In this report, 138 vulnerabilities have been publicly disclosed. Security patches for 75 of these plugins and themes are available now, so run those updates as soon as possible. If you’re a Solid Security Pro user, the version management tool may have already warned you and updated these plugins, depending on your settings.
Additionally, there are 63 plugin and theme vulnerabilities, and no patch has been available yet. If you’re a Solid Security Pro user, those vulnerabilities are already protected by the Solid Security firewall. Virtual patches from Patchstack will be applied when a vulnerability is considered high or medium risk. If no patch is forthcoming from the vendor or the vulnerable software has been marked “closed” and dropped from the official WordPress repositories, you should deactivate it soon and look for alternative solutions.
WordPress Core
WordPress 6.8.1 was released on April 30, 2025. This maintenance release includes fixes for 15 bugs throughout Core and the Block Editor, addressing issues affecting multiple areas of WordPress, including the block editor, multisite, and REST API. For a full list, refer to the release candidate announcement.
WordPress Plugins — 55 Patched / 46 Unpatched
Woocommerce Partial Shipment
- Plugin:
- Woocommerce Partial Shipment
- Plugin Slug:
- wc-partial-shipment
- Installations
- 1,000+
- Vulnerability:
- SQL Injection
- Patched in Version:
- No Fix
- Severity Score:
- High
- CVE:
- 2025-48118
Track, Analyze & Optimize by WP Tao
- Plugin Slug:
- wp-tao
- Installations
- 700+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- High
- CVE:
- 2025-48145
IndieBlocks
- Plugin:
- IndieBlocks
- Plugin Slug:
- indieblocks
- Installations
- 100+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2025-5950
One-Login
- Plugin:
- One-Login
- Plugin Slug:
- one-login
- Installations
- 70+
- Vulnerability:
- Privilege Escalation
- Patched in Version:
- No Fix
- Severity Score:
- High
- CVE:
- 2025-23974
Aeroscroll Gallery – Infinite Scroll Image Gallery & Post Grid with Photo Gallery
- Plugin Slug:
- aeroscroll-gallery
- Installations
- 50+
- Vulnerability:
- Directory Traversal
- Patched in Version:
- No Fix
- Severity Score:
- High
- CVE:
- 2025-49451
PostaPanduri
- Plugin:
- PostaPanduri
- Plugin Slug:
- postapanduri
- Installations
- 40+
- Vulnerability:
- SQL Injection
- Patched in Version:
- No Fix
- Severity Score:
- Critical
- CVE:
- 2025-49452
AI Image Lab
- Plugin:
- AI Image Lab
- Plugin Slug:
- ai-image-generator-lab
- Vulnerability:
- Cross Site Request Forgery (CSRF)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2025-4592
Auto Attachments
- Plugin:
- Auto Attachments
- Plugin Slug:
- auto-attachments
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2025-6012
Axle Demo Importer
- Plugin:
- Axle Demo Importer
- Plugin Slug:
- axle-demo-importer
- Vulnerability:
- Arbitrary File Upload
- Patched in Version:
- No Fix
- Severity Score:
- Critical
- CVE:
- 2025-4954
Bunny’s Print CSS
- Plugin:
- Bunny’s Print CSS
- Plugin Slug:
- bunnys-print-css
- Vulnerability:
- Cross Site Request Forgery (CSRF)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2025-5925
Color Palette
- Plugin:
- Color Palette
- Plugin Slug:
- color-palette
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2025-5233
Contact Us page – Contact people LITE
- Plugin:
- Contact Us page – Contact people LITE
- Plugin Slug:
- contact-us-page-contact-people
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2025-5123
Digital Marketing and Agency Templates Addons for Elementor
- Plugin:
- Digital Marketing and Agency Templates Addons for Elementor
- Plugin Slug:
- digital-marketing-agency-templates-for-elementor
- Vulnerability:
- Cross Site Request Forgery (CSRF)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2025-5938
Easy Flashcards
- Plugin:
- Easy Flashcards
- Plugin Slug:
- easy-flashcards
- Vulnerability:
- Cross Site Request Forgery (CSRF)
- Patched in Version:
- No Fix
- Severity Score:
- High
- CVE:
- 2025-6040
DIOT SCADA with MQTT
- Plugin:
- DIOT SCADA with MQTT
- Plugin Slug:
- ecava-diot-scada
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2025-4216
Elite Video Player
- Plugin:
- Elite Video Player
- Plugin Slug:
- elite-video-player
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- High
- CVE:
- 2025-30988
FW Food Menu
- Plugin:
- FW Food Menu
- Plugin Slug:
- fw-food-menu
- Vulnerability:
- Arbitrary File Upload
- Patched in Version:
- No Fix
- Severity Score:
- Critical
- CVE:
- 2025-49447
FW Gallery
- Plugin:
- FW Gallery
- Plugin Slug:
- fw-gallery
- Vulnerability:
- Arbitrary File Deletion
- Patched in Version:
- No Fix
- Severity Score:
- High
- CVE:
- 2025-49415
WPGYM
- Plugin:
- WPGYM
- Plugin Slug:
- gym-management
- Vulnerability:
- Local File Inclusion
- Patched in Version:
- No Fix
- Severity Score:
- High
- CVE:
- 2025-32549
Image Resizer On The Fly
- Plugin:
- Image Resizer On The Fly
- Plugin Slug:
- image-resizer-on-the-fly
- Vulnerability:
- Arbitrary File Deletion
- Patched in Version:
- No Fix
- Severity Score:
- High
- CVE:
- 2025-6065
REST API | Custom API Generator For Cross Platform And Import Export In WP
- Plugin:
- REST API | Custom API Generator For Cross Platform And Import Export In WP
- Plugin Slug:
- import-export-with-custom-rest-api
- Vulnerability:
- Broken Access Control
- Patched in Version:
- No Fix
- Severity Score:
- Critical
- CVE:
- 2025-5288
IRM Newsroom
- Plugin:
- IRM Newsroom
- Plugin Slug:
- irm-newsroom
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2025-4585
kk Youtube Video
- Plugin:
- kk Youtube Video
- Plugin Slug:
- kk-youtube-video
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2025-6061
CLEVER
- Plugin:
- CLEVER
- Plugin Slug:
- lbg-audio11-html5-shoutcast_history
- Vulnerability:
- Arbitrary File Download
- Patched in Version:
- No Fix
- Severity Score:
- High
- CVE:
- 2025-31635
MapSVG
- Plugin:
- MapSVG
- Plugin Slug:
- mapsvg
- Vulnerability:
- Arbitrary File Upload
- Patched in Version:
- No Fix
- Severity Score:
- Critical
- CVE:
- 2025-47559
MapSVG
- Plugin:
- MapSVG
- Plugin Slug:
- mapsvg
- Vulnerability:
- Privilege Escalation
- Patched in Version:
- No Fix
- Severity Score:
- High
- CVE:
- 2025-47561
Nasa Core
- Plugin:
- Nasa Core
- Plugin Slug:
- nasa-core
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- High
- CVE:
- 2025-39508
Ovatheme Events Manager
- Plugin:
- Ovatheme Events Manager
- Plugin Slug:
- ova-events-manager
- Vulnerability:
- Arbitrary File Upload
- Patched in Version:
- No Fix
- Severity Score:
- Critical
- CVE:
- 2025-32510
Reformer for Elementor
- Plugin:
- Reformer for Elementor
- Plugin Slug:
- reformer-elementor
- Vulnerability:
- Arbitrary File Upload
- Patched in Version:
- No Fix
- Severity Score:
- Critical
- CVE:
- 2025-49444
Restrict File Access
- Plugin:
- Restrict File Access
- Plugin Slug:
- restrict-file-access
- Vulnerability:
- Arbitrary File Download
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2025-6070
School Management
- Plugin:
- School Management
- Plugin Slug:
- school-management
- Vulnerability:
- Local File Inclusion
- Patched in Version:
- No Fix
- Severity Score:
- High
- CVE:
- 2025-47572
School Management
- Plugin:
- School Management
- Plugin Slug:
- school-management
- Vulnerability:
- SQL Injection
- Patched in Version:
- No Fix
- Severity Score:
- Critical
- CVE:
- 2025-47573
Smart Notification
- Plugin:
- Smart Notification
- Plugin Slug:
- smio-push-notification
- Vulnerability:
- SQL Injection
- Patched in Version:
- No Fix
- Severity Score:
- Critical
- CVE:
- 2025-39479
Telegram for WP
- Plugin:
- Telegram for WP
- Plugin Slug:
- telegram-for-wp
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2025-5939
Userpro
- Plugin:
- Userpro
- Plugin Slug:
- userpro
- Vulnerability:
- Arbitrary File Download
- Patched in Version:
- No Fix
- Severity Score:
- High
- CVE:
- 2025-4187
Widget Logic
- Plugin:
- Widget Logic
- Plugin Slug:
- widget-logic
- Vulnerability:
- Remote Code Execution (RCE)
- Patched in Version:
- No Fix
- Severity Score:
- Critical
- CVE:
- 2025-32222
WidgetKit Pro
- Plugin:
- WidgetKit Pro
- Plugin Slug:
- widgetkit-pro
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- High
- CVE:
- 2025-46494
WP Employee Attendance System
- Plugin:
- WP Employee Attendance System
- Plugin Slug:
- wp-employee-attendance-system
- Vulnerability:
- SQL Injection
- Patched in Version:
- No Fix
- Severity Score:
- High
- CVE:
- 2025-28972
WP Sliding Login/Dashboard Panel
- Plugin:
- WP Sliding Login/Dashboard Panel
- Plugin Slug:
- wp-sliding-logindashboard-panel
- Vulnerability:
- Cross Site Request Forgery (CSRF)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2025-5928
WP URL Shortener
- Plugin:
- WP URL Shortener
- Plugin Slug:
- wp-url-shortener
- Vulnerability:
- Cross Site Request Forgery (CSRF)
- Patched in Version:
- No Fix
- Severity Score:
- High
- CVE:
- 2025-6064
WP2HTML
- Plugin:
- WP2HTML
- Plugin Slug:
- wp2html
- Vulnerability:
- Cross Site Request Forgery (CSRF)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2025-5930
WPCRM – CRM for Contact form CF7 & WooCommerce
- Plugin:
- WPCRM – CRM for Contact form CF7 & WooCommerce
- Plugin Slug:
- wpcrm
- Vulnerability:
- SQL Injection
- Patched in Version:
- No Fix
- Severity Score:
- Critical
- CVE:
- 2025-24773
XiSearch bar
- Plugin:
- XiSearch bar
- Plugin Slug:
- xisearch-bar
- Vulnerability:
- Cross Site Request Forgery (CSRF)
- Patched in Version:
- No Fix
- Severity Score:
- High
- CVE:
- 2025-6063
Yougler Blogger Profile Page
- Plugin:
- Yougler Blogger Profile Page
- Plugin Slug:
- yougler-blogger-profile-page
- Vulnerability:
- Cross Site Request Forgery (CSRF)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2025-6062
Zen Sticky Social
- Plugin:
- Zen Sticky Social
- Plugin Slug:
- zen-social-sticky
- Vulnerability:
- Cross Site Request Forgery (CSRF)
- Patched in Version:
- No Fix
- Severity Score:
- High
- CVE:
- 2025-6055
Zotpress
- Plugin:
- Zotpress
- Plugin Slug:
- zotpress
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2025-4666
Essential Addons for Elementor – Popular Elementor Templates and Widgets
- Plugin Slug:
- essential-addons-for-elementor-lite
- Installations
- 2,000,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 6.1.13
- Severity Score:
- Medium
- CVE:
- 2024-9994
Premium Addons for Elementor
- Plugin:
- Premium Addons for Elementor
- Plugin Slug:
- premium-addons-for-elementor
- Installations
- 700,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 4.11.9
- Severity Score:
- Medium
- CVE:
- 2025-4774
The Events Calendar
- Plugin:
- The Events Calendar
- Plugin Slug:
- the-events-calendar
- Installations
- 700,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 6.13.2.1
- Severity Score:
- Medium
- CVE:
- 2025-5144
Smash Balloon Social Post Feed – Simple Social Feeds for WordPress
- Plugin Slug:
- custom-facebook-feed
- Installations
- 200,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 4.3.2
- Severity Score:
- Medium
- CVE:
- 2025-4577
File Manager Pro – Filester
- Plugin:
- File Manager Pro – Filester
- Plugin Slug:
- filester
- Installations
- 100,000+
- Vulnerability:
- Arbitrary File Upload
- Patched in Version:
- 1.8.9
- Severity Score:
- Critical
- CVE:
- 2025-3234
Social Sharing Plugin – Sassy Social Share
- Plugin Slug:
- sassy-social-share
- Installations
- 100,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 3.3.76
- Severity Score:
- High
- CVE:
- 2025-5528
Slim SEO – Fast & Automated WordPress SEO Plugin
- Plugin Slug:
- slim-seo
- Installations
- 50,000+
- Vulnerability:
- SQL Injection
- Patched in Version:
- 4.5.5
- Severity Score:
- High
- CVE:
- 2025-49854
Meks Flexible Shortcodes
- Plugin:
- Meks Flexible Shortcodes
- Plugin Slug:
- meks-flexible-shortcodes
- Installations
- 20,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 1.3.8
- Severity Score:
- Medium
- CVE:
- 2025-49855
FunnelKit Automations – Email Marketing Automation and CRM for WordPress & WooCommerce
- Plugin Slug:
- wp-marketing-automations
- Installations
- 20,000+
- Vulnerability:
- Open Redirection
- Patched in Version:
- 3.6.1
- Severity Score:
- Medium
- CVE:
- 2025-49868
WP Travel Engine – Tour Booking Plugin – Tour Operator Software
- Plugin Slug:
- wp-travel-engine
- Installations
- 20,000+
- Vulnerability:
- Broken Access Control
- Patched in Version:
- 6.5.2
- Severity Score:
- Medium
- CVE:
- 2025-5282
myCred – Points Management System For Gamification, Ranks, Badges, and Loyalty Rewards Program.
- Plugin:
- myCred – Points Management System For Gamification, Ranks, Badges, and Loyalty Rewards Program.
- Plugin Slug:
- mycred
- Installations
- 10,000+
- Vulnerability:
- Broken Access Control
- Patched in Version:
- 2.9.4.3
- Severity Score:
- Medium
- CVE:
- 2025-49872
myCred – Points Management System For Gamification, Ranks, Badges, and Loyalty Rewards Program.
- Plugin:
- myCred – Points Management System For Gamification, Ranks, Badges, and Loyalty Rewards Program.
- Plugin Slug:
- mycred
- Installations
- 10,000+
- Vulnerability:
- Broken Access Control
- Patched in Version:
- 2.9.4.3
- Severity Score:
- Medium
- CVE:
- 2025-49857
Simple Newsletter Plugin – Noptin
- Plugin Slug:
- newsletter-optin-box
- Installations
- 10,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 4.0.0
- Severity Score:
- Medium
- CVE:
- 2025-49871
Responsive Plus – Starter Templates, Advanced Features and Customizer Settings for Responsive Theme.
- Plugin:
- Responsive Plus – Starter Templates, Advanced Features and Customizer Settings for Responsive Theme.
- Plugin Slug:
- responsive-add-ons
- Installations
- 10,000+
- Vulnerability:
- Cross Site Request Forgery (CSRF)
- Patched in Version:
- 3.2.3
- Severity Score:
- Medium
- CVE:
- 2025-49856
Malcure Malware Scanner — #1 Toolset for WordPress Malware Removal
- Plugin Slug:
- wp-malware-removal
- Installations
- 10,000+
- Vulnerability:
- Broken Access Control
- Patched in Version:
- 16.9
- Severity Score:
- Medium
WP VR – 360 Panorama and Free Virtual Tour Builder For WordPress
- Plugin Slug:
- wpvr
- Installations
- 10,000+
- Vulnerability:
- Arbitrary File Upload
- Patched in Version:
- 8.5.27
- Severity Score:
- Critical
- CVE:
- 2025-47452
AutomatorWP – Automator plugin for no-code automations, webhooks & custom integrations in WordPress
- Plugin:
- AutomatorWP – Automator plugin for no-code automations, webhooks & custom integrations in WordPress
- Plugin Slug:
- automatorwp
- Installations
- 9,000+
- Vulnerability:
- SQL Injection
- Patched in Version:
- 5.2.6
- Severity Score:
- High
- CVE:
- 2025-5487
Arconix FAQ
- Plugin:
- Arconix FAQ
- Plugin Slug:
- arconix-faq
- Installations
- 8,000+
- Vulnerability:
- Broken Access Control
- Patched in Version:
- 1.9.7
- Severity Score:
- Medium
- CVE:
- 2025-49874
If-So Dynamic Content Personalization
- Plugin Slug:
- if-so
- Installations
- 8,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 1.9.3.2
- Severity Score:
- Medium
- CVE:
- 2025-49875
Event Booking & Management Plugin for WooCommerce – WpEvently – WordPress Plugin
- Plugin Slug:
- mage-eventpress
- Installations
- 8,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 4.4.3
- Severity Score:
- Medium
- CVE:
- 2025-5568
WP Dummy Content Generator
- Plugin:
- WP Dummy Content Generator
- Plugin Slug:
- wp-dummy-content-generator
- Installations
- 8,000+
- Vulnerability:
- Arbitrary Content Deletion
- Patched in Version:
- 4.0.0
- Severity Score:
- Medium
- CVE:
- 2025-49234
WP Job Portal – A Complete Recruitment System for Company or Job Board website
- Plugin Slug:
- wp-job-portal
- Installations
- 8,000+
- Vulnerability:
- SQL Injection
- Patched in Version:
- 2.3.3
- Severity Score:
- Critical
- CVE:
- 2025-48274
Xagio SEO – AI Powered SEO
- Plugin:
- Xagio SEO – AI Powered SEO
- Plugin Slug:
- xagio-seo
- Installations
- 8,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 7.1.0.17
- Severity Score:
- High
- CVE:
- 2025-3302
ProfileGrid – User Profiles, Groups and Communities
- Plugin Slug:
- profilegrid-user-profiles-groups-and-communities
- Installations
- 7,000+
- Vulnerability:
- Server Side Request Forgery (SSRF)
- Patched in Version:
- 5.9.5.3
- Severity Score:
- Medium
- CVE:
- 2025-49877
Arconix Shortcodes
- Plugin:
- Arconix Shortcodes
- Plugin Slug:
- arconix-shortcodes
- Installations
- 5,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 2.1.18
- Severity Score:
- Medium
- CVE:
- 2025-49858
CubeWP – All-in-One Dynamic Content Framework
- Plugin Slug:
- cubewp-framework
- Installations
- 5,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 1.1.24
- Severity Score:
- Medium
- CVE:
- 2025-49882
CubeWP – All-in-One Dynamic Content Framework
- Plugin Slug:
- cubewp-framework
- Installations
- 5,000+
- Vulnerability:
- Privilege Escalation
- Patched in Version:
- 1.1.24
- Severity Score:
- High
- CVE:
- 2025-4315
WPAdverts – Classifieds Plugin
- Plugin:
- WPAdverts – Classifieds Plugin
- Plugin Slug:
- wpadverts
- Installations
- 5,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 2.2.5
- Severity Score:
- Medium
- CVE:
- 2025-49878
CubeWP Forms – All-in-One Form Builder
- Plugin Slug:
- cubewp-forms
- Installations
- 4,000+
- Vulnerability:
- Broken Access Control
- Patched in Version:
- 1.1.6
- Severity Score:
- Medium
- CVE:
- 2025-49880
Responsive Blocks – WordPress Gutenberg Blocks
- Plugin Slug:
- responsive-block-editor-addons
- Installations
- 4,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 2.0.6
- Severity Score:
- Medium
- CVE:
- 2025-49881
WP Zoho for Contact Form 7, WPForms, Elementor, Formidable and Ninja Forms – CRM, Bigin
- Plugin Slug:
- cf7-zoho
- Installations
- 3,000+
- Vulnerability:
- PHP Object Injection
- Patched in Version:
- 1.3.1
- Severity Score:
- Critical
- CVE:
- 2025-49330
Majestic Support – The Leading-Edge Help Desk & Customer Support Plugin
- Plugin Slug:
- majestic-support
- Installations
- 3,000+
- Vulnerability:
- Broken Access Control
- Patched in Version:
- 1.1.1
- Severity Score:
- Medium
- CVE:
- 2025-49860
WP-DownloadManager
- Plugin:
- WP-DownloadManager
- Plugin Slug:
- wp-downloadmanager
- Installations
- 3,000+
- Vulnerability:
- Arbitrary File Download
- Patched in Version:
- 1.68.11
- Severity Score:
- Medium
- CVE:
- 2025-4798
WP Views Counter
- Plugin:
- WP Views Counter
- Plugin Slug:
- wpecounter
- Installations
- 2,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 2.0.4
- Severity Score:
- Medium
- CVE:
- 2025-49859
YITH PayPal Express Checkout for WooCommerce
- Plugin Slug:
- yith-paypal-express-checkout-for-woocommerce
- Installations
- 2,000+
- Vulnerability:
- Cross Site Request Forgery (CSRF)
- Patched in Version:
- 1.49.1
- Severity Score:
- Medium
- CVE:
- 2025-48111
Advanced Sermons
- Plugin:
- Advanced Sermons
- Plugin Slug:
- advanced-sermons
- Installations
- 1,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 3.7
- Severity Score:
- Medium
- CVE:
- 2025-49863
Ebook Store
- Plugin:
- Ebook Store
- Plugin Slug:
- ebook-store
- Installations
- 1,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 5.8009
- Severity Score:
- Medium
- CVE:
- 2025-49862
Kama Click Counter
- Plugin:
- Kama Click Counter
- Plugin Slug:
- kama-clic-counter
- Installations
- 1,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 4.0.4
- Severity Score:
- Medium
- CVE:
- 2025-49861
Membership For WooCommerce
- Plugin:
- Membership For WooCommerce
- Plugin Slug:
- membership-for-woocommerce
- Installations
- 1,000+
- Vulnerability:
- Broken Access Control
- Patched in Version:
- 2.8.2
- Severity Score:
- High
- CVE:
- 2025-49265
AFS Analytics
- Plugin:
- AFS Analytics
- Plugin Slug:
- addfreestats
- Installations
- 700+
- Vulnerability:
- Broken Access Control
- Patched in Version:
- 4.22
- Severity Score:
- Medium
- CVE:
- 2025-49864
Broadstreet
- Plugin:
- Broadstreet
- Plugin Slug:
- broadstreet
- Installations
- 700+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 1.51.8
- Severity Score:
- High
- CVE:
- 2025-4652
Traffic Monitor
- Plugin:
- Traffic Monitor
- Plugin Slug:
- traffic-monitor
- Installations
- 700+
- Vulnerability:
- Broken Access Control
- Patched in Version:
- 3.2.3
- Severity Score:
- Medium
- CVE:
- 2025-5815
Ultimate Reviews
- Plugin:
- Ultimate Reviews
- Plugin Slug:
- ultimate-reviews
- Installations
- 700+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 3.2.15
- Severity Score:
- High
- CVE:
- 2025-49266
Advanced Settings 3
- Plugin:
- Advanced Settings 3
- Plugin Slug:
- advanced-settings
- Installations
- 200+
- Vulnerability:
- Cross Site Request Forgery (CSRF)
- Patched in Version:
- 3.0.2
- Severity Score:
- Medium
- CVE:
- 2025-49865
ACF Onyx Poll
- Plugin:
- ACF Onyx Poll
- Plugin Slug:
- acf-onyx-poll
- Installations
- 100+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 1.2.0
- Severity Score:
- Medium
- CVE:
- 2025-5841
Game Review Block
- Plugin:
- Game Review Block
- Plugin Slug:
- game-review-block
- Installations
- 100+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 4.8.2
- Severity Score:
- Medium
- CVE:
- 2025-5923
TicketBAI Facturas para WooCommerce
- Plugin Slug:
- wp-ticketbai
- Installations
- 90+
- Vulnerability:
- SQL Injection
- Patched in Version:
- 3.21
- Severity Score:
- Critical
- CVE:
- 2025-24767
WP2LEADS | WordPress und KlickTipp einfach verbinden – WooCommerce und KlickTipp einfach verbinden
- Plugin:
- WP2LEADS | WordPress und KlickTipp einfach verbinden – WooCommerce und KlickTipp einfach verbinden
- Plugin Slug:
- wp2leads
- Installations
- 70+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 3.5.1
- Severity Score:
- High
- CVE:
- 2025-49316
OAuth Single Sign On – SSO (OAuth Client)
- Plugin:
- OAuth Single Sign On – SSO (OAuth Client)
- Plugin Slug:
- miniorange-oauth-oidc-single-sign-on
- Vulnerability:
- Sensitive Data Exposure
- Patched in Version:
- 18.5.4
- Severity Score:
- Medium
- CVE:
- 2025-6003
NewsLetter
- Plugin:
- NewsLetter
- Plugin Slug:
- plugin-newsletter
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 8.8.5
- Severity Score:
- Medium
- CVE:
- 2025-3581
Abandoned Cart Pro for WooCommerce
- Plugin:
- Abandoned Cart Pro for WooCommerce
- Plugin Slug:
- woocommerce-abandon-cart-pro
- Vulnerability:
- Arbitrary File Upload
- Patched in Version:
- 9.17.0
- Severity Score:
- Critical
- CVE:
- 2025-4387
Workreap (theme’s plugin)
- Plugin:
- Workreap (theme’s plugin)
- Plugin Slug:
- workreap
- Vulnerability:
- Arbitrary File Upload
- Patched in Version:
- 3.3.3
- Severity Score:
- High
- CVE:
- 2025-5012
Workreap (theme’s plugin)
- Plugin:
- Workreap (theme’s plugin)
- Plugin Slug:
- workreap
- Vulnerability:
- Broken Authentication
- Patched in Version:
- 3.3.2
- Severity Score:
- Critical
- CVE:
- 2025-4973
Automatic
- Plugin:
- Automatic
- Plugin Slug:
- wp-automatic
- Vulnerability:
- Arbitrary File Upload
- Patched in Version:
- 3.116.0
- Severity Score:
- Critical
- CVE:
- 2025-5395
eForm – WordPress Form Builder
- Plugin:
- eForm – WordPress Form Builder
- Plugin Slug:
- wp-fsqm-pro
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 4.19.1
- Severity Score:
- High
- CVE:
- 2025-48333
WordPress Themes — 20 Patched / 17 Unpatched
BodyCenter – Gym, Fitness WooCommerce WordPress Theme
- Theme:
- BodyCenter – Gym, Fitness WooCommerce WordPress Theme
- Theme Slug:
- bodycenter
- Vulnerability:
- Local File Inclusion
- Patched in Version:
- No Fix
- Severity Score:
- High
- CVE:
- 2023-25999
CraftXtore
- Theme:
- CraftXtore
- Theme Slug:
- bw-craftxtore
- Vulnerability:
- Local File Inclusion
- Patched in Version:
- No Fix
- Severity Score:
- High
- CVE:
- 2025-24770
Fitrush
- Theme:
- Fitrush
- Theme Slug:
- bw-fitrush
- Vulnerability:
- Local File Inclusion
- Patched in Version:
- No Fix
- Severity Score:
- High
- CVE:
- 2023-26005
GiftXtore
- Theme:
- GiftXtore
- Theme Slug:
- bw-giftxtore
- Vulnerability:
- Local File Inclusion
- Patched in Version:
- No Fix
- Severity Score:
- High
- CVE:
- 2025-28888
Petito
- Theme:
- Petito
- Theme Slug:
- bw-petito
- Vulnerability:
- Local File Inclusion
- Patched in Version:
- No Fix
- Severity Score:
- High
- CVE:
- 2025-27362
Zagg
- Theme:
- Zagg
- Theme Slug:
- bw-zagg
- Vulnerability:
- Local File Inclusion
- Patched in Version:
- No Fix
- Severity Score:
- High
- CVE:
- 2025-4200
DSK
- Theme:
- DSK
- Theme Slug:
- dsk
- Vulnerability:
- Local File Inclusion
- Patched in Version:
- No Fix
- Severity Score:
- High
- CVE:
- 2025-24761
Themify Edmin
- Theme:
- Themify Edmin
- Theme Slug:
- edmin
- Vulnerability:
- PHP Object Injection
- Patched in Version:
- No Fix
- Severity Score:
- High
- CVE:
- 2025-31047
Inset
- Theme:
- Inset
- Theme Slug:
- inset
- Vulnerability:
- Local File Inclusion
- Patched in Version:
- No Fix
- Severity Score:
- High
- CVE:
- 2025-26592
Photography
- Theme:
- Photography
- Theme Slug:
- photography
- Vulnerability:
- PHP Object Injection
- Patched in Version:
- No Fix
- Severity Score:
- Critical
- CVE:
- 2025-47579
SNS Anton
- Theme:
- SNS Anton
- Theme Slug:
- snsanton
- Vulnerability:
- Local File Inclusion
- Patched in Version:
- No Fix
- Severity Score:
- High
- CVE:
- 2025-28992
Avaz
- Theme:
- Avaz
- Theme Slug:
- snsavaz
- Vulnerability:
- Local File Inclusion
- Patched in Version:
- No Fix
- Severity Score:
- High
- CVE:
- 2025-28944
Evon
- Theme:
- Evon
- Theme Slug:
- snsevon
- Vulnerability:
- Local File Inclusion
- Patched in Version:
- No Fix
- Severity Score:
- High
- CVE:
- 2025-28991
Nitan
- Theme:
- Nitan
- Theme Slug:
- snsnitan
- Vulnerability:
- Local File Inclusion
- Patched in Version:
- No Fix
- Severity Score:
- High
- CVE:
- 2025-24768
Simen
- Theme:
- Simen
- Theme Slug:
- snssimen
- Vulnerability:
- Local File Inclusion
- Patched in Version:
- No Fix
- Severity Score:
- High
- CVE:
- 2025-29002
Spare
- Theme:
- Spare
- Theme Slug:
- spare
- Vulnerability:
- PHP Object Injection
- Patched in Version:
- No Fix
- Severity Score:
- Critical
- CVE:
- 2025-31919
Valen – Sport, Fashion WooCommerce WordPress Theme
- Theme:
- Valen – Sport, Fashion WooCommerce WordPress Theme
- Theme Slug:
- valen
- Vulnerability:
- Local File Inclusion
- Patched in Version:
- No Fix
- Severity Score:
- High
- CVE:
- 2025-28945
Aora
- Theme:
- Aora
- Theme Slug:
- aora
- Vulnerability:
- Local File Inclusion
- Patched in Version:
- 1.3.10
- Severity Score:
- High
- CVE:
- 2025-49260
Besa
- Theme:
- Besa
- Theme Slug:
- besa
- Vulnerability:
- Local File Inclusion
- Patched in Version:
- 2.3.10
- Severity Score:
- High
- CVE:
- 2025-49252
CozyStay
- Theme:
- CozyStay
- Theme Slug:
- cozystay
- Vulnerability:
- Local File Inclusion
- Patched in Version:
- 1.7.1
- Severity Score:
- High
- CVE:
- 2025-49508
CozyStay
- Theme:
- CozyStay
- Theme Slug:
- cozystay
- Vulnerability:
- PHP Object Injection
- Patched in Version:
- 1.7.1
- Severity Score:
- Critical
- CVE:
- 2025-49507
Diza
- Theme:
- Diza
- Theme Slug:
- diza
- Vulnerability:
- Local File Inclusion
- Patched in Version:
- 1.3.9
- Severity Score:
- High
- CVE:
- 2025-49261
Fana
- Theme:
- Fana
- Theme Slug:
- fana
- Vulnerability:
- Local File Inclusion
- Patched in Version:
- 1.1.29
- Severity Score:
- High
- CVE:
- 2025-49251
Flozen
- Theme:
- Flozen
- Theme Slug:
- flozen-theme
- Vulnerability:
- Arbitrary File Upload
- Patched in Version:
- 1.5.1
- Severity Score:
- Critical
- CVE:
- 2025-49071
GrandPrix
- Theme:
- GrandPrix
- Theme Slug:
- grandprix
- Vulnerability:
- Local File Inclusion
- Patched in Version:
- 1.6.1
- Severity Score:
- High
- CVE:
- 2025-49296
Grill and Chow
- Theme:
- Grill and Chow
- Theme Slug:
- grillandchow
- Vulnerability:
- Local File Inclusion
- Patched in Version:
- 1.6.1
- Severity Score:
- High
- CVE:
- 2025-49297
Hara
- Theme:
- Hara
- Theme Slug:
- hara
- Vulnerability:
- Local File Inclusion
- Patched in Version:
- 1.2.11
- Severity Score:
- High
- CVE:
- 2025-49259
Lasa
- Theme:
- Lasa
- Theme Slug:
- lasa
- Vulnerability:
- Local File Inclusion
- Patched in Version:
- 1.1.1
- Severity Score:
- High
- CVE:
- 2025-49253
Maia
- Theme:
- Maia
- Theme Slug:
- maia
- Vulnerability:
- Local File Inclusion
- Patched in Version:
- 1.1.16
- Severity Score:
- High
- CVE:
- 2025-49258
MediClinic
- Theme:
- MediClinic
- Theme Slug:
- mediclinic
- Vulnerability:
- Local File Inclusion
- Patched in Version:
- 2.2
- Severity Score:
- High
- CVE:
- 2025-49295
Nika
- Theme:
- Nika
- Theme Slug:
- nika
- Vulnerability:
- Local File Inclusion
- Patched in Version:
- 1.2.9
- Severity Score:
- High
- CVE:
- 2025-49254
RealHomes
- Theme:
- RealHomes
- Theme Slug:
- realhomes
- Vulnerability:
- Privilege Escalation
- Patched in Version:
- 4.4.1
- Severity Score:
- High
- CVE:
- 2025-4601
Ruza
- Theme:
- Ruza
- Theme Slug:
- ruza
- Vulnerability:
- Local File Inclusion
- Patched in Version:
- 1.0.8
- Severity Score:
- High
- CVE:
- 2025-49255
Sapa
- Theme:
- Sapa
- Theme Slug:
- sapa
- Vulnerability:
- Local File Inclusion
- Patched in Version:
- 1.1.15
- Severity Score:
- High
- CVE:
- 2025-49256
TinySalt
- Theme:
- TinySalt
- Theme Slug:
- tinysalt
- Vulnerability:
- PHP Object Injection
- Patched in Version:
- 3.10.0
- Severity Score:
- Critical
- CVE:
- 2025-49455
TinySalt
- Theme:
- TinySalt
- Theme Slug:
- tinysalt
- Vulnerability:
- Local File Inclusion
- Patched in Version:
- 3.10.0
- Severity Score:
- High
- CVE:
- 2025-49454
Zota
- Theme:
- Zota
- Theme Slug:
- zota
- Vulnerability:
- Local File Inclusion
- Patched in Version:
- 1.3.9
- Severity Score:
- High
- CVE:
- 2025-49257
Solid Security is part of Solid Suite — The best foundation for WordPress websites.
Every WordPress site needs security, backups, and management tools. That’s Solid Suite — an integrated bundle of three plugins: Solid Security, Solid Backups, and Solid Central. You also get access to Solid Academy’s learning resources for WordPress professionals. Build your next WordPress website on a solid foundation with Solid Suite!
Sign up now — Get SolidWP updates and valuable content straight to your inbox
Sign up
Get started with confidence — risk free, guaranteed
