WordPress Vulnerability Report

WordPress Vulnerability Report — March 26, 2025

Last week, 240 new vulnerabilities emerged in the WordPress ecosystem, including 226 plugins and 14 themes. 189 of the vulnerable plugins and themes remain unpatched, but Solid Security Pro users are protected by virtual patching from Patchstack.

Avatar photo
Sarah Ulmer

In this report, 240 vulnerabilities have been publicly disclosed. Security patches for 51 of these plugins and themes are available now, so run those updates as soon as possible. If you’re a Solid Security Pro user, the version management tool may have already warned you and updated these plugins, depending on your settings.

Additionally, there are 189 plugin and theme vulnerabilities with no patch available yet. If you’re a Solid Security Pro user, those vulnerabilities are already protected by the Solid Security firewall. Virtual patches from Patchstack will be applied when a vulnerability is considered high or medium risk. If no patch is forthcoming from the vendor or the vulnerable software has been marked “closed” and dropped from the official WordPress repositories, you should deactivate it soon and look for alternative solutions.

Along with poor user account security, vulnerable plugins and themes are among the top reasons why WordPress websites get hacked. Unfortunately, cyberattacks are increasing in volume and sophistication. They’re also increasingly aimed at small to mid-sized businesses.

Our WordPress Vulnerability Report covers the latest emerging WordPress plugin, theme, and core vulnerabilities. Each vulnerability will have a severity rating of LowMediumHigh, or Critical. Responsible disclosure of vulnerabilities is essential to keeping the WordPress community safe. Please share this report to help spread the word and make WordPress — and the web — more secure.

WordPress Core

WordPress 6.8 Release Candidate 1 is ready for download and testing! This version of the WordPress software is under development. Please do not install, run, or test this version of WordPress on production or mission-critical websites. Instead, it’s recommended that you evaluate RC1 on a test server and site.

No new core vulnerabilities were disclosed this week.

WordPress Plugins — 46 Patched / 180 Unpatched

teachPress

Plugin:
teachPress
Plugin Slug:
teachpress
Installations
2,000+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

GlobalPayments WooCommerce

Plugin Slug:
global-payments-woocommerce
Installations
600+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

EZ SQL Reports Shortcode Widget and DB Backup

Plugin Slug:
elisqlreports
Installations
500+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Critical
The vulnerability has not been patched. You should deactivate the plugin.

WP Email Delivery

Plugin Slug:
wp-email-delivery
Installations
100+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

AdSense Privacy Policy

Plugin:
AdSense Privacy Policy
Plugin Slug:
adsense-privacy-policy
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Advanced Dewplayer

Plugin:
Advanced Dewplayer
Plugin Slug:
advanced-dewplayer
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

AHAthat

Plugin:
AHAthat
Plugin Slug:
ahathat
Vulnerability:
SQL Injection
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

AI Preloader

Plugin:
AI Preloader
Plugin Slug:
ai-preloader
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Alert Box Block – Display notice/alerts in the front end

Plugin:
Alert Box Block – Display notice/alerts in the front end
Plugin Slug:
alert-box-block
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

AlphaOmega Captcha & Anti-Spam Filter

Plugin:
AlphaOmega Captcha & Anti-Spam Filter
Plugin Slug:
alphaomega-captcha-anti-spam
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

ANAC XML Render

Plugin:
ANAC XML Render
Plugin Slug:
anac-xml-render
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Arrow Maps

Plugin:
Arrow Maps
Plugin Slug:
ap-google-maps
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

AppExperts – WordPress to Mobile App – WooCommerce to iOs and Android Apps

Plugin:
AppExperts – WordPress to Mobile App – WooCommerce to iOs and Android Apps
Plugin Slug:
appexperts
Vulnerability:
Sensitive Data Exposure
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

AppReview

Plugin:
AppReview
Plugin Slug:
appreview
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Are you robot google recaptcha for wordpress

Plugin:
Are you robot google recaptcha for wordpress
Plugin Slug:
are-you-robot-recaptcha
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

ARPrice

Plugin:
ARPrice
Plugin Slug:
arprice
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

AuMenu

Plugin:
AuMenu
Plugin Slug:
aumenu
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Auto Load Next Post

Plugin:
Auto Load Next Post
Plugin Slug:
auto-load-next-post
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

AvaiBook

Plugin:
AvaiBook
Plugin Slug:
avaibook
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Awesome Logos

Plugin:
Awesome Logos
Plugin Slug:
awesome-logos
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Critical
The vulnerability has not been patched. You should deactivate the plugin.

banner-manager

Plugin:
banner-manager
Plugin Slug:
banner-manager
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.
Plugin:
Beautiful Link Preview
Plugin Slug:
beautiful-link-preview
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Block Logic

Plugin:
Block Logic
Plugin Slug:
block-logic
Vulnerability:
Remote Code Execution (RCE)
Patched in Version:
No Fix
Severity Score:
Critical
The vulnerability has not been patched. You should deactivate the plugin.

Blue Captcha

Plugin:
Blue Captcha
Plugin Slug:
blue-captcha
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

BMo Expo

Plugin:
BMo Expo
Plugin Slug:
bmo-expo
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Browser Address Bar Color

Plugin:
Browser Address Bar Color
Plugin Slug:
browser-address-bar-color
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Cackle

Plugin:
Cackle
Plugin Slug:
cackle
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

CallPhone’r

Plugin:
CallPhone’r
Plugin Slug:
callphoner
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

CAS Maestro

Plugin:
CAS Maestro
Plugin Slug:
cas-maestro
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Cazamba

Plugin:
Cazamba
Plugin Slug:
cazamba
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Contact Form 7 Material Design

Plugin:
Contact Form 7 Material Design
Plugin Slug:
cf7-material-design
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

UTM tags tracking for Contact Form 7

Plugin:
UTM tags tracking for Contact Form 7
Plugin Slug:
cf7-utm-tracking
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

cits-support-svg-webp-media-upload

Plugin:
cits-support-svg-webp-media-upload
Plugin Slug:
cits-support-svg-webp-media-upload
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.
Plugin:
Clink
Plugin Slug:
clink
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Code Clone

Plugin:
Code Clone
Plugin Slug:
code-clone
Vulnerability:
SQL Injection
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

CG Button

Plugin:
CG Button
Plugin Slug:
content-glass-button
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Cookies Pro

Plugin:
Cookies Pro
Plugin Slug:
cookies-pro
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.
Plugin:
CopyLink
Plugin Slug:
copy-link
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Menu Duplicator

Plugin:
Menu Duplicator
Plugin Slug:
copy-menu
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

CryoKey

Plugin:
CryoKey
Plugin Slug:
cryokey
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

CSV to Responsive Tables

Plugin:
CSV to Responsive Tables
Plugin Slug:
csv-to-webpage-plugin
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

cTabs

Plugin:
cTabs
Plugin Slug:
ctabs
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

custom-field-list-widget

Plugin:
custom-field-list-widget
Plugin Slug:
custom-field-list-widget
Vulnerability:
Local File Inclusion
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Custom Product Stickers for Woocommerce

Plugin:
Custom Product Stickers for Woocommerce
Plugin Slug:
custom-product-stickers-for-woocommerce
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Custom Script Integration

Plugin:
Custom Script Integration
Plugin Slug:
custom-script-integration
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Custom Smilies

Plugin:
Custom Smilies
Plugin Slug:
custom-smilies-se
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Management-screen-droptiles

Plugin:
Management-screen-droptiles
Plugin Slug:
cxc-sawa
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

WP Database Audit

Plugin:
WP Database Audit
Plugin Slug:
database-audit
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Driving Directions

Plugin:
Driving Directions
Plugin Slug:
ddirections
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

DesignThemes Core Features

Plugin:
DesignThemes Core Features
Plugin Slug:
designthemes-core-features
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Display Post Meta

Plugin:
Display Post Meta
Plugin Slug:
display-post-meta
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Docpro

Plugin:
Docpro
Plugin Slug:
docpro
Vulnerability:
Local File Inclusion
Patched in Version:
No Fix
Severity Score:
Critical
The vulnerability has not been patched. You should deactivate the plugin.

????? ???? ??????? ????

Plugin:
????? ???? ??????? ????
Plugin Slug:
dokme
Vulnerability:
SQL Injection
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Easy Custom Admin Bar

Plugin:
Easy Custom Admin Bar
Plugin Slug:
easy-custom-admin-bar
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Easy Page Transition

Plugin:
Easy Page Transition
Plugin Slug:
easy-page-transition
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

En Masse

Plugin:
En Masse
Plugin Slug:
en-masse-wp
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

External image replace

Plugin:
External image replace
Plugin Slug:
external-image-replace
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Secret Meta

Plugin:
Secret Meta
Plugin Slug:
facebook-secret-meta
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Fancybox Plus

Plugin:
Fancybox Plus
Plugin Slug:
fancybox-plus
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

File Away

Plugin:
File Away
Plugin Slug:
file-away
Vulnerability:
Arbitrary File Download
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

File Away

Plugin:
File Away
Plugin Slug:
file-away
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Critical
The vulnerability has not been patched. You should deactivate the plugin.
Plugin:
Fiverr.com Official Search Box
Plugin Slug:
fiverr-official-search-box
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Fix Rss Feeds

Plugin:
Fix Rss Feeds
Plugin Slug:
fix-rss-feed
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Flickr set slideshows

Plugin:
Flickr set slideshows
Plugin Slug:
flickr-set-slideshows
Vulnerability:
SQL Injection
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Flipdish Ordering System

Plugin:
Flipdish Ordering System
Plugin Slug:
flipdish-ordering-system
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

FOMO Pay Chinese Payment Solution

Plugin:
FOMO Pay Chinese Payment Solution
Plugin Slug:
fomo-payment-gateway-for-woocommerce
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Frndzk Expandable Bottom Bar

Plugin:
Frndzk Expandable Bottom Bar
Plugin Slug:
frndzk-expandable-bottom-bar
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

custom-post-edit

Plugin:
custom-post-edit
Plugin Slug:
front-end-post-edit
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Frontend Post Submission

Plugin:
Frontend Post Submission
Plugin Slug:
frontend-post-submission
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

GDPR Tools

Plugin:
GDPR Tools
Plugin Slug:
gdpr-tools
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Generate Post Thumbnails

Plugin:
Generate Post Thumbnails
Plugin Slug:
generate-post-thumbnails
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

GetShop ecommerce

Plugin:
GetShop ecommerce
Plugin Slug:
getshop-ecommerce
Vulnerability:
Local File Inclusion
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Gravity 2 PDF

Plugin:
Gravity 2 PDF
Plugin Slug:
gf2pdf
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

GMO Font Agent

Plugin:
GMO Font Agent
Plugin Slug:
gmo-font-agent
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Google Plus

Plugin:
Google Plus
Plugin Slug:
google-plus-google
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Gotcha

Plugin:
Gotcha
Plugin Slug:
gotcha-gesture-based-captcha
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

GP Back To Top

Plugin:
GP Back To Top
Plugin Slug:
gp-back-to-top
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Hacklog Remote Image Autosave

Plugin:
Hacklog Remote Image Autosave
Plugin Slug:
hacklog-remote-image-autosave
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

IG Shortcodes

Plugin:
IG Shortcodes
Plugin Slug:
ig-shortcodes
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Image Captcha

Plugin:
Image Captcha
Plugin Slug:
image-captcha
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Image Slider / Slideshow Pearlbells

Plugin:
Image Slider / Slideshow Pearlbells
Plugin Slug:
image-slider-pearlbells
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Improve My City

Plugin:
Improve My City
Plugin Slug:
improve-my-city
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

include-file

Plugin:
include-file
Plugin Slug:
include-file
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Include URL

Plugin:
Include URL
Plugin Slug:
include-url
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Info Boxes Shortcode and Widget

Plugin:
Info Boxes Shortcode and Widget
Plugin Slug:
info-boxes-shortcode-and-widget
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Infugrator

Plugin:
Infugrator
Plugin Slug:
infugrator
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Instant Appointment

Plugin:
Instant Appointment
Plugin Slug:
instant-appointment
Vulnerability:
Arbitrary File Upload
Patched in Version:
No Fix
Severity Score:
Critical
The vulnerability has not been patched. You should deactivate the plugin.

issuuPress

Plugin:
issuuPress
Plugin Slug:
issuupress
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

JiangQie Official Website Mini Program

Plugin:
JiangQie Official Website Mini Program
Plugin Slug:
jiangqie-official-website-mini-program
Vulnerability:
SQL Injection
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

jQuery Dropdown Menu

Plugin:
jQuery Dropdown Menu
Plugin Slug:
jquery-drop-down-menu-plugin
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Key4ce osTicket Bridge

Plugin:
Key4ce osTicket Bridge
Plugin Slug:
key4ce-osticket-bridge
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

LH OGP Meta

Plugin:
LH OGP Meta
Plugin Slug:
lh-ogp-meta-tags
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Lightview Plus

Plugin:
Lightview Plus
Plugin Slug:
lightview-plus
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

LinkedIn Lite

Plugin:
LinkedIn Lite
Plugin Slug:
linkedin-lite
Vulnerability:
Local File Inclusion
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

LIVE TV

Plugin:
LIVE TV
Plugin Slug:
live-tv
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Login Redirect

Plugin:
Login Redirect
Plugin Slug:
login-redirect
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Map Contact

Plugin:
Map Contact
Plugin Slug:
map-contact
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Message ticker

Plugin:
Message ticker
Plugin Slug:
message-ticker
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Mobile Navigation

Plugin:
Mobile Navigation
Plugin Slug:
mobile-navigation
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Multi Video Box

Plugin:
Multi Video Box
Plugin Slug:
multi-video-box
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Music Press Pro

Plugin:
Music Press Pro
Plugin Slug:
music-press-pro
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

My Bootstrap Menu

Plugin:
My Bootstrap Menu
Plugin Slug:
my-bootstrap-menu
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

My Default Post Content

Plugin:
My Default Post Content
Plugin Slug:
my-default-post-content
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Narnoo Operator

Plugin:
Narnoo Operator
Plugin Slug:
narnoo-shortcodes
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.
Plugin:
NextGEN Gallery Voting
Plugin Slug:
nextgen-gallery-voting
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

NS Simple Intro Loader

Plugin:
NS Simple Intro Loader
Plugin Slug:
ns-simple-intro-loader
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Easy 301 Redirects

Plugin:
Easy 301 Redirects
Plugin Slug:
odihost-easy-redirect-301
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Off Page SEO

Plugin:
Off Page SEO
Plugin Slug:
off-page-seo
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Omnify

Plugin:
Omnify
Plugin Slug:
omnify-widget
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

OSS Upload

Plugin:
OSS Upload
Plugin Slug:
oss-upload
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Pixobe Cartography

Plugin:
Pixobe Cartography
Plugin Slug:
pixobe-cartography
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.
Plugin:
Pretty file links
Plugin Slug:
pretty-file-links
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Product Puller

Plugin:
Product Puller
Plugin Slug:
product-puller
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Pro Rank Tracker

Plugin:
Pro Rank Tracker
Plugin Slug:
proranktracker
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Random Quotes

Plugin:
Random Quotes
Plugin Slug:
random-quotes
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

RDP inGroups+

Plugin:
RDP inGroups+
Plugin Slug:
rdp-ingroups
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

RDP Linkedin Login

Plugin:
RDP Linkedin Login
Plugin Slug:
rdp-linkedin-login
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.
Plugin:
Related Posts via Categories
Plugin Slug:
related-posts-via-categories
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Replace Default Words

Plugin:
Replace Default Words
Plugin Slug:
replace-default-words
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Rewrite

Plugin:
Rewrite
Plugin Slug:
rewrite
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Rizzi Guestbook

Plugin:
Rizzi Guestbook
Plugin Slug:
rizzi-guestbook
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

RWS Enquiry And Lead Follow-up

Plugin:
RWS Enquiry And Lead Follow-up
Plugin Slug:
rws-enquiry
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

s2Member Pro

Plugin:
s2Member Pro
Plugin Slug:
s2member-pro
Vulnerability:
Local File Inclusion
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Schedule

Plugin:
Schedule
Plugin Slug:
schedule
Vulnerability:
SQL Injection
Patched in Version:
No Fix
Severity Score:
Critical
The vulnerability has not been patched. You should deactivate the plugin.

Shuffle

Plugin:
Shuffle
Plugin Slug:
shuffle
Vulnerability:
SQL Injection
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Simple Optimizer

Plugin:
Simple Optimizer
Plugin Slug:
simple-optimizer
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Simple Post Series

Plugin:
Simple Post Series
Plugin Slug:
simple-post-series
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Simple Rating

Plugin:
Simple Rating
Plugin Slug:
simple-rating
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Site Editor Google Map

Plugin:
Site Editor Google Map
Plugin Slug:
site-editor-google-map
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Sleekplan

Plugin:
Sleekplan
Plugin Slug:
sleekplan
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

SoundCloud Ultimate

Plugin:
SoundCloud Ultimate
Plugin Slug:
soundcloud-ultimate
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

sourceplay-navermap

Plugin:
sourceplay-navermap
Plugin Slug:
sourceplay-navermap
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

SpatialMatch IDX

Plugin:
SpatialMatch IDX
Plugin Slug:
spatialmatch-free-lifestyle-search
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

SpeakPipe

Plugin:
SpeakPipe
Plugin Slug:
speakpipe-voicemail-for-websites
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

STEdb Forms

Plugin:
STEdb Forms
Plugin Slug:
stedb-forms
Vulnerability:
SQL Injection
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Stencies

Plugin:
Stencies
Plugin Slug:
stencies
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Super Simple Subscriptions

Plugin:
Super Simple Subscriptions
Plugin Slug:
super-simple-subscriptions
Vulnerability:
SQL Injection
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

SUPER RESPONSIVE SLIDER

Plugin:
SUPER RESPONSIVE SLIDER
Plugin Slug:
super-slider
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Super Static Cache

Plugin:
Super Static Cache
Plugin Slug:
super-static-cache
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Teleport

Plugin:
Teleport
Plugin Slug:
teleport
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Translator

Plugin:
Translator
Plugin Slug:
translator
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Trust Payments Gateway for WooCommerce

Plugin:
Trust Payments Gateway for WooCommerce
Plugin Slug:
trust-payments-hosted-payment-pages-integration
Vulnerability:
SQL Injection
Patched in Version:
No Fix
Severity Score:
Critical
The vulnerability has not been patched. You should deactivate the plugin.

Typekit plugin for WordPress

Plugin:
Typekit plugin for WordPress
Plugin Slug:
typekit
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Top Bar

Plugin:
Top Bar
Plugin Slug:
ultimate-bar
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.
Plugin:
ULTIMATE VIDEO GALLERY
Plugin Slug:
ultimate-gallery
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Upload Quota per User

Plugin:
Upload Quota per User
Plugin Slug:
upload-quota-per-user
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Visual Text Editor

Plugin:
Visual Text Editor
Plugin Slug:
visual-text-editor
Vulnerability:
Remote Code Execution (RCE)
Patched in Version:
No Fix
Severity Score:
Critical
The vulnerability has not been patched. You should deactivate the plugin.

wA11y – The Web Accessibility Toolbox

Plugin:
wA11y – The Web Accessibility Toolbox
Plugin Slug:
wa11y
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Já-Já Pagamentos for WooCommerce

Plugin:
Já-Já Pagamentos for WooCommerce
Plugin Slug:
wc-ja-ja-pagamentos-multicaixa-express
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

WooCommerce Multivendor Marketplace – REST API

Plugin:
WooCommerce Multivendor Marketplace – REST API
Plugin Slug:
wcfm-marketplace-rest-api
Vulnerability:
SQL Injection
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Weather Layer

Plugin:
Weather Layer
Plugin Slug:
weather-layer
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Bitcoin / AltCoin Payment Gateway for WooCommerce

Plugin:
Bitcoin / AltCoin Payment Gateway for WooCommerce
Plugin Slug:
woo-altcoin-payment-gateway
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

WordPress Admin Bar Improved

Plugin:
WordPress Admin Bar Improved
Plugin Slug:
wordpress-admin-bar-improved
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Secure Invites

Plugin:
Secure Invites
Plugin Slug:
wordpress-mu-secure-invites
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

WordPress SQL Backup

Plugin:
WordPress SQL Backup
Plugin Slug:
wordpress-sql-backup
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Theme Demo Bar

Plugin:
Theme Demo Bar
Plugin Slug:
wordpress-theme-demo-bar
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Ads24 Lite

Plugin:
Ads24 Lite
Plugin Slug:
wp-ad-management
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

WP Azure offload

Plugin:
WP Azure offload
Plugin Slug:
wp-azure-offload
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

WP Colorful Tag Cloud

Plugin:
WP Colorful Tag Cloud
Plugin Slug:
wp-colorful-tag-cloud
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

WP Contact Form III

Plugin:
WP Contact Form III
Plugin Slug:
wp-contact-form-iii
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

WP e-Commerce Style Email

Plugin:
WP e-Commerce Style Email
Plugin Slug:
wp-e-commerce-style-email
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Critical
The vulnerability has not been patched. You should deactivate the plugin.
Plugin:
WP Featured Entries
Plugin Slug:
wp-featured-entries
Vulnerability:
SQL Injection
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

FoodBakery

Plugin:
FoodBakery
Plugin Slug:
wp-foodbakery
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

WP Google Calendar Manager

Plugin:
WP Google Calendar Manager
Plugin Slug:
wp-gcalendar
Vulnerability:
SQL Injection
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

WP Hotjar

Plugin:
WP Hotjar
Plugin Slug:
wp-hotjar
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

WP Multistore Locator

Plugin:
WP Multistore Locator
Plugin Slug:
wp-multi-store-locator
Vulnerability:
SQL Injection
Patched in Version:
No Fix
Severity Score:
Critical
The vulnerability has not been patched. You should deactivate the plugin.

WP Odoo Form Integrator

Plugin:
WP Odoo Form Integrator
Plugin Slug:
wp-odoo-form-integrator
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

WP Parallax Content Slider

Plugin:
WP Parallax Content Slider
Plugin Slug:
wp-parallax-content-slider
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

WP Profitshare

Plugin:
WP Profitshare
Plugin Slug:
wp-profitshare
Vulnerability:
SQL Injection
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

WP Ride Booking

Plugin:
WP Ride Booking
Plugin Slug:
wp-ride-booking
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

WP Social Widget

Plugin:
WP Social Widget
Plugin Slug:
wp-social-widget
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

WordPres ????

Plugin:
WordPres ????
Plugin Slug:
wp2wb
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

WP Event Ticketing

Plugin:
WP Event Ticketing
Plugin Slug:
wpeventticketing
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Your Lightbox

Plugin:
Your Lightbox
Plugin Slug:
your-lightbox
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Yummly Rich Recipes

Plugin:
Yummly Rich Recipes
Plugin Slug:
yummly-rich-recipes
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Zalo Live Chat

Plugin:
Zalo Live Chat
Plugin Slug:
zalo-live-chat
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

ZD Scribd iPaper

Plugin:
ZD Scribd iPaper
Plugin Slug:
zd-scribd-ipaper
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

ZenphotoPress

Plugin:
ZenphotoPress
Plugin Slug:
zenphotopress
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

ZhinaTwitterWidget

Plugin:
ZhinaTwitterWidget
Plugin Slug:
zhina-twitter-widget
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.
Plugin:
Zielke Design Project Gallery
Plugin Slug:
zielke-design-project-gallery
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

WP Ghost (Hide My WP Ghost) – Security & Firewall

Plugin Slug:
hide-my-wp
Installations
200,000+
Vulnerability:
Local File Inclusion
Patched in Version:
5.4.02
Severity Score:
Critical
The vulnerability has been patched, so you should update to version 5.4.02.
Plugin Slug:
photo-gallery
Installations
200,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.8.33
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.8.33.

Custom Twitter Feeds – A Tweets Widget or X Feed Widget

Plugin Slug:
custom-twitter-feeds
Installations
100,000+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
2.3.0
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.3.0.

GiveWP – Donation Plugin and Fundraising Platform

Plugin Slug:
give
Installations
100,000+
Vulnerability:
Broken Access Control
Patched in Version:
3.22.2
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.22.2.

GiveWP – Donation Plugin and Fundraising Platform

Plugin Slug:
give
Installations
100,000+
Vulnerability:
Broken Access Control
Patched in Version:
3.22.1
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.22.1.

Pods – Custom Content Types and Fields

Plugin Slug:
pods
Installations
100,000+
Vulnerability:
SQL Injection
Patched in Version:
3.2.8.2
Severity Score:
High
The vulnerability has been patched, so you should update to version 3.2.8.2.

HT Mega – Absolute Addons For Elementor

Plugin Slug:
ht-mega-for-elementor
Installations
90,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.8.4
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.8.4.

Nested Pages

Plugin Slug:
wp-nested-pages
Installations
90,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
3.2.13
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.2.13.

Site Reviews

Plugin Slug:
site-reviews
Installations
60,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
7.2.5
Severity Score:
High
The vulnerability has been patched, so you should update to version 7.2.5.

Export and Import Users and Customers

Plugin Slug:
users-customers-import-export-for-wp-woocommerce
Installations
60,000+
Vulnerability:
Arbitrary File Download
Patched in Version:
2.6.3
Severity Score:
Low
The vulnerability has been patched, so you should update to version 2.6.3.

Export and Import Users and Customers

Plugin Slug:
users-customers-import-export-for-wp-woocommerce
Installations
60,000+
Vulnerability:
PHP Object Injection
Patched in Version:
2.6.3
Severity Score:
High
The vulnerability has been patched, so you should update to version 2.6.3.

Export and Import Users and Customers

Plugin Slug:
users-customers-import-export-for-wp-woocommerce
Installations
60,000+
Vulnerability:
Arbitrary File Deletion
Patched in Version:
2.6.3
Severity Score:
Low
The vulnerability has been patched, so you should update to version 2.6.3.

Export and Import Users and Customers

Plugin Slug:
users-customers-import-export-for-wp-woocommerce
Installations
60,000+
Vulnerability:
Server Side Request Forgery (SSRF)
Patched in Version:
2.6.3
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.6.3.

Order Export & Order Import for WooCommerce

Plugin Slug:
order-import-export-for-woocommerce
Installations
50,000+
Vulnerability:
Arbitrary File Download
Patched in Version:
2.6.1
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.6.1.

Order Export & Order Import for WooCommerce

Plugin Slug:
order-import-export-for-woocommerce
Installations
50,000+
Vulnerability:
PHP Object Injection
Patched in Version:
2.6.1
Severity Score:
High
The vulnerability has been patched, so you should update to version 2.6.1.

Order Export & Order Import for WooCommerce

Plugin Slug:
order-import-export-for-woocommerce
Installations
50,000+
Vulnerability:
Arbitrary File Deletion
Patched in Version:
2.6.1
Severity Score:
Low
The vulnerability has been patched, so you should update to version 2.6.1.

Order Export & Order Import for WooCommerce

Plugin Slug:
order-import-export-for-woocommerce
Installations
50,000+
Vulnerability:
Server Side Request Forgery (SSRF)
Patched in Version:
2.6.1
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.6.1.

Age Gate

Plugin:
Age Gate
Plugin Slug:
age-gate
Installations
40,000+
Vulnerability:
Local File Inclusion
Patched in Version:
3.5.4
Severity Score:
Critical
The vulnerability has been patched, so you should update to version 3.5.4.

NP Quote Request for WooCommerce

Plugin Slug:
woo-rfq-for-woocommerce
Installations
9,000+
Vulnerability:
Insecure Direct Object References (IDOR)
Patched in Version:
1.9.180
Severity Score:
High
The vulnerability has been patched, so you should update to version 1.9.180.

WP Compress – Instant Performance & Speed Optimization

Plugin Slug:
wp-compress-image-optimizer
Installations
8,000+
Vulnerability:
Server Side Request Forgery (SSRF)
Patched in Version:
6.30.16
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 6.30.16.

ProfileGrid – User Profiles, Groups and Communities

Plugin Slug:
profilegrid-user-profiles-groups-and-communities
Installations
7,000+
Vulnerability:
SQL Injection
Patched in Version:
5.9.4.8
Severity Score:
High
The vulnerability has been patched, so you should update to version 5.9.4.8.

Newsletters

Plugin Slug:
newsletters-lite
Installations
3,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
4.9.9.8
Severity Score:
High
The vulnerability has been patched, so you should update to version 4.9.9.8.

Digital License Manager

Plugin Slug:
digital-license-manager
Installations
600+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.7.4
Severity Score:
High
The vulnerability has been patched, so you should update to version 1.7.4.

Web Directory Free

Plugin Slug:
web-directory-free
Installations
500+
Vulnerability:
SQL Injection
Patched in Version:
1.7.7
Severity Score:
Critical
The vulnerability has been patched, so you should update to version 1.7.7.

Formality

Plugin:
Formality
Plugin Slug:
formality
Installations
200+
Vulnerability:
Local File Inclusion
Patched in Version:
1.5.8
Severity Score:
High
The vulnerability has been patched, so you should update to version 1.5.8.

Your Friendly Drag and Drop Page Builder — Make Builder

Plugin Slug:
make-builder
Installations
200+
Vulnerability:
Server Side Request Forgery (SSRF)
Patched in Version:
1.1.11
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.1.11.

DICOM Support

Plugin Slug:
dicom-support
Installations
100+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
0.10.7
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 0.10.7.

Your Simple SVG Support

Plugin Slug:
your-simple-svg-support
Installations
10+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.0.2
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.0.2.

Bitspecter Suite

Plugin Slug:
bitspecter-suite
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.1.0
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.1.0.

BoomBox Theme Extensions

Plugin:
BoomBox Theme Extensions
Plugin Slug:
boombox-theme-extensions
Vulnerability:
Privilege Escalation
Patched in Version:
1.8.1
Severity Score:
High
The vulnerability has been patched, so you should update to version 1.8.1.

Service Finder Booking

Plugin:
Service Finder Booking
Plugin Slug:
sf-booking
Vulnerability:
Privilege Escalation
Patched in Version:
5.1
Severity Score:
Critical
The vulnerability has been patched, so you should update to version 5.1.

FoodBakery

Plugin:
FoodBakery
Plugin Slug:
wp-foodbakery
Vulnerability:
Broken Access Control
Patched in Version:
4.8
Severity Score:
High
The vulnerability has been patched, so you should update to version 4.8.

WordPress Themes — 5 Patched / 9 Unpatched

AuraMart

Theme:
AuraMart
Theme Slug:
auramart
Downloads
802
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should switch themes.

Hester

Theme:
Hester
Theme Slug:
hester
Downloads
7,268
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should switch themes.

MorningTime Lite

Theme Slug:
morningtime-lite
Downloads
40,087
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should switch themes.

StoreBiz

Theme:
StoreBiz
Theme Slug:
storebiz
Downloads
102,239
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should switch themes.

Build

Theme:
Build
Theme Slug:
build
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should switch themes.

City Store

Theme:
City Store
Theme Slug:
city-store
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should switch themes.

newseqo

Theme:
newseqo
Theme Slug:
newseqo
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should switch themes.

RainbowNews

Theme:
RainbowNews
Theme Slug:
rainbownews
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should switch themes.

Whitish Lite

Theme:
Whitish Lite
Theme Slug:
whitish-lite
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should switch themes.

Altair

Theme:
Altair
Theme Slug:
altair
Vulnerability:
Settings Change
Patched in Version:
5.2.5
Severity Score:
Critical
The vulnerability has been patched, so you should update to version 5.2.5.

CozyStay

Theme:
CozyStay
Theme Slug:
cozystay
Vulnerability:
Broken Access Control
Patched in Version:
1.7.1
Severity Score:
High
The vulnerability has been patched, so you should update to version 1.7.1.

CozyStay

Theme:
CozyStay
Theme Slug:
cozystay
Vulnerability:
PHP Object Injection
Patched in Version:
1.7.1
Severity Score:
Critical
The vulnerability has been patched, so you should update to version 1.7.1.

MinimogWP

Theme:
MinimogWP
Theme Slug:
minimog
Vulnerability:
Local File Inclusion
Patched in Version:
3.8.0
Severity Score:
Critical
The vulnerability has been patched, so you should update to version 3.8.0.

TinySalt

Theme:
TinySalt
Theme Slug:
tinysalt
Vulnerability:
PHP Object Injection
Patched in Version:
3.10.0
Severity Score:
Critical
The vulnerability has been patched, so you should update to version 3.10.0.

Solid Security is part of Solid Suite — The best foundation for WordPress websites.

Every WordPress site needs security, backups, and management tools. That’s Solid Suite — an integrated bundle of three plugins: Solid Security, Solid Backups, and Solid Central. You also get access to Solid Academy’s learning resources for WordPress professionals. Build your next WordPress website on a solid foundation with Solid Suite!

Get Solid Security