WordPress Vulnerability Report

WordPress Vulnerability Report — May 21, 2025

Since last week, 359 new vulnerabilities emerged in the WordPress ecosystem, including 341 plugins and 18 themes. 165 of the vulnerable plugins and themes remain unpatched, but Solid Security Pro users are protected by virtual patching from Patchstack.

Avatar photo
Sarah Ulmer

In this report, 359 vulnerabilities have been publicly disclosed. Security patches for 194 of these plugins and themes are available now, so run those updates as soon as possible. If you’re a Solid Security Pro user, the version management tool may have already warned you and updated these plugins, depending on your settings.

Additionally, there are 165 plugin and theme vulnerabilities, and no patch has been available yet. If you’re a Solid Security Pro user, those vulnerabilities are already protected by the Solid Security firewall. Virtual patches from Patchstack will be applied when a vulnerability is considered high or medium risk. If no patch is forthcoming from the vendor or the vulnerable software has been marked “closed” and dropped from the official WordPress repositories, you should deactivate it soon and look for alternative solutions.

Along with poor user account security, vulnerable plugins and themes are among the top reasons why WordPress websites get hacked. Unfortunately, cyberattacks are increasing in volume and sophistication. They’re also increasingly aimed at small to mid-sized businesses.

Our WordPress Vulnerability Report covers the latest emerging WordPress plugin, theme, and core vulnerabilities. Each vulnerability will have a severity rating of LowMediumHigh, or Critical. Responsible disclosure of vulnerabilities is essential to keeping the WordPress community safe. Please share this report to help spread the word and make WordPress — and the web — more secure.

WordPress Core

WordPress 6.8.1 has been released! This maintenance release includes fixes for 15 bugs throughout Core and the Block Editor, addressing issues affecting multiple areas of WordPress, including the block editor, multisite, and REST API. For a full list, refer to the release candidate announcement.

Plus, WordCamp Europe 2025 lands in Basel, Switzerland, June 5-7! Connect with WordPress enthusiasts, developers, and pros for three days of learning, networking, and collaboration with the global community.

No new core vulnerabilities were disclosed this week.

WordPress Plugins — 191 Patched / 150 Unpatched

TI WooCommerce Wishlist

Plugin Slug:
ti-woocommerce-wishlist
Installations
100,000+
Vulnerability:
Arbitrary File Upload
Patched in Version:
No Fix
Severity Score:
Critical
The vulnerability has not been patched. You should deactivate the plugin.

TI WooCommerce Wishlist

Plugin Slug:
ti-woocommerce-wishlist
Installations
100,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

WP Tabs – Responsive Tabs and Custom Product Tabs

Plugin Slug:
wp-expand-tabs-free
Installations
10,000+
Vulnerability:
PHP Object Injection
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

WooCommerce POS – Point of Sale

Plugin Slug:
woocommerce-pos
Installations
6,000+
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Eventer

Plugin:
Eventer
Plugin Slug:
eventer
Installations
2,000+
Vulnerability:
SQL Injection
Patched in Version:
No Fix
Severity Score:
Critical
The vulnerability has not been patched. You should deactivate the plugin.

Eventer

Plugin:
Eventer
Plugin Slug:
eventer
Installations
2,000+
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Estatik Mortgage Calculator

Plugin Slug:
estatik-mortgage-calculator
Installations
1,000+
Vulnerability:
Local File Inclusion
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Simplelightbox

Plugin Slug:
simplelightbox
Installations
1,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

WP Notes Widget

Plugin Slug:
wp-notes-widget
Installations
1,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.
Plugin Slug:
ultraaddons-elementor-lite
Installations
900+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

ValidateCertify Free

Plugin Slug:
validar-certificados-de-cursos
Installations
900+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

MapSVG – Vector maps, Image maps, Google Maps

Plugin Slug:
mapsvg-lite-interactive-vector-maps
Installations
800+
Vulnerability:
Content Injection
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

BERTHA AI. Your AI co-pilot for WordPress and Chrome

Plugin Slug:
bertha-ai-free
Installations
700+
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Broadstreet

Plugin Slug:
broadstreet
Installations
700+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Dynamic Pricing & Discounts Lite for WooCommerce

Plugin Slug:
woo-dynamic-pricing-discounts-lite
Installations
600+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Push notification for Mobile and Web app

Plugin Slug:
push-notification-mobile-and-web-app
Installations
500+
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Wishlist

Plugin:
Wishlist
Plugin Slug:
wishlist
Installations
500+
Vulnerability:
Sensitive Data Exposure
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Wishlist

Plugin:
Wishlist
Plugin Slug:
wishlist
Installations
500+
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Import Export For WooCommerce

Plugin Slug:
import-export-for-woocommerce
Installations
300+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

STAGGS – Product Configurator Toolkit

Plugin Slug:
staggs
Installations
300+
Vulnerability:
Arbitrary File Upload
Patched in Version:
No Fix
Severity Score:
Critical
The vulnerability has not been patched. You should deactivate the plugin.

Embed and Integrate Etsy Shop

Plugin Slug:
embed-and-integrate-etsy-shop
Installations
200+
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

SEO Flow by LupsOnline

Plugin Slug:
lupsonline-link-netwerk
Installations
200+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

X Addons for Elementor

Plugin Slug:
x-addons-elementor
Installations
200+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Aptivada for WP

Plugin Slug:
aptivada-for-wp
Installations
100+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Dot html,php,xml etc pages

Plugin Slug:
dot-htmlphpxml-etc-pages
Installations
100+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Facturante – Facturación Electrónica

Plugin Slug:
facturante
Installations
100+
Vulnerability:
SQL Injection
Patched in Version:
No Fix
Severity Score:
Critical
The vulnerability has not been patched. You should deactivate the plugin.

Printcart Web to Print Product Designer for WooCommerce

Plugin Slug:
printcart-integration
Installations
100+
Vulnerability:
Arbitrary File Upload
Patched in Version:
No Fix
Severity Score:
Critical
The vulnerability has not been patched. You should deactivate the plugin.

Printcart Web to Print Product Designer for WooCommerce

Plugin Slug:
printcart-integration
Installations
100+
Vulnerability:
SQL Injection
Patched in Version:
No Fix
Severity Score:
Critical
The vulnerability has not been patched. You should deactivate the plugin.

6Storage Rentals

Plugin Slug:
6storage-rentals
Installations
60+
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Interview

Plugin:
Interview
Plugin Slug:
interview
Installations
40+
Vulnerability:
SQL Injection
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

BNS Twitter Follow Button

Plugin Slug:
bns-twitter-follow-button
Installations
10+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Real WP Shop Lite Ajax eCommerce Shopping Cart

Plugin Slug:
real-wp-shop-lite
Installations
10+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

360 Product Rotation

Plugin:
360 Product Rotation
Plugin Slug:
360-product-rotation
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

WP Ultimate Tours Builder

Plugin:
WP Ultimate Tours Builder
Plugin Slug:
WP_UltimateToursBuilder
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Advance Post Prefix

Plugin:
Advance Post Prefix
Plugin Slug:
advance-post-prefix
Vulnerability:
SQL Injection
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Advance Post Prefix

Plugin:
Advance Post Prefix
Plugin Slug:
advance-post-prefix
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Advanced Page Visit Counter

Plugin:
Advanced Page Visit Counter
Plugin Slug:
advanced-page-visit-counter
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

AffiliateImporterEb

Plugin:
AffiliateImporterEb
Plugin Slug:
affiliateimportereb
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

AffiliateImporterEb

Plugin:
AffiliateImporterEb
Plugin Slug:
affiliateimportereb
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

AlT Monitoring

Plugin:
AlT Monitoring
Plugin Slug:
alt-monitoring
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Ads Pro Plugin

Plugin:
Ads Pro Plugin
Plugin Slug:
ap-plugin-scripteo
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Audio Comments

Plugin:
Audio Comments
Plugin Slug:
audio-comments
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Radio Player Shoutcast & Icecast WordPress Plugin

Plugin:
Radio Player Shoutcast & Icecast WordPress Plugin
Plugin Slug:
audio4-html5
Vulnerability:
SQL Injection
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

BabelZ

Plugin:
BabelZ
Plugin Slug:
babelz
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Backup Database

Plugin:
Backup Database
Plugin Slug:
backup-database
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Badgearoo

Plugin:
Badgearoo
Plugin Slug:
badgearoo
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Badgearoo

Plugin:
Badgearoo
Plugin Slug:
badgearoo
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

????SEO??(????/??/Bing/????)

Plugin:
????SEO??(????/??/Bing/????)
Plugin Slug:
baiduseo
Vulnerability:
Arbitrary File Upload
Patched in Version:
No Fix
Severity Score:
Critical
The vulnerability has not been patched. You should deactivate the plugin.

Element Pack Pro

Plugin:
Element Pack Pro
Plugin Slug:
bdthemes-element-pack
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Element Pack Pro

Plugin:
Element Pack Pro
Plugin Slug:
bdthemes-element-pack
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

BTEV

Plugin:
BTEV
Plugin Slug:
bluetrait-event-viewer
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Bon Toolkit

Plugin:
Bon Toolkit
Plugin Slug:
bon-toolkit
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

WPCHURCH

Plugin:
WPCHURCH
Plugin Slug:
church-management
Vulnerability:
Local File Inclusion
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

CountDown Pro WP Plugin

Plugin:
CountDown Pro WP Plugin
Plugin Slug:
circular_countdown
Vulnerability:
SQL Injection
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Clasify Classified Listing

Plugin:
Clasify Classified Listing
Plugin Slug:
clasify-classified-listing
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Clicksold IDX

Plugin:
Clicksold IDX
Plugin Slug:
clicksold-wordpress-plugin
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

ClipArt

Plugin:
ClipArt
Plugin Slug:
clipart
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Competition Form

Plugin:
Competition Form
Plugin Slug:
competition-form
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Countdown Timer

Plugin:
Countdown Timer
Plugin Slug:
countdown-timer-block
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

CSS3 Accordions for WordPress

Plugin:
CSS3 Accordions for WordPress
Plugin Slug:
css3_accordions
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

CSS3 Accordions for WordPress

Plugin:
CSS3 Accordions for WordPress
Plugin Slug:
css3_accordions
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

CSS3 Tooltips for WordPress

Plugin:
CSS3 Tooltips for WordPress
Plugin Slug:
css3_tooltips
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

CSS3 Compare Pricing Tables for WordPress

Plugin:
CSS3 Compare Pricing Tables for WordPress
Plugin Slug:
css3_web_pricing_tables_grids
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Custom Author Base

Plugin:
Custom Author Base
Plugin Slug:
custom-author-base
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Custom Field Manager

Plugin:
Custom Field Manager
Plugin Slug:
custom-field-manager
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

DL Verification

Plugin:
DL Verification
Plugin Slug:
dl-verification
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

DL Yandex Metrika

Plugin:
DL Yandex Metrika
Plugin Slug:
dl-yandex-metrika
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Dokan Pro

Plugin:
Dokan Pro
Plugin Slug:
dokan-pro
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

S3Player – WooCommerce & Elementor Integration

Plugin:
S3Player – WooCommerce & Elementor Integration
Plugin Slug:
drm-protected-video-streaming
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

EG-Series

Plugin:
EG-Series
Plugin Slug:
eg-series
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Event Calendar

Plugin:
Event Calendar
Plugin Slug:
event-calendars
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Event Calendar

Plugin:
Event Calendar
Plugin Slug:
event-calendars
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

EventON

Plugin:
EventON
Plugin Slug:
eventON
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

FAT Services Booking

Plugin:
FAT Services Booking
Plugin Slug:
fat-services-booking
Vulnerability:
Local File Inclusion
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

File Manager Advanced Shortcode

Plugin:
File Manager Advanced Shortcode
Plugin Slug:
file-manager-advanced-shortcode
Vulnerability:
Content Injection
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Front End Users

Plugin:
Front End Users
Plugin Slug:
front-end-only-users
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Full Screen (Page) Background Image Slideshow

Plugin:
Full Screen (Page) Background Image Slideshow
Plugin Slug:
full-screen-page-background-image-slideshow
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Geocache Stat Bar Widget

Plugin:
Geocache Stat Bar Widget
Plugin Slug:
geocache-stat-bar-widget
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

WPGYM

Plugin:
WPGYM
Plugin Slug:
gym-management
Vulnerability:
SQL Injection
Patched in Version:
No Fix
Severity Score:
Critical
The vulnerability has not been patched. You should deactivate the plugin.

JavaScript Logic

Plugin:
JavaScript Logic
Plugin Slug:
javascript-logic
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

JSP Store Locator

Plugin:
JSP Store Locator
Plugin Slug:
jsp-store-locator
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

JSP Store Locator

Plugin:
JSP Store Locator
Plugin Slug:
jsp-store-locator
Vulnerability:
SQL Injection
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

jwp-a11y

Plugin:
jwp-a11y
Plugin Slug:
jwp-a11y
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Chameleon HTML5 Audio Player With/Without Playlist

Plugin:
Chameleon HTML5 Audio Player With/Without Playlist
Plugin Slug:
lbg-audio1-html5
Vulnerability:
SQL Injection
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Responsive HTML5 Audio Player PRO With Playlist

Plugin:
Responsive HTML5 Audio Player PRO With Playlist
Plugin Slug:
lbg-audio2-html5
Vulnerability:
SQL Injection
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Sticky HTML5 Music Player

Plugin:
Sticky HTML5 Music Player
Plugin Slug:
lbg-audio3-html5
Vulnerability:
SQL Injection
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Sticky Radio Player

Plugin:
Sticky Radio Player
Plugin Slug:
lbg-audio5-html5-shoutcast_sticky
Vulnerability:
SQL Injection
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Apollo

Plugin:
Apollo
Plugin Slug:
lbg-audio7_html5_full_width_sticky_pro
Vulnerability:
SQL Injection
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

SHOUT

Plugin:
SHOUT
Plugin Slug:
lbg-audio8-html5-radio_ads
Vulnerability:
SQL Injection
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.
Plugin:
illi Link Party!
Plugin Slug:
link-party
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Connexion Logs

Plugin:
Connexion Logs
Plugin Slug:
logs-de-connexion
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Connexion Logs

Plugin:
Connexion Logs
Plugin Slug:
logs-de-connexion
Vulnerability:
SQL Injection
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.
Plugin:
Magic Responsive Slider and Carousel WordPress
Plugin Slug:
magic-carousel
Vulnerability:
SQL Injection
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

MapFig Studio

Plugin:
MapFig Studio
Plugin Slug:
mapfig-studio
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

MapSVG

Plugin:
MapSVG
Plugin Slug:
mapsvg
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

MapSVG

Plugin:
MapSVG
Plugin Slug:
mapsvg
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

MapSVG

Plugin:
MapSVG
Plugin Slug:
mapsvg
Vulnerability:
Content Injection
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.
Plugin:
Multimedia Responsive Carousel with Image Video Audio Support
Plugin Slug:
multimedia-carousel
Vulnerability:
SQL Injection
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Nasa Core

Plugin:
Nasa Core
Plugin Slug:
nasa-core
Vulnerability:
Local File Inclusion
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Ninja Tables Pro

Plugin:
Ninja Tables Pro
Plugin Slug:
ninja-tables-pro
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Nokaut Offers Box

Plugin:
Nokaut Offers Box
Plugin Slug:
nokaut-offers-box
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Nokaut Offers Box

Plugin:
Nokaut Offers Box
Plugin Slug:
nokaut-offers-box
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Ntz Antispam

Plugin:
Ntz Antispam
Plugin Slug:
ntzantispam
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

TNC FlipBook

Plugin:
TNC FlipBook
Plugin Slug:
pdf-viewer-for-wordpress
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

PeoplePond

Plugin:
PeoplePond
Plugin Slug:
peoplepond
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Pixel WordPress Form BuilderPlugin & Autoresponder

Plugin:
Pixel WordPress Form BuilderPlugin & Autoresponder
Plugin Slug:
pixel-formbuilder
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Planning Center Online Giving

Plugin:
Planning Center Online Giving
Plugin Slug:
planning-center-online-giving
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

profilepro

Plugin:
profilepro
Plugin Slug:
profilepro
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Panorama – WordPress Project Management Plugin

Plugin:
Panorama – WordPress Project Management Plugin
Plugin Slug:
project-panorama-lite
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

PVN Auth Popup

Plugin:
PVN Auth Popup
Plugin Slug:
pvn-auth-popup
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

PVN Auth Popup

Plugin:
PVN Auth Popup
Plugin Slug:
pvn-auth-popup
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.
Plugin:
Simple Link Directory Pro
Plugin Slug:
qc-simple-link-directory
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

QuickCal

Plugin:
QuickCal
Plugin Slug:
quickcal
Vulnerability:
Sensitive Data Exposure
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

QuickCal

Plugin:
QuickCal
Plugin Slug:
quickcal
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Rootspersona

Plugin:
Rootspersona
Plugin Slug:
rootspersona
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Rootspersona

Plugin:
Rootspersona
Plugin Slug:
rootspersona
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Sailthru Triggermail

Plugin Slug:
sailthru-triggermail
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Salon Booking Pro

Plugin:
Salon Booking Pro
Plugin Slug:
salon-booking-plugin-pro-cc
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Simple Nav Archives

Plugin:
Simple Nav Archives
Plugin Slug:
simple-nav-archives
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.
Plugin:
Smooth Gallery Replacement
Plugin Slug:
smooth-gallery-replacement
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Spiritual Gifts Survey

Plugin:
Spiritual Gifts Survey
Plugin Slug:
spiritual-gifts-survey
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Spotlight – Social Media Feeds (Premium)

Plugin:
Spotlight – Social Media Feeds (Premium)
Plugin Slug:
spotlight-social-photo-feeds-premium
Vulnerability:
Sensitive Data Exposure
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

The Plus Addons for Elementor Pro

Plugin:
The Plus Addons for Elementor Pro
Plugin Slug:
theplus_elementor_addon
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

TwitterPosts

Plugin:
TwitterPosts
Plugin Slug:
twitter-posts
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

UberSlider

Plugin:
UberSlider
Plugin Slug:
uber-classic
Vulnerability:
SQL Injection
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Video Player & FullScreen Video Background

Plugin:
Video Player & FullScreen Video Background
Plugin Slug:
universal-video-player-and-bg
Vulnerability:
SQL Injection
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

User Profile Meta Manager

Plugin:
User Profile Meta Manager
Plugin Slug:
user-profile-meta
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Critical
The vulnerability has not been patched. You should deactivate the plugin.

Weluka Lite

Plugin:
Weluka Lite
Plugin Slug:
weluka-lite
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

WHMpress

Plugin:
WHMpress
Plugin Slug:
whmpress
Vulnerability:
Local File Inclusion
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

WHMpress

Plugin:
WHMpress
Plugin Slug:
whmpress
Vulnerability:
Local File Inclusion
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Widgets Reset

Plugin:
Widgets Reset
Plugin Slug:
widgets-reset
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

WolfNet IDX

Plugin:
WolfNet IDX
Plugin Slug:
wolfnet-idx-for-wordpress
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

CURCY

Plugin:
CURCY
Plugin Slug:
woocommerce-multi-currency
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

WOOEXIM

Plugin:
WOOEXIM
Plugin Slug:
wooexim
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

WordPress Auto Spinner

Plugin:
WordPress Auto Spinner
Plugin Slug:
wp-auto-spinner
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

WordPress????

Plugin:
WordPress????
Plugin Slug:
wp-connect
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

WP Content Security Plugin

Plugin:
WP Content Security Plugin
Plugin Slug:
wp-content-security-policy
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

WP DeskLite

Plugin:
WP DeskLite
Plugin Slug:
wp-desklite
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

WP JobHunt

Plugin:
WP JobHunt
Plugin Slug:
wp-jobhunt
Vulnerability:
Insecure Direct Object References (IDOR)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Pinterest Automatic Pin

Plugin:
Pinterest Automatic Pin
Plugin Slug:
wp-pinterest-automatic
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

WP-PManager

Plugin:
WP-PManager
Plugin Slug:
wp-programmmanager
Vulnerability:
SQL Injection
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

WP-PManager

Plugin:
WP-PManager
Plugin Slug:
wp-programmmanager
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

WPBot Pro WordPress Chatbot

Plugin:
WPBot Pro WordPress Chatbot
Plugin Slug:
wpbot-pro
Vulnerability:
PHP Object Injection
Patched in Version:
No Fix
Severity Score:
Critical
The vulnerability has not been patched. You should deactivate the plugin.

WordPress Events Calendar Registration & Tickets

Plugin:
WordPress Events Calendar Registration & Tickets
Plugin Slug:
wpeventplus
Vulnerability:
PHP Object Injection
Patched in Version:
No Fix
Severity Score:
Critical
The vulnerability has not been patched. You should deactivate the plugin.

Jetpack – WP Security, Backup, Speed, & Growth

Plugin Slug:
jetpack
Installations
4,000,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
13.8
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 13.8.

Jetpack – WP Security, Backup, Speed, & Growth

Plugin Slug:
jetpack
Installations
4,000,000+
Vulnerability:
Content Injection
Patched in Version:
13.8
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 13.8.

The Events Calendar

Plugin Slug:
the-events-calendar
Installations
700,000+
Vulnerability:
Broken Access Control
Patched in Version:
6.12.0
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 6.12.0.

The Events Calendar

Plugin Slug:
the-events-calendar
Installations
700,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
6.6.4
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 6.6.4.

Page Builder: Pagelayer – Drag and Drop website builder

Plugin Slug:
pagelayer
Installations
300,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.9.0
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.9.0.

Firelight Lightbox

Plugin Slug:
easy-fancybox
Installations
200,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.3.15
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.3.15.
Plugin Slug:
photo-gallery
Installations
200,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.8.29
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.8.29.

Download Manager

Plugin Slug:
download-manager
Installations
100,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
3.2.99
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.2.99.

Floating Notification Bar, Sticky Menu on Scroll, Announcement Banner, and Sticky Header for Any Theme – My Sticky Bar (formerly myStickymenu)

Plugin Slug:
mystickymenu
Installations
100,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.6.8
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.6.8.
Plugin Slug:
relevanssi
Installations
100,000+
Vulnerability:
SQL Injection
Patched in Version:
4.24.5
Severity Score:
High
The vulnerability has been patched, so you should update to version 4.24.5.
Plugin Slug:
responsive-lightbox
Installations
100,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.5.1
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.5.1.

Simple Lightbox

Plugin Slug:
simple-lightbox
Installations
100,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.9.4
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.9.4.

Tracking Code Manager

Plugin Slug:
tracking-code-manager
Installations
100,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.3.0
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.3.0.

Social Media Share Buttons & Social Sharing Icons

Plugin Slug:
ultimate-social-media-icons
Installations
100,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.9.1
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.9.1.

Hustle – Email Marketing, Lead Generation, Optins, Popups

Plugin Slug:
wordpress-popup
Installations
100,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
7.8.5
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 7.8.5.

Jupiter X Core

Plugin Slug:
jupiterx-core
Installations
90,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
4.9.1
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 4.9.1.

LearnPress – WordPress LMS Plugin

Plugin Slug:
learnpress
Installations
90,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
4.2.7.5.1
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 4.2.7.5.1.

Nested Pages

Plugin Slug:
wp-nested-pages
Installations
90,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
3.2.9
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.2.9.

Ajax Search Lite – Live Search & Filter

Plugin Slug:
ajax-search-lite
Installations
80,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
4.12.3
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 4.12.3.

ImageMagick Engine

Plugin Slug:
imagemagick-engine
Installations
70,000+
Vulnerability:
Remote Code Execution (RCE)
Patched in Version:
1.7.11
Severity Score:
Critical
The vulnerability has been patched, so you should update to version 1.7.11.

Exclusive Addons for Elementor

Plugin Slug:
exclusive-addons-for-elementor
Installations
60,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.7.9.1
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.7.9.1.

Qi Blocks

Plugin:
Qi Blocks
Plugin Slug:
qi-blocks
Installations
60,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.4
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.4.

WP-Members Membership Plugin

Plugin Slug:
wp-members
Installations
60,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
3.5.3
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.5.3.

WP Booking Calendar

Plugin Slug:
booking
Installations
50,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
10.11.2
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 10.11.2.

Ultimate Blocks – WordPress Blocks Plugin

Plugin Slug:
ultimate-blocks
Installations
50,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
3.3.1
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.3.1.

Visual Composer Website Builder

Plugin Slug:
visualcomposer
Installations
50,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
45.12.0
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 45.12.0.

MapPress Maps for WordPress

Plugin Slug:
mappress-google-maps-for-wordpress
Installations
40,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.93
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.93.
Plugin Slug:
robo-gallery
Installations
40,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
3.2.24
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.2.24.
Plugin Slug:
robo-gallery
Installations
40,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
3.2.22
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.2.22.

Hubbub Lite – Fast, Reliable Social Sharing Buttons

Plugin Slug:
social-pug
Installations
40,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.34.4
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.34.4.

LightPress Lightbox

Plugin Slug:
wp-jquery-lightbox
Installations
40,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.3.4
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.3.4.

Advanced Cron Manager – debug & control

Plugin Slug:
advanced-cron-manager
Installations
30,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.5.7
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.5.7.

Cost Calculator Builder

Plugin Slug:
cost-calculator-builder
Installations
30,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
3.5.0
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.5.0.

FunnelKit – Funnel Builder for WooCommerce Checkout

Plugin Slug:
funnel-builder
Installations
30,000+
Vulnerability:
SQL Injection
Patched in Version:
3.10.2
Severity Score:
High
The vulnerability has been patched, so you should update to version 3.10.2.

Social Slider Feed

Plugin Slug:
instagram-slider-widget
Installations
30,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.2.9
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.2.9.

Uncanny Toolkit for LearnDash

Plugin Slug:
uncanny-learndash-toolkit
Installations
30,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
3.7.0.3
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.7.0.3.

WP Google Review Slider

Plugin Slug:
wp-google-places-review-slider
Installations
30,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
15.6
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 15.6.

Maspik – Ultimate Spam Protection

Plugin Slug:
contact-forms-anti-spam
Installations
20,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.1.3
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.1.3.

Smart Post Show – Post Grid, Post Carousel, Post Slider, Post Timeline, Post Table, and List Category Posts, Latest Posts, Recent Posts, Popular Posts and More

Plugin Slug:
post-carousel
Installations
20,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.4.28
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.4.28.

PWA for WP – Progressive Web Apps Made Simple

Plugin Slug:
pwa-for-wp
Installations
20,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.7.72
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.7.72.

Quiz Maker

Plugin:
Quiz Maker
Plugin Slug:
quiz-maker
Installations
20,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
6.5.9.9
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 6.5.9.9.

Simple Job Board

Plugin Slug:
simple-job-board
Installations
20,000+
Vulnerability:
Sensitive Data Exposure
Patched in Version:
2.12.6
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.12.6.

Simple Job Board

Plugin Slug:
simple-job-board
Installations
20,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.12.2
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.12.2.

bunny.net – WordPress CDN Plugin

Plugin Slug:
bunnycdn
Installations
10,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.3.1
Severity Score:
High
The vulnerability has been patched, so you should update to version 2.3.1.

The GDPR Framework By Data443

Plugin Slug:
gdpr-framework
Installations
10,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.2.0
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.2.0.

Prisna GWT – Google Website Translator

Plugin Slug:
google-website-translator
Installations
10,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.4.14
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.4.14.

Responsive Contact Form Builder & Lead Generation Plugin

Plugin Slug:
lead-form-builder
Installations
10,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.9.8
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.9.8.

MB Custom Post Types & Custom Taxonomies

Plugin Slug:
mb-custom-post-type
Installations
10,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.7.7
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.7.7.

Mobile Contact Bar

Plugin Slug:
mobile-contact-bar
Installations
10,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
3.0.5
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.0.5.

Sensei LMS – Online Courses, Quizzes, & Learning

Plugin Slug:
sensei-lms
Installations
10,000+
Vulnerability:
Sensitive Data Exposure
Patched in Version:
4.20.0
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 4.20.0.

Simple Basic Contact Form

Plugin Slug:
simple-basic-contact-form
Installations
10,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
20250114
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 20250114.

Team – Team Members Showcase Plugin

Plugin Slug:
tlp-team
Installations
10,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
4.4.2
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 4.4.2.

Japanized for WooCommerce

Plugin Slug:
woocommerce-for-japan
Installations
10,000+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
2.6.41
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.6.41.

VikBooking Hotel Booking Engine & PMS

Plugin Slug:
vikbooking
Installations
9,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.7.2
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.7.2.

CM Tooltip Glossary

Plugin Slug:
enhanced-tooltipglossary
Installations
8,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
4.3.4
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 4.3.4.

If-So Dynamic Content Personalization

Plugin Slug:
if-so
Installations
8,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.8.0.3
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.8.0.3.

Travelpayouts: All Travel Brands in One Place

Plugin Slug:
travelpayouts
Installations
8,000+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
1.1.13
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.1.13.

Travelpayouts: All Travel Brands in One Place

Plugin Slug:
travelpayouts
Installations
8,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.1.14
Severity Score:
High
The vulnerability has been patched, so you should update to version 1.1.14.

AI ChatBot for WordPress – WPBot

Plugin Slug:
chatbot
Installations
7,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
6.2.4
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 6.2.4.

HD Quiz

Plugin:
HD Quiz
Plugin Slug:
hd-quiz
Installations
7,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.0.0
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.0.0.

ProfileGrid – User Profiles, Groups and Communities

Plugin Slug:
profilegrid-user-profiles-groups-and-communities
Installations
7,000+
Vulnerability:
Broken Access Control
Patched in Version:
5.9.5.2
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 5.9.5.2.

ProfileGrid – User Profiles, Groups and Communities

Plugin Slug:
profilegrid-user-profiles-groups-and-communities
Installations
7,000+
Vulnerability:
SQL Injection
Patched in Version:
5.9.5.1
Severity Score:
High
The vulnerability has been patched, so you should update to version 5.9.5.1.

Wise Chat

Plugin:
Wise Chat
Plugin Slug:
wise-chat
Installations
7,000+
Vulnerability:
Sensitive Data Exposure
Patched in Version:
3.3.4
Severity Score:
High
The vulnerability has been patched, so you should update to version 3.3.4.

Back Button Widget

Plugin Slug:
back-button-widget
Installations
6,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.7.0
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.7.0.

Easy Property Listings

Plugin Slug:
easy-property-listings
Installations
6,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
3.5.4
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.5.4.

EventON – Events Calendar

Plugin Slug:
eventon-lite
Installations
6,000+
Vulnerability:
Broken Access Control
Patched in Version:
2.4.5
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.4.5.

EventPrime – Events Calendar, Bookings and Tickets

Plugin Slug:
eventprime-event-calendar-management
Installations
6,000+
Vulnerability:
Broken Access Control
Patched in Version:
3.5.0
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.5.0.

Arconix Shortcodes

Plugin Slug:
arconix-shortcodes
Installations
5,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.1.17
Severity Score:
High
The vulnerability has been patched, so you should update to version 2.1.17.

MultiVendorX – WooCommerce Multivendor Marketplace Solutions

Plugin Slug:
dc-woocommerce-multi-vendor
Installations
5,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
4.2.23
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 4.2.23.

ElementInvader Addons for Elementor

Plugin Slug:
elementinvader-addons-for-elementor
Installations
5,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.3.6
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.3.6.

Podlove Podcast Publisher

Plugin Slug:
podlove-podcasting-plugin-for-wordpress
Installations
5,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
4.2.1
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 4.2.1.

Podlove Podcast Publisher

Plugin Slug:
podlove-podcasting-plugin-for-wordpress
Installations
5,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
4.1.24
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 4.1.24.
Plugin Slug:
responsive-gallery-grid
Installations
5,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.3.15
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.3.15.

SMS Alert Order Notifications – WooCommerce

Plugin Slug:
sms-alert
Installations
5,000+
Vulnerability:
Privilege Escalation
Patched in Version:
3.8.2
Severity Score:
High
The vulnerability has been patched, so you should update to version 3.8.2.

SMS Alert Order Notifications – WooCommerce

Plugin Slug:
sms-alert
Installations
5,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
3.8.2
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.8.2.

Melapress File Monitor

Plugin Slug:
website-file-changes-monitor
Installations
5,000+
Vulnerability:
SQL Injection
Patched in Version:
2.1.1
Severity Score:
High
The vulnerability has been patched, so you should update to version 2.1.1.

Melapress File Monitor

Plugin Slug:
website-file-changes-monitor
Installations
5,000+
Vulnerability:
SQL Injection
Patched in Version:
2.1.0
Severity Score:
High
The vulnerability has been patched, so you should update to version 2.1.0.

WPAdverts – Classifieds Plugin

Plugin Slug:
wpadverts
Installations
5,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.2.4
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.2.4.

Import Social Events

Plugin Slug:
import-facebook-events
Installations
4,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.8.6
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.8.6.

Ultimate Noindex Nofollow Tool II

Plugin Slug:
ultimate-noindex-nofollow-tool-ii
Installations
4,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.3.6
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.3.6.
Plugin Slug:
wp-auto-affiliate-links
Installations
4,000+
Vulnerability:
SQL Injection
Patched in Version:
6.4.7
Severity Score:
High
The vulnerability has been patched, so you should update to version 6.4.7.

Free Shipping Bar: Amount Left for Free Shipping for WooCommerce

Plugin Slug:
amount-left-free-shipping-woocommerce
Installations
3,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.4.7
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.4.7.

ApplyOnline – Application Form Builder and Manager

Plugin Slug:
apply-online
Installations
3,000+
Vulnerability:
Sensitive Data Exposure
Patched in Version:
2.6.3
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.6.3.

Newsletters

Plugin Slug:
newsletters-lite
Installations
3,000+
Vulnerability:
SQL Injection
Patched in Version:
4.9.9.9
Severity Score:
High
The vulnerability has been patched, so you should update to version 4.9.9.9.

User Activity Tracking and Log

Plugin Slug:
user-activity-tracking-and-log
Installations
3,000+
Vulnerability:
Other Vulnerability Type
Patched in Version:
4.1.4
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 4.1.4.

Wishlist for WooCommerce: Multi Wishlists Per Customer

Plugin Slug:
wish-list-for-woocommerce
Installations
3,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
3.2.3
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.2.3.

Additional Custom Emails & Recipients for WooCommerce

Plugin Slug:
custom-emails-for-woocommerce
Installations
2,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
3.5.2
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.5.2.

SKT Blocks – Gutenberg based Page Builder

Plugin Slug:
skt-blocks
Installations
2,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.3
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.3.
Plugin Slug:
url-coupons-for-woocommerce-by-algoritmika
Installations
2,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.7.8
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.7.8.

Change Add to Cart Button Text for WooCommerce

Plugin Slug:
add-to-cart-button-labels-for-woocommerce
Installations
1,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.2.3
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.2.3.

Auto Prune Posts

Plugin Slug:
auto-prune-posts
Installations
1,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
3.0.0
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.0.0.

Falang multilanguage for WordPress

Plugin Slug:
falang
Installations
1,000+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
1.3.62
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.3.62.

WordPress Mega Menu Block

Plugin Slug:
getwid-megamenu
Installations
1,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.0.7
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.0.7.
Plugin Slug:
ninja-gdpr-compliance
Installations
1,000+
Vulnerability:
Broken Access Control
Patched in Version:
2.7.4
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.7.4.

Product Code for WooCommerce

Plugin Slug:
product-code-for-woocommerce
Installations
1,000+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
1.5.1
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.5.1.

Product Notes Tab & Private Admin Notes for WooCommerce

Plugin Slug:
product-notes-for-woocommerce
Installations
1,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
3.1.1
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.1.1.

Tainacan

Plugin:
Tainacan
Plugin Slug:
tainacan
Installations
1,000+
Vulnerability:
Arbitrary File Deletion
Patched in Version:
0.21.15
Severity Score:
High
The vulnerability has been patched, so you should update to version 0.21.15.

Year Make Model Search for WooCommerce

Plugin Slug:
ymm-search
Installations
1,000+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
1.0.12
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.0.12.

Polls CP

Plugin:
Polls CP
Plugin Slug:
cp-polls
Installations
800+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.0.77
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.0.77.

Frontend Dashboard

Plugin Slug:
frontend-dashboard
Installations
700+
Vulnerability:
Privilege Escalation
Patched in Version:
2.2.8
Severity Score:
High
The vulnerability has been patched, so you should update to version 2.2.8.

Secure Downloads

Plugin Slug:
secure-downloads
Installations
700+
Vulnerability:
Arbitrary File Download
Patched in Version:
1.2.3
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.2.3.

Broadcast Live Video – Live Streaming : WebRTC, HLS, RTSP, RTMP

Plugin Slug:
videowhisper-live-streaming-integration
Installations
700+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
6.2.5
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 6.2.5.

Drag and Drop File Upload for Elementor Forms

Plugin Slug:
drag-and-drop-file-upload-for-elementor-forms
Installations
600+
Vulnerability:
Arbitrary File Deletion
Patched in Version:
1.5.0
Severity Score:
High
The vulnerability has been patched, so you should update to version 1.5.0.

Sharespine Woocommerce Connector

Plugin Slug:
sharespine-woocommerce-connector
Installations
600+
Vulnerability:
Broken Access Control
Patched in Version:
4.8.56
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 4.8.56.

Xpro Addons For Beaver Builder – Lite

Plugin Slug:
xpro-addons-beaver-builder-elementor
Installations
600+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.5.6
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.5.6.

Affiliates Manager Google reCAPTCHA Integration

Plugin Slug:
affiliates-manager-google-recaptcha-integration
Installations
500+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
1.0.7
Severity Score:
High
The vulnerability has been patched, so you should update to version 1.0.7.

GamiPress – Reset User

Plugin Slug:
gamipress-reset-user
Installations
500+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
1.0.1
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.0.1.

Plugin Oficial – Getnet para WooCommerce

Plugin Slug:
wc-checkout-getnet
Installations
500+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.8.1
Severity Score:
High
The vulnerability has been patched, so you should update to version 1.8.1.

Plugin Oficial – Getnet para WooCommerce

Plugin Slug:
wc-checkout-getnet
Installations
500+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.8.1
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.8.1.

WP Mapa Politico España

Plugin Slug:
wp-mapa-politico-spain
Installations
500+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
3.8.1
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.8.1.

CYAN Backup

Plugin Slug:
cyan-backup
Installations
400+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.5.3
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.5.3.

Url Rewrite Analyzer

Plugin Slug:
url-rewrite-analyzer
Installations
400+
Vulnerability:
Broken Access Control
Patched in Version:
1.3.4
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.3.4.

Bot for Telegram on WooCommerce

Plugin Slug:
bot-for-telegram-on-woocommerce
Installations
300+
Vulnerability:
Broken Access Control
Patched in Version:
1.2.7
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.2.7.

Posts per Cat

Plugin Slug:
posts-per-cat
Installations
300+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.5.0
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.5.0.

Projectopia – WordPress Project Management

Plugin Slug:
projectopia-core
Installations
300+
Vulnerability:
Broken Access Control
Patched in Version:
5.1.18
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 5.1.18.

RSVPMaker

Plugin:
RSVPMaker
Plugin Slug:
rsvpmaker
Installations
300+
Vulnerability:
SQL Injection
Patched in Version:
11.5.7
Severity Score:
High
The vulnerability has been patched, so you should update to version 11.5.7.

Subaccounts for WooCommerce

Plugin Slug:
subaccounts-for-woocommerce
Installations
300+
Vulnerability:
Broken Authentication
Patched in Version:
1.6.7
Severity Score:
High
The vulnerability has been patched, so you should update to version 1.6.7.

Wholesale Market

Plugin Slug:
wholesale-market
Installations
300+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
2.2.2
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.2.2.

AWcode Toolkit

Plugin Slug:
awcode-toolkit
Installations
200+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
1.0.19
Severity Score:
High
The vulnerability has been patched, so you should update to version 1.0.19.

B2i Investor Tools

Plugin Slug:
b2i-investor-tools
Installations
200+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.0.8
Severity Score:
High
The vulnerability has been patched, so you should update to version 1.0.8.

Push Notification for Post and BuddyPress

Plugin Slug:
push-notification-for-post-and-buddypress
Installations
200+
Vulnerability:
SQL Injection
Patched in Version:
1.94
Severity Score:
Critical
The vulnerability has been patched, so you should update to version 1.94.

WP Image Mask

Plugin Slug:
wp-image-mask
Installations
200+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
3.1.3
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.1.3.

CTT Expresso para WooCommerce

Plugin Slug:
ctt-expresso-para-woocommerce
Installations
100+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
3.2.13
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.2.13.

LogDash Activity Log

Plugin Slug:
logdash-activity-log
Installations
100+
Vulnerability:
SQL Injection
Patched in Version:
1.1.4
Severity Score:
Critical
The vulnerability has been patched, so you should update to version 1.1.4.

Payment Gateway for Telcell

Plugin Slug:
payment-gateway-for-telcell
Installations
100+
Vulnerability:
Open Redirection
Patched in Version:
2.0.4
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.0.4.

JSFiddle Shortcode

Plugin Slug:
jsfiddle-shortcode
Installations
80+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.1.3
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.1.3.

TicketBAI Facturas para WooCommerce

Plugin Slug:
wp-ticketbai
Installations
80+
Vulnerability:
Arbitrary File Deletion
Patched in Version:
3.19
Severity Score:
High
The vulnerability has been patched, so you should update to version 3.19.

Z-Downloads

Plugin Slug:
z-downloads
Installations
70+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.11.6
Severity Score:
High
The vulnerability has been patched, so you should update to version 1.11.6.

Z-Downloads

Plugin Slug:
z-downloads
Installations
70+
Vulnerability:
Arbitrary File Upload
Patched in Version:
1.11.5
Severity Score:
Critical
The vulnerability has been patched, so you should update to version 1.11.5.

Z-Downloads

Plugin Slug:
z-downloads
Installations
70+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.11.7
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.11.7.

Tours

Plugin:
Tours
Plugin Slug:
tours
Installations
20+
Vulnerability:
Broken Access Control
Patched in Version:
1.0.1
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.0.1.

EKC Tournament Manager

Plugin Slug:
ekc-tournament-manager
Installations
10+
Vulnerability:
Arbitrary File Download
Patched in Version:
2.2.2
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.2.2.

EKC Tournament Manager

Plugin Slug:
ekc-tournament-manager
Installations
10+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
2.2.2
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.2.2.

KBucket: Your Curated Content in WordPress

Plugin Slug:
kbucket
Installations
10+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
4.1.5
Severity Score:
High
The vulnerability has been patched, so you should update to version 4.1.5.

KBucket: Your Curated Content in WordPress

Plugin Slug:
kbucket
Installations
10+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
4.1.6
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 4.1.6.

Offload Videos – Bunny.net, AWS S3

Plugin Slug:
offload-videos-bunny-netaws-s3
Installations
10+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
1.0.1
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.0.1.

Simple Video Directory

Plugin Slug:
simple-media-directory
Installations
10+
Vulnerability:
SQL Injection
Patched in Version:
1.4.3
Severity Score:
Critical
The vulnerability has been patched, so you should update to version 1.4.3.

File Manager Advanced Shortcode PRO

Plugin:
File Manager Advanced Shortcode PRO
Plugin Slug:
advanced-file-manager-pro-premium
Vulnerability:
Content Injection
Patched in Version:
2.6.0
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.6.0.

ARForms Form Builder

Plugin:
ARForms Form Builder
Plugin Slug:
arforms-form-builder
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.7.1
Severity Score:
High
The vulnerability has been patched, so you should update to version 1.7.1.

Buddyboss Platform

Plugin:
Buddyboss Platform
Plugin Slug:
buddyboss-platform
Vulnerability:
Insecure Direct Object References (IDOR)
Patched in Version:
2.7.60
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.7.60.

Crawlomatic Multisite Scraper Post Generator

Plugin:
Crawlomatic Multisite Scraper Post Generator
Plugin Slug:
crawlomatic-multipage-scraper-post-generator
Vulnerability:
Arbitrary File Upload
Patched in Version:
2.6.8.2
Severity Score:
Critical
The vulnerability has been patched, so you should update to version 2.6.8.2.

EventON

Plugin:
EventON
Plugin Slug:
eventON
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
4.9.7
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 4.9.7.

Jetpack Debug Tools

Plugin:
Jetpack Debug Tools
Plugin Slug:
jetpack-debug-helper
Vulnerability:
Broken Access Control
Patched in Version:
2.0.1
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.0.1.

Ninja Forms Webhooks

Plugin:
Ninja Forms Webhooks
Plugin Slug:
ninja-forms-webhooks
Vulnerability:
Server Side Request Forgery (SSRF)
Patched in Version:
3.0.8
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.0.8.

Opal Woo Custom Product Variation

Plugin:
Opal Woo Custom Product Variation
Plugin Slug:
opal-woo-custom-product-variation
Vulnerability:
Arbitrary File Deletion
Patched in Version:
1.2.1
Severity Score:
High
The vulnerability has been patched, so you should update to version 1.2.1.

PeepSo Core: File Uploads

Plugin:
PeepSo Core: File Uploads
Plugin Slug:
peepso-files
Vulnerability:
Insecure Direct Object References (IDOR)
Patched in Version:
6.4.6.1
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 6.4.6.1.

Relevanssi Premium

Plugin:
Relevanssi Premium
Plugin Slug:
relevanssi-premium
Vulnerability:
SQL Injection
Patched in Version:
2.27.5
Severity Score:
High
The vulnerability has been patched, so you should update to version 2.27.5.

Echo RSS Feed Post Generator Plugin for WordPress

Plugin:
Echo RSS Feed Post Generator Plugin for WordPress
Plugin Slug:
rss-feed-post-generator-echo
Vulnerability:
Arbitrary File Upload
Patched in Version:
5.4.8.2
Severity Score:
Critical
The vulnerability has been patched, so you should update to version 5.4.8.2.

tarteaucitron.js for WordPress

Plugin:
tarteaucitron.js for WordPress
Plugin Slug:
tarteaucitron-wp
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
0.3.0
Severity Score:
High
The vulnerability has been patched, so you should update to version 0.3.0.

tarteaucitron.js for WordPress

Plugin:
tarteaucitron.js for WordPress
Plugin Slug:
tarteaucitron-wp
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
0.3.0
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 0.3.0.

Rankie

Plugin:
Rankie
Plugin Slug:
valvepress-rankie
Vulnerability:
Broken Access Control
Patched in Version:
1.8.2
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.8.2.

WP Content Copy Protection & No Right Click (premium)

Plugin:
WP Content Copy Protection & No Right Click (premium)
Plugin Slug:
wccp-pro
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
15.3
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 15.3.

WP Content Copy Protection & No Right Click (premium)

Plugin:
WP Content Copy Protection & No Right Click (premium)
Plugin Slug:
wccp-pro
Vulnerability:
Open Redirection
Patched in Version:
15.3
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 15.3.
Plugin:
GDPR Cookie Consent
Plugin Slug:
webtoffee-gdpr-cookie-consent
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.6.1
Severity Score:
High
The vulnerability has been patched, so you should update to version 2.6.1.
Plugin:
GDPR Cookie Consent
Plugin Slug:
webtoffee-gdpr-cookie-consent
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
2.6.1
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.6.1.

WPBot Pro WordPress Chatbot

Plugin:
WPBot Pro WordPress Chatbot
Plugin Slug:
wpbot-pro
Vulnerability:
Arbitrary File Deletion
Patched in Version:
13.7.0
Severity Score:
High
The vulnerability has been patched, so you should update to version 13.7.0.

WordPress Themes — 3 Patched / 15 Unpatched

Acerola

Theme:
Acerola
Theme Slug:
acerola
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should switch themes.

AnyWhere Elementor Pro

Theme:
AnyWhere Elementor Pro
Theme Slug:
anywhere-elementor-pro
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should switch themes.

Bimber – Viral Magazine WordPress Theme

Theme:
Bimber – Viral Magazine WordPress Theme
Theme Slug:
bimber
Vulnerability:
Local File Inclusion
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should switch themes.

Bloggie

Theme:
Bloggie
Theme Slug:
bloggie
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should switch themes.

CouponXL

Theme:
CouponXL
Theme Slug:
couponxl
Vulnerability:
Privilege Escalation
Patched in Version:
No Fix
Severity Score:
Critical
The vulnerability has not been patched. You should switch themes.

Dash

Theme:
Dash
Theme Slug:
dash
Vulnerability:
PHP Object Injection
Patched in Version:
No Fix
Severity Score:
Critical
The vulnerability has not been patched. You should switch themes.

HotStar – Multi-Purpose Business Theme

Theme:
HotStar – Multi-Purpose Business Theme
Theme Slug:
hotstar
Vulnerability:
PHP Object Injection
Patched in Version:
No Fix
Severity Score:
Critical
The vulnerability has not been patched. You should switch themes.

HotStar – Multi-Purpose Business Theme

Theme:
HotStar – Multi-Purpose Business Theme
Theme Slug:
hotstar
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should switch themes.

Jarvis – Night Club, Concert, Festival WordPress

Theme:
Jarvis – Night Club, Concert, Festival WordPress
Theme Slug:
jarvis
Vulnerability:
PHP Object Injection
Patched in Version:
No Fix
Severity Score:
Critical
The vulnerability has not been patched. You should switch themes.

The Business

Theme:
The Business
Theme Slug:
nrgbusiness
Vulnerability:
PHP Object Injection
Patched in Version:
No Fix
Severity Score:
Critical
The vulnerability has not been patched. You should switch themes.

The Business

Theme:
The Business
Theme Slug:
nrgbusiness
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should switch themes.

Plant – Gardening & Houseplants WordPress Theme

Theme:
Plant – Gardening & Houseplants WordPress Theme
Theme Slug:
plant
Vulnerability:
Sensitive Data Exposure
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should switch themes.

Rozario

Theme:
Rozario
Theme Slug:
rozario
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should switch themes.

Seven Stars

Theme:
Seven Stars
Theme Slug:
sevenstars
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should switch themes.

Spare

Theme:
Spare
Theme Slug:
spare
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should switch themes.

Motors

Theme:
Motors
Theme Slug:
motors
Vulnerability:
Privilege Escalation
Patched in Version:
5.6.68
Severity Score:
Critical
The vulnerability has been patched, so you should update to version 5.6.68.

TheGem

Theme:
TheGem
Theme Slug:
thegem
Vulnerability:
Broken Access Control
Patched in Version:
5.10.3.1
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 5.10.3.1.

TheGem

Theme:
TheGem
Theme Slug:
thegem
Vulnerability:
Arbitrary File Upload
Patched in Version:
5.10.3.1
Severity Score:
High
The vulnerability has been patched, so you should update to version 5.10.3.1.

Solid Security is part of Solid Suite — The best foundation for WordPress websites.

Every WordPress site needs security, backups, and management tools. That’s Solid Suite — an integrated bundle of three plugins: Solid Security, Solid Backups, and Solid Central. You also get access to Solid Academy’s learning resources for WordPress professionals. Build your next WordPress website on a solid foundation with Solid Suite!

Get Solid Security