WordPress Vulnerability Report

WordPress Vulnerability Report — March 18, 2026

Since last week, 159 new vulnerabilities have emerged in the WordPress ecosystem, including 6 in Core, 130 plugins, and 23 themes. Of those, 46 remain unpatched, but Solid Security Pro users are protected by virtual patching from Patchstack.

Avatar photo
Sarah Ulmer

In this report, 159 vulnerabilities have been publicly disclosed. Security patches for 113 of these Core, plugins, and themes are now available. Please run these updates as soon as possible. If you’re a Solid Security Pro user, the version management tool may have already warned you and updated these plugins, depending on your settings.

Currently, 46 plugin and theme vulnerabilities remain unpatched. If you’re a Solid Security Pro user, those vulnerabilities are already protected by the Solid Security firewall. Virtual patches from Patchstack will be applied when a vulnerability is considered high or medium risk. If no patch is forthcoming from the vendor or the vulnerable software has been marked “closed” and dropped from the official WordPress repositories, you should deactivate it soon and look for alternative solutions.

Along with poor user account security, vulnerable plugins and themes are among the top reasons why WordPress websites get hacked. Unfortunately, cyberattacks are increasing in volume and sophistication. They’re also increasingly aimed at small to mid-sized businesses.

Our WordPress Vulnerability Report covers the latest emerging WordPress plugin, theme, and core vulnerabilities. Each vulnerability will have a severity rating of LowMediumHigh, or Critical. Responsible disclosure of vulnerabilities is essential to keeping the WordPress community safe. Please share this report to help spread the word and make WordPress — and the web — more secure.

WordPress Core

WordPress 6.9.4 is now available, addressing 10 security issues and a bug that affected template file loading on a limited number of sites. Because this is a security release, it is recommended that you update your sites immediately.

Also, WordPress 7.0 Beta 5 is ready for download and testing! As this is a pre-release version, it is intended for testing and development only and should not be installed on production or mission-critical sites. Organizations should use local or staging environments to evaluate compatibility and new features before the final rollout.

WordPress 7.0 is scheduled for release on April 9, 2026.

WordPress Core

Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
6.9.2
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 6.9.2.

WordPress Core

Vulnerability:
Server Side Request Forgery (SSRF)
Patched in Version:
6.9.2
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 6.9.2.

WordPress Core

Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
6.9.2
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 6.9.2.

WordPress Core

Vulnerability:
XML External Entity (XXE)
Patched in Version:
6.9.4
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 6.9.4.

WordPress Core

Vulnerability:
Broken Access Control
Patched in Version:
6.9.4
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 6.9.4.

WordPress Core

Vulnerability:
Broken Access Control
Patched in Version:
6.9.2
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 6.9.2.

WordPress Plugins — 100 Patched / 30 Unpatched

Addi – Cuotas que se adaptan a ti

Plugin Slug:
buy-now-pay-later-addi
Installations
2,000+
Vulnerability:
Broken Authentication
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

TotalPoll for Polls and Contests

Plugin Slug:
totalpoll-lite
Installations
1,000+
Vulnerability:
Remote Code Execution (RCE)
Patched in Version:
No Fix
Severity Score:
Critical
The vulnerability has not been patched. You should deactivate the plugin.

ViaBill – WooCommerce

Plugin Slug:
viabill-woocommerce
Installations
500+
Vulnerability:
Settings Change
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Photo Contest | Competition | Video Contest

Plugin Slug:
totalcontest-lite
Installations
300+
Vulnerability:
PHP Object Injection
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Mobile App Editor – WordPress to Android App Builder

Plugin Slug:
mobile-app-editor
Installations
40+
Vulnerability:
Arbitrary File Upload
Patched in Version:
No Fix
Severity Score:
Critical
The vulnerability has not been patched. You should deactivate the plugin.

Admin Safety Guard — Login Security & 2FA

Plugin Slug:
admin-safety-guard
Installations
10+
Vulnerability:
Broken Authentication
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

ACPT (Pro) – Custom Post Types Plugin for WordPress

Plugin:
ACPT (Pro) – Custom Post Types Plugin for WordPress
Plugin Slug:
advanced-custom-post-type
Vulnerability:
Remote Code Execution (RCE)
Patched in Version:
No Fix
Severity Score:
Critical
The vulnerability has not been patched. You should deactivate the plugin.

BuilderPress

Plugin:
BuilderPress
Plugin Slug:
builderpress
Vulnerability:
Local File Inclusion
Patched in Version:
No Fix
Severity Score:
Critical
The vulnerability has not been patched. You should deactivate the plugin.

Curly Core

Plugin:
Curly Core
Plugin Slug:
curly-core
Vulnerability:
Local File Inclusion
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Darna Framework

Plugin:
Darna Framework
Plugin Slug:
darna-framework
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

DukaPress

Plugin:
DukaPress
Plugin Slug:
dukapress
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Everest Forms Pro

Plugin:
Everest Forms Pro
Plugin Slug:
everest-forms-pro
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Handmade Framework

Plugin:
Handmade Framework
Plugin Slug:
handmade-framework
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Jobica Core

Plugin:
Jobica Core
Plugin Slug:
jobica-core
Vulnerability:
Broken Authentication
Patched in Version:
No Fix
Severity Score:
Critical
The vulnerability has not been patched. You should deactivate the plugin.

Legacy Admin

Plugin:
Legacy Admin
Plugin Slug:
legacy-admin
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

MetForm Pro

Plugin:
MetForm Pro
Plugin Slug:
metform-pro
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Critical
The vulnerability has not been patched. You should deactivate the plugin.

Modern Events Calendar

Plugin:
Modern Events Calendar
Plugin Slug:
modern-events-calendar
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Penci Soledad Data Migrator

Plugin:
Penci Soledad Data Migrator
Plugin Slug:
penci-data-migrator
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

WooCommerce Infinite Scroll

Plugin:
WooCommerce Infinite Scroll
Plugin Slug:
sb-woocommerce-infinite-scroll
Vulnerability:
PHP Object Injection
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

The Aisle Core

Plugin:
The Aisle Core
Plugin Slug:
theaisle-core
Vulnerability:
Local File Inclusion
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

UiPress lite

Plugin:
UiPress lite
Plugin Slug:
uipress-lite
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Ultra WordPress Admin

Plugin:
Ultra WordPress Admin
Plugin Slug:
ultra-admin
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Unlimited Elements for Elementor (Premium)

Plugin:
Unlimited Elements for Elementor (Premium)
Plugin Slug:
unlimited-elements-for-elementor-premium
Vulnerability:
Arbitrary File Upload
Patched in Version:
No Fix
Severity Score:
Critical
The vulnerability has not been patched. You should deactivate the plugin.

Wolverine Framework

Plugin:
Wolverine Framework
Plugin Slug:
wolverine-framework
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

WZone

Plugin:
WZone
Plugin Slug:
woozone
Vulnerability:
SQL Injection
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

WZone

Plugin:
WZone
Plugin Slug:
woozone
Vulnerability:
Arbitrary File Deletion
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

WP App Bar

Plugin:
WP App Bar
Plugin Slug:
wp-app-bar
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

WooCommerce

Plugin Slug:
woocommerce
Installations
7,000,000+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
10.5.3
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 10.5.3.

MC4WP: Mailchimp for WordPress

Plugin Slug:
mailchimp-for-wp
Installations
1,000,000+
Vulnerability:
Broken Access Control
Patched in Version:
4.12.0
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 4.12.0.

The Events Calendar

Plugin Slug:
the-events-calendar
Installations
700,000+
Vulnerability:
Arbitrary File Download
Patched in Version:
6.15.17.1
Severity Score:
High
The vulnerability has been patched, so you should update to version 6.15.17.1.

Meta Box

Plugin:
Meta Box
Plugin Slug:
meta-box
Installations
500,000+
Vulnerability:
Arbitrary File Deletion
Patched in Version:
5.11.2
Severity Score:
High
The vulnerability has been patched, so you should update to version 5.11.2.

PixelYourSite – Your smart PIXEL (TAG) & API Manager

Plugin Slug:
pixelyoursite
Installations
500,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
11.2.0.1
Severity Score:
High
The vulnerability has been patched, so you should update to version 11.2.0.1.

Ally – Web Accessibility & Usability

Plugin Slug:
pojo-accessibility
Installations
500,000+
Vulnerability:
SQL Injection
Patched in Version:
4.1.0
Severity Score:
Critical
The vulnerability has been patched, so you should update to version 4.1.0.

Checkout Field Editor (Checkout Manager) for WooCommerce

Plugin Slug:
woo-checkout-field-editor-pro
Installations
500,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.1.8
Severity Score:
High
The vulnerability has been patched, so you should update to version 2.1.8.

Admin Menu Editor

Plugin Slug:
admin-menu-editor
Installations
400,000+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
1.15
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.15.

Happy Addons for Elementor

Plugin Slug:
happy-elementor-addons
Installations
400,000+
Vulnerability:
Insecure Direct Object References (IDOR)
Patched in Version:
3.21.1
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.21.1.

Happy Addons for Elementor

Plugin Slug:
happy-elementor-addons
Installations
400,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
3.21.1
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.21.1.

Unlimited Elements For Elementor

Plugin Slug:
unlimited-elements-for-elementor
Installations
300,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.0.6
Severity Score:
High
The vulnerability has been patched, so you should update to version 2.0.6.

Tutor LMS – eLearning and online course solution

Plugin Slug:
tutor
Installations
100,000+
Vulnerability:
Insecure Direct Object References (IDOR)
Patched in Version:
3.9.5
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.9.5.

Ultra Addons for Contact Form 7

Plugin Slug:
ultimate-addons-for-contact-form-7
Installations
60,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
3.5.37
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.5.37.

Advanced Product Fields (Product Addons) for WooCommerce

Plugin Slug:
advanced-product-fields-for-woocommerce
Installations
50,000+
Vulnerability:
Broken Access Control
Patched in Version:
1.6.19
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.6.19.

RTMKit

Plugin:
RTMKit
Plugin Slug:
rometheme-for-elementor
Installations
50,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.0.0
Severity Score:
High
The vulnerability has been patched, so you should update to version 2.0.0.

Calculated Fields Form

Plugin Slug:
calculated-fields-form
Installations
40,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
5.4.5.1
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 5.4.5.1.

Modular DS: Monitor, update, and backup multiple websites

Plugin Slug:
modular-connector
Installations
40,000+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
2.6.0
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.6.0.

NextScripts: Social Networks Auto-Poster

Plugin Slug:
social-networks-auto-poster-facebook-twitter-g
Installations
30,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
4.4.7
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 4.4.7.

Website LLMs.txt

Plugin Slug:
website-llms-txt
Installations
30,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
8.2.7
Severity Score:
High
The vulnerability has been patched, so you should update to version 8.2.7.

Job Postings

Plugin Slug:
job-postings
Installations
10,000+
Vulnerability:
Broken Access Control
Patched in Version:
2.8.1
Severity Score:
High
The vulnerability has been patched, so you should update to version 2.8.1.

Lead Form Builder & Contact Form

Plugin Slug:
lead-form-builder
Installations
10,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.0.2
Severity Score:
High
The vulnerability has been patched, so you should update to version 2.0.2.

Subscriptions for WooCommerce

Plugin Slug:
subscriptions-for-woocommerce
Installations
10,000+
Vulnerability:
Bypass Vulnerability
Patched in Version:
1.9.0
Severity Score:
High
The vulnerability has been patched, so you should update to version 1.9.0.

Xagio SEO – AI Powered SEO

Plugin Slug:
xagio-seo
Installations
10,000+
Vulnerability:
Privilege Escalation
Patched in Version:
7.1.0.31
Severity Score:
Critical
The vulnerability has been patched, so you should update to version 7.1.0.31.

EventPrime – Events Calendar, Bookings and Tickets

Plugin Slug:
eventprime-event-calendar-management
Installations
7,000+
Vulnerability:
Broken Access Control
Patched in Version:
4.2.7.0
Severity Score:
High
The vulnerability has been patched, so you should update to version 4.2.7.0.

NEX-Forms – Ultimate Forms Plugin for WordPress

Plugin Slug:
nex-forms-express-wp-form-builder
Installations
7,000+
Vulnerability:
Broken Access Control
Patched in Version:
9.1.10
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 9.1.10.

Reading progressbar

Plugin Slug:
reading-progress-bar
Installations
6,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.3.1
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.3.1.

Responsive Blocks – Page Builder for Blocks & Patterns

Plugin Slug:
responsive-block-editor-addons
Installations
4,000+
Vulnerability:
Broken Access Control
Patched in Version:
2.2.1
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.2.1.

JS Archive List

Plugin Slug:
jquery-archive-list-widget
Installations
3,000+
Vulnerability:
PHP Object Injection
Patched in Version:
6.2.0
Severity Score:
High
The vulnerability has been patched, so you should update to version 6.2.0.

Name Directory

Plugin Slug:
name-directory
Installations
3,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.33.0
Severity Score:
High
The vulnerability has been patched, so you should update to version 1.33.0.

Simple Ajax Chat – Add a Fast, Secure Chat Box

Plugin Slug:
simple-ajax-chat
Installations
2,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
20260301
Severity Score:
High
The vulnerability has been patched, so you should update to version 20260301.

Flexmls® IDX Plugin

Plugin Slug:
flexmls-idx
Installations
1,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
3.15.10
Severity Score:
High
The vulnerability has been patched, so you should update to version 3.15.10.

MDTF – Meta Data and Taxonomies Filter

Plugin Slug:
wp-meta-data-filter-and-taxonomy-filter
Installations
1,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.3.6
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.3.6.

Datalogics Ecommerce Delivery – Datalogics

Plugin Slug:
datalogics
Installations
400+
Vulnerability:
Privilege Escalation
Patched in Version:
2.6.60
Severity Score:
Critical
The vulnerability has been patched, so you should update to version 2.6.60.

PitchPrint

Plugin:
PitchPrint
Plugin Slug:
pitchprint
Installations
400+
Vulnerability:
Arbitrary File Deletion
Patched in Version:
11.2.0
Severity Score:
High
The vulnerability has been patched, so you should update to version 11.2.0.

Court Reservation – Manage Your Court Bookings Online

Plugin Slug:
court-reservation
Installations
100+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
1.10.9
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.10.9.

LearnPress – Sepay Payment

Plugin Slug:
learnpress-sepay-payment
Installations
100+
Vulnerability:
Broken Authentication
Patched in Version:
4.0.1
Severity Score:
High
The vulnerability has been patched, so you should update to version 4.0.1.

Pix for WooCommerce

Plugin Slug:
payment-gateway-pix-for-woocommerce
Installations
100+
Vulnerability:
Arbitrary File Upload
Patched in Version:
1.6.0
Severity Score:
Critical
The vulnerability has been patched, so you should update to version 1.6.0.

Primer MyData for Woocommerce

Plugin Slug:
primer-mydata
Installations
100+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
4.2.2
Severity Score:
High
The vulnerability has been patched, so you should update to version 4.2.2.

Paid Videochat Turnkey Site – HTML5 PPV Live Webcams

Plugin Slug:
ppv-live-webcams
Installations
30+
Vulnerability:
Privilege Escalation
Patched in Version:
7.3.21
Severity Score:
High
The vulnerability has been patched, so you should update to version 7.3.21.

ZIP Code Based Content Protection

Plugin Slug:
zip-code-based-content-protection
Installations
10+
Vulnerability:
SQL Injection
Patched in Version:
1.0.3
Severity Score:
Critical
The vulnerability has been patched, so you should update to version 1.0.3.

Divi Booster

Plugin:
Divi Booster
Plugin Slug:
divi-booster
Vulnerability:
PHP Object Injection
Patched in Version:
5.0.2
Severity Score:
Critical
The vulnerability has been patched, so you should update to version 5.0.2.

Elated Listing

Plugin:
Elated Listing
Plugin Slug:
eltd-listing
Vulnerability:
Broken Access Control
Patched in Version:
1.5
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.5.

Fusion Builder

Plugin:
Fusion Builder
Plugin Slug:
fusion-builder
Vulnerability:
Broken Access Control
Patched in Version:
3.15.0
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.15.0.

Fusion Builder

Plugin:
Fusion Builder
Plugin Slug:
fusion-builder
Vulnerability:
Broken Access Control
Patched in Version:
3.15.0
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.15.0.

Avada Core

Plugin:
Avada Core
Plugin Slug:
fusion-core
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
5.15.0
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 5.15.0.

Avada Core

Plugin:
Avada Core
Plugin Slug:
fusion-core
Vulnerability:
Broken Access Control
Patched in Version:
5.15.0
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 5.15.0.

Gravity Forms

Plugin:
Gravity Forms
Plugin Slug:
gravityforms
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.9.29
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.9.29.

JetBooking

Plugin:
JetBooking
Plugin Slug:
jet-booking
Vulnerability:
SQL Injection
Patched in Version:
4.0.3.1
Severity Score:
Critical
The vulnerability has been patched, so you should update to version 4.0.3.1.

Jobica Core

Plugin:
Jobica Core
Plugin Slug:
jobica-core
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.4.2
Severity Score:
High
The vulnerability has been patched, so you should update to version 1.4.2.

Jobica Core

Plugin:
Jobica Core
Plugin Slug:
jobica-core
Vulnerability:
PHP Object Injection
Patched in Version:
1.4.2
Severity Score:
High
The vulnerability has been patched, so you should update to version 1.4.2.

MetForm Pro

Plugin:
MetForm Pro
Plugin Slug:
metform-pro
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
3.9.7
Severity Score:
High
The vulnerability has been patched, so you should update to version 3.9.7.

Organici Library

Plugin:
Organici Library
Plugin Slug:
noo-organici-library
Vulnerability:
SQL Injection
Patched in Version:
2.1.3
Severity Score:
High
The vulnerability has been patched, so you should update to version 2.1.3.

Organici Library

Plugin:
Organici Library
Plugin Slug:
noo-organici-library
Vulnerability:
PHP Object Injection
Patched in Version:
2.1.3
Severity Score:
High
The vulnerability has been patched, so you should update to version 2.1.3.

Organici Library

Plugin:
Organici Library
Plugin Slug:
noo-organici-library
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.1.3
Severity Score:
High
The vulnerability has been patched, so you should update to version 2.1.3.

Visionary Core

Plugin:
Visionary Core
Plugin Slug:
noo-visionary-core
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.5.0
Severity Score:
High
The vulnerability has been patched, so you should update to version 1.5.0.

Visionary Core

Plugin:
Visionary Core
Plugin Slug:
noo-visionary-core
Vulnerability:
PHP Object Injection
Patched in Version:
1.5.0
Severity Score:
High
The vulnerability has been patched, so you should update to version 1.5.0.

PixelYourSite PRO

Plugin:
PixelYourSite PRO
Plugin Slug:
pixelyoursite-pro
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
12.4.0.3
Severity Score:
High
The vulnerability has been patched, so you should update to version 12.4.0.3.

tagDiv Composer

Plugin:
tagDiv Composer
Plugin Slug:
td-composer
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
5.4.3
Severity Score:
High
The vulnerability has been patched, so you should update to version 5.4.3.

tagDiv Opt-In Builder

Plugin:
tagDiv Opt-In Builder
Plugin Slug:
td-subscription
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.7.4
Severity Score:
High
The vulnerability has been patched, so you should update to version 1.7.4.

Tutor LMS Pro

Plugin:
Tutor LMS Pro
Plugin Slug:
tutor-pro
Vulnerability:
Broken Authentication
Patched in Version:
3.9.6
Severity Score:
Critical
The vulnerability has been patched, so you should update to version 3.9.6.

WordPress Themes — 7 Patched / 16 Unpatched

Amfissa

Theme:
Amfissa
Theme Slug:
amfissa
Vulnerability:
Local File Inclusion
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should switch themes.

Beelove

Theme:
Beelove
Theme Slug:
beelove
Vulnerability:
PHP Object Injection
Patched in Version:
No Fix
Severity Score:
Critical
The vulnerability has not been patched. You should switch themes.

Belfort

Theme:
Belfort
Theme Slug:
belfort
Vulnerability:
Local File Inclusion
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should switch themes.

Buisson

Theme:
Buisson
Theme Slug:
buisson
Vulnerability:
PHP Object Injection
Patched in Version:
No Fix
Severity Score:
Critical
The vulnerability has not been patched. You should switch themes.

Deston

Theme:
Deston
Theme Slug:
deston
Vulnerability:
Local File Inclusion
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should switch themes.

Emaurri

Theme:
Emaurri
Theme Slug:
emaurri
Vulnerability:
Local File Inclusion
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should switch themes.

Golo

Theme:
Golo
Theme Slug:
golo
Vulnerability:
Privilege Escalation
Patched in Version:
No Fix
Severity Score:
Critical
The vulnerability has not been patched. You should switch themes.

Jannah

Theme:
Jannah
Theme Slug:
jannah
Vulnerability:
Local File Inclusion
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should switch themes.

Love Story

Theme:
Love Story
Theme Slug:
lovestory
Vulnerability:
PHP Object Injection
Patched in Version:
No Fix
Severity Score:
Critical
The vulnerability has not been patched. You should switch themes.

LuxeDrive

Theme:
LuxeDrive
Theme Slug:
luxedrive
Vulnerability:
Local File Inclusion
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should switch themes.

Melody

Theme:
Melody
Theme Slug:
melodyschool
Vulnerability:
PHP Object Injection
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should switch themes.

MultiOffice

Theme:
MultiOffice
Theme Slug:
multioffice
Vulnerability:
Local File Inclusion
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should switch themes.

Photography

Theme:
Photography
Theme Slug:
photography
Vulnerability:
Arbitrary File Upload
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should switch themes.

Rosebud

Theme:
Rosebud
Theme Slug:
rosebud
Vulnerability:
Local File Inclusion
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should switch themes.

Work & Travel Company

Theme:
Work & Travel Company
Theme Slug:
work-travel-company
Vulnerability:
PHP Object Injection
Patched in Version:
No Fix
Severity Score:
Critical
The vulnerability has not been patched. You should switch themes.

Zorka

Theme:
Zorka
Theme Slug:
zorka
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should switch themes.

Astra

Theme:
Astra
Theme Slug:
astra
Downloads
21,720,242
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
4.12.4
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 4.12.4.

News Magazine X

Theme Slug:
news-magazine-x
Downloads
76,558
Vulnerability:
Broken Access Control
Patched in Version:
1.2.51
Severity Score:
High
The vulnerability has been patched, so you should update to version 1.2.51.

Energox

Theme:
Energox
Theme Slug:
energox
Vulnerability:
Arbitrary File Deletion
Patched in Version:
1.3
Severity Score:
High
The vulnerability has been patched, so you should update to version 1.3.

Instant VA

Theme:
Instant VA
Theme Slug:
instantva
Vulnerability:
Arbitrary File Deletion
Patched in Version:
1.0.2
Severity Score:
High
The vulnerability has been patched, so you should update to version 1.0.2.

CitiLights

Theme:
CitiLights
Theme Slug:
noo-citilights
Vulnerability:
PHP Object Injection
Patched in Version:
3.7.2
Severity Score:
High
The vulnerability has been patched, so you should update to version 3.7.2.

CitiLights

Theme:
CitiLights
Theme Slug:
noo-citilights
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
3.7.2
Severity Score:
High
The vulnerability has been patched, so you should update to version 3.7.2.

Search & Go

Theme:
Search & Go
Theme Slug:
searchgo
Vulnerability:
Privilege Escalation
Patched in Version:
2.8.1
Severity Score:
Critical
The vulnerability has been patched, so you should update to version 2.8.1.

Solid Security is part of Solid Suite — The best foundation for WordPress websites.

Every WordPress site needs security, backups, and management tools. That’s Solid Suite — an integrated bundle of three plugins: Solid Security, Solid Backups, and Solid Central. You also get access to Solid Academy’s learning resources for WordPress professionals. Build your next WordPress website on a solid foundation with Solid Suite!

Get Solid Security