WordPress Vulnerability Report

WordPress Vulnerability Report — March 19, 2025

Last week, 173 new vulnerabilities emerged in the WordPress ecosystem, including 162 plugins and 11 themes. 110 of the vulnerable plugins and themes remain unpatched, but Solid Security Pro users are protected by virtual patching from Patchstack.

Avatar photo
Sarah Ulmer

In this report, 173 vulnerabilities have been publicly disclosed. Security patches for 63 of these plugins and themes are available now, so run those updates as soon as possible. If you’re a Solid Security Pro user, the version management tool may have already warned you and updated these plugins, depending on your settings.

Additionally, there are 110 plugin and theme vulnerabilities with no patch available yet. If you’re a Solid Security Pro user, those vulnerabilities are already protected by the Solid Security firewall. Virtual patches from Patchstack will be applied when a vulnerability is considered high or medium risk. If no patch is forthcoming from the vendor or the vulnerable software has been marked “closed” and dropped from the official WordPress repositories, you should deactivate it soon and look for alternative solutions.

Along with poor user account security, vulnerable plugins and themes are among the top reasons why WordPress websites get hacked. Unfortunately, cyberattacks are increasing in volume and sophistication. They’re also increasingly aimed at small to mid-sized businesses.

Our WordPress Vulnerability Report covers the latest emerging WordPress plugin, theme, and core vulnerabilities. Each vulnerability will have a severity rating of LowMediumHigh, or Critical. Responsible disclosure of vulnerabilities is essential to keeping the WordPress community safe. Please share this report to help spread the word and make WordPress — and the web — more secure.

WordPress Core

WordPress 6.8 Beta 3 is ready for testing! This beta version of the WordPress software is under development. Please do not install, run, or test this version of WordPress on production or mission-critical websites. Instead, it is recommended you evaluate Beta 3 on a test server and site.

No new core vulnerabilities were disclosed this week.

WordPress Plugins — 57 Patched / 105 Unpatched

Post Lockdown

Plugin Slug:
post-lockdown
Installations
1,000+
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

CRM and Lead Management by vcita

Plugin Slug:
crm-customer-relationship-management-by-vcita
Installations
100+
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

WP Email Delivery

Plugin Slug:
wp-email-delivery
Installations
100+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Video Share VOD – Turnkey Video Site Builder Script

Plugin Slug:
video-share-vod
Installations
70+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

amoCRM WebForm

Plugin:
amoCRM WebForm
Plugin Slug:
amocrm-webform
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Another Events Calendar

Plugin:
Another Events Calendar
Plugin Slug:
another-events-calendar
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

ArielBrailovsky-ViralAd

Plugin:
ArielBrailovsky-ViralAd
Plugin Slug:
arielbrailovsky-viralad
Vulnerability:
SQL Injection
Patched in Version:
No Fix
Severity Score:
Critical
The vulnerability has not been patched. You should deactivate the plugin.

AS English Admin

Plugin:
AS English Admin
Plugin Slug:
as-english-admin
Vulnerability:
Open Redirection
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Awesome Surveys

Plugin:
Awesome Surveys
Plugin Slug:
awesome-surveys
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Back To Top

Plugin:
Back To Top
Plugin Slug:
backtotop
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Bee Layer Slider

Plugin:
Bee Layer Slider
Plugin Slug:
bee-layer-slider
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

binlayerpress

Plugin:
binlayerpress
Plugin Slug:
binlayerpress
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Block Spam By Math Reloaded

Plugin:
Block Spam By Math Reloaded
Plugin Slug:
block-spam-by-math-reloaded
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Block Spam By Math Reloaded

Plugin:
Block Spam By Math Reloaded
Plugin Slug:
block-spam-by-math-reloaded
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

W3Counter Free Real-Time Web Stats

Plugin:
W3Counter Free Real-Time Web Stats
Plugin Slug:
blog-stats-by-w3counter
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

BlogBuzzTime for WP

Plugin:
BlogBuzzTime for WP
Plugin Slug:
blogbuzztime-for-wp
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

CC-IMG-Shortcode

Plugin:
CC-IMG-Shortcode
Plugin Slug:
cc-img-shortcode
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Builder for Contact Form 7 by Webconstruct

Plugin:
Builder for Contact Form 7 by Webconstruct
Plugin Slug:
cf7-builder
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Contact Form 7 Select Box Editor Button

Plugin:
Contact Form 7 Select Box Editor Button
Plugin Slug:
contact-form-7-select-box-editor-button
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Contact Us By Lord Linus

Plugin:
Contact Us By Lord Linus
Plugin Slug:
contact-us-by-lord-linus
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Coronavirus (COVID-19) Notice Message

Plugin:
Coronavirus (COVID-19) Notice Message
Plugin Slug:
coronavirus-covid-19-notice-message
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Custom Dashboard Page

Plugin:
Custom Dashboard Page
Plugin Slug:
custom-dashboard-page
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

custom-field-list-widget

Plugin:
custom-field-list-widget
Plugin Slug:
custom-field-list-widget
Vulnerability:
Local File Inclusion
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Custom top bar

Plugin:
Custom top bar
Plugin Slug:
custom-top-bar
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Delete Original Image

Plugin:
Delete Original Image
Plugin Slug:
delete-original-image
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Display Template Name

Plugin:
Display Template Name
Plugin Slug:
display-template-name
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Domain Theme

Plugin:
Domain Theme
Plugin Slug:
domain-theme
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

DP ALTerminator – Missing ALT manager

Plugin:
DP ALTerminator – Missing ALT manager
Plugin Slug:
dp-alterminator-missing-alt-manager
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Easy Image Display

Plugin:
Easy Image Display
Plugin Slug:
easy-image-display
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Email Keep

Plugin:
Email Keep
Plugin Slug:
email-keep
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Email Keep

Plugin:
Email Keep
Plugin Slug:
email-keep
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.
Plugin:
Featured Posts Grid
Plugin Slug:
featured-posts-grid
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Frontpage category filter

Plugin:
Frontpage category filter
Plugin Slug:
frontpage-category-filter
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

FTP Sync

Plugin:
FTP Sync
Plugin Slug:
ftp-sync
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

GetShop ecommerce

Plugin:
GetShop ecommerce
Plugin Slug:
getshop-ecommerce
Vulnerability:
Local File Inclusion
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

GetSocial

Plugin:
GetSocial
Plugin Slug:
getsocial
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

GNUCommerce

Plugin:
GNUCommerce
Plugin Slug:
gnucommerce
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

GNUPress

Plugin:
GNUPress
Plugin Slug:
gnupress
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Go To Top

Plugin:
Go To Top
Plugin Slug:
go-to-top
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.
Plugin:
Google News Editors Picks Feed Generator
Plugin Slug:
google-news-editors-picks-news-feeds
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

In Stock Mailer for WooCommerce

Plugin:
In Stock Mailer for WooCommerce
Plugin Slug:
in-stock-mailer-for-woocommerce
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Insert Code

Plugin:
Insert Code
Plugin Slug:
insert-code
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.
Plugin:
Lava Ajax Search
Plugin Slug:
lava-ajax-search
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

LinkedIn Lite

Plugin:
LinkedIn Lite
Plugin Slug:
linkedin-lite
Vulnerability:
Local File Inclusion
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

List Mixcloud

Plugin:
List Mixcloud
Plugin Slug:
list-mixcloud
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

List of Posts from each Category plugin for WordPress

Plugin:
List of Posts from each Category plugin for WordPress
Plugin Slug:
list-posts-by-category
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Login Logger

Plugin:
Login Logger
Plugin Slug:
login-logger
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Lunar

Plugin:
Lunar
Plugin Slug:
lunar-sell-photos-online
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

MaxA/B

Plugin:
MaxA/B
Plugin Slug:
maxab
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Members page only for logged in users

Plugin:
Members page only for logged in users
Plugin Slug:
members-page-only-for-logged-in-users
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

PHP/MySQL CPU performance statistics

Plugin:
PHP/MySQL CPU performance statistics
Plugin Slug:
mywebtonet-performancestats
Vulnerability:
PHP Object Injection
Patched in Version:
No Fix
Severity Score:
Critical
The vulnerability has not been patched. You should deactivate the plugin.

No Disposable Email

Plugin:
No Disposable Email
Plugin Slug:
no-disposable-email
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

pixelstats

Plugin:
pixelstats
Plugin Slug:
pixelstats
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

PluginPass

Plugin:
PluginPass
Plugin Slug:
pluginpass-pro-plugintheme-licensing
Vulnerability:
Arbitrary File Download
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Plugins Last Updated Column

Plugin:
Plugins Last Updated Column
Plugin Slug:
plugins-last-updated-column
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Portfolio and Projects

Plugin:
Portfolio and Projects
Plugin Slug:
portfolio-and-projects
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Post Read Time

Plugin:
Post Read Time
Plugin Slug:
post-read-time
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

price-calc

Plugin:
price-calc
Plugin Slug:
price-calc
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Rankchecker.io Integration

Plugin:
Rankchecker.io Integration
Plugin Slug:
rankchecker-io-integration
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Comment Date and Gravatar remover

Plugin:
Comment Date and Gravatar remover
Plugin Slug:
remove-date-and-gravatar-under-comment
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Responsive Google Map

Plugin:
Responsive Google Map
Plugin Slug:
responsive-google-map
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

REST API TO MiniProgram

Plugin:
REST API TO MiniProgram
Plugin Slug:
rest-api-to-miniprogram
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

S3Bubble Media Streaming

Plugin:
S3Bubble Media Streaming
Plugin Slug:
s3bubble-amazon-web-services-oembed-media-streaming-support
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Schedule

Plugin:
Schedule
Plugin Slug:
schedule
Vulnerability:
SQL Injection
Patched in Version:
No Fix
Severity Score:
Critical
The vulnerability has not been patched. You should deactivate the plugin.

Schedule

Plugin:
Schedule
Plugin Slug:
schedule
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

SEO Tools

Plugin:
SEO Tools
Plugin Slug:
seo-automatic-seo-tools
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Simple Amazon Affiliate

Plugin:
Simple Amazon Affiliate
Plugin Slug:
simple-amazon-affiliate
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Social Snap

Plugin:
Social Snap
Plugin Slug:
socialsnap
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Spam Byebye

Plugin:
Spam Byebye
Plugin Slug:
spam-byebye
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Tabbed Login Widget

Plugin:
Tabbed Login Widget
Plugin Slug:
tabbed-login
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

TabGarb Pro

Plugin:
TabGarb Pro
Plugin Slug:
tabgarb
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

TBTestimonials

Plugin:
TBTestimonials
Plugin Slug:
tb-testimonials
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

ThemeEgg ToolKit

Plugin:
ThemeEgg ToolKit
Plugin Slug:
themeegg-toolkit
Vulnerability:
Arbitrary File Upload
Patched in Version:
No Fix
Severity Score:
Critical
The vulnerability has not been patched. You should deactivate the plugin.
Plugin:
Featured Image Thumbnail Grid
Plugin Slug:
thumbnail-grid
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Já-Já Pagamentos for WooCommerce

Plugin:
Já-Já Pagamentos for WooCommerce
Plugin Slug:
wc-ja-ja-pagamentos-multicaixa-express
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

WP Add Active Class To Menu Item

Plugin:
WP Add Active Class To Menu Item
Plugin Slug:
wp-add-active-class-to-menu-item
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

WP Azure offload

Plugin:
WP Azure offload
Plugin Slug:
wp-azure-offload
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

WP Bulk Post Duplicator

Plugin:
WP Bulk Post Duplicator
Plugin Slug:
wp-bulk-post-duplicator
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

WP Compare Tables

Plugin:
WP Compare Tables
Plugin Slug:
wp-compare-tables
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

WP Crowdfunding

Plugin:
WP Crowdfunding
Plugin Slug:
wp-crowdfunding
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Hashtags

Plugin:
Hashtags
Plugin Slug:
wp-hashtags
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

WP Hide Admin Bar

Plugin:
WP Hide Admin Bar
Plugin Slug:
wp-hide-admin-bar
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

WP JobHunt

Plugin:
WP JobHunt
Plugin Slug:
wp-jobhunt
Vulnerability:
Broken Authentication
Patched in Version:
No Fix
Severity Score:
Critical
The vulnerability has not been patched. You should deactivate the plugin.

WP JobHunt

Plugin:
WP JobHunt
Plugin Slug:
wp-jobhunt
Vulnerability:
Privilege Escalation
Patched in Version:
No Fix
Severity Score:
Critical
The vulnerability has not been patched. You should deactivate the plugin.

WP JobHunt

Plugin:
WP JobHunt
Plugin Slug:
wp-jobhunt
Vulnerability:
Broken Authentication
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

WP Last Modified

Plugin:
WP Last Modified
Plugin Slug:
wp-last-modified
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

WP Login Control

Plugin:
WP Login Control
Plugin Slug:
wp-login-control
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Mobile Themes

Plugin:
Mobile Themes
Plugin Slug:
wp-mobile-themes
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

WP No-Bot Question

Plugin:
WP No-Bot Question
Plugin Slug:
wp-no-bot-question
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

WP Performance Pack

Plugin:
WP Performance Pack
Plugin Slug:
wp-performance-pack
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

wordpress login form to anywhere

Plugin:
wordpress login form to anywhere
Plugin Slug:
wp-show-login-form
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

WP Simple Slideshow

Plugin:
WP Simple Slideshow
Plugin Slug:
wp-simple-slideshow
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Skitter Slideshow

Plugin:
Skitter Slideshow
Plugin Slug:
wp-skitter-slideshow
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

WP SVG Upload

Plugin:
WP SVG Upload
Plugin Slug:
wp-svg-upload
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

WP jQuery Persian Datepicker

Plugin:
WP jQuery Persian Datepicker
Plugin Slug:
wpjqp-datepicker
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

WPSchoolPress

Plugin:
WPSchoolPress
Plugin Slug:
wpschoolpress
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

WPSchoolPress

Plugin:
WPSchoolPress
Plugin Slug:
wpschoolpress
Vulnerability:
SQL Injection
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

WPSchoolPress

Plugin:
WPSchoolPress
Plugin Slug:
wpschoolpress
Vulnerability:
SQL Injection
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

WPSchoolPress

Plugin:
WPSchoolPress
Plugin Slug:
wpschoolpress
Vulnerability:
Privilege Escalation
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

XV Random Quotes

Plugin:
XV Random Quotes
Plugin Slug:
xv-random-quotes
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

XV Random Quotes

Plugin:
XV Random Quotes
Plugin Slug:
xv-random-quotes
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

ZipList Recipe

Plugin:
ZipList Recipe
Plugin Slug:
ziplist-recipe-plugin
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Zoorum Comments

Plugin:
Zoorum Comments
Plugin Slug:
zoorum-comments
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

WooCommerce

Plugin Slug:
woocommerce
Installations
8,000,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
9.7.1
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 9.7.1.

All-in-One WP Migration and Backup

Plugin Slug:
all-in-one-wp-migration
Installations
5,000,000+
Vulnerability:
PHP Object Injection
Patched in Version:
7.90
Severity Score:
High
The vulnerability has been patched, so you should update to version 7.90.

Ad Inserter – Ad Manager & AdSense Ads

Plugin Slug:
ad-inserter
Installations
300,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.8.1
Severity Score:
High
The vulnerability has been patched, so you should update to version 2.8.1.

Page Builder: Pagelayer – Drag and Drop website builder

Plugin Slug:
pagelayer
Installations
300,000+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
1.9.9
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.9.9.

LoginPress | wp-login Custom Login Page Customizer

Plugin Slug:
loginpress
Installations
200,000+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
4.0.0
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 4.0.0.

Download Manager

Plugin Slug:
download-manager
Installations
100,000+
Vulnerability:
Path Traversal
Patched in Version:
3.3.09
Severity Score:
Low
The vulnerability has been patched, so you should update to version 3.3.09.

ShareThis Dashboard for Google Analytics

Plugin Slug:
googleanalytics
Installations
100,000+
Vulnerability:
Broken Access Control
Patched in Version:
3.2.2
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.2.2.

HUSKY – Products Filter Professional for WooCommerce

Plugin Slug:
woocommerce-products-filter
Installations
100,000+
Vulnerability:
Local File Inclusion
Patched in Version:
1.3.6.5
Severity Score:
High
The vulnerability has been patched, so you should update to version 1.3.6.5.

HUSKY – Products Filter Professional for WooCommerce

Plugin Slug:
woocommerce-products-filter
Installations
100,000+
Vulnerability:
Local File Inclusion
Patched in Version:
1.3.6.6
Severity Score:
High
The vulnerability has been patched, so you should update to version 1.3.6.6.

WP Recipe Maker

Plugin Slug:
wp-recipe-maker
Installations
50,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
9.8.1
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 9.8.1.

DethemeKit for Elementor

Plugin Slug:
dethemekit-for-elementor
Installations
40,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.1.10
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.1.10.

SecuPress Free — WordPress Security

Plugin Slug:
secupress
Installations
40,000+
Vulnerability:
Broken Access Control
Patched in Version:
2.3
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.3.

InstaWP Connect – 1-click WP Staging & Migration

Plugin Slug:
instawp-connect
Installations
20,000+
Vulnerability:
Local File Inclusion
Patched in Version:
0.1.0.84
Severity Score:
High
The vulnerability has been patched, so you should update to version 0.1.0.84.

WP Test Email

Plugin Slug:
wp-test-email
Installations
20,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.1.9
Severity Score:
High
The vulnerability has been patched, so you should update to version 1.1.9.

Qubely – Advanced Gutenberg Blocks

Plugin Slug:
qubely
Installations
10,000+
Vulnerability:
Sensitive Data Exposure
Patched in Version:
1.8.14
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.8.14.

Review Schema – Review & Structure Data Schema Plugin

Plugin Slug:
review-schema
Installations
10,000+
Vulnerability:
Local File Inclusion
Patched in Version:
2.2.5
Severity Score:
High
The vulnerability has been patched, so you should update to version 2.2.5.

Finale Lite – Sales Countdown Timer & Discount for WooCommerce

Plugin Slug:
finale-woocommerce-sales-countdown-timer-discount
Installations
6,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.20.0
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.20.0.
Plugin Slug:
wp-responsive-thumbnail-slider
Installations
2,000+
Vulnerability:
SQL Injection
Patched in Version:
1.0.5
Severity Score:
High
The vulnerability has been patched, so you should update to version 1.0.5.

WPCOM Member

Plugin Slug:
wpcom-member
Installations
2,000+
Vulnerability:
SQL Injection
Patched in Version:
1.7.7
Severity Score:
Critical
The vulnerability has been patched, so you should update to version 1.7.7.

AppPresser – Mobile App Framework

Plugin Slug:
apppresser
Installations
1,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
4.4.11
Severity Score:
High
The vulnerability has been patched, so you should update to version 4.4.11.

WPCS – WordPress Currency Switcher Professional

Plugin Slug:
currency-switcher
Installations
1,000+
Vulnerability:
Content Injection
Patched in Version:
1.2.0.5
Severity Score:
High
The vulnerability has been patched, so you should update to version 1.2.0.5.

Event post

Plugin:
Event post
Plugin Slug:
event-post
Installations
1,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
5.9.9
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 5.9.9.

Omnipress

Plugin:
Omnipress
Plugin Slug:
omnipress
Installations
1,000+
Vulnerability:
Broken Access Control
Patched in Version:
1.5.5
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.5.5.

Simple Photo Feed

Plugin Slug:
simple-photo-feed
Installations
1,000+
Vulnerability:
Broken Access Control
Patched in Version:
1.4.1
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.4.1.

Church Admin

Plugin Slug:
church-admin
Installations
900+
Vulnerability:
SQL Injection
Patched in Version:
5.0.19
Severity Score:
Critical
The vulnerability has been patched, so you should update to version 5.0.19.

Maintenance Notice

Plugin Slug:
maintenance-notice
Installations
800+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
1.0.7
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.0.7.

WATI Chat and Notification

Plugin Slug:
wati-chat-and-notification
Installations
700+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
1.1.5
Severity Score:
High
The vulnerability has been patched, so you should update to version 1.1.5.

Skrill – WooCommerce

Plugin Slug:
official-skrill-woocommerce
Installations
600+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
1.0.67
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.0.67.

Accounting for WooCommerce

Plugin Slug:
accounting-for-woocommerce
Installations
500+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.6.9
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.6.9.

IP Based Login

Plugin Slug:
ip-based-login
Installations
500+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
2.4.1
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.4.1.

IP Based Login

Plugin Slug:
ip-based-login
Installations
500+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.4.1
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.4.1.

pipDisqus – Lightweight Disqus Comments

Plugin Slug:
pipdisqus
Installations
400+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.7
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.7.

Formality

Plugin:
Formality
Plugin Slug:
formality
Installations
200+
Vulnerability:
Local File Inclusion
Patched in Version:
1.5.8
Severity Score:
High
The vulnerability has been patched, so you should update to version 1.5.8.

Appsero Helper

Plugin Slug:
appsero-helper
Installations
60+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
1.3.3
Severity Score:
High
The vulnerability has been patched, so you should update to version 1.3.3.

BP Email Assign Templates

Plugin Slug:
bp-email-assign-templates
Installations
50+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.7
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.7.

BP Email Assign Templates

Plugin Slug:
bp-email-assign-templates
Installations
50+
Vulnerability:
Other Vulnerability Type
Patched in Version:
1.8
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.8.

AnalyticsWP

Plugin:
AnalyticsWP
Plugin Slug:
analyticswp
Vulnerability:
SQL Injection
Patched in Version:
2.1.0
Severity Score:
Critical
The vulnerability has been patched, so you should update to version 2.1.0.

Gtbabel

Plugin:
Gtbabel
Plugin Slug:
gtbabel
Vulnerability:
Privilege Escalation
Patched in Version:
6.6.9
Severity Score:
High
The vulnerability has been patched, so you should update to version 6.6.9.

Realteo

Plugin:
Realteo
Plugin Slug:
realteo
Vulnerability:
Broken Authentication
Patched in Version:
1.2.9
Severity Score:
Critical
The vulnerability has been patched, so you should update to version 1.2.9.

Resido

Plugin:
Resido
Plugin Slug:
resido
Vulnerability:
Broken Access Control
Patched in Version:
3.6.1
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.6.1.

Search Filter Pro

Plugin:
Search Filter Pro
Plugin Slug:
search-filter-pro
Vulnerability:
Broken Access Control
Patched in Version:
2.5.20
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.5.20.

SoundRise Music

Plugin:
SoundRise Music
Plugin Slug:
soundrise-music
Vulnerability:
Broken Access Control
Patched in Version:
1.7.1
Severity Score:
High
The vulnerability has been patched, so you should update to version 1.7.1.

VidoRev Extensions

Plugin:
VidoRev Extensions
Plugin Slug:
vidorev-extensions
Vulnerability:
Broken Access Control
Patched in Version:
2.9.9.9.9.9.6
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.9.9.9.9.9.6.

WordPress Themes — 6 Patched / 5 Unpatched

Civi

Theme:
Civi
Theme Slug:
civi
Vulnerability:
Sensitive Data Exposure
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should switch themes.

Civi

Theme:
Civi
Theme Slug:
civi
Vulnerability:
Broken Authentication
Patched in Version:
No Fix
Severity Score:
Critical
The vulnerability has not been patched. You should switch themes.

Civi

Theme:
Civi
Theme Slug:
civi
Vulnerability:
Broken Authentication
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should switch themes.

JobCareer

Theme:
JobCareer
Theme Slug:
jobcareer
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should switch themes.

Zegen

Theme:
Zegen
Theme Slug:
zegen
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should switch themes.

Design Comuni Italia

Theme:
Design Comuni Italia
Theme Slug:
design-comuni-wordpress-theme
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.1.2
Severity Score:
High
The vulnerability has been patched, so you should update to version 1.1.2.

Eco Nature

Theme:
Eco Nature
Theme Slug:
eco-nature
Vulnerability:
Broken Access Control
Patched in Version:
2.1.0
Severity Score:
High
The vulnerability has been patched, so you should update to version 2.1.0.

Industrial

Theme:
Industrial
Theme Slug:
industrial
Vulnerability:
Broken Access Control
Patched in Version:
1.7.9
Severity Score:
High
The vulnerability has been patched, so you should update to version 1.7.9.

Traveler

Theme:
Traveler
Theme Slug:
traveler
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
3.1.9
Severity Score:
High
The vulnerability has been patched, so you should update to version 3.1.9.

Traveler

Theme:
Traveler
Theme Slug:
traveler
Vulnerability:
Local File Inclusion
Patched in Version:
3.1.9
Severity Score:
High
The vulnerability has been patched, so you should update to version 3.1.9.

Workreap

Theme:
Workreap
Theme Slug:
workreap
Vulnerability:
Privilege Escalation
Patched in Version:
3.2.6
Severity Score:
Critical
The vulnerability has been patched, so you should update to version 3.2.6.

Solid Security is part of Solid Suite — The best foundation for WordPress websites.

Every WordPress site needs security, backups, and management tools. That’s Solid Suite — an integrated bundle of three plugins: Solid Security, Solid Backups, and Solid Central. You also get access to Solid Academy’s learning resources for WordPress professionals. Build your next WordPress website on a solid foundation with Solid Suite!

Get Solid Security