WordPress Vulnerability Report

WordPress Vulnerability Report — June 4, 2025

Since last week, 97 new vulnerabilities emerged in the WordPress ecosystem, including 81 plugins and 16 themes. 38 of the vulnerable plugins and themes remain unpatched, but Solid Security Pro users are protected by virtual patching from Patchstack.

Avatar photo
Sarah Ulmer

In this report, 97 vulnerabilities have been publicly disclosed. Security patches for 59 of these plugins and themes are available now, so run those updates as soon as possible. If you’re a Solid Security Pro user, the version management tool may have already warned you and updated these plugins, depending on your settings.

Additionally, there are 38 plugin and theme vulnerabilities, and no patch has been available yet. If you’re a Solid Security Pro user, those vulnerabilities are already protected by the Solid Security firewall. Virtual patches from Patchstack will be applied when a vulnerability is considered high or medium risk. If no patch is forthcoming from the vendor or the vulnerable software has been marked “closed” and dropped from the official WordPress repositories, you should deactivate it soon and look for alternative solutions.

Along with poor user account security, vulnerable plugins and themes are among the top reasons why WordPress websites get hacked. Unfortunately, cyberattacks are increasing in volume and sophistication. They’re also increasingly aimed at small to mid-sized businesses.

Our WordPress Vulnerability Report covers the latest emerging WordPress plugin, theme, and core vulnerabilities. Each vulnerability will have a severity rating of LowMediumHigh, or Critical. Responsible disclosure of vulnerabilities is essential to keeping the WordPress community safe. Please share this report to help spread the word and make WordPress — and the web — more secure.

WordPress Core

WordPress 6.8.1 was released on April 30, 2025. This maintenance release includes fixes for 15 bugs throughout Core and the Block Editor, addressing issues affecting multiple areas of WordPress, including the block editor, multisite, and REST API. For a full list, refer to the release candidate announcement.

No new core vulnerabilities were disclosed this week.

WordPress Plugins — 52 Patched / 29 Unpatched

Real Time Validation for Gravity Forms

Plugin Slug:
real-time-validation-for-gravity-forms
Installations
2,000+
Vulnerability:
Local File Inclusion
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Real Time Validation for Gravity Forms

Plugin Slug:
real-time-validation-for-gravity-forms
Installations
2,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Real Time Validation for Gravity Forms

Plugin Slug:
real-time-validation-for-gravity-forms
Installations
2,000+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.
Plugin Slug:
featured-image-plus
Installations
700+
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Spreadsheet Price Changer for WooCommerce and WP E-commerce – Light

Plugin Slug:
excel-like-price-change-for-woocommerce-and-wp-e-commerce-light
Installations
600+
Vulnerability:
Arbitrary File Download
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

History Log by click5

Plugin Slug:
history-log-by-click5
Installations
500+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Product Subtitle for WooCommerce

Plugin Slug:
product-subtitle-for-woocommerce
Installations
400+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Infility Global

Plugin Slug:
infility-global
Installations
90+
Vulnerability:
SQL Injection
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

SUMO Affiliates Pro

Plugin:
SUMO Affiliates Pro
Plugin Slug:
affs
Vulnerability:
Arbitrary File Upload
Patched in Version:
No Fix
Severity Score:
Critical
The vulnerability has not been patched. You should deactivate the plugin.
Plugin:
Apptha Slider Gallery
Plugin Slug:
apptha-slider-gallery
Vulnerability:
Arbitrary File Download
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Blog Designer PRO for WordPress

Plugin:
Blog Designer PRO for WordPress
Plugin Slug:
blog-designer-pro
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Browse As

Plugin:
Browse As
Plugin Slug:
browse-as
Vulnerability:
Broken Authentication
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

WPCHURCH

Plugin:
WPCHURCH
Plugin Slug:
church-management
Vulnerability:
Privilege Escalation
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

CSV Mass Importer

Plugin:
CSV Mass Importer
Plugin Slug:
csv-mass-importer
Vulnerability:
Arbitrary File Upload
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Daisycon prijsvergelijkers

Plugin:
Daisycon prijsvergelijkers
Plugin Slug:
daisycon
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

FastSpring

Plugin:
FastSpring
Plugin Slug:
fastspring
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Flynax Bridge

Plugin:
Flynax Bridge
Plugin Slug:
flynax-bridge
Vulnerability:
Privilege Escalation
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Gearside Developer Dashboard

Plugin:
Gearside Developer Dashboard
Plugin Slug:
gearside-developer-dashboard
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Likes and Dislikes

Plugin:
Likes and Dislikes
Plugin Slug:
inprosysmedia-likes-dislikes-post
Vulnerability:
SQL Injection
Patched in Version:
No Fix
Severity Score:
Critical
The vulnerability has not been patched. You should deactivate the plugin.

Offsprout Page Builder

Plugin:
Offsprout Page Builder
Plugin Slug:
offsprout-page-builder
Vulnerability:
Privilege Escalation
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

QuickCab

Plugin:
QuickCab
Plugin Slug:
quickcab
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

WBW Product Table PRO

Plugin:
WBW Product Table PRO
Plugin Slug:
woo-producttables-pro
Vulnerability:
SQL Injection
Patched in Version:
No Fix
Severity Score:
Critical
The vulnerability has not been patched. You should deactivate the plugin.

Woo Slider Pro

Plugin:
Woo Slider Pro
Plugin Slug:
woo-slider-pro-drag-drop-slider-builder-for-woocommerce
Vulnerability:
Arbitrary Content Deletion
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Woo Slider Pro

Plugin:
Woo Slider Pro
Plugin Slug:
woo-slider-pro-drag-drop-slider-builder-for-woocommerce
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

WooCommerce Orders & Customers Exporter

Plugin:
WooCommerce Orders & Customers Exporter
Plugin Slug:
woocommerce-orders-customers-exporter
Vulnerability:
Sensitive Data Exposure
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

WP-GeoMeta

Plugin:
WP-GeoMeta
Plugin Slug:
wp-geometa
Vulnerability:
Privilege Escalation
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

WP Guppy

Plugin:
WP Guppy
Plugin Slug:
wp-guppy
Vulnerability:
SQL Injection
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Smash Balloon Social Photo Feed – Easy Social Feeds Plugin

Plugin Slug:
instagram-feed
Installations
1,000,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
6.9.1
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 6.9.1.
Plugin Slug:
broken-link-checker
Installations
600,000+
Vulnerability:
Sensitive Data Exposure
Patched in Version:
2.4.5
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.4.5.

Ocean Extra

Plugin Slug:
ocean-extra
Installations
600,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.4.9
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.4.9.

Royal Elementor Addons and Templates

Plugin Slug:
royal-elementor-addons
Installations
600,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.7.1021
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.7.1021.
Plugin Slug:
real-cookie-banner
Installations
100,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
5.1.6
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 5.1.6.

Ninja Tables – Easy Data Table Builder

Plugin Slug:
ninja-tables
Installations
80,000+
Vulnerability:
PHP Object Injection
Patched in Version:
5.0.19
Severity Score:
Critical
The vulnerability has been patched, so you should update to version 5.0.19.

Exclusive Addons for Elementor

Plugin Slug:
exclusive-addons-for-elementor
Installations
60,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.7.9.2
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.7.9.2.

Bold Page Builder

Plugin Slug:
bold-page-builder
Installations
50,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
5.3.7
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 5.3.7.

PowerPress Podcasting plugin by Blubrry

Plugin Slug:
powerpress
Installations
30,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
11.9.18
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 11.9.18.

LA-Studio Element Kit for Elementor

Plugin Slug:
lastudio-element-kit
Installations
20,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.5.3
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.5.3.

LA-Studio Element Kit for Elementor

Plugin Slug:
lastudio-element-kit
Installations
20,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.5.3
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.5.3.

All-in-One Addons for Elementor – WidgetKit

Plugin Slug:
widgetkit-for-elementor
Installations
10,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.5.5
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.5.5.

Ultimate Gift Cards for WooCommerce

Plugin Slug:
woo-gift-cards-lite
Installations
7,000+
Vulnerability:
SQL Injection
Patched in Version:
3.1.5
Severity Score:
High
The vulnerability has been patched, so you should update to version 3.1.5.

Borderless – Elementor Addons and Templates

Plugin Slug:
borderless
Installations
6,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.7.2
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.7.2.

Simple Page Access Restriction

Plugin Slug:
simple-page-access-restriction
Installations
6,000+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
1.0.32
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.0.32.

EU/UK VAT Validation Manager for WooCommerce

Plugin Slug:
eu-vat-for-woocommerce
Installations
5,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
4.4.3
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 4.4.3.

Min Max Step Quantity Limits Manager for WooCommerce

Plugin Slug:
product-quantity-for-woocommerce
Installations
4,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
5.0.4
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 5.0.4.

WP Attachments

Plugin Slug:
wp-attachments
Installations
4,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
5.1
Severity Score:
High
The vulnerability has been patched, so you should update to version 5.1.
Plugin Slug:
wp-posts-carousel
Installations
4,000+
Vulnerability:
PHP Object Injection
Patched in Version:
1.3.13
Severity Score:
High
The vulnerability has been patched, so you should update to version 1.3.13.

WordPress Comments Import & Export

Plugin Slug:
comments-import-export-woocommerce
Installations
3,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.4.4
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.4.4.

Newsletters

Plugin Slug:
newsletters-lite
Installations
3,000+
Vulnerability:
Local File Inclusion
Patched in Version:
4.10
Severity Score:
High
The vulnerability has been patched, so you should update to version 4.10.

Volunteer Sign Up Sheets

Plugin Slug:
pta-volunteer-sign-up-sheets
Installations
2,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
5.5.5
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 5.5.5.

Quick Contact Form

Plugin Slug:
quick-contact-form
Installations
2,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
8.2.2
Severity Score:
High
The vulnerability has been patched, so you should update to version 8.2.2.

Dynamic Pricing and Discount Rules

Plugin Slug:
discount-and-dynamic-pricing
Installations
1,000+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
2.3.0
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.3.0.

The Ultimate WordPress Toolkit – WP Extended

Plugin Slug:
wpextended
Installations
1,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
3.0.16
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.0.16.

WordPress Contact Forms by Cimatti

Plugin Slug:
contact-forms
Installations
900+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
1.9.9
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.9.9.

Map Block Leaflet

Plugin Slug:
map-block-leaflet
Installations
700+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
3.2.2
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.2.2.

WP Plugin Info Card

Plugin Slug:
wp-plugin-info-card
Installations
700+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
5.4.0
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 5.4.0.

Verge3D Publishing and E-Commerce

Plugin Slug:
verge3d
Installations
600+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
4.9.4
Severity Score:
High
The vulnerability has been patched, so you should update to version 4.9.4.

Wishlist

Plugin:
Wishlist
Plugin Slug:
wishlist
Installations
500+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.0.44
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.0.44.

WP Pipes

Plugin:
WP Pipes
Plugin Slug:
wp-pipes
Installations
500+
Vulnerability:
Arbitrary File Deletion
Patched in Version:
1.4.3
Severity Score:
High
The vulnerability has been patched, so you should update to version 1.4.3.

NinjaTeam Chat for Telegram

Plugin Slug:
ninjateam-telegram
Installations
200+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.2
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.2.

Tournamatch

Plugin Slug:
tournamatch
Installations
200+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
4.6.2
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 4.6.2.

Minimal Share Buttons

Plugin Slug:
minimal-share-buttons
Installations
100+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.7.4
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.7.4.

OpenSheetMusicDisplay

Plugin Slug:
opensheetmusicdisplay
Installations
100+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.4.1
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.4.1.

Property – Real Estate Directory Listing

Plugin Slug:
property
Installations
20+
Vulnerability:
Privilege Escalation
Patched in Version:
1.0.7
Severity Score:
High
The vulnerability has been patched, so you should update to version 1.0.7.

MasterStudy LMS Pro

Plugin:
MasterStudy LMS Pro
Plugin Slug:
masterstudy-lms-learning-management-system-pro
Vulnerability:
Arbitrary File Upload
Patched in Version:
4.7.1
Severity Score:
Critical
The vulnerability has been patched, so you should update to version 4.7.1.
Plugin:
Real Cookie Banner Pro
Plugin Slug:
real-cookie-banner-pro
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
5.1.6
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 5.1.6.

wpForo Advanced Attachments

Plugin:
wpForo Advanced Attachments
Plugin Slug:
wpforo-advanced-attachments
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
3.2.0
Severity Score:
High
The vulnerability has been patched, so you should update to version 3.2.0.

WordPress Themes — 7 Patched / 9 Unpatched

Arlo

Theme:
Arlo
Theme Slug:
arlo
Vulnerability:
Local File Inclusion
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should switch themes.

FLAP – Business WordPress Theme

Theme:
FLAP – Business WordPress Theme
Theme Slug:
flap
Vulnerability:
PHP Object Injection
Patched in Version:
No Fix
Severity Score:
Critical
The vulnerability has not been patched. You should switch themes.

FlatNews

Theme:
FlatNews
Theme Slug:
flatnews
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should switch themes.

Krowd

Theme:
Krowd
Theme Slug:
krowd
Vulnerability:
Local File Inclusion
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should switch themes.

PIMP – Creative MultiPurpose

Theme:
PIMP – Creative MultiPurpose
Theme Slug:
pimp
Vulnerability:
Deserialization of untrusted data
Patched in Version:
No Fix
Severity Score:
Critical
The vulnerability has not been patched. You should switch themes.

PressGrid – Frontend Publish Reaction & Multimedia Theme

Theme:
PressGrid – Frontend Publish Reaction & Multimedia Theme
Theme Slug:
press-grid
Vulnerability:
Deserialization of untrusted data
Patched in Version:
No Fix
Severity Score:
Critical
The vulnerability has not been patched. You should switch themes.

Revo

Theme:
Revo
Theme Slug:
revo
Vulnerability:
Local File Inclusion
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should switch themes.

Soho Hotel

Theme:
Soho Hotel
Theme Slug:
soho-hotel
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should switch themes.

Spare

Theme:
Spare
Theme Slug:
spare
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should switch themes.

Courtney

Theme:
Courtney
Theme Slug:
courtney
Vulnerability:
Local File Inclusion
Patched in Version:
1.3.1
Severity Score:
High
The vulnerability has been patched, so you should update to version 1.3.1.

Lesya

Theme:
Lesya
Theme Slug:
lesya
Vulnerability:
Local File Inclusion
Patched in Version:
1.7.3
Severity Score:
High
The vulnerability has been patched, so you should update to version 1.7.3.

Lettery

Theme:
Lettery
Theme Slug:
lettery
Vulnerability:
Local File Inclusion
Patched in Version:
1.1.8
Severity Score:
High
The vulnerability has been patched, so you should update to version 1.1.8.

Minterio

Theme:
Minterio
Theme Slug:
minterio
Vulnerability:
Local File Inclusion
Patched in Version:
1.4.1
Severity Score:
High
The vulnerability has been patched, so you should update to version 1.4.1.

Mr. Murphy

Theme:
Mr. Murphy
Theme Slug:
mr-murphy
Vulnerability:
PHP Object Injection
Patched in Version:
1.2.12.1
Severity Score:
Critical
The vulnerability has been patched, so you should update to version 1.2.12.1.

Starbelly

Theme:
Starbelly
Theme Slug:
starbelly
Vulnerability:
Local File Inclusion
Patched in Version:
1.3.7
Severity Score:
High
The vulnerability has been patched, so you should update to version 1.3.7.

Sweet Dessert

Theme:
Sweet Dessert
Theme Slug:
sweet-dessert
Vulnerability:
PHP Object Injection
Patched in Version:
1.1.13
Severity Score:
Critical
The vulnerability has been patched, so you should update to version 1.1.13.

Solid Security is part of Solid Suite — The best foundation for WordPress websites.

Every WordPress site needs security, backups, and management tools. That’s Solid Suite — an integrated bundle of three plugins: Solid Security, Solid Backups, and Solid Central. You also get access to Solid Academy’s learning resources for WordPress professionals. Build your next WordPress website on a solid foundation with Solid Suite!

Get Solid Security