WordPress Vulnerability Report

WordPress Vulnerability Report — May 7, 2025

Since last week, 88 new vulnerabilities emerged in the WordPress ecosystem, including 82 plugins and 6 themes. 42 of the vulnerable plugins remain unpatched, but Solid Security Pro users are protected by virtual patching from Patchstack.

Avatar photo
Sarah Ulmer

In this report, 88 vulnerabilities have been publicly disclosed. Security patches for 46 of these plugins and themes are available now, so run those updates as soon as possible. If you’re a Solid Security Pro user, the version management tool may have already warned you and updated these plugins, depending on your settings.

Additionally, there are 42 plugin and theme vulnerabilities, and no patch has been available yet. If you’re a Solid Security Pro user, those vulnerabilities are already protected by the Solid Security firewall. Virtual patches from Patchstack will be applied when a vulnerability is considered high or medium risk. If no patch is forthcoming from the vendor or the vulnerable software has been marked “closed” and dropped from the official WordPress repositories, you should deactivate it soon and look for alternative solutions.

Along with poor user account security, vulnerable plugins and themes are among the top reasons why WordPress websites get hacked. Unfortunately, cyberattacks are increasing in volume and sophistication. They’re also increasingly aimed at small to mid-sized businesses.

Our WordPress Vulnerability Report covers the latest emerging WordPress plugin, theme, and core vulnerabilities. Each vulnerability will have a severity rating of LowMediumHigh, or Critical. Responsible disclosure of vulnerabilities is essential to keeping the WordPress community safe. Please share this report to help spread the word and make WordPress — and the web — more secure.

WordPress Core

WordPress 6.8.1 has been released! This maintenance release includes fixes for 15 bugs throughout Core and the Block Editor, addressing issues affecting multiple areas of WordPress, including the block editor, multisite, and REST API. For a full list, refer to the release candidate announcement.

Plus, WordCamp Europe 2025 lands in Basel, Switzerland, June 5-7! Connect with WordPress enthusiasts, developers, and pros for three days of learning, networking, and collaboration with the global community.

No new core vulnerabilities were disclosed this week.

WordPress Plugins — 40 Patched / 42 Unpatched

Section Widget

Plugin Slug:
section-widget
Installations
600+
Vulnerability:
Path Traversal
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Section Widget

Plugin Slug:
section-widget
Installations
600+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Crossword Compiler Puzzles

Plugin Slug:
crossword-compiler-puzzles
Installations
400+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Total processing card payments for WooCommerce

Plugin Slug:
totalprocessing-card-payments
Installations
200+
Vulnerability:
Arbitrary File Download
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Abundatrade

Plugin:
Abundatrade
Plugin Slug:
abundatrade-plugin
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Advanced Reorder Image Text Slider

Plugin:
Advanced Reorder Image Text Slider
Plugin Slug:
advanced-reorder-image-text-slider
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

AHAthat

Plugin:
AHAthat
Plugin Slug:
ahathat
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.
Plugin:
Alink Tap
Plugin Slug:
alink-tap
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Buddyboss Platform

Plugin:
Buddyboss Platform
Plugin Slug:
buddyboss-platform
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Category Widget

Plugin:
Category Widget
Plugin Slug:
category-widget
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Custom PC Builder Lite for WooCommerce

Plugin:
Custom PC Builder Lite for WooCommerce
Plugin Slug:
custom-pc-builder-lite-for-woocommerce
Vulnerability:
Settings Change
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Database Toolset

Plugin:
Database Toolset
Plugin Slug:
database-toolset
Vulnerability:
Sensitive Data Exposure
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

EC Authorize.net

Plugin:
EC Authorize.net
Plugin Slug:
ec-authorizenet
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

External image replace

Plugin:
External image replace
Plugin Slug:
external-image-replace
Vulnerability:
Arbitrary File Upload
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Flynax Bridge

Plugin:
Flynax Bridge
Plugin Slug:
flynax-bridge
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

GmapsMania

Plugin:
GmapsMania
Plugin Slug:
gmapsmania
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.
Plugin:
IGIT Related Posts With Thumb Image After Posts
Plugin Slug:
igit-related-posts-with-thumb-images-after-posts
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Job Listings

Plugin:
Job Listings
Plugin Slug:
job-listings
Vulnerability:
Privilege Escalation
Patched in Version:
No Fix
Severity Score:
Critical
The vulnerability has not been patched. You should deactivate the plugin.

KiwiChat NextClient

Plugin:
KiwiChat NextClient
Plugin Slug:
kiwichat
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

kStats Reloaded

Plugin:
kStats Reloaded
Plugin Slug:
kstats-reloaded
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

LayoutBoxx

Plugin:
LayoutBoxx
Plugin Slug:
layoutboxx
Vulnerability:
Content Injection
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Web3Press

Plugin:
Web3Press
Plugin Slug:
likecoin
Vulnerability:
Arbitrary File Download
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Custom Login and Registration

Plugin:
Custom Login and Registration
Plugin Slug:
ms-registration
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Nautic Pages

Plugin:
Nautic Pages
Plugin Slug:
nautic-pages
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

occupancyplan

Plugin:
occupancyplan
Plugin Slug:
occupancyplan
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

OTP-less one tap Sign in

Plugin:
OTP-less one tap Sign in
Plugin Slug:
otpless
Vulnerability:
Privilege Escalation
Patched in Version:
No Fix
Severity Score:
Critical
The vulnerability has not been patched. You should deactivate the plugin.

Remote Images Grabber

Plugin:
Remote Images Grabber
Plugin Slug:
remote-images-grabber
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Separator Shortcode and Widget

Plugin:
Separator Shortcode and Widget
Plugin Slug:
separator-shortcode-and-widget
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Reales WP STPT

Plugin:
Reales WP STPT
Plugin Slug:
short-tax-post
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Reales WP STPT

Plugin:
Reales WP STPT
Plugin Slug:
short-tax-post
Vulnerability:
Privilege Escalation
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Subpage List

Plugin:
Subpage List
Plugin Slug:
subpage-view
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Syndicate Out

Plugin:
Syndicate Out
Plugin Slug:
syndicate-out
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Theme Blvd Sliders

Plugin:
Theme Blvd Sliders
Plugin Slug:
theme-blvd-sliders
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Total Donations

Plugin:
Total Donations
Plugin Slug:
total-donations
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

VerticalResponse Newsletter Widget

Plugin:
VerticalResponse Newsletter Widget
Plugin Slug:
vertical-response-newsletter-widget
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Visual Builder

Plugin:
Visual Builder
Plugin Slug:
visual-builder
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Widgets as Shortcodes

Plugin:
Widgets as Shortcodes
Plugin Slug:
widgets-as-shortcodes
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Meta Keywords & Description

Plugin:
Meta Keywords & Description
Plugin Slug:
wp-meta-keywords-meta-description
Vulnerability:
Local File Inclusion
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Xavin’s Review Ratings

Plugin:
Xavin’s Review Ratings
Plugin Slug:
xavins-review-ratings
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Yame

Plugin:
Yame
Plugin Slug:
yame-linkinbio
Vulnerability:
Sensitive Data Exposure
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Newsletter – Send awesome emails from WordPress

Plugin Slug:
newsletter
Installations
300,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
8.7.1
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 8.7.1.

SureForms – Drag and Drop Form Builder for WordPress

Plugin Slug:
sureforms
Installations
200,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.4.4
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.4.4.

SureForms – Drag and Drop Form Builder for WordPress

Plugin Slug:
sureforms
Installations
200,000+
Vulnerability:
Broken Access Control
Patched in Version:
1.4.4
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.4.4.

Admin and Site Enhancements (ASE)

Plugin Slug:
admin-site-enhancements
Installations
100,000+
Vulnerability:
Bypass Vulnerability
Patched in Version:
7.6.10
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 7.6.10.

Popup and Slider Builder by Depicter – Add Email collecting Popup, Popup Modal, Coupon Popup, Image Slider, Carousel Slider, Post Slider Carousel

Plugin Slug:
depicter
Installations
100,000+
Vulnerability:
SQL Injection
Patched in Version:
3.6.2
Severity Score:
Critical
The vulnerability has been patched, so you should update to version 3.6.2.

WP Maps – Display Google Maps Perfectly with Ease

Plugin Slug:
wp-google-map-plugin
Installations
70,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
4.7.2
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 4.7.2.

Calculated Fields Form

Plugin Slug:
calculated-fields-form
Installations
50,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
5.2.62
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 5.2.62.

Seraphinite Accelerator

Plugin Slug:
seraphinite-accelerator
Installations
50,000+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
2.27.22
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.27.22.

FULL – Cliente

Plugin Slug:
full-customer
Installations
40,000+
Vulnerability:
SQL Injection
Patched in Version:
3.1.26
Severity Score:
High
The vulnerability has been patched, so you should update to version 3.1.26.

SecuPress Free — WordPress Security

Plugin Slug:
secupress
Installations
40,000+
Vulnerability:
Broken Access Control
Patched in Version:
2.3.10
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.3.10.

Page View Count

Plugin Slug:
page-views-count
Installations
20,000+
Vulnerability:
Settings Change
Patched in Version:
2.8.5
Severity Score:
High
The vulnerability has been patched, so you should update to version 2.8.5.

WordPress Simple Shopping Cart

Plugin Slug:
wordpress-simple-paypal-shopping-cart
Installations
10,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
5.1.4
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 5.1.4.

WordPress Simple Shopping Cart

Plugin Slug:
wordpress-simple-paypal-shopping-cart
Installations
10,000+
Vulnerability:
Insecure Direct Object References (IDOR)
Patched in Version:
5.1.4
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 5.1.4.

WP-Recall – Registration, Profile, Commerce & More

Plugin Slug:
wp-recall
Installations
2,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
16.26.12
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 16.26.12.

Product Category Slider for WooCommerce

Plugin Slug:
woo-category-slider-by-pluginever
Installations
1,000+
Vulnerability:
Local File Inclusion
Patched in Version:
4.3.5
Severity Score:
High
The vulnerability has been patched, so you should update to version 4.3.5.

AM LottiePlayer

Plugin Slug:
am-lottieplayer
Installations
700+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
3.5.4
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.5.4.

Projectopia – WordPress Project Management

Plugin Slug:
projectopia-core
Installations
400+
Vulnerability:
Broken Access Control
Patched in Version:
5.1.17
Severity Score:
High
The vulnerability has been patched, so you should update to version 5.1.17.

BP Messages Tool

Plugin Slug:
bp-messages-tool
Installations
200+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.5
Severity Score:
High
The vulnerability has been patched, so you should update to version 2.5.

Formality

Plugin:
Formality
Plugin Slug:
formality
Installations
200+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.5.9
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.5.9.

Cision Block

Plugin Slug:
cision-block
Installations
100+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
4.4.0
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 4.4.0.

List Children

Plugin Slug:
list-children
Installations
100+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.2.0
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.2.0.

Taxonomy Chain Menu

Plugin Slug:
taxonomy-chain-menu
Installations
100+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.0.9
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.0.9.

Ads Pro Plugin

Plugin:
Ads Pro Plugin
Plugin Slug:
ap-plugin-scripteo
Vulnerability:
SQL Injection
Patched in Version:
4.89
Severity Score:
Critical
The vulnerability has been patched, so you should update to version 4.89.

BuddyPress Platform Pro

Plugin:
BuddyPress Platform Pro
Plugin Slug:
buddyboss-platform-pro
Vulnerability:
Broken Authentication
Patched in Version:
2.7.10
Severity Score:
Critical
The vulnerability has been patched, so you should update to version 2.7.10.

Envolve Plugin

Plugin:
Envolve Plugin
Plugin Slug:
envolve-plugin
Vulnerability:
Broken Access Control
Patched in Version:
1.1.0
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.1.0.

Gravity Forms WebHooks

Plugin:
Gravity Forms WebHooks
Plugin Slug:
gravityformswebhooks
Vulnerability:
Server Side Request Forgery (SSRF)
Patched in Version:
1.7.0
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.7.0.

Order Delivery Date for WP e-Commerce

Plugin:
Order Delivery Date for WP e-Commerce
Plugin Slug:
order-delivery-date
Vulnerability:
Privilege Escalation
Patched in Version:
12.3.1
Severity Score:
Critical
The vulnerability has been patched, so you should update to version 12.3.1.

Advance Seat Reservation Management for WooCommerce

Plugin:
Advance Seat Reservation Management for WooCommerce
Plugin Slug:
scw-seat-reservation
Vulnerability:
SQL Injection
Patched in Version:
3.4
Severity Score:
Critical
The vulnerability has been patched, so you should update to version 3.4.

Multilingual CMS

Plugin:
Multilingual CMS
Plugin Slug:
sitepress-multilingual-cms
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
4.7.4
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 4.7.4.

tagDiv Composer

Plugin:
tagDiv Composer
Plugin Slug:
td-composer
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
5.4.1
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 5.4.1.

tagDiv Opt-In Builder

Plugin:
tagDiv Opt-In Builder
Plugin Slug:
td-subscription
Vulnerability:
SQL Injection
Patched in Version:
1.7.1
Severity Score:
High
The vulnerability has been patched, so you should update to version 1.7.1.

Ultimate Auction Pro

Plugin:
Ultimate Auction Pro
Plugin Slug:
ultimate-woocommerce-auction-pro
Vulnerability:
SQL Injection
Patched in Version:
1.5.3
Severity Score:
Critical
The vulnerability has been patched, so you should update to version 1.5.3.

WordPress Themes — 6 Patched / 0 Unpatched

NewsBlogger

Theme Slug:
newsblogger
Downloads
100,624
Vulnerability:
Arbitrary File Upload
Patched in Version:
0.2.5.2
Severity Score:
High
The vulnerability has been patched, so you should update to version 0.2.5.2.

NewsBlogger

Theme Slug:
newsblogger
Downloads
100,624
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
0.2.5.5
Severity Score:
High
The vulnerability has been patched, so you should update to version 0.2.5.5.

Homey

Theme:
Homey
Theme Slug:
homey
Vulnerability:
Broken Access Control
Patched in Version:
2.4.5
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.4.5.

Homey

Theme:
Homey
Theme Slug:
homey
Vulnerability:
Insecure Direct Object References (IDOR)
Patched in Version:
2.4.5
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.4.5.

Kleo

Theme:
Kleo
Theme Slug:
kleo
Vulnerability:
Broken Access Control
Patched in Version:
5.4.4
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 5.4.4.

Motors

Theme:
Motors
Theme Slug:
motors
Vulnerability:
Content Injection
Patched in Version:
5.6.66
Severity Score:
High
The vulnerability has been patched, so you should update to version 5.6.66.

Solid Security is part of Solid Suite — The best foundation for WordPress websites.

Every WordPress site needs security, backups, and management tools. That’s Solid Suite — an integrated bundle of three plugins: Solid Security, Solid Backups, and Solid Central. You also get access to Solid Academy’s learning resources for WordPress professionals. Build your next WordPress website on a solid foundation with Solid Suite!

Get Solid Security