In this report, 149 vulnerabilities have been publicly disclosed. Security patches for 67 of these plugins and themes are now available. Please run these updates as soon as possible. If you’re a Solid Security Pro user, the version management tool may have already warned you and updated these plugins, depending on your settings.
Currently, 82 plugin and theme vulnerabilities remain unpatched. If you’re a Solid Security Pro user, those vulnerabilities are already protected by the Solid Security firewall. Virtual patches from Patchstack will be applied when a vulnerability is considered high or medium risk. If no patch is forthcoming from the vendor or the vulnerable software has been marked “closed” and dropped from the official WordPress repositories, you should deactivate it soon and look for alternative solutions.
WordPress Core
WordPress 6.8.3 was released on September 30, 2025. This is a security release that features two fixes. As this is a security release, we recommend updating your sites immediately. For more information on WordPress 6.8.3, please visit the version page on the HelpHub site.
WordPress 6.9 Release Candidate 2 (RC2) is now available for testing. This version is still under development and should not be installed on production or mission-critical websites. Instead, test RC2 on a staging or test site. You can read more on the WordPress Core blog for details on how to download and test this release.
The final release of WordPress 6.9 is scheduled for December 2, 2025. For updates, testing information, and release announcements, visit the Make WordPress Core blog.
WordPress Plugins — 67 Patched / 81 Unpatched
Enable SVG, WebP, and ICO Upload
- Plugin:
- Enable SVG, WebP, and ICO Upload
- Plugin Slug:
- enable-svg-webp-ico-upload
- Installations
- 10,000+
- Vulnerability:
- Arbitrary File Upload
- Patched in Version:
- No Fix
- Severity Score:
- Critical
- CVE:
- 2025-13069
Enable SVG, WebP, and ICO Upload
- Plugin:
- Enable SVG, WebP, and ICO Upload
- Plugin Slug:
- enable-svg-webp-ico-upload
- Installations
- 10,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2025-12457
Gutenify – Visual Site Builder Blocks & Site Templates.
- Plugin Slug:
- gutenify
- Installations
- 6,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2025-8605
Stock Management for WooCommerce by Shelf Planner
- Plugin Slug:
- shelf-planner
- Installations
- 100+
- Vulnerability:
- Broken Access Control
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2025-11894
Stock Management for WooCommerce by Shelf Planner
- Plugin Slug:
- shelf-planner
- Installations
- 100+
- Vulnerability:
- Sensitive Data Exposure
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2025-11891
Simple User Import Export
- Plugin:
- Simple User Import Export
- Plugin Slug:
- a3-user-importer
- Vulnerability:
- CSV Injection
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2025-13133
ACF Flexible Layouts Manager
- Plugin:
- ACF Flexible Layouts Manager
- Plugin Slug:
- acf-flexible-layouts-manager
- Vulnerability:
- Broken Access Control
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2025-12937
Add Multiple Marker
- Plugin:
- Add Multiple Marker
- Plugin Slug:
- add-multiple-marker
- Vulnerability:
- Broken Access Control
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2025-11999
Auto Amazon Links
- Plugin:
- Auto Amazon Links
- Plugin Slug:
- amazon-auto-links
- Vulnerability:
- Arbitrary File Download
- Patched in Version:
- No Fix
- Severity Score:
- High
- CVE:
- 2025-11451
ArtiBot
- Plugin:
- ArtiBot
- Plugin Slug:
- artibot
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- High
- CVE:
- 2025-12078
Authors List
- Plugin:
- Authors List
- Plugin Slug:
- authors-list
- Vulnerability:
- Sensitive Data Exposure
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2025-12010
Restrictions for BuddyPress
- Plugin:
- Restrictions for BuddyPress
- Plugin Slug:
- bp-restrict
- Vulnerability:
- Broken Access Control
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2025-12391
Category and Product Woocommerce Tabs
- Plugin:
- Category and Product Woocommerce Tabs
- Plugin Slug:
- category-and-product-woocommerce-tabs
- Vulnerability:
- Local File Inclusion
- Patched in Version:
- No Fix
- Severity Score:
- High
- CVE:
- 2025-13088
Chart Expert
- Plugin:
- Chart Expert
- Plugin Slug:
- chart-expert
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2025-12753
Coil Web Monetization
- Plugin:
- Coil Web Monetization
- Plugin Slug:
- coil-web-monetization
- Vulnerability:
- Cross Site Request Forgery (CSRF)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2025-9625
Coon Google Maps
- Plugin:
- Coon Google Maps
- Plugin Slug:
- coon-google-maps
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2025-12662
WP????????? for CPI
- Plugin:
- WP????????? for CPI
- Plugin Slug:
- cpi-wp-migration
- Vulnerability:
- Arbitrary File Upload
- Patched in Version:
- No Fix
- Severity Score:
- Critical
- CVE:
- 2025-11170
Crypto
- Plugin:
- Crypto
- Plugin Slug:
- crypto
- Vulnerability:
- Sensitive Data Exposure
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2025-11986
Crypto
- Plugin:
- Crypto
- Plugin Slug:
- crypto
- Vulnerability:
- Arbitrary File Deletion
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2025-11988
CSV to SortTable
- Plugin:
- CSV to SortTable
- Plugin Slug:
- csv-to-sorttable
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2025-12823
CTL Arcade Lite
- Plugin:
- CTL Arcade Lite
- Plugin Slug:
- ctl-arcade-lite
- Vulnerability:
- Cross Site Request Forgery (CSRF)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2025-11886
Document Pro Elementor
- Plugin:
- Document Pro Elementor
- Plugin Slug:
- document-pro-elementor
- Vulnerability:
- Sensitive Data Exposure
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2025-11997
Download Panel (Biggiko Team)
- Plugin:
- Download Panel (Biggiko Team)
- Plugin Slug:
- download-panel
- Vulnerability:
- Broken Access Control
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2025-12961
Elastic Theme Editor
- Plugin:
- Elastic Theme Editor
- Plugin Slug:
- elastic-theme-editor
- Vulnerability:
- Arbitrary File Upload
- Patched in Version:
- No Fix
- Severity Score:
- Critical
- CVE:
- 2025-12637
Eventbee Ticketing Widget
- Plugin:
- Eventbee Ticketing Widget
- Plugin Slug:
- eventbee-ticketing-widget
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2025-11856
everviz
- Plugin:
- everviz
- Plugin Slug:
- everviz
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2025-11868
Find Unused Images
- Plugin:
- Find Unused Images
- Plugin Slug:
- find-unused-images
- Vulnerability:
- Broken Access Control
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2025-11996
Five9 Live Chat
- Plugin:
- Five9 Live Chat
- Plugin Slug:
- five9
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2025-11829
Fleet Manager
- Plugin:
- Fleet Manager
- Plugin Slug:
- fleet
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2025-12538
Geopost
- Plugin:
- Geopost
- Plugin Slug:
- geopost
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2025-12754
Astra Security Suite
- Plugin:
- Astra Security Suite
- Plugin Slug:
- getastra
- Vulnerability:
- Arbitrary File Upload
- Patched in Version:
- No Fix
- Severity Score:
- Critical
- CVE:
- 2025-11521
GitHub Gist Shortcode
- Plugin:
- GitHub Gist Shortcode
- Plugin Slug:
- github-gist-shortcode
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2025-12667
Holiday class post calendar
- Plugin:
- Holiday class post calendar
- Plugin Slug:
- holiday-class-post-calendar
- Vulnerability:
- Remote Code Execution (RCE)
- Patched in Version:
- No Fix
- Severity Score:
- Critical
- CVE:
- 2025-12813
Jeba Cute forkit
- Plugin:
- Jeba Cute forkit
- Plugin Slug:
- jeba-cute-forkit
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2025-12663
Like-it
- Plugin:
- Like-it
- Plugin Slug:
- like-it
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- High
- CVE:
- 2025-12404
Live Photos on WordPress
- Plugin:
- Live Photos on WordPress
- Plugin Slug:
- live-photos
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2025-12651
Local Syndication
- Plugin:
- Local Syndication
- Plugin Slug:
- local-syndication
- Vulnerability:
- Server Side Request Forgery (SSRF)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2025-12962
Make Email Customizer for WooCommerce
- Plugin:
- Make Email Customizer for WooCommerce
- Plugin Slug:
- make-email-customizer-for-woocommerce
- Vulnerability:
- Settings Change
- Patched in Version:
- No Fix
- Severity Score:
- High
- CVE:
- 2025-11237
Mementor Core
- Plugin:
- Mementor Core
- Plugin Slug:
- mementor-core
- Vulnerability:
- Privilege Escalation
- Patched in Version:
- No Fix
- Severity Score:
- High
- CVE:
- 2025-11168
Meta Display Block
- Plugin:
- Meta Display Block
- Plugin Slug:
- meta-display-block
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2025-12088
Multiple Roles per User
- Plugin:
- Multiple Roles per User
- Plugin Slug:
- multiple-roles-per-user
- Vulnerability:
- Broken Access Control
- Patched in Version:
- No Fix
- Severity Score:
- High
- CVE:
- 2025-11620
My Geo Posts Free
- Plugin:
- My Geo Posts Free
- Plugin Slug:
- my-geo-posts-free
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2025-11863
Ninja Countdown
- Plugin:
- Ninja Countdown
- Plugin Slug:
- ninja-countdown
- Vulnerability:
- Broken Access Control
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2025-12665
Nonaki
- Plugin:
- Nonaki
- Plugin Slug:
- nonaki-email-template-customizer
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2025-12644
Twitter Feed
- Plugin:
- Twitter Feed
- Plugin Slug:
- ot-twitter-feed
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2025-11860
Paypal Donation Shortcode
- Plugin:
- Paypal Donation Shortcode
- Plugin Slug:
- paypal-donation-shortcode
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2025-11859
Drag & Drop Builder
- Plugin:
- Drag & Drop Builder
- Plugin Slug:
- pie-forms-for-wp
- Vulnerability:
- Arbitrary File Upload
- Patched in Version:
- No Fix
- Severity Score:
- Critical
- CVE:
- 2025-12528
Precise Columns
- Plugin:
- Precise Columns
- Plugin Slug:
- precise-columns
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2025-11869
Preload Current Images
- Plugin:
- Preload Current Images
- Plugin Slug:
- preload-current-images
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2025-12658
Premmerce Wholesale Pricing for WooCommerce
- Plugin:
- Premmerce Wholesale Pricing for WooCommerce
- Plugin Slug:
- premmerce-woocommerce-wholesale-pricing
- Vulnerability:
- SQL Injection
- Patched in Version:
- No Fix
- Severity Score:
- High
- CVE:
- 2025-12411
Progress Bar Blocks for Gutenberg
- Plugin:
- Progress Bar Blocks for Gutenberg
- Plugin Slug:
- progressmatify-blocks
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2025-12880
Project Honey Pot Spam Trap
- Plugin:
- Project Honey Pot Spam Trap
- Plugin Slug:
- project-honey-pot-spam-trap
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- High
- CVE:
- 2025-12406
Quicq
- Plugin:
- Quicq
- Plugin Slug:
- quicq
- Vulnerability:
- Broken Access Control
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2025-12015
RandomQuotr
- Plugin:
- RandomQuotr
- Plugin Slug:
- randomquotr
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2025-12632
Save as PDF Button
- Plugin:
- Save as PDF Button
- Plugin Slug:
- save-as-pdf
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2025-8397
Share to Google Classroom
- Plugin:
- Share to Google Classroom
- Plugin Slug:
- share-to-google-classroom
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2025-12711
Simple Donate
- Plugin:
- Simple Donate
- Plugin Slug:
- simple-donate
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2025-11882
Skip to Timestamp
- Plugin:
- Skip to Timestamp
- Plugin Slug:
- skip-to-timestamp
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2025-11805
Slippy Slider
- Plugin:
- Slippy Slider
- Plugin Slug:
- slippy-slider-responsive-touch-navigation-slider
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2025-11874
Squirrels Auto Inventory
- Plugin:
- Squirrels Auto Inventory
- Plugin Slug:
- squirrels-auto-inventory
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2025-12631
The Permalinks Cascade
- Plugin:
- The Permalinks Cascade
- Plugin Slug:
- the-permalinks-cascade
- Vulnerability:
- Broken Access Control
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2025-12372
The Total Book Project
- Plugin:
- The Total Book Project
- Plugin Slug:
- the-total-book-project
- Vulnerability:
- Insecure Direct Object References (IDOR)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2025-12126
Top Friends
- Plugin:
- Top Friends
- Plugin Slug:
- top-friends
- Vulnerability:
- Cross Site Request Forgery (CSRF)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2025-12827
Cryptocurrency Payment Gateway for WooCommerce
- Plugin:
- Cryptocurrency Payment Gateway for WooCommerce
- Plugin Slug:
- triplea-cryptocurrency-payment-gateway-for-woocommerce
- Vulnerability:
- Broken Access Control
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2025-12392
WP Twitter Auto Publish
- Plugin:
- WP Twitter Auto Publish
- Plugin Slug:
- twitter-auto-publish
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- High
- CVE:
- 2025-12079
Ungapped Widgets
- Plugin:
- Ungapped Widgets
- Plugin Slug:
- ungapped-widgets
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2025-12652
USB Qr Code Scanner For Woocommerce
- Plugin:
- USB Qr Code Scanner For Woocommerce
- Plugin Slug:
- usb-qr-code-scanner-for-woocommerce
- Vulnerability:
- Cross Site Request Forgery (CSRF)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2025-12588
Wisly
- Plugin:
- Wisly
- Plugin Slug:
- wisly
- Vulnerability:
- Insecure Direct Object References (IDOR)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2025-11532
Woocommerce – Products By Custom Tax
- Plugin:
- Woocommerce – Products By Custom Tax
- Plugin Slug:
- woocommerce-products-by-custom-tax
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2025-11821
WP Admin Microblog
- Plugin:
- WP Admin Microblog
- Plugin Slug:
- wp-admin-microblog
- Vulnerability:
- Cross Site Request Forgery (CSRF)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2025-12173
WP BBCode
- Plugin:
- WP BBCode
- Plugin Slug:
- wp-bbcode
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2025-11873
WP Bootstrap Tabs
- Plugin:
- WP Bootstrap Tabs
- Plugin Slug:
- wp-bootstrap-tabs
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2025-11822
WP Count Down Timer
- Plugin:
- WP Count Down Timer
- Plugin Slug:
- wp-count-down-timer
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2025-12668
WP Custom Admin Login Page Logo
- Plugin:
- WP Custom Admin Login Page Logo
- Plugin Slug:
- wp-custom-login-page-logo
- Vulnerability:
- Cross Site Request Forgery (CSRF)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2025-12132
Flickr Show
- Plugin:
- Flickr Show
- Plugin Slug:
- wp-flickrshow
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2025-12672
WordPress Content Flipper
- Plugin:
- WordPress Content Flipper
- Plugin Slug:
- wp-flipper
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2025-11769
WP-Iconics
- Plugin:
- WP-Iconics
- Plugin Slug:
- wp-iconics
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2025-12671
WP-OAuth
- Plugin:
- WP-OAuth
- Plugin Slug:
- wp-oauth
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- High
- CVE:
- 2025-12021
WP Headless CMS Framework
- Plugin:
- WP Headless CMS Framework
- Plugin Slug:
- wp-rest-headless
- Vulnerability:
- Bypass Vulnerability
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2025-11260
WP-Walla
- Plugin:
- WP-Walla
- Plugin Slug:
- wp-walla
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- High
- CVE:
- 2025-12589
YSlider
- Plugin:
- YSlider
- Plugin Slug:
- yslider
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- High
- CVE:
- 2025-12590
All in One SEO – Powerful SEO Plugin to Boost SEO Rankings & Increase Traffic
- Plugin Slug:
- all-in-one-seo-pack
- Installations
- 3,000,000+
- Vulnerability:
- Broken Access Control
- Patched in Version:
- 4.9.0
- Severity Score:
- Medium
- CVE:
- 2025-12847
Page Builder: Pagelayer – Drag and Drop website builder
- Plugin Slug:
- pagelayer
- Installations
- 400,000+
- Vulnerability:
- Insecure Direct Object References (IDOR)
- Patched in Version:
- 2.0.6
- Severity Score:
- Medium
- CVE:
- 2025-12366
Blocksy Companion
- Plugin:
- Blocksy Companion
- Plugin Slug:
- blocksy-companion
- Installations
- 300,000+
- Vulnerability:
- Arbitrary File Upload
- Patched in Version:
- 2.1.20
- Severity Score:
- Critical
- CVE:
- 2025-12846
Broken Link Checker by AIOSEO – Easily Fix/Monitor Internal and External links
- Plugin Slug:
- broken-link-checker-seo
- Installations
- 300,000+
- Vulnerability:
- Broken Access Control
- Patched in Version:
- 1.2.6
- Severity Score:
- Medium
- CVE:
- 2025-11734
SureForms – Contact Form, Custom Form Builder, Calculator & More
- Plugin Slug:
- sureforms
- Installations
- 300,000+
- Vulnerability:
- Broken Access Control
- Patched in Version:
- 1.13.2
- Severity Score:
- Medium
- CVE:
- 2025-12536
WP Go Maps (formerly WP Google Maps)
- Plugin Slug:
- wp-google-maps
- Installations
- 300,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 9.0.48
- Severity Score:
- High
- CVE:
- 2025-11307
Post Type Switcher
- Plugin:
- Post Type Switcher
- Plugin Slug:
- post-type-switcher
- Installations
- 200,000+
- Vulnerability:
- Insecure Direct Object References (IDOR)
- Patched in Version:
- 4.0.1
- Severity Score:
- Medium
- CVE:
- 2025-12524
WP Migrate Lite – WordPress Migration Made Easy
- Plugin Slug:
- wp-migrate-db
- Installations
- 200,000+
- Vulnerability:
- Server Side Request Forgery (SSRF)
- Patched in Version:
- 2.7.7
- Severity Score:
- High
- CVE:
- 2025-11427
AI Engine
AI Engine
- Plugin:
- AI Engine
- Plugin Slug:
- ai-engine
- Installations
- 100,000+
- Vulnerability:
- PHP Object Injection
- Patched in Version:
- 3.1.9
- Severity Score:
- High
- CVE:
- 2025-12844
Element Pack Addons for Elementor
- Plugin Slug:
- bdthemes-element-pack-lite
- Installations
- 100,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 8.3.5
- Severity Score:
- Medium
- CVE:
- 2025-13196
Gallery Plugin for WordPress – Envira Photo Gallery
- Plugin Slug:
- envira-gallery-lite
- Installations
- 100,000+
- Vulnerability:
- Broken Access Control
- Patched in Version:
- 1.12.1
- Severity Score:
- Medium
- CVE:
- 2025-12377
Image Gallery – Photo Grid & Video Gallery
- Plugin Slug:
- modula-best-grid-gallery
- Installations
- 100,000+
- Vulnerability:
- Broken Access Control
- Patched in Version:
- 2.12.29
- Severity Score:
- Medium
- CVE:
- 2025-12494
VK All in One Expansion Unit
- Plugin:
- VK All in One Expansion Unit
- Plugin Slug:
- vk-all-in-one-expansion-unit
- Installations
- 100,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 9.112.2
- Severity Score:
- Medium
- CVE:
- 2025-11265
Import any XML, CSV or Excel File to WordPress
- Plugin Slug:
- wp-all-import
- Installations
- 100,000+
- Vulnerability:
- Remote Code Execution (RCE)
- Patched in Version:
- 4.0.0
- Severity Score:
- Critical
- CVE:
- 2025-12733
Booking for Appointments and Events Calendar – Amelia
- Plugin Slug:
- ameliabooking
- Installations
- 90,000+
- Vulnerability:
- SQL Injection
- Patched in Version:
- 1.2.36
- Severity Score:
- Critical
- CVE:
- 2025-12482
Qi Blocks
- Plugin:
- Qi Blocks
- Plugin Slug:
- qi-blocks
- Installations
- 60,000+
- Vulnerability:
- Broken Access Control
- Patched in Version:
- 1.4.4
- Severity Score:
- Medium
- CVE:
- 2025-12182
Booking Calendar
- Plugin:
- Booking Calendar
- Plugin Slug:
- booking
- Installations
- 50,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 10.14.8
- Severity Score:
- Medium
- CVE:
- 2025-64381
Live sales notification for WooCommerce
- Plugin Slug:
- live-sales-notifications-for-woocommerce
- Installations
- 50,000+
- Vulnerability:
- Broken Access Control
- Patched in Version:
- 2.3.40
- Severity Score:
- High
- CVE:
- 2025-12955
Pixel Manager for WooCommerce – Track Conversions and Analytics, Google Ads, TikTok and more
- Plugin:
- Pixel Manager for WooCommerce – Track Conversions and Analytics, Google Ads, TikTok and more
- Plugin Slug:
- woocommerce-google-adwords-conversion-tracking-tag
- Installations
- 50,000+
- Vulnerability:
- Sensitive Data Exposure
- Patched in Version:
- 1.49.3
- Severity Score:
- Medium
- CVE:
- 2025-12545
WP Duplicate Page
- Plugin:
- WP Duplicate Page
- Plugin Slug:
- wp-duplicate-page
- Installations
- 50,000+
- Vulnerability:
- Broken Access Control
- Patched in Version:
- 1.8
- Severity Score:
- Medium
- CVE:
- 2025-12481
RTMKit
Data Tables Generator by Supsystic
- Plugin Slug:
- data-tables-generator-by-supsystic
- Installations
- 20,000+
- Vulnerability:
- Arbitrary File Deletion
- Patched in Version:
- 1.10.46
- Severity Score:
- Medium
- CVE:
- 2025-12089
Welcart e-Commerce
- Plugin:
- Welcart e-Commerce
- Plugin Slug:
- usc-e-shop
- Installations
- 20,000+
- Vulnerability:
- Broken Access Control
- Patched in Version:
- 2.11.25
- Severity Score:
- Medium
- CVE:
- 2025-12979
WP Import – Ultimate CSV XML Importer for WordPress
- Plugin Slug:
- wp-ultimate-csv-importer
- Installations
- 20,000+
- Vulnerability:
- Broken Access Control
- Patched in Version:
- 7.33.1
- Severity Score:
- Medium
- CVE:
- 2025-12732
Asgaros Forum
- Plugin:
- Asgaros Forum
- Plugin Slug:
- asgaros-forum
- Installations
- 10,000+
- Vulnerability:
- Cross Site Request Forgery (CSRF)
- Patched in Version:
- 3.3.0
- Severity Score:
- Medium
- CVE:
- 2025-12901
Classified Listing – AI-Powered Classified ads & Business Directory Plugin
- Plugin Slug:
- classified-listing
- Installations
- 10,000+
- Vulnerability:
- Content Spoofing
- Patched in Version:
- 5.0.4
- Severity Score:
- Medium
- CVE:
- 2025-7711
Classified Listing – AI-Powered Classified ads & Business Directory Plugin
- Plugin Slug:
- classified-listing
- Installations
- 10,000+
- Vulnerability:
- Broken Access Control
- Patched in Version:
- 5.2.1
- Severity Score:
- Medium
- CVE:
- 2025-12953
Contact Form Email
- Plugin:
- Contact Form Email
- Plugin Slug:
- contact-form-to-email
- Installations
- 10,000+
- Vulnerability:
- Broken Access Control
- Patched in Version:
- 1.3.59
- Severity Score:
- Medium
- CVE:
- 2025-64369
Passster – Password Protect Pages and Content
- Plugin Slug:
- content-protector
- Installations
- 10,000+
- Vulnerability:
- Sensitive Data Exposure
- Patched in Version:
- 4.2.20
- Severity Score:
- High
- CVE:
- 2025-64218
GeoDirectory – WP Business Directory Plugin and Classified Listings Directory
- Plugin Slug:
- geodirectory
- Installations
- 10,000+
- Vulnerability:
- Broken Access Control
- Patched in Version:
- 2.8.140
- Severity Score:
- Medium
- CVE:
- 2025-12833
LifterLMS – WP LMS for eLearning, Online Courses, & Quizzes
- Plugin Slug:
- lifterlms
- Installations
- 10,000+
- Vulnerability:
- Privilege Escalation
- Patched in Version:
- 9.1.1
- Severity Score:
- High
- CVE:
- 2025-11923
MasterStudy LMS WordPress Plugin – for Online Courses and Education
- Plugin Slug:
- masterstudy-lms-learning-management-system
- Installations
- 10,000+
- Vulnerability:
- SQL Injection
- Patched in Version:
- 3.6.28
- Severity Score:
- High
- CVE:
- 2025-64366
Photonic Gallery & Lightbox for Flickr, SmugMug & Others
- Plugin Slug:
- photonic
- Installations
- 10,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 3.22
- Severity Score:
- Medium
- CVE:
- 2025-12691
Checkout Files Upload for WooCommerce
- Plugin Slug:
- checkout-files-upload-woocommerce
- Installations
- 7,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 2.2.2
- Severity Score:
- High
- CVE:
- 2025-4212
Poll Maker – Versus Polls, Anonymous Polls, Image Polls
- Plugin Slug:
- poll-maker
- Installations
- 7,000+
- Vulnerability:
- SQL Injection
- Patched in Version:
- 6.0.8
- Severity Score:
- High
- CVE:
- 2025-12620
Project Management & Task Manager with Kanban Board & Gantt Chart – WP Project Manager
- Plugin Slug:
- wedevs-project-manager
- Installations
- 7,000+
- Vulnerability:
- SQL Injection
- Patched in Version:
- 2.6.27
- Severity Score:
- High
- CVE:
- 2025-8994
Survey Maker
- Plugin:
- Survey Maker
- Plugin Slug:
- survey-maker
- Installations
- 6,000+
- Vulnerability:
- Broken Access Control
- Patched in Version:
- 5.1.9.5
- Severity Score:
- Medium
- CVE:
- 2025-64276
Survey Maker
- Plugin:
- Survey Maker
- Plugin Slug:
- survey-maker
- Installations
- 6,000+
- Vulnerability:
- Broken Access Control
- Patched in Version:
- 5.1.9.5
- Severity Score:
- Medium
- CVE:
- 2025-12891
Booking Calendar | Appointment Booking | Bookit
- Plugin Slug:
- bookit
- Installations
- 5,000+
- Vulnerability:
- Broken Access Control
- Patched in Version:
- 2.5.1
- Severity Score:
- High
- CVE:
- 2025-12633
Icon List Block – Add Icon-Based Lists with Custom Styles
- Plugin Slug:
- icon-list-block
- Installations
- 5,000+
- Vulnerability:
- Server Side Request Forgery (SSRF)
- Patched in Version:
- 1.2.2
- Severity Score:
- Medium
- CVE:
- 2025-12376
Specific Content For Mobile – Customize the mobile version without redirections
- Plugin Slug:
- specific-content-for-mobile
- Installations
- 5,000+
- Vulnerability:
- SQL Injection
- Patched in Version:
- 0.5.6
- Severity Score:
- High
- CVE:
- 2025-11454
Team Members Showcase
- Plugin:
- Team Members Showcase
- Plugin Slug:
- wps-team
- Installations
- 4,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 3.5.0
- Severity Score:
- High
- CVE:
- 2025-11560
CoSchedule
- Plugin:
- CoSchedule
- Plugin Slug:
- coschedule-by-todaymade
- Installations
- 3,000+
- Vulnerability:
- Broken Access Control
- Patched in Version:
- 3.4.1
- Severity Score:
- Medium
- CVE:
- 2025-49913
Payment Plugins Braintree For WooCommerce
- Plugin Slug:
- woo-payment-gateway
- Installations
- 3,000+
- Vulnerability:
- Broken Access Control
- Patched in Version:
- 3.2.79
- Severity Score:
- High
- CVE:
- 2025-12903
WP Plugin Manager – Deactivate plugins per page
- Plugin Slug:
- wp-plugin-manager
- Installations
- 3,000+
- Vulnerability:
- Cross Site Request Forgery (CSRF)
- Patched in Version:
- 1.4.8
- Severity Score:
- Medium
- CVE:
- 2025-64271
Hydra Booking — Appointment Scheduling & Booking Calendar
- Plugin Slug:
- hydra-booking
- Installations
- 2,000+
- Vulnerability:
- Bypass Vulnerability
- Patched in Version:
- 1.1.28
- Severity Score:
- Medium
- CVE:
- 2025-12788
Hydra Booking — Appointment Scheduling & Booking Calendar
- Plugin Slug:
- hydra-booking
- Installations
- 2,000+
- Vulnerability:
- Broken Access Control
- Patched in Version:
- 1.1.28
- Severity Score:
- Medium
- CVE:
- 2025-12787
MembershipWorks – Membership, Events & Directory
- Plugin Slug:
- memberfindme
- Installations
- 2,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 6.15
- Severity Score:
- Medium
- CVE:
- 2025-12018
Comment Edit Core – Simple Comment Editing
- Plugin Slug:
- simple-comment-editing
- Installations
- 2,000+
- Vulnerability:
- Sensitive Data Exposure
- Patched in Version:
- 3.2.0
- Severity Score:
- Medium
- CVE:
- 2025-12681
PDF Builder for WooCommerce. Create invoices,packing slips and more
- Plugin Slug:
- woo-pdf-invoice-builder
- Installations
- 2,000+
- Vulnerability:
- Broken Access Control
- Patched in Version:
- 1.2.151
- Severity Score:
- Medium
- CVE:
- 2025-64269
School Management System – WPSchoolPress
- Plugin Slug:
- wpschoolpress
- Installations
- 2,000+
- Vulnerability:
- SQL Injection
- Patched in Version:
- 2.2.24
- Severity Score:
- High
- CVE:
- 2025-11981
Appointment Booking Calendar
- Plugin:
- Appointment Booking Calendar
- Plugin Slug:
- appointment-booking-calendar
- Installations
- 1,000+
- Vulnerability:
- Broken Access Control
- Patched in Version:
- 1.3.96
- Severity Score:
- Medium
- CVE:
- 2025-64261
Contest Gallery – Upload, Vote & Sell with PayPal and Stripe
- Plugin Slug:
- contest-gallery
- Installations
- 1,000+
- Vulnerability:
- Broken Access Control
- Patched in Version:
- 28.0.3
- Severity Score:
- Medium
- CVE:
- 2025-12849
Creta Testimonial Showcase
- Plugin:
- Creta Testimonial Showcase
- Plugin Slug:
- creta-testimonial-showcase
- Installations
- 1,000+
- Vulnerability:
- Local File Inclusion
- Patched in Version:
- 1.2.4
- Severity Score:
- High
- CVE:
- 2025-10686
TNC Toolbox: Web Performance
- Plugin:
- TNC Toolbox: Web Performance
- Plugin Slug:
- tnc-toolbox
- Installations
- 1,000+
- Vulnerability:
- Privilege Escalation
- Patched in Version:
- 2.0.0
- Severity Score:
- Critical
- CVE:
- 2025-12539
Thumbnail Slider With Lightbox
- Plugin:
- Thumbnail Slider With Lightbox
- Plugin Slug:
- wp-responsive-slider-with-lightbox
- Installations
- 800+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 1.0.22
- Severity Score:
- Medium
- CVE:
- 2024-5020
Theater for WordPress
- Plugin:
- Theater for WordPress
- Plugin Slug:
- theatre
- Installations
- 600+
- Vulnerability:
- Broken Access Control
- Patched in Version:
- 0.19
- Severity Score:
- Medium
- CVE:
- 2025-64259
SNORDIAN’s H5PxAPIkatchu
- Plugin:
- SNORDIAN’s H5PxAPIkatchu
- Plugin Slug:
- h5pxapikatchu
- Installations
- 500+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 0.4.18
- Severity Score:
- High
- CVE:
- 2025-12904
WP Dropzone
- Plugin:
- WP Dropzone
- Plugin Slug:
- wp-dropzone
- Installations
- 100+
- Vulnerability:
- Arbitrary File Upload
- Patched in Version:
- 1.1.1
- Severity Score:
- Critical
- CVE:
- 2025-12775
Wishlist and Save for later for Woocommerce
- Plugin Slug:
- aco-wishlist-for-woocommerce
- Installations
- 80+
- Vulnerability:
- Insecure Direct Object References (IDOR)
- Patched in Version:
- 1.1.23
- Severity Score:
- Medium
- CVE:
- 2025-12087
EasyCommerce – AI-Powered Ecommerce To Sell Physical & Digital Products
- Plugin Slug:
- easycommerce
- Installations
- 70+
- Vulnerability:
- Privilege Escalation
- Patched in Version:
- 1.8.3
- Severity Score:
- Critical
- CVE:
- 2025-11457
Magazine Companion
- Plugin:
- Magazine Companion
- Plugin Slug:
- bnm-blocks
- Installations
- 60+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 1.2.4
- Severity Score:
- Medium
- CVE:
- 2025-11828
Alt Text Generator AI – Auto Generate & Bulk Update Alt Texts For Images
- Plugin Slug:
- alt-text-generator
- Installations
- 40+
- Vulnerability:
- Broken Access Control
- Patched in Version:
- 1.8.4
- Severity Score:
- Medium
- CVE:
- 2025-12113
0 Day Analytics
- Plugin:
- 0 Day Analytics
- Plugin Slug:
- 0-day-analytics
- Installations
- 30+
- Vulnerability:
- SQL Injection
- Patched in Version:
- 4.1.0
- Severity Score:
- High
- CVE:
- 2025-64293
Easy Email Subscription
- Plugin:
- Easy Email Subscription
- Plugin Slug:
- email-subscription-with-secure-captcha
- Installations
- 30+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 1.3.1
- Severity Score:
- High
- CVE:
- 2025-11994
Gravity Forms
- Plugin:
- Gravity Forms
- Plugin Slug:
- gravityforms
- Vulnerability:
- Arbitrary File Upload
- Patched in Version:
- 2.9.22
- Severity Score:
- Critical
- CVE:
- 2025-12974
WordPress Themes — 0 Patched / 1 Unpatched
Angel
- Theme:
- Angel
- Theme Slug:
- angel
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2025-10295
Solid Security is part of Solid Suite — The best foundation for WordPress websites.
Every WordPress site needs security, backups, and management tools. That’s Solid Suite — an integrated bundle of three plugins: Solid Security, Solid Backups, and Solid Central. You also get access to Solid Academy’s learning resources for WordPress professionals. Build your next WordPress website on a solid foundation with Solid Suite!
Sign up now — Get SolidWP updates and valuable content straight to your inbox
Sign up
Get started with confidence — risk free, guaranteed
