodox Calendar

Plugin:
Bg Orthodox Calendar
Plugin Slug:
bg-orthodox-calendar
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.
Plugin:
BNS Featured Category
Plugin Slug:
bns-featured-category
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

BP Profile as Homepage

Plugin:
BP Profile as Homepage
Plugin Slug:
bp-profile-as-homepage
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Bunny’s Print CSS

Plugin:
Bunny’s Print CSS
Plugin Slug:
bunnys-print-css
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

WPCHURCH

Plugin:
WPCHURCH
Plugin Slug:
church-management
Vulnerability:
SQL Injection
Patched in Version:
No Fix
Severity Score:
Critical
The vulnerability has not been patched. You should deactivate the plugin.

HyperComments

Plugin:
HyperComments
Plugin Slug:
comments-with-hypercommentscom
Vulnerability:
Privilege Escalation
Patched in Version:
No Fix
Severity Score:
Critical
The vulnerability has not been patched. You should deactivate the plugin.

Complete Google Seo Scan

Plugin:
Complete Google Seo Scan
Plugin Slug:
complete-google-seo-scan
Vulnerability:
SQL Injection
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Contact Form

Plugin:
Contact Form
Plugin Slug:
contact-form-ready
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

WordPress Ajax Load More and Infinite Scroll

Plugin:
WordPress Ajax Load More and Infinite Scroll
Plugin Slug:
cpt-ajax-load-more
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

CubePoints

Plugin:
CubePoints
Plugin Slug:
cubepoints
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Custom Bulk/Quick Edit

Plugin:
Custom Bulk/Quick Edit
Plugin Slug:
custom-bulkquick-edit
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Custom Category/Post Type Post order

Plugin:
Custom Category/Post Type Post order
Plugin Slug:
custom-post-order-category
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Developer Formatter

Plugin:
Developer Formatter
Plugin Slug:
devformatter
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Slack Notifications by dorzki

Plugin:
Slack Notifications by dorzki
Plugin Slug:
dorzki-notifications-to-slack
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

ZoomSounds

Plugin:
ZoomSounds
Plugin Slug:
dzs-zoomsounds
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Elegant Visitor Counter

Plugin:
Elegant Visitor Counter
Plugin Slug:
elegant-visitor-counter
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Universal Video Player

Plugin:
Universal Video Player
Plugin Slug:
elementor_widget_universal_video_player
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

elfsight Contact Form widget

Plugin:
elfsight Contact Form widget
Plugin Slug:
elfsight-contact-form
Vulnerability:
Sensitive Data Exposure
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Elite Video Player

Plugin:
Elite Video Player
Plugin Slug:
elite-video-player
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Foxit eSign for WordPress

Plugin:
Foxit eSign for WordPress
Plugin Slug:
esign-genie-for-wp
Vulnerability:
Other Vulnerability Type
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

ESV Bible Shortcode for WordPress

Plugin:
ESV Bible Shortcode for WordPress
Plugin Slug:
esv-bible-shortcode-for-wordpress
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

FastBook

Plugin:
FastBook
Plugin Slug:
fastbook-responsive-appointment-booking-and-scheduling-system
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

File Provider

Plugin:
File Provider
Plugin Slug:
file-provider
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

File Provider

Plugin:
File Provider
Plugin Slug:
file-provider
Vulnerability:
SQL Injection
Patched in Version:
No Fix
Severity Score:
Critical
The vulnerability has not been patched. You should deactivate the plugin.

Free WP Mail SMTP

Plugin:
Free WP Mail SMTP
Plugin Slug:
free-wp-mail-smtp
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Global Translator

Plugin:
Global Translator
Plugin Slug:
global-translator
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Global Translator

Plugin:
Global Translator
Plugin Slug:
global-translator
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Hide It

Plugin:
Hide It
Plugin Slug:
hide-it
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Hive Support

Plugin:
Hive Support
Plugin Slug:
hive-support
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Hive Support

Plugin:
Hive Support
Plugin Slug:
hive-support
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Image Hover Effects Block

Plugin:
Image Hover Effects Block
Plugin Slug:
image-hover-effects-block
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

InWave Jobs

Plugin:
InWave Jobs
Plugin Slug:
iwjob
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Critical
The vulnerability has not been patched. You should deactivate the plugin.

KI Live Video Conferences

Plugin:
KI Live Video Conferences
Plugin Slug:
ki-live-video-conferences
Vulnerability:
Sensitive Data Exposure
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

KI Live Video Conferences

Plugin:
KI Live Video Conferences
Plugin Slug:
ki-live-video-conferences
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Konami Easter Egg

Plugin:
Konami Easter Egg
Plugin Slug:
konami-easter-egg
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Layouts for Elementor

Plugin:
Layouts for Elementor
Plugin Slug:
layouts-for-elementor
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

CLEVER

Plugin:
CLEVER
Plugin Slug:
lbg-audio11-html5-shoutcast_history
Vulnerability:
Arbitrary File Download
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Sticky Radio Player

Plugin:
Sticky Radio Player
Plugin Slug:
lbg-audio5-html5-shoutcast_sticky
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

SHOUT

Plugin:
SHOUT
Plugin Slug:
lbg-audio8-html5-radio_ads
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

WP Lead Capturing Pages

Plugin:
WP Lead Capturing Pages
Plugin Slug:
leadcapture
Vulnerability:
SQL Injection
Patched in Version:
No Fix
Severity Score:
Critical
The vulnerability has not been patched. You should deactivate the plugin.

MapSVG

Plugin:
MapSVG
Plugin Slug:
mapsvg
Vulnerability:
Privilege Escalation
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Mediabay – WordPress Media Library Folders

Plugin:
Mediabay – WordPress Media Library Folders
Plugin Slug:
mediabay
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

No Spam At All

Plugin:
No Spam At All
Plugin Slug:
no-spam-at-all
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.
Plugin:
Paged Gallery
Plugin Slug:
paged-gallery
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Payment QR WooCommerce

Plugin:
Payment QR WooCommerce
Plugin Slug:
payment-qr-woo
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Personal Favicon

Plugin:
Personal Favicon
Plugin Slug:
personal-favicon
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Post Author

Plugin:
Post Author
Plugin Slug:
post-author
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Post Custom Templates Lite

Plugin:
Post Custom Templates Lite
Plugin Slug:
post-custom-templates-lite
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Powie’s Uptime Robot

Plugin:
Powie’s Uptime Robot
Plugin Slug:
powies-uptime-robot
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Recent Posts Slider Responsive

Plugin:
Recent Posts Slider Responsive
Plugin Slug:
recent-posts-slider-responsive
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Responsive Flipbooks

Plugin:
Responsive Flipbooks
Plugin Slug:
responsive-flipbooks
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Revolution Video Player

Plugin:
Revolution Video Player
Plugin Slug:
revolution_video_player
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Runners Log

Plugin:
Runners Log
Plugin Slug:
runners-log
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Seofy Core

Plugin:
Seofy Core
Plugin Slug:
seofy-core
Vulnerability:
Local File Inclusion
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Simple Google Static Map

Plugin:
Simple Google Static Map
Plugin Slug:
simple-google-static-map
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Simple Nested Menu

Plugin Slug:
simple-nested-menu
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

SocialMark

Plugin:
SocialMark
Plugin Slug:
socialmark
Vulnerability:
Server Side Request Forgery (SSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

StageShow

Plugin:
StageShow
Plugin Slug:
stageshow
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Motors – Events

Plugin:
Motors – Events
Plugin Slug:
stm-motors-events
Vulnerability:
Local File Inclusion
Patched in Version:
No Fix
Severity Score:
Critical
The vulnerability has not been patched. You should deactivate the plugin.

Stop Spammers

Plugin:
Stop Spammers
Plugin Slug:
stop-spammer-registrations-plugin
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

The Holiday Calendar

Plugin:
The Holiday Calendar
Plugin Slug:
the-holiday-calendar
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Universal Video Player

Plugin:
Universal Video Player
Plugin Slug:
universal_video_player
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Video Embeds

Plugin:
Video Embeds
Plugin Slug:
video-embeds
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Direct Checkout for WooCommerce Lite

Plugin:
Direct Checkout for WooCommerce Lite
Plugin Slug:
woo-direct-checkout-lite
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

WooCommerce Photo Reviews – Review Reminders – Review for Discounts

Plugin:
WooCommerce Photo Reviews – Review Reminders – Review for Discounts
Plugin Slug:
woocommerce-photo-reviews
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

WooCommerce Ultimate Gift Card – Create, Sell and Manage Gift Cards with Customized Email Templates

Plugin:
WooCommerce Ultimate Gift Card – Create, Sell and Manage Gift Cards with Customized Email Templates
Plugin Slug:
woocommerce-ultimate-gift-card
Vulnerability:
SQL Injection
Patched in Version:
No Fix
Severity Score:
Critical
The vulnerability has not been patched. You should deactivate the plugin.

WooBeWoo Product Filter Pro

Plugin:
WooBeWoo Product Filter Pro
Plugin Slug:
woofilter-pro
Vulnerability:
SQL Injection
Patched in Version:
No Fix
Severity Score:
Critical
The vulnerability has not been patched. You should deactivate the plugin.

Wp Easy Allopass

Plugin:
Wp Easy Allopass
Plugin Slug:
wordpress-easy-allopass
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

WP-Addpub

Plugin:
WP-Addpub
Plugin Slug:
wp-addpub
Vulnerability:
SQL Injection
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

WP Biographia

Plugin:
WP Biographia
Plugin Slug:
wp-biographia
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

WP Email Debug

Plugin:
WP Email Debug
Plugin Slug:
wp-email-debug
Vulnerability:
Privilege Escalation
Patched in Version:
No Fix
Severity Score:
Critical
The vulnerability has not been patched. You should deactivate the plugin.
Plugin:
WP Featured Content Slider
Plugin Slug:
wp-featured-content-slider
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Freemind Viewer

Plugin:
Freemind Viewer
Plugin Slug:
wp-freemind
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

WP Mail Options

Plugin:
WP Mail Options
Plugin Slug:
wp-mail-options
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

WP Online Users Stats

Plugin:
WP Online Users Stats
Plugin Slug:
wp-online-users-stats
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

WP-Recall

Plugin:
WP-Recall
Plugin Slug:
wp-recall
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

WP Security Master

Plugin Slug:
wp-security-master
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

WP Text Expander

Plugin:
WP Text Expander
Plugin Slug:
wp-text-expander
Vulnerability:
SQL Injection
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.
Plugin:
YouTube Simple Gallery
Plugin Slug:
youtube-simple-gallery
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.
Plugin Slug:
broken-link-checker
Installations
600,000+
Vulnerability:
Sensitive Data Exposure
Patched in Version:
2.4.5
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.4.5.

Ocean Extra

Plugin Slug:
ocean-extra
Installations
600,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.4.9
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.4.9.

WP Shortcodes Plugin — Shortcodes Ultimate

Plugin Slug:
shortcodes-ultimate
Installations
500,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
7.4.0
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 7.4.0.

Simple History – Track, Log, and Audit WordPress Changes

Plugin Slug:
simple-history
Installations
300,000+
Vulnerability:
Sensitive Data Exposure
Patched in Version:
5.8.2
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 5.8.2.
Plugin Slug:
real-cookie-banner
Installations
100,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
5.1.6
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 5.1.6.

Social Sharing Plugin – Sassy Social Share

Plugin Slug:
sassy-social-share
Installations
100,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
3.3.76
Severity Score:
High
The vulnerability has been patched, so you should update to version 3.3.76.

Ninja Tables – Easy Data Table Builder

Plugin Slug:
ninja-tables
Installations
80,000+
Vulnerability:
PHP Object Injection
Patched in Version:
5.0.19
Severity Score:
Critical
The vulnerability has been patched, so you should update to version 5.0.19.

WP Table Builder – WordPress Table Plugin

Plugin Slug:
wp-table-builder
Installations
60,000+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
2.0.7
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.0.7.

WPtouch – Make your WordPress Website Mobile-Friendly

Plugin Slug:
wptouch
Installations
60,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
4.3.61
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 4.3.61.

Calculated Fields Form

Plugin Slug:
calculated-fields-form
Installations
50,000+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
5.3.59
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 5.3.59.

Greenshift – animation and page builder blocks

Plugin Slug:
greenshift-animation-and-page-builder-blocks
Installations
50,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
11.5.7
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 11.5.7.
Plugin Slug:
sina-extension-for-elementor
Installations
50,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
3.7.0
Severity Score:
High
The vulnerability has been patched, so you should update to version 3.7.0.

FancyBox for WordPress

Plugin Slug:
fancybox-for-wordpress
Installations
40,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
3.3.6
Severity Score:
High
The vulnerability has been patched, so you should update to version 3.3.6.

?????? ????? ??????? Persian WooCommerce SMS

Plugin Slug:
persian-woocommerce-sms
Installations
40,000+
Vulnerability:
SQL Injection
Patched in Version:
7.1.0
Severity Score:
High
The vulnerability has been patched, so you should update to version 7.1.0.

Simple Membership

Plugin Slug:
simple-membership
Installations
40,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
4.6.4
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 4.6.4.

RTMKit Addons for Elementor

Plugin Slug:
rometheme-for-elementor
Installations
30,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.6.1
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.6.1.

Print Invoice & Delivery Notes for WooCommerce

Plugin Slug:
woocommerce-delivery-notes
Installations
30,000+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
5.6.0
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 5.6.0.

Welcart e-Commerce

Plugin Slug:
usc-e-shop
Installations
20,000+
Vulnerability:
Arbitrary File Deletion
Patched in Version:
2.11.14
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.11.14.

Backup and Staging by WP Time Capsule

Plugin Slug:
wp-time-capsule
Installations
20,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.22.24
Severity Score:
High
The vulnerability has been patched, so you should update to version 1.22.24.

Store Locator WordPress

Plugin Slug:
agile-store-locator
Installations
10,000+
Vulnerability:
Arbitrary File Upload
Patched in Version:
1.5.3
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.5.3.

Store Locator WordPress

Plugin Slug:
agile-store-locator
Installations
10,000+
Vulnerability:
SQL Injection
Patched in Version:
1.5.2
Severity Score:
High
The vulnerability has been patched, so you should update to version 1.5.2.

Bellows Accordion Menu

Plugin Slug:
bellows-accordion-menu
Installations
10,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.4.4
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.4.4.

Music Player for Elementor – Audio Player & Podcast Player

Plugin Slug:
music-player-for-elementor
Installations
10,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.4.7
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.4.7.

ShiftNav – Responsive Mobile Menu

Plugin Slug:
shiftnav-responsive-mobile-menu
Installations
10,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.8.1
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.8.1.

WP Multilang – Translation and Multilingual Plugin

Plugin Slug:
wp-multilang
Installations
10,000+
Vulnerability:
Local File Inclusion
Patched in Version:
2.4.19.1
Severity Score:
High
The vulnerability has been patched, so you should update to version 2.4.19.1.

Ultimate Gift Cards for WooCommerce

Plugin Slug:
woo-gift-cards-lite
Installations
7,000+
Vulnerability:
SQL Injection
Patched in Version:
3.1.5
Severity Score:
High
The vulnerability has been patched, so you should update to version 3.1.5.

Password Policy Manager | Password Manager

Plugin Slug:
password-policy-manager
Installations
5,000+
Vulnerability:
Broken Authentication
Patched in Version:
2.0.5
Severity Score:
High
The vulnerability has been patched, so you should update to version 2.0.5.

WP Social Widget

Plugin Slug:
wp-social-widget
Installations
5,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.3.1
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.3.1.

Min Max Step Quantity Limits Manager for WooCommerce

Plugin Slug:
product-quantity-for-woocommerce
Installations
4,000+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
5.1.1
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 5.1.1.

WordPress Comments Import & Export

Plugin Slug:
comments-import-export-woocommerce
Installations
3,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.4.4
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.4.4.

The Events Calendar Countdown Addon

Plugin Slug:
countdown-for-the-events-calendar
Installations
3,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.4.10
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.4.10.

Libro de Reclamaciones y Quejas

Plugin Slug:
libro-de-reclamaciones-y-quejas
Installations
3,000+
Vulnerability:
SQL Injection
Patched in Version:
1.0
Severity Score:
High
The vulnerability has been patched, so you should update to version 1.0.

Newsletters

Plugin Slug:
newsletters-lite
Installations
3,000+
Vulnerability:
Local File Inclusion
Patched in Version:
4.10
Severity Score:
High
The vulnerability has been patched, so you should update to version 4.10.

WP Maintenance Mode & Site Under Construction

Plugin Slug:
wp-maintenance-mode-site-under-construction
Installations
3,000+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
4.4
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 4.4.

BlockStrap Page Builder – Bootstrap Blocks

Plugin Slug:
blockstrap-page-builder-blocks
Installations
2,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
0.1.37
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 0.1.37.

oik

Plugin:
oik
Plugin Slug:
oik
Installations
2,000+
Vulnerability:
Broken Access Control
Patched in Version:
4.15.2
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 4.15.2.

Event post

Plugin:
Event post
Plugin Slug:
event-post
Installations
1,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
5.10.2
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 5.10.2.

WP Gravity Forms Salesforce

Plugin Slug:
gf-salesforce-crmperks
Installations
1,000+
Vulnerability:
Open Redirection
Patched in Version:
1.4.8
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.4.8.

Market Exporter

Plugin Slug:
market-exporter
Installations
1,000+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
2.0.23
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.0.23.

Membership For WooCommerce

Plugin Slug:
membership-for-woocommerce
Installations
1,000+
Vulnerability:
Broken Access Control
Patched in Version:
2.8.2
Severity Score:
High
The vulnerability has been patched, so you should update to version 2.8.2.

Newspack Newsletters

Plugin Slug:
newspack-newsletters
Installations
1,000+
Vulnerability:
Open Redirection
Patched in Version:
3.14.0
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.14.0.

Product Catalog Simple

Plugin Slug:
post-type-x
Installations
1,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.8.2
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.8.2.

Raychat

Plugin:
Raychat
Plugin Slug:
raychat
Installations
1,000+
Vulnerability:
Broken Access Control
Patched in Version:
2.2.0
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.2.0.

Stock Locations for WooCommerce

Plugin Slug:
stock-locations-for-woocommerce
Installations
1,000+
Vulnerability:
Broken Access Control
Patched in Version:
2.8.7
Severity Score:
High
The vulnerability has been patched, so you should update to version 2.8.7.

Vayu Blocks – Website Builder for the Block Editor

Plugin Slug:
vayu-blocks
Installations
1,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.3.2
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.3.2.

WordPress CRM Plugin – WP-CRM System

Plugin Slug:
wp-crm-system
Installations
1,000+
Vulnerability:
Broken Access Control
Patched in Version:
3.4.3
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.4.3.

WP Time Slots Booking Form

Plugin Slug:
wp-time-slots-booking-form
Installations
1,000+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
1.2.31
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.2.31.

WordPress Contact Forms by Cimatti

Plugin Slug:
contact-forms
Installations
900+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
1.9.9
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.9.9.

WP Gravity Forms Constant Contact Plugin

Plugin Slug:
gf-constant-contact
Installations
900+
Vulnerability:
Open Redirection
Patched in Version:
1.1.1
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.1.1.

PDF for WPForms + Drag and Drop Template Builder

Plugin Slug:
pdf-for-wpforms
Installations
900+
Vulnerability:
Broken Access Control
Patched in Version:
5.6.1
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 5.6.1.

Ultimate WP Mail

Plugin Slug:
ultimate-wp-mail
Installations
900+
Vulnerability:
Broken Authentication
Patched in Version:
1.3.6
Severity Score:
High
The vulnerability has been patched, so you should update to version 1.3.6.

FraudLabs Pro for WooCommerce

Plugin Slug:
fraudlabs-pro-for-woocommerce
Installations
800+
Vulnerability:
Broken Access Control
Patched in Version:
2.22.12
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.22.12.

Booking Ultra Pro Appointments Booking Calendar Plugin

Plugin Slug:
booking-ultra-pro
Installations
700+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.1.21
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.1.21.

Broadstreet

Plugin Slug:
broadstreet
Installations
700+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.51.8
Severity Score:
High
The vulnerability has been patched, so you should update to version 1.51.8.

Frontend Dashboard

Plugin Slug:
frontend-dashboard
Installations
700+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.2.9
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.2.9.

WP Team – WordPress Team Member Plugin

Plugin Slug:
ht-team-member
Installations
700+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.1.8
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.1.8.

POEditor

Plugin:
POEditor
Plugin Slug:
poeditor
Installations
700+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
0.9.11
Severity Score:
High
The vulnerability has been patched, so you should update to version 0.9.11.

WC MyParcel Belgium

Plugin Slug:
wc-myparcel-belgium
Installations
700+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
4.5.6
Severity Score:
High
The vulnerability has been patched, so you should update to version 4.5.6.

WP Page Loading

Plugin Slug:
wp-page-loading
Installations
700+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
1.0.7
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.0.7.

WP Plugin Info Card

Plugin Slug:
wp-plugin-info-card
Installations
700+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
5.4.0
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 5.4.0.

Search with Typesense

Plugin Slug:
search-with-typesense
Installations
600+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.0.11
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.0.11.

Verge3D Publishing and E-Commerce

Plugin Slug:
verge3d
Installations
600+
Vulnerability:
Broken Access Control
Patched in Version:
4.9.5
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 4.9.5.

404 Page by SeedProd

Plugin Slug:
404-page
Installations
500+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.0.2
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.0.2.

DocsPress – Online Documentation

Plugin Slug:
docspress
Installations
500+
Vulnerability:
Broken Access Control
Patched in Version:
2.5.3
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.5.3.

Job Board Manager

Plugin Slug:
job-board-manager
Installations
500+
Vulnerability:
Broken Access Control
Patched in Version:
2.1.61
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.1.61.

WebHotelier for WordPress

Plugin Slug:
webhotelier
Installations
500+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.10.0
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.10.0.

Audio Editor & Recorder

Plugin Slug:
audio-editor-recorder
Installations
200+
Vulnerability:
Broken Access Control
Patched in Version:
2.2.2
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.2.2.

Knowledge Base

Plugin Slug:
knowledgebase
Installations
100+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.3.1
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.3.1.

MyStyle Custom Product Designer

Plugin Slug:
mystyle-custom-product-designer
Installations
80+
Vulnerability:
SQL Injection
Patched in Version:
3.21.2
Severity Score:
Critical
The vulnerability has been patched, so you should update to version 3.21.2.

LTL Freight Quotes – Day & Ross Edition

Plugin Slug:
ltl-freight-quotes-day-ross-edition
Installations
10+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.1.11
Severity Score:
High
The vulnerability has been patched, so you should update to version 2.1.11.

Art Theme

Plugin:
Art Theme
Plugin Slug:
art-theme
Vulnerability:
Broken Access Control
Patched in Version:
3.12.3
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.12.3.

Civi Framework

Plugin:
Civi Framework
Plugin Slug:
civi-framework
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
2.1.6.4
Severity Score:
High
The vulnerability has been patched, so you should update to version 2.1.6.4.

Crawlomatic Multisite Scraper Post Generator

Plugin:
Crawlomatic Multisite Scraper Post Generator
Plugin Slug:
crawlomatic-multipage-scraper-post-generator
Vulnerability:
Sensitive Data Exposure
Patched in Version:
2.6.9
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.6.9.

Crawlomatic Multisite Scraper Post Generator

Plugin:
Crawlomatic Multisite Scraper Post Generator
Plugin Slug:
crawlomatic-multipage-scraper-post-generator
Vulnerability:
Broken Access Control
Patched in Version:
2.6.9
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.6.9.

LTL Freight Quotes – Daylight Edition

Plugin Slug:
ltl-freight-quotes-daylight-edition
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.2.7
Severity Score:
High
The vulnerability has been patched, so you should update to version 2.2.7.

LTL Freight Quotes – Freightview Edition

Plugin Slug:
ltl-freight-quotes-freightview-edition
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.0.12
Severity Score:
High
The vulnerability has been patched, so you should update to version 1.0.12.

Modern Events Calendar Lite

Plugin:
Modern Events Calendar Lite
Plugin Slug:
modern-events-calendar-lite
Vulnerability:
Sensitive Data Exposure
Patched in Version:
7.22
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 7.22.

Nasa Core

Plugin:
Nasa Core
Plugin Slug:
nasa-core
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
6.4.1
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 6.4.1.

BRW

Plugin:
BRW
Plugin Slug:
ova-brw
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.8.7
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.8.7.

BRW

Plugin:
BRW
Plugin Slug:
ova-brw
Vulnerability:
Local File Inclusion
Patched in Version:
1.8.7
Severity Score:
High
The vulnerability has been patched, so you should update to version 1.8.7.

NewsLetter

Plugin:
NewsLetter
Plugin Slug:
plugin-newsletter
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
8.8.5
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 8.8.5.

NewsLetter

Plugin:
NewsLetter
Plugin Slug:
plugin-newsletter
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
8.8.2
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 8.8.2.
Plugin:
Real Cookie Banner Pro
Plugin Slug:
real-cookie-banner-pro
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
5.1.6
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 5.1.6.

Team Showcase

Plugin:
Team Showcase
Plugin Slug:
team-showcase-cm
Vulnerability:
Content Injection
Patched in Version:
25.05.13
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 25.05.13.

Team Showcase

Plugin:
Team Showcase
Plugin Slug:
team-showcase-cm
Vulnerability:
Broken Access Control
Patched in Version:
25.05.13
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 25.05.13.

Testimonials Showcase

Plugin:
Testimonials Showcase
Plugin Slug:
testimonials-showcase
Vulnerability:
Broken Access Control
Patched in Version:
1.9.18
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.9.18.

Abandoned Cart Pro for WooCommerce

Plugin:
Abandoned Cart Pro for WooCommerce
Plugin Slug:
woocommerce-abandon-cart-pro
Vulnerability:
Arbitrary File Upload
Patched in Version:
9.17.0
Severity Score:
Critical
The vulnerability has been patched, so you should update to version 9.17.0.

WP User Frontend Pro

Plugin:
WP User Frontend Pro
Plugin Slug:
wp-user-frontend-pro
Vulnerability:
Arbitrary File Upload
Patched in Version:
4.1.4
Severity Score:
Critical
The vulnerability has been patched, so you should update to version 4.1.4.

WP User Frontend Pro

Plugin:
WP User Frontend Pro
Plugin Slug:
wp-user-frontend-pro
Vulnerability:
Arbitrary File Deletion
Patched in Version:
4.1.4
Severity Score:
High
The vulnerability has been patched, so you should update to version 4.1.4.

wpForo Advanced Attachments

Plugin:
wpForo Advanced Attachments
Plugin Slug:
wpforo-advanced-attachments
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
3.2.0
Severity Score:
High
The vulnerability has been patched, so you should update to version 3.2.0.

WordPress Themes — 14 Patched / 21 Unpatched

Arlo

Theme:
Arlo
Theme Slug:
arlo
Vulnerability:
Local File Inclusion
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should switch themes.

BodyCenter – Gym, Fitness WooCommerce WordPress Theme

Theme:
BodyCenter – Gym, Fitness WooCommerce WordPress Theme
Theme Slug:
bodycenter
Vulnerability:
Local File Inclusion
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should switch themes.

CraftXtore

Theme:
CraftXtore
Theme Slug:
bw-craftxtore
Vulnerability:
Local File Inclusion
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should switch themes.

Fitrush

Theme:
Fitrush
Theme Slug:
bw-fitrush
Vulnerability:
Local File Inclusion
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should switch themes.

GiftXtore

Theme:
GiftXtore
Theme Slug:
bw-giftxtore
Vulnerability:
Local File Inclusion
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should switch themes.

Petito

Theme:
Petito
Theme Slug:
bw-petito
Vulnerability:
Local File Inclusion
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should switch themes.

Car Repair Services

Theme:
Car Repair Services
Theme Slug:
car-repair-services
Vulnerability:
Server Side Request Forgery (SSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should switch themes.

Themify Edmin

Theme:
Themify Edmin
Theme Slug:
edmin
Vulnerability:
PHP Object Injection
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should switch themes.

FLAP – Business WordPress Theme

Theme:
FLAP – Business WordPress Theme
Theme Slug:
flap
Vulnerability:
PHP Object Injection
Patched in Version:
No Fix
Severity Score:
Critical
The vulnerability has not been patched. You should switch themes.

FlatNews

Theme:
FlatNews
Theme Slug:
flatnews
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should switch themes.

Inset

Theme:
Inset
Theme Slug:
inset
Vulnerability:
Local File Inclusion
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should switch themes.

Krowd

Theme:
Krowd
Theme Slug:
krowd
Vulnerability:
Local File Inclusion
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should switch themes.

PIMP – Creative MultiPurpose

Theme:
PIMP – Creative MultiPurpose
Theme Slug:
pimp
Vulnerability:
Deserialization of untrusted data
Patched in Version:
No Fix
Severity Score:
Critical
The vulnerability has not been patched. You should switch themes.

PressGrid – Frontend Publish Reaction & Multimedia Theme

Theme:
PressGrid – Frontend Publish Reaction & Multimedia Theme
Theme Slug:
press-grid
Vulnerability:
Deserialization of untrusted data
Patched in Version:
No Fix
Severity Score:
Critical
The vulnerability has not been patched. You should switch themes.

Revo

Theme:
Revo
Theme Slug:
revo
Vulnerability:
Local File Inclusion
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should switch themes.

SNS Anton

Theme:
SNS Anton
Theme Slug:
snsanton
Vulnerability:
Local File Inclusion
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should switch themes.

Avaz

Theme:
Avaz
Theme Slug:
snsavaz
Vulnerability:
Local File Inclusion
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should switch themes.

Nitan

Theme:
Nitan
Theme Slug:
snsnitan
Vulnerability:
Local File Inclusion
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should switch themes.

Soho Hotel

Theme:
Soho Hotel
Theme Slug:
soho-hotel
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should switch themes.

Spare

Theme:
Spare
Theme Slug:
spare
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should switch themes.

Valen – Sport, Fashion WooCommerce WordPress Theme

Theme:
Valen – Sport, Fashion WooCommerce WordPress Theme
Theme Slug:
valen
Vulnerability:
Local File Inclusion
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should switch themes.

Courtney

Theme:
Courtney
Theme Slug:
courtney
Vulnerability:
Local File Inclusion
Patched in Version:
1.3.1
Severity Score:
High
The vulnerability has been patched, so you should update to version 1.3.1.

CozyStay

Theme:
CozyStay
Theme Slug:
cozystay
Vulnerability:
PHP Object Injection
Patched in Version:
1.7.1
Severity Score:
Critical
The vulnerability has been patched, so you should update to version 1.7.1.

GrandPrix

Theme:
GrandPrix
Theme Slug:
grandprix
Vulnerability:
Local File Inclusion
Patched in Version:
1.6.1
Severity Score:
High
The vulnerability has been patched, so you should update to version 1.6.1.

Grill and Chow

Theme:
Grill and Chow
Theme Slug:
grillandchow
Vulnerability:
Local File Inclusion
Patched in Version:
1.6.1
Severity Score:
High
The vulnerability has been patched, so you should update to version 1.6.1.

Lesya

Theme:
Lesya
Theme Slug:
lesya
Vulnerability:
Local File Inclusion
Patched in Version:
1.7.3
Severity Score:
High
The vulnerability has been patched, so you should update to version 1.7.3.

Lettery

Theme:
Lettery
Theme Slug:
lettery
Vulnerability:
Local File Inclusion
Patched in Version:
1.1.8
Severity Score:
High
The vulnerability has been patched, so you should update to version 1.1.8.

MediClinic

Theme:
MediClinic
Theme Slug:
mediclinic
Vulnerability:
Local File Inclusion
Patched in Version:
2.2
Severity Score:
High
The vulnerability has been patched, so you should update to version 2.2.

Minterio

Theme:
Minterio
Theme Slug:
minterio
Vulnerability:
Local File Inclusion
Patched in Version:
1.4.1
Severity Score:
High
The vulnerability has been patched, so you should update to version 1.4.1.

Mr. Murphy

Theme:
Mr. Murphy
Theme Slug:
mr-murphy
Vulnerability:
PHP Object Injection
Patched in Version:
1.2.12.1
Severity Score:
Critical
The vulnerability has been patched, so you should update to version 1.2.12.1.

RealHomes

Theme:
RealHomes
Theme Slug:
realhomes
Vulnerability:
Privilege Escalation
Patched in Version:
4.4.1
Severity Score:
High
The vulnerability has been patched, so you should update to version 4.4.1.

Starbelly

Theme:
Starbelly
Theme Slug:
starbelly
Vulnerability:
Local File Inclusion
Patched in Version:
1.3.7
Severity Score:
High
The vulnerability has been patched, so you should update to version 1.3.7.

Sweet Dessert

Theme:
Sweet Dessert
Theme Slug:
sweet-dessert
Vulnerability:
PHP Object Injection
Patched in Version:
1.1.13
Severity Score:
Critical
The vulnerability has been patched, so you should update to version 1.1.13.

TinySalt

Theme:
TinySalt
Theme Slug:
tinysalt
Vulnerability:
PHP Object Injection
Patched in Version:
3.10.0
Severity Score:
Critical
The vulnerability has been patched, so you should update to version 3.10.0.

TinySalt

Theme:
TinySalt
Theme Slug:
tinysalt
Vulnerability:
Local File Inclusion
Patched in Version:
3.10.0
Severity Score:
High
The vulnerability has been patched, so you should update to version 3.10.0.

Solid Security is part of Solid Suite — The best foundation for WordPress websites.

Every WordPress site needs security, backups, and management tools. That’s Solid Suite — an integrated bundle of three plugins: Solid Security, Solid Backups, and Solid Central. You also get access to Solid Academy’s learning resources for WordPress professionals. Build your next WordPress website on a solid foundation with Solid Suite!

Get Solid Security