WordPress Vulnerability Report

WordPress Vulnerability Report — May 14, 2025

Since last week, 234 new vulnerabilities emerged in the WordPress ecosystem, including 230 plugins and 4 themes. 92 of the vulnerable plugins remain unpatched, but Solid Security Pro users are protected by virtual patching from Patchstack.

Avatar photo
Sarah Ulmer

In this report, 234 vulnerabilities have been publicly disclosed. Security patches for 142 of these plugins and themes are available now, so run those updates as soon as possible. If you’re a Solid Security Pro user, the version management tool may have already warned you and updated these plugins, depending on your settings.

Additionally, there are 92 plugin and theme vulnerabilities, and no patch has been available yet. If you’re a Solid Security Pro user, those vulnerabilities are already protected by the Solid Security firewall. Virtual patches from Patchstack will be applied when a vulnerability is considered high or medium risk. If no patch is forthcoming from the vendor or the vulnerable software has been marked “closed” and dropped from the official WordPress repositories, you should deactivate it soon and look for alternative solutions.

Along with poor user account security, vulnerable plugins and themes are among the top reasons why WordPress websites get hacked. Unfortunately, cyberattacks are increasing in volume and sophistication. They’re also increasingly aimed at small to mid-sized businesses.

Our WordPress Vulnerability Report covers the latest emerging WordPress plugin, theme, and core vulnerabilities. Each vulnerability will have a severity rating of LowMediumHigh, or Critical. Responsible disclosure of vulnerabilities is essential to keeping the WordPress community safe. Please share this report to help spread the word and make WordPress — and the web — more secure.

WordPress Core

WordPress 6.8.1 has been released! This maintenance release includes fixes for 15 bugs throughout Core and the Block Editor, addressing issues affecting multiple areas of WordPress, including the block editor, multisite, and REST API. For a full list, refer to the release candidate announcement.

Plus, WordCamp Europe 2025 lands in Basel, Switzerland, June 5-7! Connect with WordPress enthusiasts, developers, and pros for three days of learning, networking, and collaboration with the global community.

No new core vulnerabilities were disclosed this week.

WordPress Plugins — 138 Patched / 92 Unpatched

Plugin Slug:
intelly-related-posts
Installations
100,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

List category posts

Plugin Slug:
list-category-posts
Installations
90,000+
Vulnerability:
Local File Inclusion
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

WP Maintenance

Plugin Slug:
wp-maintenance
Installations
50,000+
Vulnerability:
PHP Object Injection
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

WordPress Infinite Scroll – Ajax Load More

Plugin Slug:
ajax-load-more
Installations
40,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

User Login History

Plugin Slug:
user-login-history
Installations
10,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Easy PayPal & Stripe Buy Now Button

Plugin Slug:
wp-ecommerce-paypal
Installations
10,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Spiraclethemes Site Library

Plugin Slug:
spiraclethemes-site-library
Installations
2,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

WPBakery Visual Composer WHMCS Elements

Plugin Slug:
void-visual-whmcs-element
Installations
2,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

WP-Recall – Registration, Profile, Commerce & More

Plugin Slug:
wp-recall
Installations
2,000+
Vulnerability:
Local File Inclusion
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

aBlocks – WordPress Gutenberg Blocks

Plugin Slug:
ablocks
Installations
1,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Web Accessibility with Max Access

Plugin Slug:
accessibility-toolbar
Installations
1,000+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Amazon Product in a Post Plugin

Plugin Slug:
amazon-product-in-a-post-plugin
Installations
1,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Awin – Advertiser Tracking for WooCommerce

Plugin Slug:
awin-advertiser-tracking
Installations
1,000+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

belingoGeo

Plugin:
belingoGeo
Plugin Slug:
belingogeo
Installations
1,000+
Vulnerability:
Arbitrary File Download
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

BMI Adult & Kid Calculator

Plugin Slug:
bmi-adultkid-calculator
Installations
1,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

CBX Map for Google Map & OpenStreetMap

Plugin Slug:
cbxgooglemap
Installations
1,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

ContentStudio

Plugin Slug:
contentstudio
Installations
1,000+
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Contribuinte Checkout

Plugin Slug:
contribuinte-checkout
Installations
1,000+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

DoFollow Case by Case

Plugin Slug:
dofollow-case-by-case
Installations
1,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

DoFollow Case by Case

Plugin Slug:
dofollow-case-by-case
Installations
1,000+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Ebook Store

Plugin Slug:
ebook-store
Installations
1,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Email Notification on Login

Plugin Slug:
email-notification-on-login
Installations
1,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

????? ?? ???? – ???? ?? ????

Plugin Slug:
pgall-for-woocommerce
Installations
1,000+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Sidebar Manager Light

Plugin Slug:
sidebar-manager-light
Installations
1,000+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Smaily for WP

Plugin Slug:
smaily-for-wp
Installations
1,000+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Woobox

Plugin:
Woobox
Plugin Slug:
woobox
Installations
1,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Woobox

Plugin:
Woobox
Plugin Slug:
woobox
Installations
1,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

WordPress CRM Plugin – WP-CRM System

Plugin Slug:
wp-crm-system
Installations
1,000+
Vulnerability:
PHP Object Injection
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

WordPress Webinar Plugin – WebinarPress

Plugin Slug:
wp-webinarsystem
Installations
1,000+
Vulnerability:
Server Side Request Forgery (SSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

WPSpeed

Plugin:
WPSpeed
Plugin Slug:
wpspeed
Installations
1,000+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

xili-tidy-tags

Plugin Slug:
xili-tidy-tags
Installations
1,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.
Plugin Slug:
bulk-featured-image
Installations
900+
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Really Simple Under Construction Page

Plugin Slug:
really-simple-under-construction
Installations
700+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

WP jQuery DataTable

Plugin Slug:
wp-jquery-datatable
Installations
700+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Beacon Lead Magnets and Lead Capture

Plugin Slug:
beacon-by
Installations
600+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Submission DOM tracking for Contact Form 7

Plugin Slug:
cf7-submission-dom-tracking
Installations
600+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Color Your Bar

Plugin Slug:
color-your-bar
Installations
600+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

CookieCode

Plugin:
CookieCode
Plugin Slug:
cookiecode
Installations
600+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

EasyMe Connect

Plugin Slug:
easyme-connect
Installations
600+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

LiveAgent – Omnichannel Help Desk & Live Chat Software

Plugin Slug:
liveagent
Installations
600+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

N360 | Splash Screen

Plugin Slug:
n360-splash-screen
Installations
600+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Show All Comments

Plugin Slug:
show-all-comments-in-one-page
Installations
600+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

WP Discord Invite

Plugin Slug:
wp-discord-invite
Installations
600+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

WP Pipes

Plugin:
WP Pipes
Plugin Slug:
wp-pipes
Installations
600+
Vulnerability:
Server Side Request Forgery (SSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

DELUCKS SEO

Plugin Slug:
delucks-seo
Installations
500+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Lead Form Data Collection to CRM

Plugin Slug:
wp-leads-builder-any-crm
Installations
500+
Vulnerability:
Privilege Escalation
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

ELEX WordPress HelpDesk & Customer Ticketing System

Plugin Slug:
elex-helpdesk-customer-support-ticket-system
Installations
400+
Vulnerability:
Arbitrary File Upload
Patched in Version:
No Fix
Severity Score:
Critical
The vulnerability has not been patched. You should deactivate the plugin.

FunnelCockpit

Plugin Slug:
funnelcockpit
Installations
400+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Ajar in5 Embed

Plugin Slug:
ajar-productions-in5-embed
Installations
300+
Vulnerability:
Arbitrary File Upload
Patched in Version:
No Fix
Severity Score:
Critical
The vulnerability has not been patched. You should deactivate the plugin.

Pays – WooCommerce Payment Gateway

Plugin Slug:
axima-payment-gateway
Installations
300+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Integrations of Zoho CRM with Elementor form

Plugin Slug:
integrations-of-zoho-crm-with-elementor-form
Installations
300+
Vulnerability:
Open Redirection
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Calculate Prices based on Distance For WooCommerce

Plugin Slug:
calculate-prices-based-on-distance-for-woocommerce
Installations
100+
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Credova Financial

Plugin Slug:
credova-financial
Installations
100+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Soccer Live Scores

Plugin Slug:
soccer-live-scores
Installations
100+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

PSW Front-end Login & Registration

Plugin Slug:
psw-login-and-registration
Installations
90+
Vulnerability:
Broken Authentication
Patched in Version:
No Fix
Severity Score:
Critical
The vulnerability has not been patched. You should deactivate the plugin.

WP Podcasts Manager

Plugin Slug:
wp-podcasts-manager
Installations
80+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Supertext Translation and Proofreading

Plugin Slug:
polylang-supertext
Installations
60+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

StoreKeeper for WooCommerce

Plugin Slug:
storekeeper-for-woocommerce
Installations
50+
Vulnerability:
Arbitrary File Upload
Patched in Version:
No Fix
Severity Score:
Critical
The vulnerability has not been patched. You should deactivate the plugin.

CarDealerPress

Plugin Slug:
cardealerpress
Installations
40+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

ELEX Product Feed for WooCommerce

Plugin Slug:
elex-product-feed
Installations
30+
Vulnerability:
SQL Injection
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

BNS Twitter Follow Button

Plugin Slug:
bns-twitter-follow-button
Installations
10+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

1 Click WordPress Migration

Plugin:
1 Click WordPress Migration
Plugin Slug:
1-click-migration
Vulnerability:
Arbitrary File Upload
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

AHAthat

Plugin:
AHAthat
Plugin Slug:
ahathat
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.
Plugin:
Awesome Gallery
Plugin Slug:
awesome-gallery
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

External image replace

Plugin:
External image replace
Plugin Slug:
external-image-replace
Vulnerability:
Arbitrary File Upload
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Frontend Login and Registration Blocks

Plugin:
Frontend Login and Registration Blocks
Plugin Slug:
frontend-login-and-registration-blocks
Vulnerability:
Privilege Escalation
Patched in Version:
No Fix
Severity Score:
Critical
The vulnerability has not been patched. You should deactivate the plugin.

LayoutBoxx

Plugin:
LayoutBoxx
Plugin Slug:
layoutboxx
Vulnerability:
Content Injection
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

LessButtons Social Sharing and Statistics

Plugin:
LessButtons Social Sharing and Statistics
Plugin Slug:
lessbuttons
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Multiple Post Type Order

Plugin:
Multiple Post Type Order
Plugin Slug:
multiple-post-type-order
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

PeproDev Ultimate Profile Solutions

Plugin:
PeproDev Ultimate Profile Solutions
Plugin Slug:
peprodev-ups
Vulnerability:
Broken Authentication
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

PeproDev Ultimate Profile Solutions

Plugin:
PeproDev Ultimate Profile Solutions
Plugin Slug:
peprodev-ups
Vulnerability:
Broken Authentication
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

PeproDev Ultimate Profile Solutions

Plugin:
PeproDev Ultimate Profile Solutions
Plugin Slug:
peprodev-ups
Vulnerability:
Privilege Escalation
Patched in Version:
No Fix
Severity Score:
Critical
The vulnerability has not been patched. You should deactivate the plugin.

QS Dark Mode

Plugin:
QS Dark Mode
Plugin Slug:
qs-dark-mode
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Reales WP STPT

Plugin:
Reales WP STPT
Plugin Slug:
short-tax-post
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Reales WP STPT

Plugin:
Reales WP STPT
Plugin Slug:
short-tax-post
Vulnerability:
Privilege Escalation
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

WP SmartPay

Plugin:
WP SmartPay
Plugin Slug:
smartpay
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Woocommerce Multiple Addresses

Plugin:
Woocommerce Multiple Addresses
Plugin Slug:
woocommerce-multiple-addresses
Vulnerability:
Privilege Escalation
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

WordPress Review Plugin

Plugin:
WordPress Review Plugin
Plugin Slug:
wp-review
Vulnerability:
Local File Inclusion
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

WP shop

Plugin:
WP shop
Plugin Slug:
wpshop
Vulnerability:
Privilege Escalation
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

WP shop

Plugin:
WP shop
Plugin Slug:
wpshop
Vulnerability:
Insecure Direct Object References (IDOR)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Xavin’s List Subpages

Plugin:
Xavin’s List Subpages
Plugin Slug:
xavins-list-subpages
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

LiteSpeed Cache

Plugin Slug:
litespeed-cache
Installations
7,000,000+
Vulnerability:
Server Side Request Forgery (SSRF)
Patched in Version:
7.1
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 7.1.

Royal Elementor Addons and Templates

Plugin Slug:
royal-elementor-addons
Installations
600,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.7.1018
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.7.1018.

Jeg Elementor Kit

Plugin Slug:
jeg-elementor-kit
Installations
300,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.6.13
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.6.13.

Newsletter – Send awesome emails from WordPress

Plugin Slug:
newsletter
Installations
300,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
8.7.1
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 8.7.1.

Firelight Lightbox

Plugin Slug:
easy-fancybox
Installations
200,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.3.15
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.3.15.

Popup and Slider Builder by Depicter – Add Email collecting Popup, Popup Modal, Coupon Popup, Image Slider, Carousel Slider, Post Slider Carousel

Plugin Slug:
depicter
Installations
100,000+
Vulnerability:
SQL Injection
Patched in Version:
3.6.2
Severity Score:
Critical
The vulnerability has been patched, so you should update to version 3.6.2.

Login Lockdown & Protection

Plugin Slug:
login-lockdown
Installations
100,000+
Vulnerability:
Broken Access Control
Patched in Version:
2.12
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.12.
Plugin Slug:
relevanssi
Installations
100,000+
Vulnerability:
SQL Injection
Patched in Version:
4.24.5
Severity Score:
High
The vulnerability has been patched, so you should update to version 4.24.5.
Plugin Slug:
relevanssi
Installations
100,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
4.24.4
Severity Score:
High
The vulnerability has been patched, so you should update to version 4.24.4.

Download Monitor

Plugin Slug:
download-monitor
Installations
90,000+
Vulnerability:
Local File Inclusion
Patched in Version:
5.0.23
Severity Score:
High
The vulnerability has been patched, so you should update to version 5.0.23.

Jupiter X Core

Plugin Slug:
jupiterx-core
Installations
90,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
4.8.12
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 4.8.12.
Plugin Slug:
contextual-related-posts
Installations
70,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
4.0.3
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 4.0.3.

Bold Page Builder

Plugin Slug:
bold-page-builder
Installations
50,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
5.3.1
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 5.3.1.

Bold Page Builder

Plugin Slug:
bold-page-builder
Installations
50,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
5.3.3
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 5.3.3.

Ultimate Blocks – WordPress Blocks Plugin

Plugin Slug:
ultimate-blocks
Installations
50,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
3.3.0
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.3.0.

Ditty – Responsive News Tickers, Sliders, and Lists

Plugin Slug:
ditty-news-ticker
Installations
40,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
3.1.52
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.1.52.
Plugin Slug:
robo-gallery
Installations
40,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
5.0.3
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 5.0.3.

LightPress Lightbox

Plugin Slug:
wp-jquery-lightbox
Installations
40,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.3.4
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.3.4.

Envo Extra

Plugin:
Envo Extra
Plugin Slug:
envo-extra
Installations
30,000+
Vulnerability:
Broken Access Control
Patched in Version:
1.9.10
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.9.10.

WP SEO Structured Data Schema

Plugin Slug:
wp-seo-structured-data-schema
Installations
30,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.8.0
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.8.0.
Plugin Slug:
beaf-before-and-after-gallery
Installations
20,000+
Vulnerability:
Arbitrary File Upload
Patched in Version:
4.6.11
Severity Score:
Critical
The vulnerability has been patched, so you should update to version 4.6.11.

Accept Donations with PayPal & Stripe

Plugin Slug:
easy-paypal-donation
Installations
20,000+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
1.5
Severity Score:
High
The vulnerability has been patched, so you should update to version 1.5.

Meks Flexible Shortcodes

Plugin Slug:
meks-flexible-shortcodes
Installations
20,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.3.7
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.3.7.

PW WooCommerce Bulk Edit

Plugin Slug:
pw-bulk-edit
Installations
20,000+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
2.135
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.135.
Plugin Slug:
top-10
Installations
20,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
4.1.1
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 4.1.1.

BlockSpare: Gutenberg Blocks & Patterns for Blogs, Magazines, Business Sites – Post Grids, Sliders, Carousels, Counters, Page Builder & Starter Site Imports, No Coding Needed

Plugin Slug:
blockspare
Installations
10,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
3.2.10
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.2.10.

AI Power: Complete AI Pack

Plugin Slug:
gpt3-ai-content-generator
Installations
10,000+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
1.9.15
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.9.15.

Graphina – Elementor Charts and Graphs

Plugin Slug:
graphina-elementor-charts-and-graphs
Installations
10,000+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
3.0.5
Severity Score:
High
The vulnerability has been patched, so you should update to version 3.0.5.

Graphina – Elementor Charts and Graphs

Plugin Slug:
graphina-elementor-charts-and-graphs
Installations
10,000+
Vulnerability:
Broken Access Control
Patched in Version:
3.0.5
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.0.5.
Plugin Slug:
meow-gallery
Installations
10,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
5.2.8
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 5.2.8.

NEX-Forms – Ultimate Forms Plugin for WordPress

Plugin Slug:
nex-forms-express-wp-form-builder
Installations
10,000+
Vulnerability:
Arbitrary Code Execution
Patched in Version:
8.9.2
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 8.9.2.

NEX-Forms – Ultimate Forms Plugin for WordPress

Plugin Slug:
nex-forms-express-wp-form-builder
Installations
10,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
8.9.2
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 8.9.2.

Countdown Timer – Widget Countdown

Plugin Slug:
widget-countdown
Installations
10,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.7.5
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.7.5.

Contact Form 7 – PayPal & Stripe Add-on

Plugin Slug:
contact-form-7-paypal-add-on
Installations
9,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.4.1
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.4.1.

Cozy Blocks – Page Builder for Gutenberg & Site Editor with Post Blocks, WooCommerce Blocks, Magazine Blocks & WordPress Gutenberg Blocks

Plugin Slug:
cozy-addons
Installations
9,000+
Vulnerability:
Broken Access Control
Patched in Version:
2.1.23
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.1.23.

WP Compress – Instant Performance & Speed Optimization

Plugin Slug:
wp-compress-image-optimizer
Installations
9,000+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
6.30.31
Severity Score:
High
The vulnerability has been patched, so you should update to version 6.30.31.

WP Hotel Booking

Plugin Slug:
wp-hotel-booking
Installations
8,000+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
2.2.0
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.2.0.

Dynamic Pricing With Discount Rules for WooCommerce

Plugin Slug:
aco-woo-dynamic-pricing
Installations
7,000+
Vulnerability:
SQL Injection
Patched in Version:
4.5.9
Severity Score:
High
The vulnerability has been patched, so you should update to version 4.5.9.

ProfileGrid – User Profiles, Groups and Communities

Plugin Slug:
profilegrid-user-profiles-groups-and-communities
Installations
7,000+
Vulnerability:
SQL Injection
Patched in Version:
5.9.5.1
Severity Score:
High
The vulnerability has been patched, so you should update to version 5.9.5.1.

Simple File List

Plugin Slug:
simple-file-list
Installations
7,000+
Vulnerability:
Settings Change
Patched in Version:
6.1.14
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 6.1.14.

TrackShip for WooCommerce

Plugin Slug:
trackship-for-woocommerce
Installations
7,000+
Vulnerability:
SQL Injection
Patched in Version:
1.9.2
Severity Score:
High
The vulnerability has been patched, so you should update to version 1.9.2.

Better Search – Relevant search results for WordPress

Plugin Slug:
better-search
Installations
6,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
4.1.1
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 4.1.1.

Drag and Drop Multiple File Upload for WooCommerce

Plugin Slug:
drag-and-drop-multiple-file-upload-for-woocommerce
Installations
6,000+
Vulnerability:
Arbitrary File Upload
Patched in Version:
1.1.7
Severity Score:
Critical
The vulnerability has been patched, so you should update to version 1.1.7.

EventON – Events Calendar

Plugin Slug:
eventon-lite
Installations
6,000+
Vulnerability:
Local File Inclusion
Patched in Version:
2.4.2
Severity Score:
High
The vulnerability has been patched, so you should update to version 2.4.2.

Hotel Booking

Plugin Slug:
nd-booking
Installations
5,000+
Vulnerability:
Local File Inclusion
Patched in Version:
3.7
Severity Score:
High
The vulnerability has been patched, so you should update to version 3.7.

Simple Blog Stats

Plugin Slug:
simple-blog-stats
Installations
5,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
20250423
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 20250423.

SMS Alert Order Notifications – WooCommerce

Plugin Slug:
sms-alert
Installations
5,000+
Vulnerability:
Privilege Escalation
Patched in Version:
3.8.2
Severity Score:
High
The vulnerability has been patched, so you should update to version 3.8.2.

SMS Alert Order Notifications – WooCommerce

Plugin Slug:
sms-alert
Installations
5,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
3.8.2
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.8.2.

SMS Alert Order Notifications – WooCommerce

Plugin Slug:
sms-alert
Installations
5,000+
Vulnerability:
SQL Injection
Patched in Version:
3.8.2
Severity Score:
Critical
The vulnerability has been patched, so you should update to version 3.8.2.

WPAdverts – Classifieds Plugin

Plugin Slug:
wpadverts
Installations
5,000+
Vulnerability:
Local File Inclusion
Patched in Version:
2.2.3
Severity Score:
High
The vulnerability has been patched, so you should update to version 2.2.3.

Ovation Elements

Plugin Slug:
ovation-elements
Installations
4,000+
Vulnerability:
Broken Access Control
Patched in Version:
1.1.3
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.1.3.

Hash Form – Drag & Drop Form Builder

Plugin Slug:
hash-form
Installations
3,000+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
1.2.9
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.2.9.

Media Hygiene: Remove or Delete Unused Images and More!

Plugin Slug:
media-hygiene
Installations
3,000+
Vulnerability:
Broken Access Control
Patched in Version:
4.0.1
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 4.0.1.

Mollie Forms

Plugin Slug:
mollie-forms
Installations
3,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.7.13
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.7.13.

Newsletters

Plugin Slug:
newsletters-lite
Installations
3,000+
Vulnerability:
SQL Injection
Patched in Version:
4.9.9.9
Severity Score:
High
The vulnerability has been patched, so you should update to version 4.9.9.9.

Solace Extra

Plugin Slug:
solace-extra
Installations
3,000+
Vulnerability:
Server Side Request Forgery (SSRF)
Patched in Version:
1.3.2
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.3.2.

Challan – PDF Invoice & Packing Slip for WooCommerce

Plugin Slug:
webappick-pdf-invoice-for-woocommerce
Installations
3,000+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
3.7.59
Severity Score:
High
The vulnerability has been patched, so you should update to version 3.7.59.

Display Eventbrite Events

Plugin Slug:
widget-for-eventbrite-api
Installations
3,000+
Vulnerability:
Local File Inclusion
Patched in Version:
6.3
Severity Score:
High
The vulnerability has been patched, so you should update to version 6.3.

Beds24 Online Booking

Plugin Slug:
beds24-online-booking
Installations
2,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.0.30
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.0.30.

CoinPayments.net Payment Gateway for WooCommerce

Plugin Slug:
coinpayments-payment-gateway-for-woocommerce
Installations
2,000+
Vulnerability:
PHP Object Injection
Patched in Version:
1.0.18
Severity Score:
Critical
The vulnerability has been patched, so you should update to version 1.0.18.

SendPulse Email Marketing Newsletter

Plugin Slug:
sendpulse-email-marketing-newsletter
Installations
2,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.1.7
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.1.7.

SKT Skill Bar

Plugin Slug:
skt-skill-bar
Installations
2,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.5
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.5.

CC BMI Calculator

Plugin Slug:
cc-bmi-calculator
Installations
1,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.1.1
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.1.1.
Plugin Slug:
contest-gallery
Installations
1,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
26.0.7
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 26.0.7.

Easy PayPal Events & Tickets

Plugin Slug:
easy-paypal-events-tickets
Installations
1,000+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
1.3
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.3.

Logo Showcase

Plugin Slug:
logo-showcase
Installations
1,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
3.0.5
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.0.5.

Music Player for WooCommerce

Plugin Slug:
music-player-for-woocommerce
Installations
1,000+
Vulnerability:
Broken Access Control
Patched in Version:
1.6.0
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.6.0.

Progress Bar

Plugin Slug:
progress-bar
Installations
1,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.2.4
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.2.4.

Ultimate WP Mail

Plugin Slug:
ultimate-wp-mail
Installations
1,000+
Vulnerability:
SQL Injection
Patched in Version:
1.3.5
Severity Score:
High
The vulnerability has been patched, so you should update to version 1.3.5.

Ultimate WP Mail

Plugin Slug:
ultimate-wp-mail
Installations
1,000+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
1.3.5
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.3.5.

FundEngine – Donation and Crowdfunding Platform

Plugin Slug:
wp-fundraising-donation
Installations
1,000+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
1.7.4
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.7.4.

XT Event Widget for Social Events

Plugin Slug:
xt-facebook-events
Installations
1,000+
Vulnerability:
Local File Inclusion
Patched in Version:
1.1.8
Severity Score:
High
The vulnerability has been patched, so you should update to version 1.1.8.

Display Remote Posts Block

Plugin Slug:
display-remote-posts-block
Installations
800+
Vulnerability:
Server Side Request Forgery (SSRF)
Patched in Version:
1.1.1
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.1.1.

AWEOS WP Lock

Plugin Slug:
aweos-wp-lock
Installations
700+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.4.9
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.4.9.

Frontend Dashboard

Plugin Slug:
frontend-dashboard
Installations
700+
Vulnerability:
Privilege Escalation
Patched in Version:
2.2.8
Severity Score:
High
The vulnerability has been patched, so you should update to version 2.2.8.

Frontend Dashboard

Plugin Slug:
frontend-dashboard
Installations
700+
Vulnerability:
Privilege Escalation
Patched in Version:
2.2.7
Severity Score:
Critical
The vulnerability has been patched, so you should update to version 2.2.7.

Quran multilanguage Text & Audio

Plugin Slug:
quran-text-multilanguage
Installations
700+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.3.24
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.3.24.

Seznam Webmaster

Plugin Slug:
seznam-webmaster
Installations
700+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
1.4.8
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.4.8.

WP DPE-GES

Plugin:
WP DPE-GES
Plugin Slug:
wp-dpe-ges
Installations
700+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.7
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.7.

Custom Checkout Fields for WooCommerce

Plugin Slug:
custom-checkout-fields-for-woocommerce
Installations
600+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.9.0
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.9.0.

Cool Author Box – For Widget and Post Content

Plugin Slug:
hm-cool-author-box-widget
Installations
600+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
3.0.1
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.0.1.

Listamester

Plugin Slug:
listamester
Installations
600+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
2.3.7
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.3.7.

Easy Replace Image

Plugin Slug:
easy-replace-image
Installations
500+
Vulnerability:
Server Side Request Forgery (SSRF)
Patched in Version:
3.5.1
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.5.1.
Plugin Slug:
ngg-smart-image-search
Installations
500+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
3.4.1
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.4.1.

Product Time Countdown for WooCommerce

Plugin Slug:
product-countdown-for-woocommerce
Installations
500+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.6.3
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.6.3.

TrueBooker – Appointment Booking and Scheduler Plugin.

Plugin Slug:
truebooker-appointment-booking
Installations
500+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
1.0.8
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.0.8.

Simple calendar for Elementor

Plugin Slug:
simple-calendar-for-elementor
Installations
400+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
1.6.6
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.6.6.

WZ Followed Posts – Display what visitors are reading

Plugin Slug:
where-did-they-go-from-here
Installations
400+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
3.1.1
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.1.1.

WP Gravity Forms Dynamics CRM

Plugin Slug:
gf-dynamics-crm
Installations
300+
Vulnerability:
Open Redirection
Patched in Version:
1.1.5
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.1.5.

Subaccounts for WooCommerce

Plugin Slug:
subaccounts-for-woocommerce
Installations
300+
Vulnerability:
Broken Authentication
Patched in Version:
1.6.7
Severity Score:
High
The vulnerability has been patched, so you should update to version 1.6.7.
Plugin Slug:
activity-link-preview-for-buddypress
Installations
200+
Vulnerability:
Server Side Request Forgery (SSRF)
Patched in Version:
1.6.0
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.6.0.

B2i Investor Tools

Plugin Slug:
b2i-investor-tools
Installations
200+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.0.8
Severity Score:
High
The vulnerability has been patched, so you should update to version 1.0.8.

Cart tracking for WooCommerce

Plugin Slug:
cart-tracking-for-woocommerce
Installations
200+
Vulnerability:
SQL Injection
Patched in Version:
1.0.18
Severity Score:
High
The vulnerability has been patched, so you should update to version 1.0.18.

EUCookieLaw

Plugin Slug:
eucookielaw
Installations
200+
Vulnerability:
Arbitrary File Download
Patched in Version:
2.7.3
Severity Score:
High
The vulnerability has been patched, so you should update to version 2.7.3.

WP Gravity Forms Zendesk

Plugin Slug:
gf-zendesk
Installations
200+
Vulnerability:
Open Redirection
Patched in Version:
1.1.3
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.1.3.

LocateAndFilter

Plugin Slug:
locateandfilter
Installations
200+
Vulnerability:
Broken Access Control
Patched in Version:
1.6.17
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.6.17.

Product Quantity Dropdown For Woocommerce

Plugin Slug:
product-quantity-dropdown-for-woocommerce
Installations
200+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
1.3
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.3.
Plugin Slug:
spostarbust
Installations
200+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
1.2.04.25
Severity Score:
High
The vulnerability has been patched, so you should update to version 1.2.04.25.

Integration for WooCommerce and Salesforce

Plugin Slug:
woo-salesforce-plugin-crm-perks
Installations
200+
Vulnerability:
Open Redirection
Patched in Version:
1.7.6
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.7.6.

Cision Block

Plugin Slug:
cision-block
Installations
100+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
4.4.0
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 4.4.0.

Wiki Embed

Plugin:
Wiki Embed
Plugin Slug:
wiki-embed
Installations
100+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
1.4.7
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.4.7.

GS Variation Swatches for WooCommerce

Plugin Slug:
gs-woo-variation-swatches
Installations
50+
Vulnerability:
Broken Access Control
Patched in Version:
3.0.5
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.0.5.

WPBookit

Plugin:
WPBookit
Plugin Slug:
wpbookit
Installations
50+
Vulnerability:
Privilege Escalation
Patched in Version:
1.0.3
Severity Score:
Critical
The vulnerability has been patched, so you should update to version 1.0.3.

BuddyPress Platform Pro

Plugin:
BuddyPress Platform Pro
Plugin Slug:
buddyboss-platform-pro
Vulnerability:
Broken Authentication
Patched in Version:
2.7.10
Severity Score:
Critical
The vulnerability has been patched, so you should update to version 2.7.10.

Cost Calculator for Elementor

Plugin:
Cost Calculator for Elementor
Plugin Slug:
cost-calculator-for-elementor
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.3.4
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.3.4.

Envolve Plugin

Plugin:
Envolve Plugin
Plugin Slug:
envolve-plugin
Vulnerability:
Arbitrary File Upload
Patched in Version:
1.1.0
Severity Score:
Critical
The vulnerability has been patched, so you should update to version 1.1.0.

Envolve Plugin

Plugin:
Envolve Plugin
Plugin Slug:
envolve-plugin
Vulnerability:
Broken Access Control
Patched in Version:
1.1.0
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.1.0.

IMITHEMES Listing

Plugin:
IMITHEMES Listing
Plugin Slug:
imithemes-listing
Vulnerability:
Privilege Escalation
Patched in Version:
3.4
Severity Score:
Critical
The vulnerability has been patched, so you should update to version 3.4.

Opal Woo Custom Product Variation

Plugin:
Opal Woo Custom Product Variation
Plugin Slug:
opal-woo-custom-product-variation
Vulnerability:
Arbitrary File Deletion
Patched in Version:
1.2.1
Severity Score:
High
The vulnerability has been patched, so you should update to version 1.2.1.

PGS Core

Plugin:
PGS Core
Plugin Slug:
pgs-core
Vulnerability:
PHP Object Injection
Patched in Version:
5.9.0
Severity Score:
Critical
The vulnerability has been patched, so you should update to version 5.9.0.

PGS Core

Plugin:
PGS Core
Plugin Slug:
pgs-core
Vulnerability:
SQL Injection
Patched in Version:
5.9.0
Severity Score:
Critical
The vulnerability has been patched, so you should update to version 5.9.0.

PGS Core

Plugin:
PGS Core
Plugin Slug:
pgs-core
Vulnerability:
Broken Access Control
Patched in Version:
5.9.0
Severity Score:
High
The vulnerability has been patched, so you should update to version 5.9.0.

Relevanssi Premium

Plugin:
Relevanssi Premium
Plugin Slug:
relevanssi-premium
Vulnerability:
SQL Injection
Patched in Version:
2.27.5
Severity Score:
High
The vulnerability has been patched, so you should update to version 2.27.5.

WordPress Themes — 4 Patched / 0 Unpatched

Blocksy

Theme:
Blocksy
Theme Slug:
blocksy
Downloads
4,484,472
Vulnerability:
Broken Access Control
Patched in Version:
2.0.98
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.0.98.

TheGem

Theme:
TheGem
Theme Slug:
thegem
Vulnerability:
Broken Access Control
Patched in Version:
5.10.3.1
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 5.10.3.1.

TheGem

Theme:
TheGem
Theme Slug:
thegem
Vulnerability:
Arbitrary File Upload
Patched in Version:
5.10.3.1
Severity Score:
High
The vulnerability has been patched, so you should update to version 5.10.3.1.

Wolmart

Theme:
Wolmart
Theme Slug:
wolmart
Vulnerability:
Content Injection
Patched in Version:
1.8.12
Severity Score:
High
The vulnerability has been patched, so you should update to version 1.8.12.

Solid Security is part of Solid Suite — The best foundation for WordPress websites.

Every WordPress site needs security, backups, and management tools. That’s Solid Suite — an integrated bundle of three plugins: Solid Security, Solid Backups, and Solid Central. You also get access to Solid Academy’s learning resources for WordPress professionals. Build your next WordPress website on a solid foundation with Solid Suite!

Get Solid Security