WordPress Vulnerability Report

WordPress Vulnerability Report — November 26, 2025

Since last week, 164 new vulnerabilities have emerged in the WordPress ecosystem, including 163 plugins and 1 theme. Of those, 75 remain unpatched, but Solid Security Pro users are protected by virtual patching from Patchstack.

Avatar photo
Sarah Ulmer

In this report, 164 vulnerabilities have been publicly disclosed. Security patches for 89 of these plugins and themes are now available. Please run these updates as soon as possible. If you’re a Solid Security Pro user, the version management tool may have already warned you and updated these plugins, depending on your settings.

Currently, 75 plugin and theme vulnerabilities remain unpatched. If you’re a Solid Security Pro user, those vulnerabilities are already protected by the Solid Security firewall. Virtual patches from Patchstack will be applied when a vulnerability is considered high or medium risk. If no patch is forthcoming from the vendor or the vulnerable software has been marked “closed” and dropped from the official WordPress repositories, you should deactivate it soon and look for alternative solutions.

Along with poor user account security, vulnerable plugins and themes are among the top reasons why WordPress websites get hacked. Unfortunately, cyberattacks are increasing in volume and sophistication. They’re also increasingly aimed at small to mid-sized businesses.

Our WordPress Vulnerability Report covers the latest emerging WordPress plugin, theme, and core vulnerabilities. Each vulnerability will have a severity rating of LowMediumHigh, or Critical. Responsible disclosure of vulnerabilities is essential to keeping the WordPress community safe. Please share this report to help spread the word and make WordPress — and the web — more secure.

WordPress Core

WordPress 6.8.3 was released on September 30, 2025. This is a security release that features two fixes. As this is a security release, we recommend updating your sites immediately. For more information on WordPress 6.8.3, please visit the version page on the HelpHub site.

WordPress 6.9 Release Candidate 3 (RC3) is now available for testing. This version is still under development and should not be installed on production or mission-critical websites. Instead, test RC2 on a staging or test site. You can read more on the WordPress Core blog for details on how to download and test this release.

The final release of WordPress 6.9 is scheduled for December 2, 2025. For updates, testing information, and release announcements, visit the Make WordPress Core blog.

No new core vulnerabilities were disclosed this week.

WordPress Plugins — 89 Patched / 74 Unpatched

Image Hover Effects Ultimate

Plugin Slug:
image-hover-effects-ultimate
Installations
20,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Enable SVG, WebP, and ICO Upload

Plugin Slug:
enable-svg-webp-ico-upload
Installations
10,000+
Vulnerability:
Arbitrary File Upload
Patched in Version:
No Fix
Severity Score:
Critical
The vulnerability has not been patched. You should deactivate the plugin.

Enable SVG, WebP, and ICO Upload

Plugin Slug:
enable-svg-webp-ico-upload
Installations
10,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.
Plugin Slug:
gallery-with-thumbnail-slider
Installations
3,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

?????

Plugin:
?????
Plugin Slug:
keydatas
Installations
2,000+
Vulnerability:
Arbitrary File Download
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Simple User Import Export

Plugin:
Simple User Import Export
Plugin Slug:
a3-user-importer
Vulnerability:
CSV Injection
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Ace Post Type Builder

Plugin:
Ace Post Type Builder
Plugin Slug:
ace-post-type-builder
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

ACF Flexible Layouts Manager

Plugin:
ACF Flexible Layouts Manager
Plugin Slug:
acf-flexible-layouts-manager
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

OrderConvo

Plugin:
OrderConvo
Plugin Slug:
admin-and-client-message-after-order-for-woocommerce
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

OrderConvo

Plugin:
OrderConvo
Plugin Slug:
admin-and-client-message-after-order-for-woocommerce
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

ArtiBot

Plugin:
ArtiBot
Plugin Slug:
artibot
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Attention Bar

Plugin:
Attention Bar
Plugin Slug:
attention-bar
Vulnerability:
SQL Injection
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

AudioTube

Plugin:
AudioTube
Plugin Slug:
audiotube
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

AuthorSure

Plugin:
AuthorSure
Plugin Slug:
authorsure
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Autochat Automatic Conversation

Plugin:
Autochat Automatic Conversation
Plugin Slug:
auyautochat-for-wp
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

BigBuy Dropshipping Connector for WooCommerce

Plugin:
BigBuy Dropshipping Connector for WooCommerce
Plugin Slug:
bigbuy-wc-dropshipping-connector
Vulnerability:
Sensitive Data Exposure
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Bookme – Free Online Appointment Booking and Scheduling Plugin

Plugin:
Bookme – Free Online Appointment Booking and Scheduling Plugin
Plugin Slug:
bookme-free-appointment-booking-system
Vulnerability:
SQL Injection
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Restrictions for BuddyPress

Plugin:
Restrictions for BuddyPress
Plugin Slug:
bp-restrict
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

BrightTALK WordPress Shortcode

Plugin:
BrightTALK WordPress Shortcode
Plugin Slug:
brighttalk-wp-shortcode
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Bulma Shortcodes

Plugin:
Bulma Shortcodes
Plugin Slug:
bulma-shortcodes
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Category and Product Woocommerce Tabs

Plugin:
Category and Product Woocommerce Tabs
Plugin Slug:
category-and-product-woocommerce-tabs
Vulnerability:
Local File Inclusion
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Chamber Dashboard Business Directory

Plugin:
Chamber Dashboard Business Directory
Plugin Slug:
chamber-dashboard-business-directory
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Coil Web Monetization

Plugin:
Coil Web Monetization
Plugin Slug:
coil-web-monetization
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

CSV to SortTable

Plugin:
CSV to SortTable
Plugin Slug:
csv-to-sorttable
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Custom Post Type

Plugin:
Custom Post Type
Plugin Slug:
custom-post-type
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Display Pages Shortcode

Plugin:
Display Pages Shortcode
Plugin Slug:
display-pages-shortcode
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Download Panel (Biggiko Team)

Plugin:
Download Panel (Biggiko Team)
Plugin Slug:
download-panel
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

YouTube Subscribe

Plugin:
YouTube Subscribe
Plugin Slug:
easy-youtube-subscribe
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

everviz

Plugin:
everviz
Plugin Slug:
everviz
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Flo Forms

Plugin:
Flo Forms
Plugin Slug:
flo-forms
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

HotelRunner Booking Widget

Plugin:
HotelRunner Booking Widget
Plugin Slug:
hotelrunner
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Inline frame – Iframe

Plugin:
Inline frame – Iframe
Plugin Slug:
inline-frame-iframe
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Islamic Phrases

Plugin:
Islamic Phrases
Plugin Slug:
islamic-phrases
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Just Highlight

Plugin:
Just Highlight
Plugin Slug:
just-highlight
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

LightGallery WP

Plugin:
LightGallery WP
Plugin Slug:
lightgallerywp
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Like-it

Plugin:
Like-it
Plugin Slug:
like-it
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Local Syndication

Plugin:
Local Syndication
Plugin Slug:
local-syndication
Vulnerability:
Server Side Request Forgery (SSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Locker Content

Plugin Slug:
locker-content
Vulnerability:
Sensitive Data Exposure
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Conditionnal Maintenance Mode for WordPress

Plugin:
Conditionnal Maintenance Mode for WordPress
Plugin Slug:
maintenance-mode-based-on-user-roles
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Make Email Customizer for WooCommerce

Plugin:
Make Email Customizer for WooCommerce
Plugin Slug:
make-email-customizer-for-woocommerce
Vulnerability:
Settings Change
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Meta Display Block

Plugin:
Meta Display Block
Plugin Slug:
meta-display-block
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Mstore Mobile App

Plugin:
Mstore Mobile App
Plugin Slug:
mstoreapp-mobile-app
Vulnerability:
Privilege Escalation
Patched in Version:
No Fix
Severity Score:
Critical
The vulnerability has not been patched. You should deactivate the plugin.

Multiple Roles per User

Plugin:
Multiple Roles per User
Plugin Slug:
multiple-roles-per-user
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Frontend File Manager

Plugin:
Frontend File Manager
Plugin Slug:
nmedia-user-file-uploader
Vulnerability:
Insecure Direct Object References (IDOR)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Peer Publish

Plugin:
Peer Publish
Plugin Slug:
peer-publish
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Drag & Drop Builder

Plugin:
Drag & Drop Builder
Plugin Slug:
pie-forms-for-wp
Vulnerability:
Arbitrary File Upload
Patched in Version:
No Fix
Severity Score:
Critical
The vulnerability has not been patched. You should deactivate the plugin.

Pollcaster Shortcode Plugin

Plugin:
Pollcaster Shortcode Plugin
Plugin Slug:
pollcaster-shortcode
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Premmerce Wholesale Pricing for WooCommerce

Plugin:
Premmerce Wholesale Pricing for WooCommerce
Plugin Slug:
premmerce-woocommerce-wholesale-pricing
Vulnerability:
SQL Injection
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Project Honey Pot Spam Trap

Plugin:
Project Honey Pot Spam Trap
Plugin Slug:
project-honey-pot-spam-trap
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

ProjectList

Plugin:
ProjectList
Plugin Slug:
projectlist
Vulnerability:
SQL Injection
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Realty Portal

Plugin:
Realty Portal
Plugin Slug:
realty-portal
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Refund Request for WooCommerce

Plugin:
Refund Request for WooCommerce
Plugin Slug:
refund-request-for-woocommerce
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Shortcodes Bootstrap

Plugin:
Shortcodes Bootstrap
Plugin Slug:
shortcodes-bootstrap
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Social Images Widget

Plugin:
Social Images Widget
Plugin Slug:
social-images-widget
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Stock Tools

Plugin:
Stock Tools
Plugin Slug:
stock-tools
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Surbma | MiniCRM Shortcode

Plugin:
Surbma | MiniCRM Shortcode
Plugin Slug:
surbma-minicrm-shortcode
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.
Plugin:
The Permalinks Cascade
Plugin Slug:
the-permalinks-cascade
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Tips Shortcode

Plugin:
Tips Shortcode
Plugin Slug:
tips-shortcode
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Cryptocurrency (Token), Launchpad (Presale), ICO & IDO, Airdrop by TokenICO

Plugin:
Cryptocurrency (Token), Launchpad (Presale), ICO & IDO, Airdrop by TokenICO
Plugin Slug:
tokenico-cryptocurrency-token-launchpad-presale-ico-ido-airdrop
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Cryptocurrency (Token), Launchpad (Presale), ICO & IDO, Airdrop by TokenICO

Plugin:
Cryptocurrency (Token), Launchpad (Presale), ICO & IDO, Airdrop by TokenICO
Plugin Slug:
tokenico-cryptocurrency-token-launchpad-presale-ico-ido-airdrop
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Top Friends

Plugin:
Top Friends
Plugin Slug:
top-friends
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Cryptocurrency Payment Gateway for WooCommerce

Plugin:
Cryptocurrency Payment Gateway for WooCommerce
Plugin Slug:
triplea-cryptocurrency-payment-gateway-for-woocommerce
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

WP Twitter Auto Publish

Plugin:
WP Twitter Auto Publish
Plugin Slug:
twitter-auto-publish
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Padlet Shortcode

Plugin:
Padlet Shortcode
Plugin Slug:
wallwisher-shortcode
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Mstore Mobile App

Plugin:
Mstore Mobile App
Plugin Slug:
woo-mstoreapp-mobile-app
Vulnerability:
Privilege Escalation
Patched in Version:
No Fix
Severity Score:
Critical
The vulnerability has not been patched. You should deactivate the plugin.

WP Admin Microblog

Plugin:
WP Admin Microblog
Plugin Slug:
wp-admin-microblog
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.
Plugin:
WP AUDIO GALLERY
Plugin Slug:
wp-audio-gallery
Vulnerability:
Arbitrary File Deletion
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

WP Company Info

Plugin:
WP Company Info
Plugin Slug:
wp-company-info
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Shortcode for Google Street View

Plugin:
Shortcode for Google Street View
Plugin Slug:
wp-google-street-view-shortcode
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

WPSite Shortcode

Plugin:
WPSite Shortcode
Plugin Slug:
wpsite-shortcode
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Zweb Social Mobile

Plugin:
Zweb Social Mobile
Plugin Slug:
zweb-social-mobile
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Code Snippets

Plugin Slug:
code-snippets
Installations
1,000,000+
Vulnerability:
Remote Code Execution (RCE)
Patched in Version:
3.9.2
Severity Score:
High
The vulnerability has been patched, so you should update to version 3.9.2.

W3 Total Cache

Plugin Slug:
w3-total-cache
Installations
1,000,000+
Vulnerability:
Remote Code Execution (RCE)
Patched in Version:
2.8.13
Severity Score:
Critical
The vulnerability has been patched, so you should update to version 2.8.13.

YITH WooCommerce Wishlist

Plugin Slug:
yith-woocommerce-wishlist
Installations
500,000+
Vulnerability:
Broken Access Control
Patched in Version:
4.10.1
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 4.10.1.

YITH WooCommerce Wishlist

Plugin Slug:
yith-woocommerce-wishlist
Installations
500,000+
Vulnerability:
Insecure Direct Object References (IDOR)
Patched in Version:
4.10.1
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 4.10.1.

SiteSEO – SEO Simplified

Plugin Slug:
siteseo
Installations
400,000+
Vulnerability:
Insecure Direct Object References (IDOR)
Patched in Version:
1.3.3
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.3.3.

SiteSEO – SEO Simplified

Plugin Slug:
siteseo
Installations
400,000+
Vulnerability:
Broken Authentication
Patched in Version:
1.3.3
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.3.3.

WP Go Maps (formerly WP Google Maps)

Plugin Slug:
wp-google-maps
Installations
300,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
9.0.48
Severity Score:
High
The vulnerability has been patched, so you should update to version 9.0.48.

Post Type Switcher

Plugin Slug:
post-type-switcher
Installations
200,000+
Vulnerability:
Insecure Direct Object References (IDOR)
Patched in Version:
4.0.1
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 4.0.1.

WP Migrate Lite – WordPress Migration Made Easy

Plugin Slug:
wp-migrate-db
Installations
200,000+
Vulnerability:
Server Side Request Forgery (SSRF)
Patched in Version:
2.7.7
Severity Score:
High
The vulnerability has been patched, so you should update to version 2.7.7.

AI Engine

Plugin:
AI Engine
Plugin Slug:
ai-engine
Installations
100,000+
Vulnerability:
Server Side Request Forgery (SSRF)
Patched in Version:
3.1.9
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.1.9.

Element Pack Addons for Elementor

Plugin Slug:
bdthemes-element-pack-lite
Installations
100,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
8.3.5
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 8.3.5.

GiveWP – Donation Plugin and Fundraising Platform

Plugin Slug:
give
Installations
100,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
4.13.1
Severity Score:
High
The vulnerability has been patched, so you should update to version 4.13.1.
Plugin Slug:
responsive-lightbox
Installations
100,000+
Vulnerability:
Server Side Request Forgery (SSRF)
Patched in Version:
2.5.4
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.5.4.

VK All in One Expansion Unit

Plugin Slug:
vk-all-in-one-expansion-unit
Installations
100,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
9.112.2
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 9.112.2.

Booking for Appointments and Events Calendar – Amelia

Plugin Slug:
ameliabooking
Installations
90,000+
Vulnerability:
Sensitive Data Exposure
Patched in Version:
1.2.37
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.2.37.

HT Mega – Absolute Addons For Elementor

Plugin Slug:
ht-mega-for-elementor
Installations
80,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
3.0.1
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.0.1.

LearnPress – WordPress LMS Plugin

Plugin Slug:
learnpress
Installations
80,000+
Vulnerability:
Broken Access Control
Patched in Version:
4.3.0
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 4.3.0.

Live sales notification for WooCommerce

Plugin Slug:
live-sales-notifications-for-woocommerce
Installations
60,000+
Vulnerability:
Broken Access Control
Patched in Version:
2.3.40
Severity Score:
High
The vulnerability has been patched, so you should update to version 2.3.40.

Blog2Social: Social Media Auto Post & Scheduler

Plugin Slug:
blog2social
Installations
50,000+
Vulnerability:
Broken Access Control
Patched in Version:
8.7.1
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 8.7.1.

WP Duplicate Page

Plugin Slug:
wp-duplicate-page
Installations
50,000+
Vulnerability:
Broken Access Control
Patched in Version:
1.8
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.8.

OneClick Chat to Order

Plugin Slug:
oneclick-whatsapp-order
Installations
40,000+
Vulnerability:
Sensitive Data Exposure
Patched in Version:
1.0.9
Severity Score:
High
The vulnerability has been patched, so you should update to version 1.0.9.

RTMKit

Plugin:
RTMKit
Plugin Slug:
rometheme-for-elementor
Installations
40,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.6.6
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.6.6.

Custom Order Numbers for WooCommerce

Plugin Slug:
custom-order-numbers-for-woocommerce
Installations
20,000+
Vulnerability:
Broken Access Control
Patched in Version:
1.11.1
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.11.1.

New User Approve

Plugin Slug:
new-user-approve
Installations
20,000+
Vulnerability:
Sensitive Data Exposure
Patched in Version:
3.1.0
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.1.0.

Quiz Maker

Plugin:
Quiz Maker
Plugin Slug:
quiz-maker
Installations
20,000+
Vulnerability:
Sensitive Data Exposure
Patched in Version:
6.7.0.81
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 6.7.0.81.

PPOM – Product Addons & Custom Fields for WooCommerce

Plugin Slug:
woocommerce-product-addon
Installations
20,000+
Vulnerability:
Broken Access Control
Patched in Version:
33.0.17
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 33.0.17.

WP Import – Ultimate CSV XML Importer for WordPress

Plugin Slug:
wp-ultimate-csv-importer
Installations
20,000+
Vulnerability:
PHP Object Injection
Patched in Version:
7.34
Severity Score:
High
The vulnerability has been patched, so you should update to version 7.34.

Checkout Files Upload for WooCommerce

Plugin Slug:
checkout-files-upload-woocommerce
Installations
7,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.2.2
Severity Score:
High
The vulnerability has been patched, so you should update to version 2.2.2.
Plugin Slug:
portfolio-wp
Installations
7,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.2.2
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.2.2.

Icon List Block – Add Icon-Based Lists with Custom Styles

Plugin Slug:
icon-list-block
Installations
5,000+
Vulnerability:
Server Side Request Forgery (SSRF)
Patched in Version:
1.2.2
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.2.2.

Return Refund and Exchange For WooCommerce

Plugin Slug:
woo-refund-and-exchange-lite
Installations
5,000+
Vulnerability:
Insecure Direct Object References (IDOR)
Patched in Version:
4.5.6
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 4.5.6.

Team Members Showcase

Plugin Slug:
wps-team
Installations
4,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
3.5.0
Severity Score:
High
The vulnerability has been patched, so you should update to version 3.5.0.

Property Hive

Plugin Slug:
propertyhive
Installations
3,000+
Vulnerability:
Broken Access Control
Patched in Version:
2.1.13
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.1.13.

WP Directory Kit

Plugin Slug:
wpdirectorykit
Installations
3,000+
Vulnerability:
SQL Injection
Patched in Version:
1.4.4
Severity Score:
Critical
The vulnerability has been patched, so you should update to version 1.4.4.

Accordion Slider

Plugin Slug:
accordion-slider
Installations
2,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.9.14
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.9.14.

Extensions for Leaflet Map

Plugin Slug:
extensions-leaflet-map
Installations
2,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
4.9
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 4.9.

Groundhogg — CRM, Newsletters, and Marketing Automation

Plugin Slug:
groundhogg
Installations
2,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
4.2.6.1
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 4.2.6.1.

Vitepos – Point of Sale (POS) for WooCommerce

Plugin Slug:
vitepos-lite
Installations
2,000+
Vulnerability:
Arbitrary File Upload
Patched in Version:
3.3.1
Severity Score:
Critical
The vulnerability has been patched, so you should update to version 3.3.1.

Appointment Booking Calendar

Plugin Slug:
appointment-booking-calendar
Installations
1,000+
Vulnerability:
Broken Access Control
Patched in Version:
1.3.97
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.3.97.

CBX Bookmark & Favorite

Plugin Slug:
cbxwpbookmark
Installations
1,000+
Vulnerability:
Broken Access Control
Patched in Version:
2.0.2
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.0.2.

CP Contact Form with PayPal

Plugin Slug:
cp-contact-form-with-paypal
Installations
1,000+
Vulnerability:
Broken Access Control
Patched in Version:
1.3.57
Severity Score:
High
The vulnerability has been patched, so you should update to version 1.3.57.

GSheetConnector For Ninja Forms

Plugin Slug:
gsheetconnector-ninja-forms
Installations
1,000+
Vulnerability:
Broken Access Control
Patched in Version:
2.0.2
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.0.2.

Tainacan

Plugin:
Tainacan
Plugin Slug:
tainacan
Installations
1,000+
Vulnerability:
Sensitive Data Exposure
Patched in Version:
1.0.1
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.0.1.

Tainacan

Plugin:
Tainacan
Plugin Slug:
tainacan
Installations
1,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.0.1
Severity Score:
High
The vulnerability has been patched, so you should update to version 1.0.1.
Plugin Slug:
tp-woocommerce-product-gallery
Installations
1,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.0.0
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.0.0.

Better Chat Support for Messenger

Plugin Slug:
better-chat-support
Installations
800+
Vulnerability:
Broken Access Control
Patched in Version:
1.2.19
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.2.19.

Booking Calendar Contact Form

Plugin Slug:
booking-calendar-contact-form
Installations
600+
Vulnerability:
Broken Access Control
Patched in Version:
1.2.61
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.2.61.

Show Variations as Single Products Woocommerce

Plugin Slug:
woo-show-single-variations-shop-category
Installations
500+
Vulnerability:
Broken Access Control
Patched in Version:
3.0
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.0.

Checkbox

Plugin:
Checkbox
Plugin Slug:
checkbox
Installations
400+
Vulnerability:
Broken Access Control
Patched in Version:
2.8.11
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.8.11.

ELEX WordPress HelpDesk & Customer Ticketing System

Plugin Slug:
elex-helpdesk-customer-support-ticket-system
Installations
300+
Vulnerability:
Broken Access Control
Patched in Version:
3.3.2
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.3.2.

ELEX WordPress HelpDesk & Customer Ticketing System

Plugin Slug:
elex-helpdesk-customer-support-ticket-system
Installations
300+
Vulnerability:
Insecure Direct Object References (IDOR)
Patched in Version:
3.3.0
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.3.0.

ELEX WordPress HelpDesk & Customer Ticketing System

Plugin Slug:
elex-helpdesk-customer-support-ticket-system
Installations
300+
Vulnerability:
Arbitrary File Upload
Patched in Version:
3.3.2
Severity Score:
Critical
The vulnerability has been patched, so you should update to version 3.3.2.

ELEX WordPress HelpDesk & Customer Ticketing System

Plugin Slug:
elex-helpdesk-customer-support-ticket-system
Installations
300+
Vulnerability:
Broken Access Control
Patched in Version:
3.3.1
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.3.1.

Simple User Registration

Plugin Slug:
wp-registration
Installations
300+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
6.7
Severity Score:
High
The vulnerability has been patched, so you should update to version 6.7.

WP Delete Post Copies

Plugin Slug:
etruel-del-post-copies
Installations
200+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
6.0.3
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 6.0.3.

WP Login and Register using JWT

Plugin Slug:
login-register-using-jwt
Installations
200+
Vulnerability:
Broken Access Control
Patched in Version:
3.1.0
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.1.0.

Time Slot – Booking and Appointment Scheduling

Plugin Slug:
timeslot
Installations
200+
Vulnerability:
Broken Access Control
Patched in Version:
1.4.8
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.4.8.

EchBay Admin Security

Plugin Slug:
echbay-admin-security
Installations
100+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.3.1
Severity Score:
High
The vulnerability has been patched, so you should update to version 1.3.1.

WP Dropzone

Plugin Slug:
wp-dropzone
Installations
100+
Vulnerability:
Arbitrary File Upload
Patched in Version:
1.1.1
Severity Score:
Critical
The vulnerability has been patched, so you should update to version 1.1.1.

Affiliate AI Lite

Plugin Slug:
affiliate-ai-lite
Installations
40+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.0.2
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.0.2.

WSChat – WordPress Live Chat

Plugin Slug:
wschat-live-chat
Installations
40+
Vulnerability:
Broken Access Control
Patched in Version:
3.1.7
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.1.7.

Community Events

Plugin Slug:
community-events
Installations
30+
Vulnerability:
SQL Injection
Patched in Version:
1.5.5
Severity Score:
Critical
The vulnerability has been patched, so you should update to version 1.5.5.

Pet-Manager – Petfinder

Plugin Slug:
tier-management-petfinder
Installations
20+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
3.6.2
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.6.2.

WPBookit

Plugin:
WPBookit
Plugin Slug:
wpbookit
Installations
20+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.0.7
Severity Score:
High
The vulnerability has been patched, so you should update to version 1.0.7.

atec Duplicate Page & Post

Plugin Slug:
atec-duplicate-page-post
Vulnerability:
Broken Access Control
Patched in Version:
1.2.21
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.2.21.

Gravity Forms

Plugin:
Gravity Forms
Plugin Slug:
gravityforms
Vulnerability:
Arbitrary File Upload
Patched in Version:
2.9.22
Severity Score:
Critical
The vulnerability has been patched, so you should update to version 2.9.22.

Zegen Core

Plugin:
Zegen Core
Plugin Slug:
zegen-core
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
2.0.2
Severity Score:
Critical
The vulnerability has been patched, so you should update to version 2.0.2.

WordPress Themes — 0 Patched / 1 Unpatched

OnePress

Theme:
OnePress
Theme Slug:
onepress
Downloads
2,469,341
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should switch themes.

Solid Security is part of Solid Suite — The best foundation for WordPress websites.

Every WordPress site needs security, backups, and management tools. That’s Solid Suite — an integrated bundle of three plugins: Solid Security, Solid Backups, and Solid Central. You also get access to Solid Academy’s learning resources for WordPress professionals. Build your next WordPress website on a solid foundation with Solid Suite!

Get Solid Security