WordPress Vulnerability Report

WordPress Vulnerability Report — March 12, 2025

Last week, 143 new vulnerabilities emerged in the WordPress ecosystem, including 129 plugins and 14 themes. 57 of the vulnerable plugins and themes remain unpatched, but Solid Security Pro users are protected by virtual patching from Patchstack.

Avatar photo
Sarah Ulmer

In this report, 143 vulnerabilities have been publicly disclosed. Security patches for 86 of these plugins and themes are available now, so run those updates as soon as possible. If you’re a Solid Security Pro user, the version management tool may have already warned you and updated these plugins, depending on your settings.

Additionally, there are 57 plugin and theme vulnerabilities with no patch available yet. If you’re a Solid Security Pro user, those vulnerabilities are already protected by the Solid Security firewall. Virtual patches from Patchstack will be applied when a vulnerability is considered high or medium risk. If no patch is forthcoming from the vendor or the vulnerable software has been marked “closed” and dropped from the official WordPress repositories, you should deactivate it soon and look for alternative solutions.

Along with poor user account security, vulnerable plugins and themes are among the top reasons why WordPress websites get hacked. Unfortunately, cyberattacks are increasing in volume and sophistication. They’re also increasingly aimed at small to mid-sized businesses.

Our WordPress Vulnerability Report covers the latest emerging WordPress plugin, theme, and core vulnerabilities. Each vulnerability will have a severity rating of LowMediumHigh, or Critical. Responsible disclosure of vulnerabilities is essential to keeping the WordPress community safe. Please share this report to help spread the word and make WordPress — and the web — more secure.

WordPress Core

WordPress 6.8 Beta 2 is ready for testing! This beta version of the WordPress software is under development. Please do not install, run, or test this version of WordPress on production or mission-critical websites. Instead, you should evaluate Beta 2 on a test server and site.

No new core vulnerabilities were disclosed this week.

WordPress Plugins — 78 Patched / 51 Unpatched

SEO Plugin by Squirrly SEO

Plugin Slug:
squirrly-seo
Installations
100,000+
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Master Slider – Responsive Touch Slider

Plugin Slug:
master-slider
Installations
80,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

All-in-One Addons for Elementor – WidgetKit

Plugin Slug:
widgetkit-for-elementor
Installations
10,000+
Vulnerability:
Sensitive Data Exposure
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Wishlist for WooCommerce: Multi Wishlists Per Customer

Plugin Slug:
wish-list-for-woocommerce
Installations
3,000+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

SearchIQ – The Search Solution

Plugin Slug:
searchiq
Installations
1,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Point Maker

Plugin Slug:
point-maker
Installations
100+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Recently Purchased Products For Woo

Plugin Slug:
recently-purchased-products-for-woo
Installations
60+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Allow PHP Execute

Plugin:
Allow PHP Execute
Plugin Slug:
allow-php-execute
Vulnerability:
Content Injection
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Code Snippets CPT

Plugin:
Code Snippets CPT
Plugin Slug:
code-snippets-cpt
Vulnerability:
Content Injection
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Contact Us By Lord Linus

Plugin:
Contact Us By Lord Linus
Plugin Slug:
contact-us-by-lord-linus
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

CS Framework

Plugin:
CS Framework
Plugin Slug:
cs-framework
Vulnerability:
Arbitrary File Download
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

DesignThemes Core Features

Plugin:
DesignThemes Core Features
Plugin Slug:
designthemes-core-features
Vulnerability:
Arbitrary File Download
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Download HTML TinyMCE Button

Plugin:
Download HTML TinyMCE Button
Plugin Slug:
download-html-tinymce-button
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

URL Shortener | Conversion Tracking | AB Testing | WooCommerce

Plugin:
URL Shortener | Conversion Tracking | AB Testing | WooCommerce
Plugin Slug:
easy-broken-link-checker
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

URL Shortener | Conversion Tracking | AB Testing | WooCommerce

Plugin:
URL Shortener | Conversion Tracking | AB Testing | WooCommerce
Plugin Slug:
easy-broken-link-checker
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

WooMail

Plugin:
WooMail
Plugin Slug:
email-customizer-for-woocommerce-with-drag-drop-builder
Vulnerability:
SQL Injection
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Email Keep

Plugin:
Email Keep
Plugin Slug:
email-keep
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Email Keep

Plugin:
Email Keep
Plugin Slug:
email-keep
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Ultimate Video Player

Plugin:
Ultimate Video Player
Plugin Slug:
fwduvp
Vulnerability:
Arbitrary File Download
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

I Am Gloria

Plugin:
I Am Gloria
Plugin Slug:
gloria-assistant-by-webtronic-labs
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Hero Maps Premium

Plugin:
Hero Maps Premium
Plugin Slug:
hmapsprem
Vulnerability:
SQL Injection
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Hero Mega Menu – Responsive WordPress Menu Plugin

Plugin:
Hero Mega Menu – Responsive WordPress Menu Plugin
Plugin Slug:
hmenu
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Hero Slider

Plugin:
Hero Slider
Plugin Slug:
hslide
Vulnerability:
SQL Injection
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

InWave Jobs

Plugin:
InWave Jobs
Plugin Slug:
iwjob
Vulnerability:
Privilege Escalation
Patched in Version:
No Fix
Severity Score:
Critical
The vulnerability has not been patched. You should deactivate the plugin.

Limit Bio

Plugin:
Limit Bio
Plugin Slug:
limit-bio
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Limit Bio

Plugin:
Limit Bio
Plugin Slug:
limit-bio
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.
Plugin:
Link My Posts
Plugin Slug:
linkmyposts
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

mEintopf

Plugin:
mEintopf
Plugin Slug:
meintopf
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

miniOrange Social Login and Register Pro Addon

Plugin:
miniOrange Social Login and Register Pro Addon
Plugin Slug:
miniorange-login-openid-pro
Vulnerability:
Broken Authentication
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

My Quota

Plugin:
My Quota
Plugin Slug:
my-quota
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Ninja Pages

Plugin:
Ninja Pages
Plugin Slug:
ninja-page-categories-and-tags
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

WP Online Contract

Plugin:
WP Online Contract
Plugin Slug:
onlinecontract
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Passbeemedia Web Push Notification

Plugin:
Passbeemedia Web Push Notification
Plugin Slug:
passbeemedia-web-push-notifications
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Post Lockdown

Plugin:
Post Lockdown
Plugin Slug:
post-lockdown
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Post Meta Data Manager

Plugin:
Post Meta Data Manager
Plugin Slug:
post-meta-data-manager
Vulnerability:
Privilege Escalation
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

WooCommerce Recover Abandoned Cart

Plugin:
WooCommerce Recover Abandoned Cart
Plugin Slug:
rac
Vulnerability:
PHP Object Injection
Patched in Version:
No Fix
Severity Score:
Critical
The vulnerability has not been patched. You should deactivate the plugin.

Razorpay Subscription Button Elementor Plugin

Plugin:
Razorpay Subscription Button Elementor Plugin
Plugin Slug:
razorpay-subscription-button-elementor
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

School Management

Plugin:
School Management
Plugin Slug:
school-management
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

School Management

Plugin:
School Management
Plugin Slug:
school-management
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

School Management

Plugin:
School Management
Plugin Slug:
school-management
Vulnerability:
Privilege Escalation
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Shortcode Cleaner Lite

Plugin:
Shortcode Cleaner Lite
Plugin Slug:
shortcode-cleaner-lite
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Simple Notification

Plugin:
Simple Notification
Plugin Slug:
simple-notification
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

SpotBot

Plugin:
SpotBot
Plugin Slug:
spotbot
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

WoWPth

Plugin:
WoWPth
Plugin Slug:
wowpth
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

WordPress Awesome Import & Export Plugin – Import & Export WordPress Data

Plugin:
WordPress Awesome Import & Export Plugin – Import & Export WordPress Data
Plugin Slug:
wp-awesome-import-export
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

WP Click Info

Plugin:
WP Click Info
Plugin Slug:
wp-click-info
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

WP e-Customers Beta

Plugin:
WP e-Customers Beta
Plugin Slug:
wp-e-customers
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

WP-PManager

Plugin:
WP-PManager
Plugin Slug:
wp-programmmanager
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

WP Real Estate Manager

Plugin:
WP Real Estate Manager
Plugin Slug:
wp-realestate-manager
Vulnerability:
Privilege Escalation
Patched in Version:
No Fix
Severity Score:
Critical
The vulnerability has not been patched. You should deactivate the plugin.

Years Since

Plugin:
Years Since
Plugin Slug:
years-since
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

PixelYourSite – Your smart PIXEL (TAG) & API Manager

Plugin Slug:
pixelyoursite
Installations
500,000+
Vulnerability:
PHP Object Injection
Patched in Version:
10.1.1.2
Severity Score:
Critical
The vulnerability has been patched, so you should update to version 10.1.1.2.

WP Shortcodes Plugin — Shortcodes Ultimate

Plugin Slug:
shortcodes-ultimate
Installations
500,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
7.3.4
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 7.3.4.

Post SMTP – WP SMTP Plugin with Email Logs and Mobile App for Failure Notifications – Gmail SMTP, Office 365, Brevo, Mailgun, Amazon SES and more

Plugin Slug:
post-smtp
Installations
400,000+
Vulnerability:
SQL Injection
Patched in Version:
3.1.3
Severity Score:
High
The vulnerability has been patched, so you should update to version 3.1.3.

Page Builder: Pagelayer – Drag and Drop website builder

Plugin Slug:
pagelayer
Installations
200,000+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
1.9.9
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.9.9.

WP Activity Log

Plugin Slug:
wp-security-audit-log
Installations
200,000+
Vulnerability:
PHP Object Injection
Patched in Version:
5.3.3
Severity Score:
High
The vulnerability has been patched, so you should update to version 5.3.3.

Admin and Site Enhancements (ASE)

Plugin Slug:
admin-site-enhancements
Installations
100,000+
Vulnerability:
Bypass Vulnerability
Patched in Version:
7.6.10
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 7.6.10.

bbPress

Plugin:
bbPress
Plugin Slug:
bbpress
Installations
100,000+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
2.6.12
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.6.12.

Download Manager

Plugin Slug:
download-manager
Installations
100,000+
Vulnerability:
Sensitive Data Exposure
Patched in Version:
3.3.07
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.3.07.

GiveWP – Donation Plugin and Fundraising Platform

Plugin Slug:
give
Installations
100,000+
Vulnerability:
PHP Object Injection
Patched in Version:
3.20.0
Severity Score:
Critical
The vulnerability has been patched, so you should update to version 3.20.0.

SEO Plugin by Squirrly SEO

Plugin Slug:
squirrly-seo
Installations
100,000+
Vulnerability:
SQL Injection
Patched in Version:
12.4.06
Severity Score:
High
The vulnerability has been patched, so you should update to version 12.4.06.

VK Blocks

Plugin:
VK Blocks
Plugin Slug:
vk-blocks
Installations
100,000+
Vulnerability:
Broken Access Control
Patched in Version:
1.95.0.3
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.95.0.3.

HUSKY – Products Filter Professional for WooCommerce

Plugin Slug:
woocommerce-products-filter
Installations
100,000+
Vulnerability:
Local File Inclusion
Patched in Version:
1.3.6.6
Severity Score:
High
The vulnerability has been patched, so you should update to version 1.3.6.6.

HT Mega – Absolute Addons For Elementor

Plugin Slug:
ht-mega-for-elementor
Installations
90,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.8.3
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.8.3.

Print Invoice & Delivery Notes for WooCommerce

Plugin Slug:
woocommerce-delivery-notes
Installations
30,000+
Vulnerability:
Sensitive Data Exposure
Patched in Version:
5.5.0
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 5.5.0.

RomethemeKit For Elementor

Plugin Slug:
rometheme-for-elementor
Installations
20,000+
Vulnerability:
Broken Access Control
Patched in Version:
1.5.4
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.5.4.

140+ Widgets | Xpro Addons For Elementor – FREE

Plugin Slug:
xpro-elementor-addons
Installations
20,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.4.6.8
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.4.6.8.

Qubely – Advanced Gutenberg Blocks

Plugin Slug:
qubely
Installations
10,000+
Vulnerability:
Sensitive Data Exposure
Patched in Version:
1.8.14
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.8.14.

SupportCandy – Helpdesk & Customer Support Ticket System

Plugin Slug:
supportcandy
Installations
10,000+
Vulnerability:
Insecure Direct Object References (IDOR)
Patched in Version:
3.3.1
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.3.1.

WPGet API – Connect to any external REST API

Plugin Slug:
wpgetapi
Installations
10,000+
Vulnerability:
Server Side Request Forgery (SSRF)
Patched in Version:
2.25.1
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.25.1.

Notibar – Notification Bar for WordPress

Plugin Slug:
notibar
Installations
7,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.1.6
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.1.6.

EventPrime – Events Calendar, Bookings and Tickets

Plugin Slug:
eventprime-event-calendar-management
Installations
5,000+
Vulnerability:
Broken Access Control
Patched in Version:
4.0.7.4
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 4.0.7.4.

Podlove Podcast Publisher

Plugin Slug:
podlove-podcasting-plugin-for-wordpress
Installations
5,000+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
4.2.3
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 4.2.3.

Product Input Fields for WooCommerce

Plugin Slug:
product-input-fields-for-woocommerce
Installations
5,000+
Vulnerability:
Arbitrary File Upload
Patched in Version:
1.12.2
Severity Score:
High
The vulnerability has been patched, so you should update to version 1.12.2.

VikRentCar Car Rental Management System

Plugin Slug:
vikrentcar
Installations
4,000+
Vulnerability:
Arbitrary File Upload
Patched in Version:
1.4.3
Severity Score:
High
The vulnerability has been patched, so you should update to version 1.4.3.
Plugin Slug:
wp-posts-carousel
Installations
4,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.3.8
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.3.8.

Moving Media Library

Plugin Slug:
moving-media-library
Installations
3,000+
Vulnerability:
Directory Traversal
Patched in Version:
1.23
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.23.

Wallet System for WooCommerce

Plugin Slug:
wallet-system-for-woocommerce
Installations
3,000+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
2.6.3
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.6.3.

Wallet System for WooCommerce

Plugin Slug:
wallet-system-for-woocommerce
Installations
3,000+
Vulnerability:
Broken Access Control
Patched in Version:
2.6.3
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.6.3.

SMTP by BestWebSoft

Plugin Slug:
bws-smtp
Installations
2,000+
Vulnerability:
Arbitrary File Upload
Patched in Version:
1.2.0
Severity Score:
High
The vulnerability has been patched, so you should update to version 1.2.0.

Eventer

Plugin:
Eventer
Plugin Slug:
eventer
Installations
2,000+
Vulnerability:
SQL Injection
Patched in Version:
3.9.9.3
Severity Score:
High
The vulnerability has been patched, so you should update to version 3.9.9.3.

teachPress

Plugin:
teachPress
Plugin Slug:
teachpress
Installations
2,000+
Vulnerability:
SQL Injection
Patched in Version:
9.0.8
Severity Score:
High
The vulnerability has been patched, so you should update to version 9.0.8.

WP-Recall – Registration, Profile, Commerce & More

Plugin Slug:
wp-recall
Installations
2,000+
Vulnerability:
Broken Access Control
Patched in Version:
16.26.12
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 16.26.12.

WP-Recall – Registration, Profile, Commerce & More

Plugin Slug:
wp-recall
Installations
2,000+
Vulnerability:
SQL Injection
Patched in Version:
16.26.12
Severity Score:
Critical
The vulnerability has been patched, so you should update to version 16.26.12.

WP-Recall – Registration, Profile, Commerce & More

Plugin Slug:
wp-recall
Installations
2,000+
Vulnerability:
Broken Access Control
Patched in Version:
16.26.12
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 16.26.12.

WP-Recall – Registration, Profile, Commerce & More

Plugin Slug:
wp-recall
Installations
2,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
16.26.12
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 16.26.12.

WPCOM Member

Plugin Slug:
wpcom-member
Installations
2,000+
Vulnerability:
Privilege Escalation
Patched in Version:
1.7.6
Severity Score:
Critical
The vulnerability has been patched, so you should update to version 1.7.6.
Plugin Slug:
wpgsi
Installations
2,000+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
3.8.3
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.8.3.

WPCS – WordPress Currency Switcher Professional

Plugin Slug:
currency-switcher
Installations
1,000+
Vulnerability:
Content Injection
Patched in Version:
1.2.0.5
Severity Score:
High
The vulnerability has been patched, so you should update to version 1.2.0.5.

Flexmls® IDX Plugin

Plugin Slug:
flexmls-idx
Installations
1,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
3.14.29
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.14.29.
Plugin Slug:
greek-multi-tool
Installations
1,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.3.2
Severity Score:
High
The vulnerability has been patched, so you should update to version 2.3.2.

Simple Download Counter

Plugin Slug:
simple-download-counter
Installations
1,000+
Vulnerability:
Arbitrary File Download
Patched in Version:
2.1
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.1.

Solace Extra

Plugin Slug:
solace-extra
Installations
1,000+
Vulnerability:
Arbitrary File Upload
Patched in Version:
1.3.1
Severity Score:
High
The vulnerability has been patched, so you should update to version 1.3.1.

Ultimate WordPress Auction Plugin

Plugin Slug:
ultimate-auction
Installations
1,000+
Vulnerability:
Arbitrary Content Deletion
Patched in Version:
4.3.0
Severity Score:
High
The vulnerability has been patched, so you should update to version 4.3.0.

m1.DownloadList

Plugin Slug:
m1downloadlist
Installations
500+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
0.20
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 0.20.
Plugin Slug:
gallery-styles
Installations
300+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.3.5
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.3.5.

Reservit Hotel

Plugin Slug:
reservit-hotel
Installations
300+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
3.0
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.0.

Multiple Shipping And Billing Address For Woocommerce

Plugin Slug:
different-shipping-and-billing-address-for-woocommerce
Installations
200+
Vulnerability:
SQL Injection
Patched in Version:
1.5
Severity Score:
Critical
The vulnerability has been patched, so you should update to version 1.5.

WPBookit

Plugin:
WPBookit
Plugin Slug:
wpbookit
Installations
70+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
1.0.2
Severity Score:
High
The vulnerability has been patched, so you should update to version 1.0.2.

Appsero Helper

Plugin Slug:
appsero-helper
Installations
50+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
1.3.3
Severity Score:
High
The vulnerability has been patched, so you should update to version 1.3.3.

Platform.ly for WooCommerce

Plugin Slug:
platformly-for-woocommerce
Installations
10+
Vulnerability:
Server Side Request Forgery (SSRF)
Patched in Version:
1.1.7
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.1.7.

Aiomatic

Plugin:
Aiomatic
Plugin Slug:
aiomatic-automatic-ai-content-writer
Vulnerability:
Arbitrary File Upload
Patched in Version:
2.3.9
Severity Score:
High
The vulnerability has been patched, so you should update to version 2.3.9.

Aiomatic

Plugin:
Aiomatic
Plugin Slug:
aiomatic-automatic-ai-content-writer
Vulnerability:
Broken Access Control
Patched in Version:
2.3.7
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.3.7.

Animation Addons for Elementor Pro

Plugin:
Animation Addons for Elementor Pro
Plugin Slug:
animation-addons-for-elementor-pro
Vulnerability:
Broken Access Control
Patched in Version:
1.7
Severity Score:
High
The vulnerability has been patched, so you should update to version 1.7.

CS Framework

Plugin:
CS Framework
Plugin Slug:
cs-framework
Vulnerability:
Arbitrary File Deletion
Patched in Version:
7.1
Severity Score:
High
The vulnerability has been patched, so you should update to version 7.1.

Edd Google Sheet Connector Pro

Plugin:
Edd Google Sheet Connector Pro
Plugin Slug:
edd-google-sheet-connector-pro
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
1.4
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.4.

Easy Digital Downloads Google Sheet Connector

Plugin Slug:
gsheetconnector-easy-digital-downloads
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
1.6.6
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.6.6.

Gtbabel

Plugin:
Gtbabel
Plugin Slug:
gtbabel
Vulnerability:
Privilege Escalation
Patched in Version:
6.6.9
Severity Score:
High
The vulnerability has been patched, so you should update to version 6.6.9.

Javo Core

Plugin:
Javo Core
Plugin Slug:
javo-core
Vulnerability:
Privilege Escalation
Patched in Version:
3.0.0.266
Severity Score:
Critical
The vulnerability has been patched, so you should update to version 3.0.0.266.

School Management

Plugin:
School Management
Plugin Slug:
school-management
Vulnerability:
SQL Injection
Patched in Version:
93.0.0
Severity Score:
High
The vulnerability has been patched, so you should update to version 93.0.0.

School Management

Plugin:
School Management
Plugin Slug:
school-management
Vulnerability:
SQL Injection
Patched in Version:
93.0.0
Severity Score:
High
The vulnerability has been patched, so you should update to version 93.0.0.

Social Share And Social Locker

Plugin:
Social Share And Social Locker
Plugin Slug:
social-share-and-social-locker-arsocial
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.4.2
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.4.2.

WooCommerce Multi Currency – Currency Switcher

Plugin:
WooCommerce Multi Currency – Currency Switcher
Plugin Slug:
woocommerce-multi-currency
Vulnerability:
SQL Injection
Patched in Version:
2.3.7
Severity Score:
Critical
The vulnerability has been patched, so you should update to version 2.3.7.

WordPress Themes — 8 Patched / 6 Unpatched

Sparkling

Theme Slug:
sparkling
Downloads
1,345,012
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should switch themes.

Homey

Theme:
Homey
Theme Slug:
homey
Vulnerability:
Privilege Escalation
Patched in Version:
No Fix
Severity Score:
Critical
The vulnerability has not been patched. You should switch themes.

Lafka

Theme:
Lafka
Theme Slug:
lafka
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should switch themes.

Listingo

Theme:
Listingo
Theme Slug:
listingo
Vulnerability:
Content Injection
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should switch themes.

VEDA

Theme:
VEDA
Theme Slug:
veda
Vulnerability:
PHP Object Injection
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should switch themes.

Zass

Theme:
Zass
Theme Slug:
zass
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should switch themes.

Newscrunch

Theme Slug:
newscrunch
Downloads
177,662
Vulnerability:
Arbitrary File Upload
Patched in Version:
1.8.4.1
Severity Score:
Critical
The vulnerability has been patched, so you should update to version 1.8.4.1.

Newscrunch

Theme Slug:
newscrunch
Downloads
177,662
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
1.8.4.1
Severity Score:
High
The vulnerability has been patched, so you should update to version 1.8.4.1.

VW Storefront

Theme Slug:
vw-storefront
Downloads
60,192
Vulnerability:
Broken Access Control
Patched in Version:
1.0.0
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.0.0.

Flex Mag

Theme:
Flex Mag
Theme Slug:
flex-mag
Vulnerability:
Broken Access Control
Patched in Version:
3.6.0
Severity Score:
High
The vulnerability has been patched, so you should update to version 3.6.0.

Golo

Theme:
Golo
Theme Slug:
golo
Vulnerability:
Broken Access Control
Patched in Version:
1.6.11
Severity Score:
Critical
The vulnerability has been patched, so you should update to version 1.6.11.

Homey

Theme:
Homey
Theme Slug:
homey
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
2.4.4
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.4.4.

Homey

Theme:
Homey
Theme Slug:
homey
Vulnerability:
Broken Authentication
Patched in Version:
2.4.4
Severity Score:
High
The vulnerability has been patched, so you should update to version 2.4.4.

JNews

Theme:
JNews
Theme Slug:
jnews
Vulnerability:
Broken Access Control
Patched in Version:
11.6.7
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 11.6.7.

Solid Security is part of Solid Suite — The best foundation for WordPress websites.

Every WordPress site needs security, backups, and management tools. That’s Solid Suite — an integrated bundle of three plugins: Solid Security, Solid Backups, and Solid Central. You also get access to Solid Academy’s learning resources for WordPress professionals. Build your next WordPress website on a solid foundation with Solid Suite!

Get Solid Security