WordPress Vulnerability Report

WordPress Vulnerability Report — May 28, 2025

Since last week, 180 new vulnerabilities emerged in the WordPress ecosystem, including 134 plugins and 46 themes. 92 of the vulnerable plugins and themes remain unpatched, but Solid Security Pro users are protected by virtual patching from Patchstack.

Avatar photo
Sarah Ulmer

In this report, 180 vulnerabilities have been publicly disclosed. Security patches for 88 of these plugins and themes are available now, so run those updates as soon as possible. If you’re a Solid Security Pro user, the version management tool may have already warned you and updated these plugins, depending on your settings.

Additionally, there are 92 plugin and theme vulnerabilities, and no patch has been available yet. If you’re a Solid Security Pro user, those vulnerabilities are already protected by the Solid Security firewall. Virtual patches from Patchstack will be applied when a vulnerability is considered high or medium risk. If no patch is forthcoming from the vendor or the vulnerable software has been marked “closed” and dropped from the official WordPress repositories, you should deactivate it soon and look for alternative solutions.

Along with poor user account security, vulnerable plugins and themes are among the top reasons why WordPress websites get hacked. Unfortunately, cyberattacks are increasing in volume and sophistication. They’re also increasingly aimed at small to mid-sized businesses.

Our WordPress Vulnerability Report covers the latest emerging WordPress plugin, theme, and core vulnerabilities. Each vulnerability will have a severity rating of LowMediumHigh, or Critical. Responsible disclosure of vulnerabilities is essential to keeping the WordPress community safe. Please share this report to help spread the word and make WordPress — and the web — more secure.

WordPress Core

WordPress 6.8.1 has been released! This maintenance release includes fixes for 15 bugs throughout Core and the Block Editor, addressing issues affecting multiple areas of WordPress, including the block editor, multisite, and REST API. For a full list, refer to the release candidate announcement.

Plus, WordCamp Europe 2025 lands in Basel, Switzerland, June 5-7! Connect with WordPress enthusiasts, developers, and pros for three days of learning, networking, and collaboration with the global community.

No new core vulnerabilities were disclosed this week.

WordPress Plugins — 74 Patched / 60 Unpatched

Essential Real Estate

Plugin Slug:
essential-real-estate
Installations
9,000+
Vulnerability:
Local File Inclusion
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Simplelightbox

Plugin Slug:
simplelightbox
Installations
1,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

StyleAI

Plugin:
StyleAI
Plugin Slug:
relentlosoftware
Installations
700+
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Spreadsheet Price Changer for WooCommerce and WP E-commerce – Light

Plugin Slug:
excel-like-price-change-for-woocommerce-and-wp-e-commerce-light
Installations
600+
Vulnerability:
Remote Code Execution (RCE)
Patched in Version:
No Fix
Severity Score:
Critical
The vulnerability has not been patched. You should deactivate the plugin.

Spreadsheet Price Changer for WooCommerce and WP E-commerce – Light

Plugin Slug:
excel-like-price-change-for-woocommerce-and-wp-e-commerce-light
Installations
600+
Vulnerability:
Privilege Escalation
Patched in Version:
No Fix
Severity Score:
Critical
The vulnerability has not been patched. You should deactivate the plugin.

Dynamic Pricing & Discounts Lite for WooCommerce

Plugin Slug:
woo-dynamic-pricing-discounts-lite
Installations
600+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

CryptoCloud – Crypto Payment Gateway

Plugin Slug:
cryptocloud-crypto-payment-gateway
Installations
500+
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

MetalpriceAPI

Plugin Slug:
metalpriceapi
Installations
400+
Vulnerability:
Remote Code Execution (RCE)
Patched in Version:
No Fix
Severity Score:
Critical
The vulnerability has not been patched. You should deactivate the plugin.

Embed and Integrate Etsy Shop

Plugin Slug:
embed-and-integrate-etsy-shop
Installations
200+
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

miniOrange Discord Integration

Plugin Slug:
miniorange-discord-integration
Installations
100+
Vulnerability:
Local File Inclusion
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Splitit

Plugin:
Splitit
Plugin Slug:
splitit-installment-payments
Installations
100+
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Binary MLM Plan

Plugin Slug:
binary-mlm-plan
Installations
60+
Vulnerability:
SQL Injection
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

4stats

Plugin:
4stats
Plugin Slug:
4stats
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

WhatsCart – Whatsapp Abandoned Cart Recovery, Order Notifications, Chat Box, OTP for WooCommerce

Plugin:
WhatsCart – Whatsapp Abandoned Cart Recovery, Order Notifications, Chat Box, OTP for WooCommerce
Plugin Slug:
WhatsCart-for-WooCommerce
Vulnerability:
SQL Injection
Patched in Version:
No Fix
Severity Score:
Critical
The vulnerability has not been patched. You should deactivate the plugin.

Animated Buttons

Plugin:
Animated Buttons
Plugin Slug:
animated-buttons
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Ads Pro Plugin

Plugin:
Ads Pro Plugin
Plugin Slug:
ap-plugin-scripteo
Vulnerability:
Local File Inclusion
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Blog Designer PRO for WordPress

Plugin:
Blog Designer PRO for WordPress
Plugin Slug:
blog-designer-pro
Vulnerability:
Local File Inclusion
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

WPCHURCH

Plugin:
WPCHURCH
Plugin Slug:
church-management
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

DPEPress

Plugin:
DPEPress
Plugin Slug:
dpepress
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.
Plugin:
DZS Video Gallery
Plugin Slug:
dzs-videogallery
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.
Plugin:
DZS Video Gallery
Plugin Slug:
dzs-videogallery
Vulnerability:
PHP Object Injection
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.
Plugin:
DZS Video Gallery
Plugin Slug:
dzs-videogallery
Vulnerability:
PHP Object Injection
Patched in Version:
No Fix
Severity Score:
Critical
The vulnerability has not been patched. You should deactivate the plugin.

ZoomSounds

Plugin:
ZoomSounds
Plugin Slug:
dzs-zoomsounds
Vulnerability:
PHP Object Injection
Patched in Version:
No Fix
Severity Score:
Critical
The vulnerability has not been patched. You should deactivate the plugin.

Formulario de contacto SalesUp!

Plugin:
Formulario de contacto SalesUp!
Plugin Slug:
formularios-de-contacto-salesup
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Goodlayers Hostel

Plugin:
Goodlayers Hostel
Plugin Slug:
gdlr-hostel
Vulnerability:
SQL Injection
Patched in Version:
No Fix
Severity Score:
Critical
The vulnerability has not been patched. You should deactivate the plugin.

Goodlayers Hostel

Plugin:
Goodlayers Hostel
Plugin Slug:
gdlr-hostel
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Goodlayers Hostel

Plugin:
Goodlayers Hostel
Plugin Slug:
gdlr-hostel
Vulnerability:
PHP Object Injection
Patched in Version:
No Fix
Severity Score:
Critical
The vulnerability has not been patched. You should deactivate the plugin.

Goodlayers Hotel

Plugin:
Goodlayers Hotel
Plugin Slug:
gdlr-hotel
Vulnerability:
SQL Injection
Patched in Version:
No Fix
Severity Score:
Critical
The vulnerability has not been patched. You should deactivate the plugin.

Goodlayers Hotel

Plugin:
Goodlayers Hotel
Plugin Slug:
gdlr-hotel
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Goodlayers Hotel

Plugin:
Goodlayers Hotel
Plugin Slug:
gdlr-hotel
Vulnerability:
PHP Object Injection
Patched in Version:
No Fix
Severity Score:
Critical
The vulnerability has not been patched. You should deactivate the plugin.

Hospital Management System

Plugin:
Hospital Management System
Plugin Slug:
hospital-management
Vulnerability:
Privilege Escalation
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Hospital Management System

Plugin:
Hospital Management System
Plugin Slug:
hospital-management
Vulnerability:
Arbitrary File Upload
Patched in Version:
No Fix
Severity Score:
Critical
The vulnerability has not been patched. You should deactivate the plugin.

JobHunt Job Alerts

Plugin:
JobHunt Job Alerts
Plugin Slug:
jobhunt-notifications
Vulnerability:
Arbitrary Content Deletion
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

JP Students Result Management System Premium

Plugin:
JP Students Result Management System Premium
Plugin Slug:
jp-students-result-system-premium
Vulnerability:
Arbitrary File Upload
Patched in Version:
No Fix
Severity Score:
Critical
The vulnerability has not been patched. You should deactivate the plugin.

KBx Pro Ultimate

Plugin:
KBx Pro Ultimate
Plugin Slug:
knowledgebase-helpdesk-pro
Vulnerability:
Arbitrary File Deletion
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

MapSVG

Plugin:
MapSVG
Plugin Slug:
mapsvg
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

MapSVG

Plugin:
MapSVG
Plugin Slug:
mapsvg
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Nasa Core

Plugin:
Nasa Core
Plugin Slug:
nasa-core
Vulnerability:
Local File Inclusion
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Posts Extended

Plugin:
Posts Extended
Plugin Slug:
network-posts-extended
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Pixel WordPress Form BuilderPlugin & Autoresponder

Plugin:
Pixel WordPress Form BuilderPlugin & Autoresponder
Plugin Slug:
pixel-formbuilder
Vulnerability:
SQL Injection
Patched in Version:
No Fix
Severity Score:
Critical
The vulnerability has not been patched. You should deactivate the plugin.

Raisely Donation Form

Plugin:
Raisely Donation Form
Plugin Slug:
raisely-donation-form
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Rootspersona

Plugin:
Rootspersona
Plugin Slug:
rootspersona
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Rootspersona

Plugin:
Rootspersona
Plugin Slug:
rootspersona
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

School Management

Plugin:
School Management
Plugin Slug:
school-management
Vulnerability:
SQL Injection
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

School Management

Plugin:
School Management
Plugin Slug:
school-management
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Bus Ticket Booking with Seat Reservation for WooCommerce

Plugin:
Bus Ticket Booking with Seat Reservation for WooCommerce
Plugin Slug:
scw-bus-seat-reservation
Vulnerability:
SQL Injection
Patched in Version:
No Fix
Severity Score:
Critical
The vulnerability has not been patched. You should deactivate the plugin.

Simple Business Directory Pro

Plugin:
Simple Business Directory Pro
Plugin Slug:
simple-business-directory-pro
Vulnerability:
Privilege Escalation
Patched in Version:
No Fix
Severity Score:
Critical
The vulnerability has not been patched. You should deactivate the plugin.

Smart Forms

Plugin:
Smart Forms
Plugin Slug:
smart-forms
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

eMagicOne Store Manager

Plugin:
eMagicOne Store Manager
Plugin Slug:
store-manager-connector
Vulnerability:
Arbitrary File Deletion
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

eMagicOne Store Manager

Plugin:
eMagicOne Store Manager
Plugin Slug:
store-manager-connector
Vulnerability:
Arbitrary File Download
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

eMagicOne Store Manager

Plugin:
eMagicOne Store Manager
Plugin Slug:
store-manager-connector
Vulnerability:
Arbitrary File Upload
Patched in Version:
No Fix
Severity Score:
Critical
The vulnerability has not been patched. You should deactivate the plugin.

User Profile Meta Manager

Plugin:
User Profile Meta Manager
Plugin Slug:
user-profile-meta
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Critical
The vulnerability has not been patched. You should deactivate the plugin.

Affiliate Sales in Google Analytics and other tools

Plugin:
Affiliate Sales in Google Analytics and other tools
Plugin Slug:
wecantrack
Vulnerability:
Open Redirection
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

WP Post Modules for Elementor

Plugin:
WP Post Modules for Elementor
Plugin Slug:
wp-post-modules-el
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

WP YouTube Video Optimizer

Plugin:
WP YouTube Video Optimizer
Plugin Slug:
wp-youtube-video-optimizer
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Glossary by WPPedia

Plugin:
Glossary by WPPedia
Plugin Slug:
wppedia
Vulnerability:
PHP Object Injection
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

WooCommerce

Plugin Slug:
woocommerce
Installations
8,000,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
9.3.4
Severity Score:
High
The vulnerability has been patched, so you should update to version 9.3.4.

TablePress – Tables in WordPress made easy

Plugin Slug:
tablepress
Installations
700,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
3.1.3
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.1.3.

The Events Calendar

Plugin Slug:
the-events-calendar
Installations
700,000+
Vulnerability:
Broken Access Control
Patched in Version:
6.12.0
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 6.12.0.

Page Builder: Pagelayer – Drag and Drop website builder

Plugin Slug:
pagelayer
Installations
300,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.0.1
Severity Score:
High
The vulnerability has been patched, so you should update to version 2.0.1.

Solid Mail – SMTP email and logging made by SolidWP

Plugin Slug:
wp-smtp
Installations
70,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.1.6
Severity Score:
High
The vulnerability has been patched, so you should update to version 2.1.6.

Exclusive Addons for Elementor

Plugin Slug:
exclusive-addons-for-elementor
Installations
60,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.7.9.2
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.7.9.2.

Exclusive Addons for Elementor

Plugin Slug:
exclusive-addons-for-elementor
Installations
60,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.7.9.1
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.7.9.1.

Qi Blocks

Plugin:
Qi Blocks
Plugin Slug:
qi-blocks
Installations
60,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.4
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.4.

Blog2Social: Social Media Auto Post & Scheduler

Plugin Slug:
blog2social
Installations
50,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
8.4.0
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 8.4.0.

Slim SEO – Fast & Automated WordPress SEO Plugin

Plugin Slug:
slim-seo
Installations
50,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
4.5.4
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 4.5.4.

Ultimate Blocks – WordPress Blocks Plugin

Plugin Slug:
ultimate-blocks
Installations
50,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
3.3.1
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.3.1.

Visual Composer Website Builder

Plugin Slug:
visualcomposer
Installations
50,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
45.12.0
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 45.12.0.

Cost Calculator Builder

Plugin Slug:
cost-calculator-builder
Installations
30,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
3.5.0
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.5.0.

bunny.net – WordPress CDN Plugin

Plugin Slug:
bunnycdn
Installations
10,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.3.1
Severity Score:
High
The vulnerability has been patched, so you should update to version 2.3.1.

Japanized for WooCommerce

Plugin Slug:
woocommerce-for-japan
Installations
10,000+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
2.6.41
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.6.41.

Back Button Widget

Plugin Slug:
back-button-widget
Installations
6,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.7.0
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.7.0.

Leadinfo

Plugin:
Leadinfo
Plugin Slug:
leadinfo
Installations
6,000+
Vulnerability:
Settings Change
Patched in Version:
2.1
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.1.

ElementInvader Addons for Elementor

Plugin Slug:
elementinvader-addons-for-elementor
Installations
5,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.3.6
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.3.6.

WPAdverts – Classifieds Plugin

Plugin Slug:
wpadverts
Installations
5,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.2.4
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.2.4.

MultiVendorX – WooCommerce Multivendor Marketplace Solutions

Plugin Slug:
dc-woocommerce-multi-vendor
Installations
4,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
4.2.23
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 4.2.23.

Import Social Events

Plugin Slug:
import-facebook-events
Installations
4,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.8.6
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.8.6.

Free Shipping Bar: Amount Left for Free Shipping for WooCommerce

Plugin Slug:
amount-left-free-shipping-woocommerce
Installations
3,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.4.7
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.4.7.

Hot Random Image

Plugin Slug:
hot-random-image
Installations
3,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.9.3
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.9.3.

Hot Random Image

Plugin Slug:
hot-random-image
Installations
3,000+
Vulnerability:
Path Traversal
Patched in Version:
1.9.3
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.9.3.

Wishlist for WooCommerce: Multi Wishlists Per Customer

Plugin Slug:
wish-list-for-woocommerce
Installations
3,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
3.2.3
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.2.3.

Additional Custom Emails & Recipients for WooCommerce

Plugin Slug:
custom-emails-for-woocommerce
Installations
2,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
3.5.2
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.5.2.

SKT Blocks – Gutenberg based Page Builder

Plugin Slug:
skt-blocks
Installations
2,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.3
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.3.
Plugin Slug:
url-coupons-for-woocommerce-by-algoritmika
Installations
2,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.7.8
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.7.8.

Change Add to Cart Button Text for WooCommerce

Plugin Slug:
add-to-cart-button-labels-for-woocommerce
Installations
1,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.2.3
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.2.3.

Falang multilanguage for WordPress

Plugin Slug:
falang
Installations
1,000+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
1.3.62
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.3.62.

WordPress Mega Menu Block

Plugin Slug:
getwid-megamenu
Installations
1,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.0.7
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.0.7.
Plugin Slug:
ninja-gdpr-compliance
Installations
1,000+
Vulnerability:
Broken Access Control
Patched in Version:
2.7.4
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.7.4.

Product Code for WooCommerce

Plugin Slug:
product-code-for-woocommerce
Installations
1,000+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
1.5.1
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.5.1.

Product Notes Tab & Private Admin Notes for WooCommerce

Plugin Slug:
product-notes-for-woocommerce
Installations
1,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
3.1.1
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.1.1.

WP Smart Import : Import any XML File to WordPress

Plugin Slug:
wp-smart-import
Installations
1,000+
Vulnerability:
Local File Inclusion
Patched in Version:
1.1.4
Severity Score:
High
The vulnerability has been patched, so you should update to version 1.1.4.

Year Make Model Search for WooCommerce

Plugin Slug:
ymm-search
Installations
1,000+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
1.0.12
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.0.12.

Broadcast Live Video – Live Streaming : WebRTC, HLS, RTSP, RTMP

Plugin Slug:
videowhisper-live-streaming-integration
Installations
700+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
6.2.5
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 6.2.5.

Xpro Addons For Beaver Builder – Lite

Plugin Slug:
xpro-addons-beaver-builder-elementor
Installations
600+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.5.6
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.5.6.

Affiliates Manager Google reCAPTCHA Integration

Plugin Slug:
affiliates-manager-google-recaptcha-integration
Installations
500+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
1.0.7
Severity Score:
High
The vulnerability has been patched, so you should update to version 1.0.7.

Visual Header

Plugin Slug:
visual-header
Installations
500+
Vulnerability:
Broken Access Control
Patched in Version:
1.5
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.5.

WP Mapa Politico España

Plugin Slug:
wp-mapa-politico-spain
Installations
500+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
3.8.1
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.8.1.

Url Rewrite Analyzer

Plugin Slug:
url-rewrite-analyzer
Installations
400+
Vulnerability:
Broken Access Control
Patched in Version:
1.3.4
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.3.4.

Bot for Telegram on WooCommerce

Plugin Slug:
bot-for-telegram-on-woocommerce
Installations
300+
Vulnerability:
Broken Access Control
Patched in Version:
1.2.7
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.2.7.

Projectopia – WordPress Project Management

Plugin Slug:
projectopia-core
Installations
300+
Vulnerability:
Broken Access Control
Patched in Version:
5.1.18
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 5.1.18.

RSVPMaker

Plugin:
RSVPMaker
Plugin Slug:
rsvpmaker
Installations
300+
Vulnerability:
SQL Injection
Patched in Version:
11.5.7
Severity Score:
High
The vulnerability has been patched, so you should update to version 11.5.7.

AWcode Toolkit

Plugin Slug:
awcode-toolkit
Installations
200+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
1.0.19
Severity Score:
High
The vulnerability has been patched, so you should update to version 1.0.19.

WP Image Mask

Plugin Slug:
wp-image-mask
Installations
200+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
3.1.3
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.1.3.

Infocob CRM Forms

Plugin Slug:
infocob-crm-forms
Installations
100+
Vulnerability:
Arbitrary File Download
Patched in Version:
2.4.1
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.4.1.

Pix 4x sem juros – Pagaleve

Plugin Slug:
wc-pagaleve
Installations
100+
Vulnerability:
PHP Object Injection
Patched in Version:
1.6.10
Severity Score:
Critical
The vulnerability has been patched, so you should update to version 1.6.10.

Property – Real Estate Directory Listing

Plugin Slug:
property
Installations
30+
Vulnerability:
Privilege Escalation
Patched in Version:
1.0.7
Severity Score:
High
The vulnerability has been patched, so you should update to version 1.0.7.

Advanced Database Cleaner PRO

Plugin:
Advanced Database Cleaner PRO
Plugin Slug:
advanced-database-cleaner-pro
Vulnerability:
Path Traversal
Patched in Version:
3.2.11
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.2.11.

Digits

Plugin:
Digits
Plugin Slug:
digits
Vulnerability:
Privilege Escalation
Patched in Version:
8.4.6.1
Severity Score:
Critical
The vulnerability has been patched, so you should update to version 8.4.6.1.

Order Delivery Date for WP e-Commerce

Plugin:
Order Delivery Date for WP e-Commerce
Plugin Slug:
order-delivery-date
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
12.4.0
Severity Score:
High
The vulnerability has been patched, so you should update to version 12.4.0.

Tourmaster

Plugin:
Tourmaster
Plugin Slug:
tourmaster
Vulnerability:
Local File Inclusion
Patched in Version:
5.3.9
Severity Score:
High
The vulnerability has been patched, so you should update to version 5.3.9.

WordPress Themes — 14 Patched / 32 Unpatched

Acerola

Theme:
Acerola
Theme Slug:
acerola
Vulnerability:
PHP Object Injection
Patched in Version:
No Fix
Severity Score:
Critical
The vulnerability has not been patched. You should switch themes.

Avantage

Theme:
Avantage
Theme Slug:
avantage
Vulnerability:
PHP Object Injection
Patched in Version:
No Fix
Severity Score:
Critical
The vulnerability has not been patched. You should switch themes.

Backpack Traveler

Theme:
Backpack Traveler
Theme Slug:
backpacktraveler
Vulnerability:
Local File Inclusion
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should switch themes.

Bloggie

Theme:
Bloggie
Theme Slug:
bloggie
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should switch themes.

Butcher

Theme:
Butcher
Theme Slug:
butcher
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should switch themes.

Butcher

Theme:
Butcher
Theme Slug:
butcher
Vulnerability:
Local File Inclusion
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should switch themes.

Capie

Theme:
Capie
Theme Slug:
capie
Vulnerability:
Local File Inclusion
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should switch themes.

Car Dealer

Theme:
Car Dealer
Theme Slug:
cardealer
Vulnerability:
PHP Object Injection
Patched in Version:
No Fix
Severity Score:
Critical
The vulnerability has not been patched. You should switch themes.

CouponXL

Theme:
CouponXL
Theme Slug:
couponxl
Vulnerability:
Privilege Escalation
Patched in Version:
No Fix
Severity Score:
Critical
The vulnerability has not been patched. You should switch themes.

Crafts & Arts

Theme:
Crafts & Arts
Theme Slug:
crafts-and-arts
Vulnerability:
PHP Object Injection
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should switch themes.

Dash

Theme:
Dash
Theme Slug:
dash
Vulnerability:
PHP Object Injection
Patched in Version:
No Fix
Severity Score:
Critical
The vulnerability has not been patched. You should switch themes.

Entrada

Theme:
Entrada
Theme Slug:
entrada
Vulnerability:
SQL Injection
Patched in Version:
No Fix
Severity Score:
Critical
The vulnerability has not been patched. You should switch themes.

Enzio – Responsive Business WordPress Theme

Theme:
Enzio – Responsive Business WordPress Theme
Theme Slug:
enzio
Vulnerability:
Local File Inclusion
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should switch themes.

Finance Consultant

Theme:
Finance Consultant
Theme Slug:
finance
Vulnerability:
PHP Object Injection
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should switch themes.

Fish House

Theme:
Fish House
Theme Slug:
fish-house
Vulnerability:
PHP Object Injection
Patched in Version:
No Fix
Severity Score:
Critical
The vulnerability has not been patched. You should switch themes.

Grand Tour | Travel Agency WordPress

Theme:
Grand Tour | Travel Agency WordPress
Theme Slug:
grandtour
Vulnerability:
PHP Object Injection
Patched in Version:
No Fix
Severity Score:
Critical
The vulnerability has not been patched. You should switch themes.

Healsoul

Theme:
Healsoul
Theme Slug:
healsoul
Vulnerability:
Local File Inclusion
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should switch themes.

HotStar – Multi-Purpose Business Theme

Theme:
HotStar – Multi-Purpose Business Theme
Theme Slug:
hotstar
Vulnerability:
PHP Object Injection
Patched in Version:
No Fix
Severity Score:
Critical
The vulnerability has not been patched. You should switch themes.

Insurance

Theme:
Insurance
Theme Slug:
insurance
Vulnerability:
PHP Object Injection
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should switch themes.

Jarvis – Night Club, Concert, Festival WordPress

Theme:
Jarvis – Night Club, Concert, Festival WordPress
Theme Slug:
jarvis
Vulnerability:
PHP Object Injection
Patched in Version:
No Fix
Severity Score:
Critical
The vulnerability has not been patched. You should switch themes.

Kiamo – Responsive Business Service WordPress Theme

Theme:
Kiamo – Responsive Business Service WordPress Theme
Theme Slug:
kiamo
Vulnerability:
Local File Inclusion
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should switch themes.

La Boom

Theme:
La Boom
Theme Slug:
laboom
Vulnerability:
Local File Inclusion
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should switch themes.

Medicare

Theme:
Medicare
Theme Slug:
medicare
Vulnerability:
PHP Object Injection
Patched in Version:
No Fix
Severity Score:
Critical
The vulnerability has not been patched. You should switch themes.

The Business

Theme:
The Business
Theme Slug:
nrgbusiness
Vulnerability:
PHP Object Injection
Patched in Version:
No Fix
Severity Score:
Critical
The vulnerability has not been patched. You should switch themes.

Ogami

Theme:
Ogami
Theme Slug:
ogami
Vulnerability:
Local File Inclusion
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should switch themes.

Oxpitan

Theme:
Oxpitan
Theme Slug:
oxpitan
Vulnerability:
Local File Inclusion
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should switch themes.

Pet World

Theme:
Pet World
Theme Slug:
petsworld
Vulnerability:
PHP Object Injection
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should switch themes.

Photography

Theme:
Photography
Theme Slug:
photography
Vulnerability:
PHP Object Injection
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should switch themes.

Umberto

Theme:
Umberto
Theme Slug:
umberto
Vulnerability:
PHP Object Injection
Patched in Version:
No Fix
Severity Score:
Critical
The vulnerability has not been patched. You should switch themes.

Vizeon – Business Consulting

Theme:
Vizeon – Business Consulting
Theme Slug:
vizeon
Vulnerability:
Local File Inclusion
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should switch themes.

Winnex

Theme:
Winnex
Theme Slug:
winnex
Vulnerability:
Local File Inclusion
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should switch themes.

Yozi

Theme:
Yozi
Theme Slug:
yozi
Vulnerability:
Local File Inclusion
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should switch themes.

Ashley

Theme:
Ashley
Theme Slug:
ashley
Vulnerability:
Local File Inclusion
Patched in Version:
1.8.0
Severity Score:
High
The vulnerability has been patched, so you should update to version 1.8.0.

Builty

Theme:
Builty
Theme Slug:
builty
Vulnerability:
Local File Inclusion
Patched in Version:
1.5.0
Severity Score:
High
The vulnerability has been patched, so you should update to version 1.5.0.

ITSulu

Theme:
ITSulu
Theme Slug:
itsulu
Vulnerability:
Local File Inclusion
Patched in Version:
1.5.0
Severity Score:
High
The vulnerability has been patched, so you should update to version 1.5.0.

Kaffen

Theme:
Kaffen
Theme Slug:
kaffen
Vulnerability:
Local File Inclusion
Patched in Version:
1.2.6
Severity Score:
High
The vulnerability has been patched, so you should update to version 1.2.6.

Kids Planet

Theme:
Kids Planet
Theme Slug:
kidsplanet
Vulnerability:
PHP Object Injection
Patched in Version:
2.2.14.1
Severity Score:
Critical
The vulnerability has been patched, so you should update to version 2.2.14.1.

Kinsley

Theme:
Kinsley
Theme Slug:
kinsley
Vulnerability:
Local File Inclusion
Patched in Version:
3.4.5
Severity Score:
High
The vulnerability has been patched, so you should update to version 3.4.5.

Larson

Theme:
Larson
Theme Slug:
larson
Vulnerability:
Local File Inclusion
Patched in Version:
1.6.0
Severity Score:
High
The vulnerability has been patched, so you should update to version 1.6.0.

Luique

Theme:
Luique
Theme Slug:
luique
Vulnerability:
Local File Inclusion
Patched in Version:
1.3.1
Severity Score:
High
The vulnerability has been patched, so you should update to version 1.3.1.

Madara

Theme:
Madara
Theme Slug:
madara
Vulnerability:
Local File Inclusion
Patched in Version:
2.2.2.1
Severity Score:
High
The vulnerability has been patched, so you should update to version 2.2.2.1.

Motors

Theme:
Motors
Theme Slug:
motors
Vulnerability:
Privilege Escalation
Patched in Version:
5.6.68
Severity Score:
Critical
The vulnerability has been patched, so you should update to version 5.6.68.

Ober

Theme:
Ober
Theme Slug:
ober
Vulnerability:
Local File Inclusion
Patched in Version:
1.3.4
Severity Score:
High
The vulnerability has been patched, so you should update to version 1.3.4.

Ruizarch

Theme:
Ruizarch
Theme Slug:
ruizarch
Vulnerability:
Local File Inclusion
Patched in Version:
1.2.0
Severity Score:
High
The vulnerability has been patched, so you should update to version 1.2.0.

Samantha

Theme:
Samantha
Theme Slug:
samantha
Vulnerability:
Local File Inclusion
Patched in Version:
1.2.0
Severity Score:
High
The vulnerability has been patched, so you should update to version 1.2.0.

Wilmër

Theme:
Wilmër
Theme Slug:
wilmer
Vulnerability:
Local File Inclusion
Patched in Version:
3.4.2
Severity Score:
High
The vulnerability has been patched, so you should update to version 3.4.2.

Solid Security is part of Solid Suite — The best foundation for WordPress websites.

Every WordPress site needs security, backups, and management tools. That’s Solid Suite — an integrated bundle of three plugins: Solid Security, Solid Backups, and Solid Central. You also get access to Solid Academy’s learning resources for WordPress professionals. Build your next WordPress website on a solid foundation with Solid Suite!

Get Solid Security