WordPress Vulnerability Report

WordPress Vulnerability Report — November 19, 2025

Since last week, 149 new vulnerabilities have emerged in the WordPress ecosystem, including 148 plugins and 1 theme. Of those, 82 remain unpatched, but Solid Security Pro users are protected by virtual patching from Patchstack.

Avatar photo
Sarah Ulmer

In this report, 149 vulnerabilities have been publicly disclosed. Security patches for 67 of these plugins and themes are now available. Please run these updates as soon as possible. If you’re a Solid Security Pro user, the version management tool may have already warned you and updated these plugins, depending on your settings.

Currently, 82 plugin and theme vulnerabilities remain unpatched. If you’re a Solid Security Pro user, those vulnerabilities are already protected by the Solid Security firewall. Virtual patches from Patchstack will be applied when a vulnerability is considered high or medium risk. If no patch is forthcoming from the vendor or the vulnerable software has been marked “closed” and dropped from the official WordPress repositories, you should deactivate it soon and look for alternative solutions.

Along with poor user account security, vulnerable plugins and themes are among the top reasons why WordPress websites get hacked. Unfortunately, cyberattacks are increasing in volume and sophistication. They’re also increasingly aimed at small to mid-sized businesses.

Our WordPress Vulnerability Report covers the latest emerging WordPress plugin, theme, and core vulnerabilities. Each vulnerability will have a severity rating of LowMediumHigh, or Critical. Responsible disclosure of vulnerabilities is essential to keeping the WordPress community safe. Please share this report to help spread the word and make WordPress — and the web — more secure.

WordPress Core

WordPress 6.8.3 was released on September 30, 2025. This is a security release that features two fixes. As this is a security release, we recommend updating your sites immediately. For more information on WordPress 6.8.3, please visit the version page on the HelpHub site.

WordPress 6.9 Release Candidate 2 (RC2) is now available for testing. This version is still under development and should not be installed on production or mission-critical websites. Instead, test RC2 on a staging or test site. You can read more on the WordPress Core blog for details on how to download and test this release.

The final release of WordPress 6.9 is scheduled for December 2, 2025. For updates, testing information, and release announcements, visit the Make WordPress Core blog.

No new core vulnerabilities were disclosed this week.

WordPress Plugins — 67 Patched / 81 Unpatched

Enable SVG, WebP, and ICO Upload

Plugin Slug:
enable-svg-webp-ico-upload
Installations
10,000+
Vulnerability:
Arbitrary File Upload
Patched in Version:
No Fix
Severity Score:
Critical
The vulnerability has not been patched. You should deactivate the plugin.

Enable SVG, WebP, and ICO Upload

Plugin Slug:
enable-svg-webp-ico-upload
Installations
10,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Stock Management for WooCommerce by Shelf Planner

Plugin Slug:
shelf-planner
Installations
100+
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Stock Management for WooCommerce by Shelf Planner

Plugin Slug:
shelf-planner
Installations
100+
Vulnerability:
Sensitive Data Exposure
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Simple User Import Export

Plugin:
Simple User Import Export
Plugin Slug:
a3-user-importer
Vulnerability:
CSV Injection
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

ACF Flexible Layouts Manager

Plugin:
ACF Flexible Layouts Manager
Plugin Slug:
acf-flexible-layouts-manager
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Add Multiple Marker

Plugin:
Add Multiple Marker
Plugin Slug:
add-multiple-marker
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.
Plugin:
Auto Amazon Links
Plugin Slug:
amazon-auto-links
Vulnerability:
Arbitrary File Download
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

ArtiBot

Plugin:
ArtiBot
Plugin Slug:
artibot
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Authors List

Plugin:
Authors List
Plugin Slug:
authors-list
Vulnerability:
Sensitive Data Exposure
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Restrictions for BuddyPress

Plugin:
Restrictions for BuddyPress
Plugin Slug:
bp-restrict
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Category and Product Woocommerce Tabs

Plugin:
Category and Product Woocommerce Tabs
Plugin Slug:
category-and-product-woocommerce-tabs
Vulnerability:
Local File Inclusion
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Chart Expert

Plugin:
Chart Expert
Plugin Slug:
chart-expert
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Coil Web Monetization

Plugin:
Coil Web Monetization
Plugin Slug:
coil-web-monetization
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Coon Google Maps

Plugin:
Coon Google Maps
Plugin Slug:
coon-google-maps
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

WP????????? for CPI

Plugin:
WP????????? for CPI
Plugin Slug:
cpi-wp-migration
Vulnerability:
Arbitrary File Upload
Patched in Version:
No Fix
Severity Score:
Critical
The vulnerability has not been patched. You should deactivate the plugin.

Crypto

Plugin:
Crypto
Plugin Slug:
crypto
Vulnerability:
Sensitive Data Exposure
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Crypto

Plugin:
Crypto
Plugin Slug:
crypto
Vulnerability:
Arbitrary File Deletion
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

CSV to SortTable

Plugin:
CSV to SortTable
Plugin Slug:
csv-to-sorttable
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

CTL Arcade Lite

Plugin:
CTL Arcade Lite
Plugin Slug:
ctl-arcade-lite
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Document Pro Elementor

Plugin:
Document Pro Elementor
Plugin Slug:
document-pro-elementor
Vulnerability:
Sensitive Data Exposure
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Download Panel (Biggiko Team)

Plugin:
Download Panel (Biggiko Team)
Plugin Slug:
download-panel
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Elastic Theme Editor

Plugin:
Elastic Theme Editor
Plugin Slug:
elastic-theme-editor
Vulnerability:
Arbitrary File Upload
Patched in Version:
No Fix
Severity Score:
Critical
The vulnerability has not been patched. You should deactivate the plugin.

Eventbee Ticketing Widget

Plugin:
Eventbee Ticketing Widget
Plugin Slug:
eventbee-ticketing-widget
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

everviz

Plugin:
everviz
Plugin Slug:
everviz
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Find Unused Images

Plugin:
Find Unused Images
Plugin Slug:
find-unused-images
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Five9 Live Chat

Plugin:
Five9 Live Chat
Plugin Slug:
five9
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Fleet Manager

Plugin:
Fleet Manager
Plugin Slug:
fleet
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Geopost

Plugin:
Geopost
Plugin Slug:
geopost
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Astra Security Suite

Plugin:
Astra Security Suite
Plugin Slug:
getastra
Vulnerability:
Arbitrary File Upload
Patched in Version:
No Fix
Severity Score:
Critical
The vulnerability has not been patched. You should deactivate the plugin.

GitHub Gist Shortcode

Plugin:
GitHub Gist Shortcode
Plugin Slug:
github-gist-shortcode
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Holiday class post calendar

Plugin:
Holiday class post calendar
Plugin Slug:
holiday-class-post-calendar
Vulnerability:
Remote Code Execution (RCE)
Patched in Version:
No Fix
Severity Score:
Critical
The vulnerability has not been patched. You should deactivate the plugin.

Jeba Cute forkit

Plugin:
Jeba Cute forkit
Plugin Slug:
jeba-cute-forkit
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Like-it

Plugin:
Like-it
Plugin Slug:
like-it
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Live Photos on WordPress

Plugin:
Live Photos on WordPress
Plugin Slug:
live-photos
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Local Syndication

Plugin:
Local Syndication
Plugin Slug:
local-syndication
Vulnerability:
Server Side Request Forgery (SSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Make Email Customizer for WooCommerce

Plugin:
Make Email Customizer for WooCommerce
Plugin Slug:
make-email-customizer-for-woocommerce
Vulnerability:
Settings Change
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Mementor Core

Plugin:
Mementor Core
Plugin Slug:
mementor-core
Vulnerability:
Privilege Escalation
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Meta Display Block

Plugin:
Meta Display Block
Plugin Slug:
meta-display-block
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Multiple Roles per User

Plugin:
Multiple Roles per User
Plugin Slug:
multiple-roles-per-user
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

My Geo Posts Free

Plugin:
My Geo Posts Free
Plugin Slug:
my-geo-posts-free
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Ninja Countdown

Plugin:
Ninja Countdown
Plugin Slug:
ninja-countdown
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Nonaki

Plugin:
Nonaki
Plugin Slug:
nonaki-email-template-customizer
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Twitter Feed

Plugin:
Twitter Feed
Plugin Slug:
ot-twitter-feed
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Paypal Donation Shortcode

Plugin:
Paypal Donation Shortcode
Plugin Slug:
paypal-donation-shortcode
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Drag & Drop Builder

Plugin:
Drag & Drop Builder
Plugin Slug:
pie-forms-for-wp
Vulnerability:
Arbitrary File Upload
Patched in Version:
No Fix
Severity Score:
Critical
The vulnerability has not been patched. You should deactivate the plugin.

Precise Columns

Plugin:
Precise Columns
Plugin Slug:
precise-columns
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Preload Current Images

Plugin:
Preload Current Images
Plugin Slug:
preload-current-images
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Premmerce Wholesale Pricing for WooCommerce

Plugin:
Premmerce Wholesale Pricing for WooCommerce
Plugin Slug:
premmerce-woocommerce-wholesale-pricing
Vulnerability:
SQL Injection
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Progress Bar Blocks for Gutenberg

Plugin:
Progress Bar Blocks for Gutenberg
Plugin Slug:
progressmatify-blocks
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Project Honey Pot Spam Trap

Plugin:
Project Honey Pot Spam Trap
Plugin Slug:
project-honey-pot-spam-trap
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Quicq

Plugin:
Quicq
Plugin Slug:
quicq
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

RandomQuotr

Plugin:
RandomQuotr
Plugin Slug:
randomquotr
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Save as PDF Button

Plugin:
Save as PDF Button
Plugin Slug:
save-as-pdf
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Share to Google Classroom

Plugin:
Share to Google Classroom
Plugin Slug:
share-to-google-classroom
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Simple Donate

Plugin:
Simple Donate
Plugin Slug:
simple-donate
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Skip to Timestamp

Plugin:
Skip to Timestamp
Plugin Slug:
skip-to-timestamp
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Slippy Slider

Plugin:
Slippy Slider
Plugin Slug:
slippy-slider-responsive-touch-navigation-slider
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Squirrels Auto Inventory

Plugin:
Squirrels Auto Inventory
Plugin Slug:
squirrels-auto-inventory
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.
Plugin:
The Permalinks Cascade
Plugin Slug:
the-permalinks-cascade
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

The Total Book Project

Plugin Slug:
the-total-book-project
Vulnerability:
Insecure Direct Object References (IDOR)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Top Friends

Plugin:
Top Friends
Plugin Slug:
top-friends
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Cryptocurrency Payment Gateway for WooCommerce

Plugin:
Cryptocurrency Payment Gateway for WooCommerce
Plugin Slug:
triplea-cryptocurrency-payment-gateway-for-woocommerce
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

WP Twitter Auto Publish

Plugin:
WP Twitter Auto Publish
Plugin Slug:
twitter-auto-publish
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Ungapped Widgets

Plugin:
Ungapped Widgets
Plugin Slug:
ungapped-widgets
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

USB Qr Code Scanner For Woocommerce

Plugin:
USB Qr Code Scanner For Woocommerce
Plugin Slug:
usb-qr-code-scanner-for-woocommerce
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Wisly

Plugin:
Wisly
Plugin Slug:
wisly
Vulnerability:
Insecure Direct Object References (IDOR)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Woocommerce – Products By Custom Tax

Plugin:
Woocommerce – Products By Custom Tax
Plugin Slug:
woocommerce-products-by-custom-tax
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

WP Admin Microblog

Plugin:
WP Admin Microblog
Plugin Slug:
wp-admin-microblog
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

WP BBCode

Plugin:
WP BBCode
Plugin Slug:
wp-bbcode
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

WP Bootstrap Tabs

Plugin:
WP Bootstrap Tabs
Plugin Slug:
wp-bootstrap-tabs
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

WP Count Down Timer

Plugin:
WP Count Down Timer
Plugin Slug:
wp-count-down-timer
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.
Plugin:
WP Custom Admin Login Page Logo
Plugin Slug:
wp-custom-login-page-logo
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Flickr Show

Plugin:
Flickr Show
Plugin Slug:
wp-flickrshow
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

WordPress Content Flipper

Plugin:
WordPress Content Flipper
Plugin Slug:
wp-flipper
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

WP-Iconics

Plugin:
WP-Iconics
Plugin Slug:
wp-iconics
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

WP-OAuth

Plugin:
WP-OAuth
Plugin Slug:
wp-oauth
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

WP Headless CMS Framework

Plugin:
WP Headless CMS Framework
Plugin Slug:
wp-rest-headless
Vulnerability:
Bypass Vulnerability
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

WP-Walla

Plugin:
WP-Walla
Plugin Slug:
wp-walla
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

YSlider

Plugin:
YSlider
Plugin Slug:
yslider
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Page Builder: Pagelayer – Drag and Drop website builder

Plugin Slug:
pagelayer
Installations
400,000+
Vulnerability:
Insecure Direct Object References (IDOR)
Patched in Version:
2.0.6
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.0.6.

Blocksy Companion

Plugin Slug:
blocksy-companion
Installations
300,000+
Vulnerability:
Arbitrary File Upload
Patched in Version:
2.1.20
Severity Score:
Critical
The vulnerability has been patched, so you should update to version 2.1.20.

WP Go Maps (formerly WP Google Maps)

Plugin Slug:
wp-google-maps
Installations
300,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
9.0.48
Severity Score:
High
The vulnerability has been patched, so you should update to version 9.0.48.

Post Type Switcher

Plugin Slug:
post-type-switcher
Installations
200,000+
Vulnerability:
Insecure Direct Object References (IDOR)
Patched in Version:
4.0.1
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 4.0.1.

WP Migrate Lite – WordPress Migration Made Easy

Plugin Slug:
wp-migrate-db
Installations
200,000+
Vulnerability:
Server Side Request Forgery (SSRF)
Patched in Version:
2.7.7
Severity Score:
High
The vulnerability has been patched, so you should update to version 2.7.7.

AI Engine

Plugin:
AI Engine
Plugin Slug:
ai-engine
Installations
100,000+
Vulnerability:
Server Side Request Forgery (SSRF)
Patched in Version:
3.1.9
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.1.9.

AI Engine

Plugin:
AI Engine
Plugin Slug:
ai-engine
Installations
100,000+
Vulnerability:
PHP Object Injection
Patched in Version:
3.1.9
Severity Score:
High
The vulnerability has been patched, so you should update to version 3.1.9.

Element Pack Addons for Elementor

Plugin Slug:
bdthemes-element-pack-lite
Installations
100,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
8.3.5
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 8.3.5.
Plugin Slug:
envira-gallery-lite
Installations
100,000+
Vulnerability:
Broken Access Control
Patched in Version:
1.12.1
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.12.1.
Plugin Slug:
modula-best-grid-gallery
Installations
100,000+
Vulnerability:
Broken Access Control
Patched in Version:
2.12.29
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.12.29.

VK All in One Expansion Unit

Plugin Slug:
vk-all-in-one-expansion-unit
Installations
100,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
9.112.2
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 9.112.2.

Import any XML, CSV or Excel File to WordPress

Plugin Slug:
wp-all-import
Installations
100,000+
Vulnerability:
Remote Code Execution (RCE)
Patched in Version:
4.0.0
Severity Score:
Critical
The vulnerability has been patched, so you should update to version 4.0.0.

Qi Blocks

Plugin:
Qi Blocks
Plugin Slug:
qi-blocks
Installations
60,000+
Vulnerability:
Broken Access Control
Patched in Version:
1.4.4
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.4.4.

Booking Calendar

Plugin Slug:
booking
Installations
50,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
10.14.8
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 10.14.8.

Live sales notification for WooCommerce

Plugin Slug:
live-sales-notifications-for-woocommerce
Installations
50,000+
Vulnerability:
Broken Access Control
Patched in Version:
2.3.40
Severity Score:
High
The vulnerability has been patched, so you should update to version 2.3.40.

WP Duplicate Page

Plugin Slug:
wp-duplicate-page
Installations
50,000+
Vulnerability:
Broken Access Control
Patched in Version:
1.8
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.8.

RTMKit

Plugin:
RTMKit
Plugin Slug:
rometheme-for-elementor
Installations
40,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.6.6
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.6.6.

Data Tables Generator by Supsystic

Plugin Slug:
data-tables-generator-by-supsystic
Installations
20,000+
Vulnerability:
Arbitrary File Deletion
Patched in Version:
1.10.46
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.10.46.

Welcart e-Commerce

Plugin Slug:
usc-e-shop
Installations
20,000+
Vulnerability:
Broken Access Control
Patched in Version:
2.11.25
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.11.25.

WP Import – Ultimate CSV XML Importer for WordPress

Plugin Slug:
wp-ultimate-csv-importer
Installations
20,000+
Vulnerability:
Broken Access Control
Patched in Version:
7.33.1
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 7.33.1.

Asgaros Forum

Plugin Slug:
asgaros-forum
Installations
10,000+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
3.3.0
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.3.0.

Contact Form Email

Plugin Slug:
contact-form-to-email
Installations
10,000+
Vulnerability:
Broken Access Control
Patched in Version:
1.3.59
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.3.59.

Passster – Password Protect Pages and Content

Plugin Slug:
content-protector
Installations
10,000+
Vulnerability:
Sensitive Data Exposure
Patched in Version:
4.2.20
Severity Score:
High
The vulnerability has been patched, so you should update to version 4.2.20.

Checkout Files Upload for WooCommerce

Plugin Slug:
checkout-files-upload-woocommerce
Installations
7,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.2.2
Severity Score:
High
The vulnerability has been patched, so you should update to version 2.2.2.

Survey Maker

Plugin Slug:
survey-maker
Installations
6,000+
Vulnerability:
Broken Access Control
Patched in Version:
5.1.9.5
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 5.1.9.5.

Survey Maker

Plugin Slug:
survey-maker
Installations
6,000+
Vulnerability:
Broken Access Control
Patched in Version:
5.1.9.5
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 5.1.9.5.

Booking Calendar | Appointment Booking | Bookit

Plugin Slug:
bookit
Installations
5,000+
Vulnerability:
Broken Access Control
Patched in Version:
2.5.1
Severity Score:
High
The vulnerability has been patched, so you should update to version 2.5.1.

Icon List Block – Add Icon-Based Lists with Custom Styles

Plugin Slug:
icon-list-block
Installations
5,000+
Vulnerability:
Server Side Request Forgery (SSRF)
Patched in Version:
1.2.2
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.2.2.

Team Members Showcase

Plugin Slug:
wps-team
Installations
4,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
3.5.0
Severity Score:
High
The vulnerability has been patched, so you should update to version 3.5.0.

CoSchedule

Plugin:
CoSchedule
Plugin Slug:
coschedule-by-todaymade
Installations
3,000+
Vulnerability:
Broken Access Control
Patched in Version:
3.4.1
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.4.1.

Payment Plugins Braintree For WooCommerce

Plugin Slug:
woo-payment-gateway
Installations
3,000+
Vulnerability:
Broken Access Control
Patched in Version:
3.2.79
Severity Score:
High
The vulnerability has been patched, so you should update to version 3.2.79.

WP Plugin Manager – Deactivate plugins per page

Plugin Slug:
wp-plugin-manager
Installations
3,000+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
1.4.8
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.4.8.

MembershipWorks – Membership, Events & Directory

Plugin Slug:
memberfindme
Installations
2,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
6.15
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 6.15.

Comment Edit Core – Simple Comment Editing

Plugin Slug:
simple-comment-editing
Installations
2,000+
Vulnerability:
Sensitive Data Exposure
Patched in Version:
3.2.0
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.2.0.

School Management System – WPSchoolPress

Plugin Slug:
wpschoolpress
Installations
2,000+
Vulnerability:
SQL Injection
Patched in Version:
2.2.24
Severity Score:
High
The vulnerability has been patched, so you should update to version 2.2.24.

Appointment Booking Calendar

Plugin Slug:
appointment-booking-calendar
Installations
1,000+
Vulnerability:
Broken Access Control
Patched in Version:
1.3.96
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.3.96.

Creta Testimonial Showcase

Plugin Slug:
creta-testimonial-showcase
Installations
1,000+
Vulnerability:
Local File Inclusion
Patched in Version:
1.2.4
Severity Score:
High
The vulnerability has been patched, so you should update to version 1.2.4.

TNC Toolbox: Web Performance

Plugin Slug:
tnc-toolbox
Installations
1,000+
Vulnerability:
Privilege Escalation
Patched in Version:
2.0.0
Severity Score:
Critical
The vulnerability has been patched, so you should update to version 2.0.0.

Thumbnail Slider With Lightbox

Plugin Slug:
wp-responsive-slider-with-lightbox
Installations
800+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.0.22
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.0.22.

Theater for WordPress

Plugin Slug:
theatre
Installations
600+
Vulnerability:
Broken Access Control
Patched in Version:
0.19
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 0.19.

SNORDIAN’s H5PxAPIkatchu

Plugin Slug:
h5pxapikatchu
Installations
500+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
0.4.18
Severity Score:
High
The vulnerability has been patched, so you should update to version 0.4.18.

WP Dropzone

Plugin Slug:
wp-dropzone
Installations
100+
Vulnerability:
Arbitrary File Upload
Patched in Version:
1.1.1
Severity Score:
Critical
The vulnerability has been patched, so you should update to version 1.1.1.

Wishlist and Save for later for Woocommerce

Plugin Slug:
aco-wishlist-for-woocommerce
Installations
80+
Vulnerability:
Insecure Direct Object References (IDOR)
Patched in Version:
1.1.23
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.1.23.

Magazine Companion

Plugin Slug:
bnm-blocks
Installations
60+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.2.4
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.2.4.

0 Day Analytics

Plugin Slug:
0-day-analytics
Installations
30+
Vulnerability:
SQL Injection
Patched in Version:
4.1.0
Severity Score:
High
The vulnerability has been patched, so you should update to version 4.1.0.

Easy Email Subscription

Plugin Slug:
email-subscription-with-secure-captcha
Installations
30+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.3.1
Severity Score:
High
The vulnerability has been patched, so you should update to version 1.3.1.

Gravity Forms

Plugin:
Gravity Forms
Plugin Slug:
gravityforms
Vulnerability:
Arbitrary File Upload
Patched in Version:
2.9.22
Severity Score:
Critical
The vulnerability has been patched, so you should update to version 2.9.22.

WordPress Themes — 0 Patched / 1 Unpatched

Angel

Theme:
Angel
Theme Slug:
angel
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should switch themes.

Solid Security is part of Solid Suite — The best foundation for WordPress websites.

Every WordPress site needs security, backups, and management tools. That’s Solid Suite — an integrated bundle of three plugins: Solid Security, Solid Backups, and Solid Central. You also get access to Solid Academy’s learning resources for WordPress professionals. Build your next WordPress website on a solid foundation with Solid Suite!

Get Solid Security