WordPress Vulnerability Report

WordPress Vulnerability Report — November 12, 2025

Since last week, 199 new vulnerabilities have emerged in the WordPress ecosystem, including 197 plugins and 2 themes. Of those, 95 remain unpatched, but Solid Security Pro users are protected by virtual patching from Patchstack.

Avatar photo
Sarah Ulmer

In this report, 199 vulnerabilities have been publicly disclosed. Security patches for 104 of these plugins and themes are now available. Please run these updates as soon as possible. If you’re a Solid Security Pro user, the version management tool may have already warned you and updated these plugins, depending on your settings.

Currently, 95 plugin and theme vulnerabilities remain unpatched. If you’re a Solid Security Pro user, those vulnerabilities are already protected by the Solid Security firewall. Virtual patches from Patchstack will be applied when a vulnerability is considered high or medium risk. If no patch is forthcoming from the vendor or the vulnerable software has been marked “closed” and dropped from the official WordPress repositories, you should deactivate it soon and look for alternative solutions.

Along with poor user account security, vulnerable plugins and themes are among the top reasons why WordPress websites get hacked. Unfortunately, cyberattacks are increasing in volume and sophistication. They’re also increasingly aimed at small to mid-sized businesses.

Our WordPress Vulnerability Report covers the latest emerging WordPress plugin, theme, and core vulnerabilities. Each vulnerability will have a severity rating of LowMediumHigh, or Critical. Responsible disclosure of vulnerabilities is essential to keeping the WordPress community safe. Please share this report to help spread the word and make WordPress — and the web — more secure.

WordPress Core

WordPress 6.8.3 was released on September 30, 2025. This is a security release that features two fixes. As this is a security release, we recommend updating your sites immediately. For more information on WordPress 6.8.3, please visit the version page on the HelpHub site.

WordPress 6.9 Release Candidate 1 (RC1) is now available for testing. This version is still under development and should not be installed on production or mission-critical websites. Instead, test RC1 on a staging or test site. You can read more on the WordPress Core blog for details on how to download and test this release.

The final release of WordPress 6.9 is scheduled for December 2, 2025. For updates, testing information, and release announcements, visit the Make WordPress Core blog.

No new core vulnerabilities were disclosed this week.

WordPress Plugins — 103 Patched / 94 Unpatched

WP Snow Effect

Plugin Slug:
wp-snow-effect
Installations
1,000+
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Image Comparison Addon for Elementor

Plugin Slug:
image-comparison-elementor-addon
Installations
100+
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Master Blocks – Ultimate Gutenberg Blocks for Marketers

Plugin Slug:
ultimate-blocks-for-gutenberg
Installations
100+
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Magazine Companion

Plugin Slug:
bnm-blocks
Installations
50+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Content Locker for Elementor

Plugin Slug:
content-locker-for-elementor
Installations
40+
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Ace User Management

Plugin Slug:
ace-user-management
Vulnerability:
Broken Authentication
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Add Multiple Marker

Plugin:
Add Multiple Marker
Plugin Slug:
add-multiple-marker
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Ai Auto Tool Content Writing Assistant (Gemini Writer, ChatGPT ) All in One

Plugin:
Ai Auto Tool Content Writing Assistant (Gemini Writer, ChatGPT ) All in One
Plugin Slug:
ai-auto-tool
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.
Plugin:
Auto Amazon Links
Plugin Slug:
amazon-auto-links
Vulnerability:
Arbitrary File Download
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Authors List

Plugin:
Authors List
Plugin Slug:
authors-list
Vulnerability:
Sensitive Data Exposure
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Multi-language Responsive Portfolio

Plugin:
Multi-language Responsive Portfolio
Plugin Slug:
bootstrap-multi-language-responsive-portfolio
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Associados Amazon

Plugin:
Associados Amazon
Plugin Slug:
brzon
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

CE21 Suite

Plugin:
CE21 Suite
Plugin Slug:
ce21-suite
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Critical
The vulnerability has not been patched. You should deactivate the plugin.

CE21 Suite

Plugin:
CE21 Suite
Plugin Slug:
ce21-suite
Vulnerability:
Privilege Escalation
Patched in Version:
No Fix
Severity Score:
Critical
The vulnerability has not been patched. You should deactivate the plugin.

Centangle Team Showcase

Plugin:
Centangle Team Showcase
Plugin Slug:
centangle-team
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Chart Expert

Plugin:
Chart Expert
Plugin Slug:
chart-expert
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Clubmember

Plugin:
Clubmember
Plugin Slug:
clubmember
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Coon Google Maps

Plugin:
Coon Google Maps
Plugin Slug:
coon-google-maps
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

WP????????? for CPI

Plugin:
WP????????? for CPI
Plugin Slug:
cpi-wp-migration
Vulnerability:
Arbitrary File Upload
Patched in Version:
No Fix
Severity Score:
Critical
The vulnerability has not been patched. You should deactivate the plugin.

Crypto

Plugin:
Crypto
Plugin Slug:
crypto
Vulnerability:
Sensitive Data Exposure
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Crypto

Plugin:
Crypto
Plugin Slug:
crypto
Vulnerability:
Arbitrary File Deletion
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Crypto Payment Gateway with Payeer for WooCommerce

Plugin:
Crypto Payment Gateway with Payeer for WooCommerce
Plugin Slug:
crypto-payment-gateway-with-payeer-for-woocommerce
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

CTL Arcade Lite

Plugin:
CTL Arcade Lite
Plugin Slug:
ctl-arcade-lite
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Document Pro Elementor

Plugin:
Document Pro Elementor
Plugin Slug:
document-pro-elementor
Vulnerability:
Sensitive Data Exposure
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

DominoKit

Plugin:
DominoKit
Plugin Slug:
dominokit
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Download Counter Button

Plugin:
Download Counter Button
Plugin Slug:
download-counter-button
Vulnerability:
Arbitrary File Download
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Elastic Theme Editor

Plugin:
Elastic Theme Editor
Plugin Slug:
elastic-theme-editor
Vulnerability:
Arbitrary File Upload
Patched in Version:
No Fix
Severity Score:
Critical
The vulnerability has not been patched. You should deactivate the plugin.

Elegance Menu

Plugin:
Elegance Menu
Plugin Slug:
elegance-menu
Vulnerability:
Local File Inclusion
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

EM Beer Manager

Plugin:
EM Beer Manager
Plugin Slug:
em-beer-manager
Vulnerability:
Arbitrary File Upload
Patched in Version:
No Fix
Severity Score:
Critical
The vulnerability has not been patched. You should deactivate the plugin.

Eventbee Ticketing Widget

Plugin:
Eventbee Ticketing Widget
Plugin Slug:
eventbee-ticketing-widget
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Find Unused Images

Plugin:
Find Unused Images
Plugin Slug:
find-unused-images
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Five9 Live Chat

Plugin:
Five9 Live Chat
Plugin Slug:
five9
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Fleet Manager

Plugin:
Fleet Manager
Plugin Slug:
fleet
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Free Quotation

Plugin:
Free Quotation
Plugin Slug:
free-quotation
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Geopost

Plugin:
Geopost
Plugin Slug:
geopost
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Astra Security Suite

Plugin:
Astra Security Suite
Plugin Slug:
getastra
Vulnerability:
Arbitrary File Upload
Patched in Version:
No Fix
Severity Score:
Critical
The vulnerability has not been patched. You should deactivate the plugin.

GitHub Gist Shortcode

Plugin:
GitHub Gist Shortcode
Plugin Slug:
github-gist-shortcode
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Holiday class post calendar

Plugin:
Holiday class post calendar
Plugin Slug:
holiday-class-post-calendar
Vulnerability:
Remote Code Execution (RCE)
Patched in Version:
No Fix
Severity Score:
Critical
The vulnerability has not been patched. You should deactivate the plugin.

Import Export For WooCommerce

Plugin:
Import Export For WooCommerce
Plugin Slug:
import-export-for-woocommerce
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Jeba Cute forkit

Plugin:
Jeba Cute forkit
Plugin Slug:
jeba-cute-forkit
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

KiotViet Sync

Plugin:
KiotViet Sync
Plugin Slug:
kiotvietsync
Vulnerability:
Arbitrary File Upload
Patched in Version:
No Fix
Severity Score:
Critical
The vulnerability has not been patched. You should deactivate the plugin.

KiotViet Sync

Plugin:
KiotViet Sync
Plugin Slug:
kiotvietsync
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

KiotViet Sync

Plugin:
KiotViet Sync
Plugin Slug:
kiotvietsync
Vulnerability:
Sensitive Data Exposure
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Label Plugins

Plugin:
Label Plugins
Plugin Slug:
label-plugins
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

LinkedIn Resume

Plugin:
LinkedIn Resume
Plugin Slug:
linkedin-resume
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Live Photos on WordPress

Plugin:
Live Photos on WordPress
Plugin Slug:
live-photos
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

LMB^Box Smileys

Plugin:
LMB^Box Smileys
Plugin Slug:
lmbbox-smileys
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

MapMap

Plugin:
MapMap
Plugin Slug:
mapmap
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

MeetingList

Plugin:
MeetingList
Plugin Slug:
meeting-list
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Mementor Core

Plugin:
Mementor Core
Plugin Slug:
mementor-core
Vulnerability:
Privilege Escalation
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

My Geo Posts Free

Plugin:
My Geo Posts Free
Plugin Slug:
my-geo-posts-free
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Nari Accountant

Plugin:
Nari Accountant
Plugin Slug:
nari-accountant
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Ninja Countdown

Plugin:
Ninja Countdown
Plugin Slug:
ninja-countdown
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Nonaki

Plugin:
Nonaki
Plugin Slug:
nonaki-email-template-customizer
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Twitter Feed

Plugin:
Twitter Feed
Plugin Slug:
ot-twitter-feed
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Pagerank Tools

Plugin:
Pagerank Tools
Plugin Slug:
pagerank-tools
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Paypal Donation Shortcode

Plugin:
Paypal Donation Shortcode
Plugin Slug:
paypal-donation-shortcode
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.
Plugin:
Posts Navigation Links for Sections and Headings
Plugin Slug:
posts-navigation-links-for-sections-and-headings-free-by-wp-masters
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Precise Columns

Plugin:
Precise Columns
Plugin Slug:
precise-columns
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Preload Current Images

Plugin:
Preload Current Images
Plugin Slug:
preload-current-images
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Progress Bar Blocks for Gutenberg

Plugin:
Progress Bar Blocks for Gutenberg
Plugin Slug:
progressmatify-blocks
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

RandomQuotr

Plugin:
RandomQuotr
Plugin Slug:
randomquotr
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Reuse Builder

Plugin:
Reuse Builder
Plugin Slug:
reuse-builder
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

SH Contextual Help

Plugin:
SH Contextual Help
Plugin Slug:
sh-contextual-help
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Share to Google Classroom

Plugin:
Share to Google Classroom
Plugin Slug:
share-to-google-classroom
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Shelf Planner

Plugin:
Shelf Planner
Plugin Slug:
shelf-planner
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Shelf Planner

Plugin:
Shelf Planner
Plugin Slug:
shelf-planner
Vulnerability:
Sensitive Data Exposure
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Simple Donate

Plugin:
Simple Donate
Plugin Slug:
simple-donate
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Simple User Capabilities

Plugin:
Simple User Capabilities
Plugin Slug:
simple-user-capabilities
Vulnerability:
Privilege Escalation
Patched in Version:
No Fix
Severity Score:
Critical
The vulnerability has not been patched. You should deactivate the plugin.

Simple User Capabilities

Plugin:
Simple User Capabilities
Plugin Slug:
simple-user-capabilities
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Skip to Timestamp

Plugin:
Skip to Timestamp
Plugin Slug:
skip-to-timestamp
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Slippy Slider

Plugin:
Slippy Slider
Plugin Slug:
slippy-slider-responsive-touch-navigation-slider
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

SMS for WordPress

Plugin:
SMS for WordPress
Plugin Slug:
sms4wp
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Squirrels Auto Inventory

Plugin:
Squirrels Auto Inventory
Plugin Slug:
squirrels-auto-inventory
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

The Total Book Project

Plugin Slug:
the-total-book-project
Vulnerability:
Insecure Direct Object References (IDOR)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Top Bar Notification

Plugin:
Top Bar Notification
Plugin Slug:
top-bar-notification
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Ungapped Widgets

Plugin:
Ungapped Widgets
Plugin Slug:
ungapped-widgets
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

USB Qr Code Scanner For Woocommerce

Plugin:
USB Qr Code Scanner For Woocommerce
Plugin Slug:
usb-qr-code-scanner-for-woocommerce
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

ViaAds

Plugin:
ViaAds
Plugin Slug:
viaads
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Wisly

Plugin:
Wisly
Plugin Slug:
wisly
Vulnerability:
Insecure Direct Object References (IDOR)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Woocommerce – Products By Custom Tax

Plugin:
Woocommerce – Products By Custom Tax
Plugin Slug:
woocommerce-products-by-custom-tax
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

WP BBCode

Plugin:
WP BBCode
Plugin Slug:
wp-bbcode
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

WP Bootstrap Tabs

Plugin:
WP Bootstrap Tabs
Plugin Slug:
wp-bootstrap-tabs
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

WP Carticon

Plugin:
WP Carticon
Plugin Slug:
wp-carticon
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

WP Count Down Timer

Plugin:
WP Count Down Timer
Plugin Slug:
wp-count-down-timer
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.
Plugin:
WP Custom Admin Login Page Logo
Plugin Slug:
wp-custom-login-page-logo
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Flickr Show

Plugin:
Flickr Show
Plugin Slug:
wp-flickrshow
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

WP Global Screen Options

Plugin:
WP Global Screen Options
Plugin Slug:
wp-global-screen-options
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

WP-Iconics

Plugin:
WP-Iconics
Plugin Slug:
wp-iconics
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

WP-OAuth

Plugin:
WP-OAuth
Plugin Slug:
wp-oauth
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

WP-Walla

Plugin:
WP-Walla
Plugin Slug:
wp-walla
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Social Media WPCF7 Stop Words

Plugin:
Social Media WPCF7 Stop Words
Plugin Slug:
wpcf7-stop-words
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

YSlider

Plugin:
YSlider
Plugin Slug:
yslider
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Spectra Gutenberg Blocks – Website Builder for the Block Editor

Plugin Slug:
ultimate-addons-for-gutenberg
Installations
1,000,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.19.15
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.19.15.

TablePress – Tables in WordPress made easy

Plugin Slug:
tablepress
Installations
700,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
3.2.5
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.2.5.

The Events Calendar

Plugin Slug:
the-events-calendar
Installations
700,000+
Vulnerability:
SQL Injection
Patched in Version:
6.15.10
Severity Score:
Critical
The vulnerability has been patched, so you should update to version 6.15.10.

The Events Calendar

Plugin Slug:
the-events-calendar
Installations
700,000+
Vulnerability:
Sensitive Data Exposure
Patched in Version:
6.15.10
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 6.15.10.

SiteSEO – SEO Simplified

Plugin Slug:
siteseo
Installations
400,000+
Vulnerability:
Broken Access Control
Patched in Version:
1.3.2
Severity Score:
Low
The vulnerability has been patched, so you should update to version 1.3.2.

Ad Inserter – Ad Manager & AdSense Ads

Plugin Slug:
ad-inserter
Installations
300,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.8.8
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.8.8.

Blocksy Companion

Plugin Slug:
blocksy-companion
Installations
300,000+
Vulnerability:
Arbitrary File Upload
Patched in Version:
2.1.20
Severity Score:
Critical
The vulnerability has been patched, so you should update to version 2.1.20.

Advanced Ads – Ad Manager & AdSense

Plugin Slug:
advanced-ads
Installations
100,000+
Vulnerability:
Arbitrary Code Execution
Patched in Version:
2.0.13
Severity Score:
High
The vulnerability has been patched, so you should update to version 2.0.13.

AI Engine

Plugin:
AI Engine
Plugin Slug:
ai-engine
Installations
100,000+
Vulnerability:
Privilege Escalation
Patched in Version:
3.1.4
Severity Score:
Critical
The vulnerability has been patched, so you should update to version 3.1.4.

Popup and Slider Builder by Depicter – Add Email collecting Popup, Popup Modal, Coupon Popup, Image Slider, Carousel Slider, Post Slider Carousel

Plugin Slug:
depicter
Installations
100,000+
Vulnerability:
Broken Access Control
Patched in Version:
4.0.5
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 4.0.5.

Download Manager

Plugin Slug:
download-manager
Installations
100,000+
Vulnerability:
Broken Access Control
Patched in Version:
3.3.31
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.3.31.
Plugin Slug:
envira-gallery-lite
Installations
100,000+
Vulnerability:
Broken Access Control
Patched in Version:
1.12.0
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.12.0.

Schema & Structured Data for WP & AMP

Plugin Slug:
schema-and-structured-data-for-wp
Installations
100,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.52
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.52.

Strong Testimonials

Plugin Slug:
strong-testimonials
Installations
90,000+
Vulnerability:
Content Injection
Patched in Version:
3.2.17
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.2.17.

List category posts

Plugin Slug:
list-category-posts
Installations
80,000+
Vulnerability:
Sensitive Data Exposure
Patched in Version:
0.93.0
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 0.93.0.

Greenshift – animation and page builder blocks

Plugin Slug:
greenshift-animation-and-page-builder-blocks
Installations
60,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
12.2.8
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 12.2.8.

Qi Blocks

Plugin:
Qi Blocks
Plugin Slug:
qi-blocks
Installations
60,000+
Vulnerability:
Broken Access Control
Patched in Version:
1.4.4
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.4.4.

Premium Portfolio Features for Phlox theme

Plugin Slug:
auxin-portfolio
Installations
50,000+
Vulnerability:
Local File Inclusion
Patched in Version:
2.3.12
Severity Score:
High
The vulnerability has been patched, so you should update to version 2.3.12.

Blog2Social: Social Media Auto Post & Scheduler

Plugin Slug:
blog2social
Installations
50,000+
Vulnerability:
Server Side Request Forgery (SSRF)
Patched in Version:
8.6.1
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 8.6.1.

Blog2Social: Social Media Auto Post & Scheduler

Plugin Slug:
blog2social
Installations
50,000+
Vulnerability:
Broken Access Control
Patched in Version:
8.6.1
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 8.6.1.
Plugin Slug:
quick-featured-images
Installations
50,000+
Vulnerability:
SQL Injection
Patched in Version:
13.7.4
Severity Score:
High
The vulnerability has been patched, so you should update to version 13.7.4.

Better Find and Replace – AI-Powered Suggestions

Plugin Slug:
real-time-auto-find-and-replace
Installations
50,000+
Vulnerability:
Arbitrary Code Execution
Patched in Version:
1.7.8
Severity Score:
High
The vulnerability has been patched, so you should update to version 1.7.8.

Better Find and Replace – AI-Powered Suggestions

Plugin Slug:
real-time-auto-find-and-replace
Installations
50,000+
Vulnerability:
Broken Access Control
Patched in Version:
1.7.8
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.7.8.

FunnelKit – Funnel Builder for WooCommerce Checkout

Plugin Slug:
funnel-builder
Installations
40,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
3.12.0.1
Severity Score:
High
The vulnerability has been patched, so you should update to version 3.12.0.1.

PowerPress Podcasting plugin by Blubrry

Plugin Slug:
powerpress
Installations
30,000+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
11.14
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 11.14.

Inactive Logout

Plugin Slug:
inactive-logout
Installations
20,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
3.6.0
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.6.0.

wpForo Forum

Plugin Slug:
wpforo
Installations
20,000+
Vulnerability:
SQL Injection
Patched in Version:
2.4.10
Severity Score:
High
The vulnerability has been patched, so you should update to version 2.4.10.

Asgaros Forum

Plugin Slug:
asgaros-forum
Installations
10,000+
Vulnerability:
SQL Injection
Patched in Version:
3.2.0
Severity Score:
Critical
The vulnerability has been patched, so you should update to version 3.2.0.

CSS & JavaScript Toolbox

Plugin Slug:
css-javascript-toolbox
Installations
10,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
12.0.6
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 12.0.6.

WP2Social Auto Publish

Plugin Slug:
facebook-auto-publish
Installations
10,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.4.8
Severity Score:
High
The vulnerability has been patched, so you should update to version 2.4.8.

Graphina – Charts and Graphs For Elementor

Plugin Slug:
graphina-elementor-charts-and-graphs
Installations
10,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
3.1.9
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.1.9.

Groups

Plugin:
Groups
Plugin Slug:
groups
Installations
10,000+
Vulnerability:
Insecure Direct Object References (IDOR)
Patched in Version:
3.8.0
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.8.0.

HTML Forms – Simple WordPress Forms Plugin

Plugin Slug:
html-forms
Installations
10,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.5.6
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.5.6.

Mang Board WP

Plugin Slug:
mangboard
Installations
10,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.3.2
Severity Score:
High
The vulnerability has been patched, so you should update to version 2.3.2.
Plugin Slug:
visual-link-preview
Installations
10,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.2.8
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.2.8.

WPeMatico RSS Feed Fetcher

Plugin Slug:
wpematico
Installations
10,000+
Vulnerability:
Server Side Request Forgery (SSRF)
Patched in Version:
2.8.12
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.8.12.

aThemes Addons for Elementor

Plugin Slug:
athemes-addons-for-elementor-lite
Installations
8,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.1.6
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.1.6.

EventPrime – Events Calendar, Bookings and Tickets

Plugin Slug:
eventprime-event-calendar-management
Installations
7,000+
Vulnerability:
Broken Access Control
Patched in Version:
4.2.0.1
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 4.2.0.1.

Insert Headers and Footers Code – HT Script

Plugin Slug:
insert-headers-and-footers-script
Installations
7,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.1.7
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.1.7.
Plugin Slug:
b-carousel-block
Installations
5,000+
Vulnerability:
Broken Access Control
Patched in Version:
1.1.6
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.1.6.

ElementInvader Addons for Elementor

Plugin Slug:
elementinvader-addons-for-elementor
Installations
4,000+
Vulnerability:
Broken Access Control
Patched in Version:
1.4.1
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.4.1.

Document Library Lite

Plugin Slug:
document-library-lite
Installations
3,000+
Vulnerability:
Broken Access Control
Patched in Version:
1.1.7
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.1.7.

Extensions for Leaflet Map

Plugin Slug:
extensions-leaflet-map
Installations
2,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
4.8
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 4.8.

Footnotes Made Easy

Plugin Slug:
footnotes-made-easy
Installations
2,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
3.0.8
Severity Score:
High
The vulnerability has been patched, so you should update to version 3.0.8.

Page & Post Notes

Plugin Slug:
page-post-notes
Installations
2,000+
Vulnerability:
Broken Access Control
Patched in Version:
1.3.5
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.3.5.

Flexible Refund and Return Order for WooCommerce

Plugin Slug:
flexible-refund-and-return-order-for-woocommerce
Installations
1,000+
Vulnerability:
Broken Access Control
Patched in Version:
1.0.43
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.0.43.

Connector Wizard (formerly LC Wizard)

Plugin Slug:
ghl-wizard
Installations
1,000+
Vulnerability:
Privilege Escalation
Patched in Version:
1.4.0
Severity Score:
High
The vulnerability has been patched, so you should update to version 1.4.0.

WP Airbnb Review Slider

Plugin Slug:
wp-airbnb-review-slider
Installations
1,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
4.4
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 4.4.

WP Discourse

Plugin Slug:
wp-discourse
Installations
1,000+
Vulnerability:
Sensitive Data Exposure
Patched in Version:
2.6.0
Severity Score:
Low
The vulnerability has been patched, so you should update to version 2.6.0.

WPCOM Member

Plugin Slug:
wpcom-member
Installations
1,000+
Vulnerability:
Local File Inclusion
Patched in Version:
1.7.15
Severity Score:
High
The vulnerability has been patched, so you should update to version 1.7.15.

Smart Auto Upload Images – Import External Images

Plugin Slug:
smart-auto-upload-images
Installations
900+
Vulnerability:
Arbitrary File Upload
Patched in Version:
1.2.1
Severity Score:
Critical
The vulnerability has been patched, so you should update to version 1.2.1.

TNC Toolbox: Web Performance

Plugin Slug:
tnc-toolbox
Installations
800+
Vulnerability:
Privilege Escalation
Patched in Version:
2.0.0
Severity Score:
Critical
The vulnerability has been patched, so you should update to version 2.0.0.

Easy Upload Files During Checkout

Plugin Slug:
easy-upload-files-during-checkout
Installations
600+
Vulnerability:
Arbitrary File Upload
Patched in Version:
2.9.9
Severity Score:
High
The vulnerability has been patched, so you should update to version 2.9.9.

Contact Form 7 AWeber Extension

Plugin Slug:
integrate-contact-form-7-and-aweber
Installations
400+
Vulnerability:
Broken Access Control
Patched in Version:
0.1.43
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 0.1.43.

RealPress – Real Estate Plugin

Plugin Slug:
realpress
Installations
400+
Vulnerability:
Broken Access Control
Patched in Version:
1.1.0
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.1.0.

CYAN Backup

Plugin Slug:
cyan-backup
Installations
300+
Vulnerability:
Arbitrary File Deletion
Patched in Version:
2.5.5
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.5.5.

Alex Reservations: Smart Restaurant Booking

Plugin Slug:
alex-reservations
Installations
200+
Vulnerability:
Arbitrary File Upload
Patched in Version:
2.2.4
Severity Score:
High
The vulnerability has been patched, so you should update to version 2.2.4.

Simple Downloads List

Plugin Slug:
simple-downloads-list
Installations
100+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.5.0
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.5.0.

Image Hover Effects for Elementor

Plugin Slug:
image-hover-effects-elementor-addon
Installations
60+
Vulnerability:
Broken Access Control
Patched in Version:
1.0.2.4
Severity Score:
High
The vulnerability has been patched, so you should update to version 1.0.2.4.

Schema Scalpel

Plugin Slug:
schema-scalpel
Installations
50+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.6.2
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.6.2.

Community Events

Plugin Slug:
community-events
Installations
40+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.5.3
Severity Score:
High
The vulnerability has been patched, so you should update to version 1.5.3.

Easy Email Subscription

Plugin Slug:
email-subscription-with-secure-captcha
Installations
30+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
1.3.1
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.3.1.

Easy Email Subscription

Plugin Slug:
email-subscription-with-secure-captcha
Installations
30+
Vulnerability:
SQL Injection
Patched in Version:
1.3.1
Severity Score:
High
The vulnerability has been patched, so you should update to version 1.3.1.

Saphali LiqPay for donate

Plugin Slug:
saphali-liqpay-for-donate
Installations
30+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.0.3
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.0.3.

Folderly

Plugin:
Folderly
Plugin Slug:
folderly
Installations
10+
Vulnerability:
Broken Access Control
Patched in Version:
0.3.1
Severity Score:
Low
The vulnerability has been patched, so you should update to version 0.3.1.

Academy LMS Pro

Plugin:
Academy LMS Pro
Plugin Slug:
academy-pro
Vulnerability:
Sensitive Data Exposure
Patched in Version:
3.3.9
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.3.9.

SUMO Affiliates Pro

Plugin:
SUMO Affiliates Pro
Plugin Slug:
affs
Vulnerability:
Sensitive Data Exposure
Patched in Version:
11.1.0
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 11.1.0.

Doccure Core

Plugin:
Doccure Core
Plugin Slug:
doccure
Vulnerability:
Privilege Escalation
Patched in Version:
1.5.4
Severity Score:
Critical
The vulnerability has been patched, so you should update to version 1.5.4.

Everest Forms Pro

Plugin:
Everest Forms Pro
Plugin Slug:
everest-forms-pro
Vulnerability:
PHP Object Injection
Patched in Version:
1.9.8
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.9.8.

Gravity Forms

Plugin:
Gravity Forms
Plugin Slug:
gravityforms
Vulnerability:
Arbitrary File Upload
Patched in Version:
2.9.21
Severity Score:
Critical
The vulnerability has been patched, so you should update to version 2.9.21.

Integrate Google Drive

Plugin:
Integrate Google Drive
Plugin Slug:
integrate-google-drive
Vulnerability:
Sensitive Data Exposure
Patched in Version:
1.5.4
Severity Score:
High
The vulnerability has been patched, so you should update to version 1.5.4.

JetElements For Elementor

Plugin:
JetElements For Elementor
Plugin Slug:
jet-elements
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.7.12.1
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.7.12.1.

Ohio Extra

Plugin:
Ohio Extra
Plugin Slug:
ohio-extra
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
3.6.1
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.6.1.

Ovatheme Events Manager

Plugin:
Ovatheme Events Manager
Plugin Slug:
ova-events-manager
Vulnerability:
Broken Access Control
Patched in Version:
1.8.7
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.8.7.

Rey Core

Plugin:
Rey Core
Plugin Slug:
rey-core
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
3.1.9
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.1.9.

WordPress Themes — 1 Patched / 1 Unpatched

Kallyas

Theme:
Kallyas
Theme Slug:
kallyas
Vulnerability:
Remote Code Execution (RCE)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should switch themes.

Kallyas

Theme:
Kallyas
Theme Slug:
kallyas
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
4.24.0
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 4.24.0.

Solid Security is part of Solid Suite — The best foundation for WordPress websites.

Every WordPress site needs security, backups, and management tools. That’s Solid Suite — an integrated bundle of three plugins: Solid Security, Solid Backups, and Solid Central. You also get access to Solid Academy’s learning resources for WordPress professionals. Build your next WordPress website on a solid foundation with Solid Suite!

Get Solid Security