WordPress Vulnerability Report

WordPress Vulnerability Report — June 25, 2025

Since last week, 177 new vulnerabilities emerged in the WordPress ecosystem, including 161 plugins and 16 themes. 118 of the vulnerable plugins and themes remain unpatched, but Solid Security Pro users are protected by virtual patching from Patchstack.

Avatar photo
Sarah Ulmer

In this report, 177 vulnerabilities have been publicly disclosed. Security patches for 59 of these plugins and themes are available now, so run those updates as soon as possible. If you’re a Solid Security Pro user, the version management tool may have already warned you and updated these plugins, depending on your settings.

Additionally, there are 118 plugin and theme vulnerabilities, and no patch has been available yet. If you’re a Solid Security Pro user, those vulnerabilities are already protected by the Solid Security firewall. Virtual patches from Patchstack will be applied when a vulnerability is considered high or medium risk. If no patch is forthcoming from the vendor or the vulnerable software has been marked “closed” and dropped from the official WordPress repositories, you should deactivate it soon and look for alternative solutions.

Along with poor user account security, vulnerable plugins and themes are among the top reasons why WordPress websites get hacked. Unfortunately, cyberattacks are increasing in volume and sophistication. They’re also increasingly aimed at small to mid-sized businesses.

Our WordPress Vulnerability Report covers the latest emerging WordPress plugin, theme, and core vulnerabilities. Each vulnerability will have a severity rating of LowMediumHigh, or Critical. Responsible disclosure of vulnerabilities is essential to keeping the WordPress community safe. Please share this report to help spread the word and make WordPress — and the web — more secure.

WordPress Core

WordPress 6.8.1 was released on April 30, 2025. This maintenance release includes fixes for 15 bugs throughout Core and the Block Editor, addressing issues affecting multiple areas of WordPress, including the block editor, multisite, and REST API. For a full list, refer to the release candidate announcement.

No new core vulnerabilities were disclosed this week.

WordPress Plugins — 56 Patched / 105 Unpatched

Zapier for WordPress

Plugin Slug:
zapier
Installations
50,000+
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Auto Upload Images

Plugin Slug:
auto-upload-images
Installations
30,000+
Vulnerability:
Server Side Request Forgery (SSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

PowerPress Podcasting plugin by Blubrry

Plugin Slug:
powerpress
Installations
30,000+
Vulnerability:
Server Side Request Forgery (SSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

WP Visitor Statistics (Real Time Traffic)

Plugin Slug:
wp-stats-manager
Installations
30,000+
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

WP Customer Area

Plugin Slug:
customer-area
Installations
10,000+
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Job Postings

Plugin Slug:
job-postings
Installations
10,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

User Roles and Capabilities

Plugin Slug:
user-roles-and-capabilities
Installations
10,000+
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

WP User Profile Avatar

Plugin Slug:
wp-user-profile-avatar
Installations
10,000+
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.
Plugin Slug:
cookie-script-com
Installations
9,000+
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Download Attachments

Plugin Slug:
download-attachments
Installations
9,000+
Vulnerability:
Insecure Direct Object References (IDOR)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Media Hygiene: Remove or Delete Unused Images and More!

Plugin Slug:
media-hygiene
Installations
4,000+
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Automatically Hierarchic Categories in Menu

Plugin Slug:
automatically-hierarchic-categories-in-menu
Installations
3,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

ContentStudio

Plugin Slug:
contentstudio
Installations
1,000+
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

WP Inventory Manager

Plugin Slug:
wp-inventory-manager
Installations
1,000+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

WPThumb

Plugin:
WPThumb
Plugin Slug:
wp-thumb
Installations
1,000+
Vulnerability:
Server Side Request Forgery (SSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Football Pool

Plugin Slug:
football-pool
Installations
900+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

ATP Call Now

Plugin Slug:
atp-call-now
Installations
800+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Better Random Redirect

Plugin Slug:
better-random-redirect
Installations
800+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

CodePen Embed Block

Plugin Slug:
codepen-embed-block
Installations
800+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

RDFa Breadcrumb

Plugin Slug:
rdfa-breadcrumb
Installations
800+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.
Plugin Slug:
simple-sticky-footer
Installations
800+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Spoki – Chat Buttons and WooCommerce Notifications

Plugin Slug:
spoki
Installations
800+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Tealium

Plugin:
Tealium
Plugin Slug:
tealium
Installations
800+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

WP Social AutoConnect

Plugin Slug:
wp-fb-autoconnect
Installations
800+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Polls CP

Plugin:
Polls CP
Plugin Slug:
cp-polls
Installations
700+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Code Engine

Plugin Slug:
code-engine
Installations
600+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

FormLift for Infusionsoft Web Forms

Plugin Slug:
formlift
Installations
600+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Trusty Whistleblowing Solution

Plugin Slug:
trusty-whistleblowing-solution
Installations
600+
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

UpStream: a Project Management Plugin for WordPress

Plugin Slug:
upstream
Installations
600+
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Gutenberg Blocks – ACF Blocks Suite

Plugin Slug:
acf-blocks
Installations
500+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Anant Addons for Elementor

Plugin Slug:
anant-addons-for-elementor
Installations
500+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Hand Talk

Plugin:
Hand Talk
Plugin Slug:
handtalk
Installations
500+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.
Plugin Slug:
pdpa-consent
Installations
500+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

WP Register Profile With Shortcode

Plugin Slug:
wp-register-profile-with-shortcode
Installations
500+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

WP Voting Contest Lite

Plugin Slug:
wp-voting-contest
Installations
500+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Contact Form 7 AWeber Extension

Plugin Slug:
integrate-contact-form-7-and-aweber
Installations
400+
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

IP Based Login

Plugin Slug:
ip-based-login
Installations
400+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Buying Buddy IDX CRM – Real Estate MLS Plugin

Plugin Slug:
buying-buddy-idx-crm
Installations
300+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

TM Replace Howdy

Plugin Slug:
tm-replace-howdy
Installations
300+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

WooCommerce Fortnox Integration

Plugin Slug:
woocommerce-fortnox-integration
Installations
300+
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

WP Roadmap – Product Feedback Board

Plugin Slug:
wp-roadmap
Installations
300+
Vulnerability:
SQL Injection
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Abandoned Contact Form 7

Plugin Slug:
abandoned-contact-form-7
Installations
200+
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Lewe ChordPress – ChordPro Text Formatter

Plugin Slug:
chordpress
Installations
200+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

CSV Importer Improved

Plugin Slug:
csv-importer-improved
Installations
200+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

eDS Responsive Menu

Plugin Slug:
eds-responsive-menu
Installations
200+
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.
Plugin Slug:
esselinknu-settings
Installations
200+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Fyrebox Quizzes

Plugin Slug:
fyrebox-shortcode
Installations
200+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Knowledge Base – Knowledge Base Maker

Plugin Slug:
knowledge-base-maker
Installations
200+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Creative Contact Form

Plugin Slug:
sexy-contact-form
Installations
200+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

WP-DownloadCounter

Plugin Slug:
wp-downloadcounter
Installations
200+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Mailing Group Listserv

Plugin Slug:
wp-mailing-group
Installations
200+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Bluff Post

Plugin:
Bluff Post
Plugin Slug:
bluff-post
Installations
100+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Enhanced Blocks – Page Builder Blocks for Gutenberg

Plugin Slug:
enhanced-blocks
Installations
100+
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Import YouTube videos as WP Posts

Plugin Slug:
import-youtube-videos-as-wp-post
Installations
100+
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Inventory Presser – Car Dealer Listings

Plugin Slug:
inventory-presser
Installations
100+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

National Weather Service Alerts

Plugin Slug:
national-weather-service-alerts
Installations
100+
Vulnerability:
Local File Inclusion
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Logo Manager For Samandehi

Plugin Slug:
samandehi-logo-manager
Installations
100+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Scroll UP

Plugin:
Scroll UP
Plugin Slug:
scroll-to-up
Installations
100+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

TinyNav

Plugin:
TinyNav
Plugin Slug:
tinynav
Installations
100+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Video List Manager

Plugin Slug:
video-list-manager
Installations
100+
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Video List Manager

Plugin Slug:
video-list-manager
Installations
100+
Vulnerability:
SQL Injection
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Change Cart button Colors WooCommerce

Plugin Slug:
wc-style
Installations
100+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

WP User Stylesheet Switcher

Plugin Slug:
wp-user-stylesheet-switcher
Installations
100+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

xili-dictionary

Plugin Slug:
xili-dictionary
Installations
100+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Zara 4 Image Compression

Plugin Slug:
zara-4
Installations
100+
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Infility Global

Plugin Slug:
infility-global
Installations
90+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

MDJM Event Management

Plugin Slug:
mobile-dj-manager
Installations
90+
Vulnerability:
Privilege Escalation
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Photo Express for Google

Plugin Slug:
photo-express-for-google
Installations
80+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

XML Travel Portal Widget

Plugin Slug:
oganro-reservation-widget
Installations
70+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

SpecFit-Virtual Try On Woocommerce

Plugin Slug:
try-on-for-woocommerce
Installations
60+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

DirectIQ Email Marketing

Plugin Slug:
directiq-wp
Installations
40+
Vulnerability:
SQL Injection
Patched in Version:
No Fix
Severity Score:
Critical
The vulnerability has not been patched. You should deactivate the plugin.

Live Sports Streamthunder

Plugin Slug:
live-sports-streamthunder
Installations
40+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Oganro Travel Portal Search Widget for HotelBeds APITUDE API

Plugin Slug:
oganro-travel-portal-search-widget-for-hotelbeds-apitude-api
Installations
10+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

PixelBeds Channel Manager and Hotel Booking Engine

Plugin Slug:
pixelbeds-channel-manager-booking-engine
Installations
10+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Backwp

Plugin:
Backwp
Plugin Slug:
backwp
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Bulk YouTube Post Creator

Plugin:
Bulk YouTube Post Creator
Plugin Slug:
bulk-youtube-post-creator
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.
Plugin:
ClipLink
Plugin Slug:
cliplink
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

CSV Me

Plugin:
CSV Me
Plugin Slug:
csv-me
Vulnerability:
Arbitrary File Upload
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Evangelische Termine

Plugin:
Evangelische Termine
Plugin Slug:
evangtermine
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

FastBook

Plugin:
FastBook
Plugin Slug:
fastbook-responsive-appointment-booking-and-scheduling-system
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Flexo Counter

Plugin:
Flexo Counter
Plugin Slug:
flexo-countdown
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Image Shadow

Plugin:
Image Shadow
Plugin Slug:
image-shadow
Vulnerability:
Arbitrary File Deletion
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

BRW

Plugin:
BRW
Plugin Slug:
ova-brw
Vulnerability:
Local File Inclusion
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Pixabay Images

Plugin:
Pixabay Images
Plugin Slug:
pixabay-images
Vulnerability:
Arbitrary File Upload
Patched in Version:
No Fix
Severity Score:
Critical
The vulnerability has not been patched. You should deactivate the plugin.
Plugin:
Simple Link Directory
Plugin Slug:
qc-simple-link-directory
Vulnerability:
SQL Injection
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

School Management

Plugin:
School Management
Plugin Slug:
school-management
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Smart Notification

Plugin:
Smart Notification
Plugin Slug:
smio-push-notification
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Virtual Moderator

Plugin:
Virtual Moderator
Plugin Slug:
virtual-moderator
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Woocommerce Line Notify

Plugin:
Woocommerce Line Notify
Plugin Slug:
woo-line-notify
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

JobSearch

Plugin:
JobSearch
Plugin Slug:
wp-jobsearch
Vulnerability:
Insecure Direct Object References (IDOR)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

WP Optimize By xTraffic

Plugin:
WP Optimize By xTraffic
Plugin Slug:
wp-optimize-by-xtraffic
Vulnerability:
PHP Object Injection
Patched in Version:
No Fix
Severity Score:
Critical
The vulnerability has not been patched. You should deactivate the plugin.

WP-Recall

Plugin:
WP-Recall
Plugin Slug:
wp-recall
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

WPCRM – CRM for Contact form CF7 & WooCommerce

Plugin:
WPCRM – CRM for Contact form CF7 & WooCommerce
Plugin Slug:
wpcrm
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Recipes manager – WPH

Plugin Slug:
wph-recipes-manager
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

WPKit For Elementor

Plugin:
WPKit For Elementor
Plugin Slug:
wpkit-elementor
Vulnerability:
Privilege Escalation
Patched in Version:
No Fix
Severity Score:
Critical
The vulnerability has not been patched. You should deactivate the plugin.

ElementsKit Elementor Addons and Templates

Plugin Slug:
elementskit-lite
Installations
1,000,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
3.5.3
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.5.3.

Click to Chat – HoliThemes

Plugin Slug:
click-to-chat-for-whatsapp
Installations
600,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
4.23
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 4.23.

YITH WooCommerce Wishlist

Plugin Slug:
yith-woocommerce-wishlist
Installations
600,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
4.6.0
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 4.6.0.

Breeze – WordPress Cache Plugin

Plugin Slug:
breeze
Installations
400,000+
Vulnerability:
Broken Access Control
Patched in Version:
2.2.14
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.2.14.

Firelight Lightbox

Plugin Slug:
easy-fancybox
Installations
200,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.3.17
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.3.17.

Ivory Search – WordPress Search Plugin

Plugin Slug:
add-search-to-menu
Installations
100,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
5.5.10
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 5.5.10.

AI Engine

Plugin:
AI Engine
Plugin Slug:
ai-engine
Installations
100,000+
Vulnerability:
Broken Access Control
Patched in Version:
2.8.4
Severity Score:
High
The vulnerability has been patched, so you should update to version 2.8.4.

Download Manager

Plugin Slug:
download-manager
Installations
100,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
3.3.19
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.3.19.

File Manager Pro – Filester

Plugin Slug:
filester
Installations
100,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.8.9
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.8.9.

GiveWP – Donation Plugin and Fundraising Platform

Plugin Slug:
give
Installations
100,000+
Vulnerability:
Broken Access Control
Patched in Version:
4.3.1
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 4.3.1.

HUSKY – Products Filter Professional for WooCommerce

Plugin Slug:
woocommerce-products-filter
Installations
100,000+
Vulnerability:
Local File Inclusion
Patched in Version:
1.3.7.1
Severity Score:
High
The vulnerability has been patched, so you should update to version 1.3.7.1.

Master Slider – Responsive Touch Slider

Plugin Slug:
master-slider
Installations
70,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
3.10.9
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.10.9.

Drag and Drop Multiple File Upload for Contact Form 7

Plugin Slug:
drag-and-drop-multiple-file-upload-contact-form-7
Installations
60,000+
Vulnerability:
Arbitrary File Upload
Patched in Version:
1.3.9.0
Severity Score:
High
The vulnerability has been patched, so you should update to version 1.3.9.0.

Ultra Addons for Contact Form 7

Plugin Slug:
ultimate-addons-for-contact-form-7
Installations
60,000+
Vulnerability:
Arbitrary File Upload
Patched in Version:
3.5.13
Severity Score:
High
The vulnerability has been patched, so you should update to version 3.5.13.

WP-Members Membership Plugin

Plugin Slug:
wp-members
Installations
60,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
3.5.4.1
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.5.4.1.

Blog2Social: Social Media Auto Post & Scheduler

Plugin Slug:
blog2social
Installations
50,000+
Vulnerability:
SQL Injection
Patched in Version:
8.4.5
Severity Score:
High
The vulnerability has been patched, so you should update to version 8.4.5.

WordPress Infinite Scroll – Ajax Load More

Plugin Slug:
ajax-load-more
Installations
40,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
7.4.1
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 7.4.1.

tarteaucitron.io

Plugin Slug:
tarteaucitronjs
Installations
10,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.9.5
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.9.5.

eCommerce Product Catalog Plugin for WordPress

Plugin Slug:
ecommerce-product-catalog
Installations
9,000+
Vulnerability:
PHP Object Injection
Patched in Version:
3.4.4
Severity Score:
High
The vulnerability has been patched, so you should update to version 3.4.4.

Poll, Survey & Quiz Maker Plugin by Opinion Stage

Plugin Slug:
social-polls-by-opinionstage
Installations
8,000+
Vulnerability:
Broken Access Control
Patched in Version:
19.10.0
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 19.10.0.

WP Dummy Content Generator

Plugin Slug:
wp-dummy-content-generator
Installations
8,000+
Vulnerability:
Arbitrary Content Deletion
Patched in Version:
4.0.0
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 4.0.0.

ProfileGrid – User Profiles, Groups and Communities

Plugin Slug:
profilegrid-user-profiles-groups-and-communities
Installations
7,000+
Vulnerability:
Full Path Disclosure (FPD)
Patched in Version:
= 5.9.5.3
Severity Score:
Medium
The vulnerability has been patched, so you should update to version = 5.9.5.3.

Wise Chat

Plugin:
Wise Chat
Plugin Slug:
wise-chat
Installations
7,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
3.3.5
Severity Score:
High
The vulnerability has been patched, so you should update to version 3.3.5.

Modern Footnotes

Plugin Slug:
modern-footnotes
Installations
6,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.4.20
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.4.20.

Sitekit

Plugin:
Sitekit
Plugin Slug:
sitekit
Installations
2,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.0
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.0.

YITH PayPal Express Checkout for WooCommerce

Plugin Slug:
yith-paypal-express-checkout-for-woocommerce
Installations
2,000+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
1.49.1
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.49.1.

Off-Canvas Sidebars & Menus (Slidebars)

Plugin Slug:
off-canvas-sidebars
Installations
1,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
0.5.8.5
Severity Score:
High
The vulnerability has been patched, so you should update to version 0.5.8.5.
Plugin Slug:
related-products-manager-woocommerce
Installations
1,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.6.3
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.6.3.

WPComplete

Plugin:
WPComplete
Plugin Slug:
wpcomplete
Installations
1,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.9.5.1
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.9.5.1.

Conference Scheduler

Plugin Slug:
conference-scheduler
Installations
300+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.5.2
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.5.2.

Euro FxRef Currency Converter

Plugin Slug:
euro-fxref-currency-converter
Installations
200+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.0.3
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.0.3.
Plugin Slug:
simple-logo-carousel
Installations
100+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.9.4
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.9.4.

StreamWeasels Kick Integration

Plugin Slug:
streamweasels-kick-integration
Installations
100+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.1.4
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.1.4.

Target Video Easy Publish

Plugin Slug:
brid-video-easy-publish
Installations
70+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
3.8.6
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.8.6.

ANON::form embedded secure form

Plugin Slug:
anonform-embedded-secure-form
Installations
10+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.8
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.8.

Aiomatic

Plugin:
Aiomatic
Plugin Slug:
aiomatic-automatic-ai-content-writer
Vulnerability:
Arbitrary File Upload
Patched in Version:
2.5.1
Severity Score:
High
The vulnerability has been patched, so you should update to version 2.5.1.

Drag and Drop Multiple File Upload (Pro) – WooCommerce

Plugin:
Drag and Drop Multiple File Upload (Pro) – WooCommerce
Plugin Slug:
drag-and-drop-file-upload-wc-pro
Vulnerability:
Arbitrary File Upload
Patched in Version:
5.0.7
Severity Score:
Critical
The vulnerability has been patched, so you should update to version 5.0.7.

Elementor Pro

Plugin:
Elementor Pro
Plugin Slug:
elementor-pro
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
3.29.1
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.29.1.

WPBakery Page Builder

Plugin:
WPBakery Page Builder
Plugin Slug:
js_composer
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
8.5
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 8.5.

Echo RSS Feed Post Generator Plugin for WordPress

Plugin:
Echo RSS Feed Post Generator Plugin for WordPress
Plugin Slug:
rss-feed-post-generator-echo
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
5.4.9
Severity Score:
High
The vulnerability has been patched, so you should update to version 5.4.9.

Rankie

Plugin:
Rankie
Plugin Slug:
valvepress-rankie
Vulnerability:
SQL Injection
Patched in Version:
1.8.2
Severity Score:
High
The vulnerability has been patched, so you should update to version 1.8.2.

WordPress Themes — 3 Patched / 13 Unpatched

Fitness Park

Theme Slug:
fitness-park
Downloads
20,395
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should switch themes.

Hello FSE Blog

Theme Slug:
hello-fse-blog
Downloads
11,256
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should switch themes.

Spark Multipurpose

Theme Slug:
spark-multipurpose
Downloads
5,635
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should switch themes.

Zita

Theme:
Zita
Theme Slug:
zita
Downloads
405,453
Vulnerability:
Local File Inclusion
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should switch themes.

Zenny

Theme:
Zenny
Theme Slug:
bw-zenny
Vulnerability:
Local File Inclusion
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should switch themes.

HYDRO

Theme:
HYDRO
Theme Slug:
hydro
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should switch themes.

LMS

Theme:
LMS
Theme Slug:
lms
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should switch themes.

MagOne

Theme:
MagOne
Theme Slug:
magone
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should switch themes.

MBStore – Digital WooCommerce WordPress Theme

Theme:
MBStore – Digital WooCommerce WordPress Theme
Theme Slug:
mbstore
Vulnerability:
Local File Inclusion
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should switch themes.

Nuss

Theme:
Nuss
Theme Slug:
nuss
Vulnerability:
PHP Object Injection
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should switch themes.

Sala

Theme:
Sala
Theme Slug:
sala
Vulnerability:
PHP Object Injection
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should switch themes.

Seven Stars

Theme:
Seven Stars
Theme Slug:
sevenstars
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should switch themes.

Sofass

Theme:
Sofass
Theme Slug:
sofass
Vulnerability:
Local File Inclusion
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should switch themes.

OceanWP

Theme:
OceanWP
Theme Slug:
oceanwp
Downloads
8,544,159
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
4.1.0
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 4.1.0.

Amely

Theme:
Amely
Theme Slug:
amely
Vulnerability:
SQL Injection
Patched in Version:
3.2.0
Severity Score:
Critical
The vulnerability has been patched, so you should update to version 3.2.0.

Puca

Theme:
Puca
Theme Slug:
puca
Vulnerability:
Local File Inclusion
Patched in Version:
2.6.34
Severity Score:
High
The vulnerability has been patched, so you should update to version 2.6.34.

Solid Security is part of Solid Suite — The best foundation for WordPress websites.

Every WordPress site needs security, backups, and management tools. That’s Solid Suite — an integrated bundle of three plugins: Solid Security, Solid Backups, and Solid Central. You also get access to Solid Academy’s learning resources for WordPress professionals. Build your next WordPress website on a solid foundation with Solid Suite!

Get Solid Security