WordPress Vulnerability Report

WordPress Vulnerability Report — October 15, 2025

Since last week, 64 new vulnerabilities have emerged in the WordPress ecosystem, including 61 plugins and 3 themes. Of those, 18 remain unpatched, but Solid Security Pro users are protected by virtual patching from Patchstack.

Avatar photo
Sarah Ulmer

In this report, 64 vulnerabilities have been publicly disclosed. Security patches for 46 of these plugins and themes are now available. Please run these updates as soon as possible. If you’re a Solid Security Pro user, the version management tool may have already warned you and updated these plugins, depending on your settings.

Currently, 18 plugin and theme vulnerabilities remain unpatched. If you’re a Solid Security Pro user, those vulnerabilities are already protected by the Solid Security firewall. Virtual patches from Patchstack will be applied when a vulnerability is considered high or medium risk. If no patch is forthcoming from the vendor or the vulnerable software has been marked “closed” and dropped from the official WordPress repositories, you should deactivate it soon and look for alternative solutions.

Along with poor user account security, vulnerable plugins and themes are among the top reasons why WordPress websites get hacked. Unfortunately, cyberattacks are increasing in volume and sophistication. They’re also increasingly aimed at small to mid-sized businesses.

Our WordPress Vulnerability Report covers the latest emerging WordPress plugin, theme, and core vulnerabilities. Each vulnerability will have a severity rating of LowMediumHigh, or Critical. Responsible disclosure of vulnerabilities is essential to keeping the WordPress community safe. Please share this report to help spread the word and make WordPress — and the web — more secure.

WordPress Core

WordPress 6.8.3 was released on September 30, 2025! This is a security release that features two fixes. As this is a security release, we recommend updating your sites immediately. For more information on WordPress 6.8.3, please visit the version page on the HelpHub site.

No new core vulnerabilities were disclosed this week.

WordPress Plugins — 43 Patched / 18 Unpatched

WP Gmail SMTP

Plugin Slug:
wp-gmail-smtp
Installations
1,000+
Vulnerability:
Sensitive Data Exposure
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Block Country

Plugin Slug:
block-country
Installations
70+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Simple Stripe

Plugin Slug:
simple-stripe
Installations
70+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Slick Google Map

Plugin Slug:
slick-google-map
Installations
60+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Stock History & Reports Manager for WooCommerce

Plugin Slug:
stock-snapshot-for-woocommerce
Installations
60+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

wpNamedUsers

Plugin Slug:
wpnamedusers
Installations
60+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Code Quality Control Tool

Plugin:
Code Quality Control Tool
Plugin Slug:
code-quality-control-tool
Vulnerability:
Sensitive Data Exposure
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Course Redirects for Learndash

Plugin:
Course Redirects for Learndash
Plugin Slug:
course-redirects-for-learndash
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Custom 404 Pro

Plugin:
Custom 404 Pro
Plugin Slug:
custom-404-pro
Vulnerability:
SQL Injection
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Easy Plugin Stats

Plugin:
Easy Plugin Stats
Plugin Slug:
easy-plugin-stats
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Find Me On

Plugin:
Find Me On
Plugin Slug:
find-me-on
Vulnerability:
SQL Injection
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Page Blocks

Plugin:
Page Blocks
Plugin Slug:
page-blocks
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

TwentyFourth WP Scraper

Plugin:
TwentyFourth WP Scraper
Plugin Slug:
twentyfourth-wp-scraper
Vulnerability:
Server Side Request Forgery (SSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

WooCommerce Designer Pro

Plugin:
WooCommerce Designer Pro
Plugin Slug:
wc-designer-pro
Vulnerability:
Arbitrary File Deletion
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

WidgetPack Comment System

Plugin:
WidgetPack Comment System
Plugin Slug:
widgetpack-comment-system
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

WP Easy Toggles

Plugin:
WP Easy Toggles
Plugin Slug:
wp-easy-toggles
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

WordPress Live Webcam Widget & Shortcode

Plugin:
WordPress Live Webcam Widget & Shortcode
Plugin Slug:
wp-webcam-widget-shortcode
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Enable Media Replace

Plugin Slug:
enable-media-replace
Installations
600,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
4.1.7
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 4.1.7.

WP Reset

Plugin:
WP Reset
Plugin Slug:
wp-reset
Installations
400,000+
Vulnerability:
Sensitive Data Exposure
Patched in Version:
2.06
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.06.

Blocksy Companion

Plugin Slug:
blocksy-companion
Installations
300,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.1.15
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.1.15.

WP Go Maps (formerly WP Google Maps)

Plugin Slug:
wp-google-maps
Installations
300,000+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
9.0.47
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 9.0.47.

Colibri Page Builder

Plugin Slug:
colibri-page-builder
Installations
100,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.0.335
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.0.335.
Plugin Slug:
responsive-lightbox
Installations
100,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.5.3
Severity Score:
High
The vulnerability has been patched, so you should update to version 2.5.3.

WPC Smart Wishlist for WooCommerce

Plugin Slug:
woo-smart-wishlist
Installations
100,000+
Vulnerability:
Insecure Direct Object References (IDOR)
Patched in Version:
5.0.4
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 5.0.4.
Plugin Slug:
featured-image-from-url
Installations
80,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
5.2.8
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 5.2.8.

All In One Login — WP Admin Login Page Security and Customization with Google reCAPTCHA, Social Login, Limit Login Attempt, 2FA, and more.

Plugin Slug:
change-wp-admin-login
Installations
70,000+
Vulnerability:
Bypass Vulnerability
Patched in Version:
2.0.9
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.0.9.

Search & Filter

Plugin Slug:
search-filter
Installations
50,000+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
1.2.18
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.2.18.

Welcart e-Commerce

Plugin Slug:
usc-e-shop
Installations
20,000+
Vulnerability:
SQL Injection
Patched in Version:
2.11.22
Severity Score:
High
The vulnerability has been patched, so you should update to version 2.11.22.

Web Accessibility by accessiBe

Plugin Slug:
accessibe
Installations
10,000+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
2.11
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.11.

Motors – Car Dealership & Classified Listings Plugin

Plugin Slug:
motors-car-dealership-classified-listings
Installations
10,000+
Vulnerability:
Arbitrary File Deletion
Patched in Version:
1.4.90
Severity Score:
High
The vulnerability has been patched, so you should update to version 1.4.90.

NEX-Forms – Ultimate Forms Plugin for WordPress

Plugin Slug:
nex-forms-express-wp-form-builder
Installations
9,000+
Vulnerability:
SQL Injection
Patched in Version:
9.1.7
Severity Score:
High
The vulnerability has been patched, so you should update to version 9.1.7.

Error Log Viewer by BestWebSoft

Plugin Slug:
error-log-viewer
Installations
6,000+
Vulnerability:
Arbitrary File Download
Patched in Version:
1.1.7
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.1.7.

Survey Maker

Plugin Slug:
survey-maker
Installations
6,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
5.1.8.9
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 5.1.8.9.

Chartify – WordPress Chart Plugin

Plugin Slug:
chart-builder
Installations
4,000+
Vulnerability:
Broken Access Control
Patched in Version:
3.6.0
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.6.0.
Plugin Slug:
cookie-notice-consent
Installations
1,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.6.6
Severity Score:
High
The vulnerability has been patched, so you should update to version 1.6.6.

GSheetConnector For Gravity Forms

Plugin Slug:
gsheetconnector-gravity-forms
Installations
1,000+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
1.3.24
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.3.24.

GSheetConnector For Gravity Forms

Plugin Slug:
gsheetconnector-gravity-forms
Installations
1,000+
Vulnerability:
Broken Access Control
Patched in Version:
1.3.28
Severity Score:
High
The vulnerability has been patched, so you should update to version 1.3.28.

My auctions allegro

Plugin Slug:
my-auctions-allegro-free-edition
Installations
500+
Vulnerability:
SQL Injection
Patched in Version:
3.6.32
Severity Score:
High
The vulnerability has been patched, so you should update to version 3.6.32.

Draft List

Plugin:
Draft List
Plugin Slug:
simple-draft-list
Installations
50+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.6.2
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.6.2.

Community Events

Plugin Slug:
community-events
Installations
40+
Vulnerability:
SQL Injection
Patched in Version:
1.5.2
Severity Score:
Critical
The vulnerability has been patched, so you should update to version 1.5.2.

Lisfinity Core

Plugin:
Lisfinity Core
Plugin Slug:
lisfinity-core
Vulnerability:
Privilege Escalation
Patched in Version:
1.5.0
Severity Score:
High
The vulnerability has been patched, so you should update to version 1.5.0.

Ovatheme Events Manager

Plugin:
Ovatheme Events Manager
Plugin Slug:
ova-events-manager
Vulnerability:
Arbitrary File Upload
Patched in Version:
1.8.6
Severity Score:
Critical
The vulnerability has been patched, so you should update to version 1.8.6.

Slider Revolution

Plugin:
Slider Revolution
Plugin Slug:
revslider
Vulnerability:
Broken Access Control
Patched in Version:
6.7.38
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 6.7.38.

Service Finder Booking

Plugin:
Service Finder Booking
Plugin Slug:
sf-booking
Vulnerability:
Broken Authentication
Patched in Version:
6.1
Severity Score:
Critical
The vulnerability has been patched, so you should update to version 6.1.

Ultimate Addons for WPBakery Page Builder

Plugin:
Ultimate Addons for WPBakery Page Builder
Plugin Slug:
ultimate_vc_addons
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
3.21.1
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.21.1.

WP Freeio

Plugin:
WP Freeio
Plugin Slug:
wp-freeio
Vulnerability:
Privilege Escalation
Patched in Version:
1.2.22
Severity Score:
Critical
The vulnerability has been patched, so you should update to version 1.2.22.

WP JobHunt

Plugin:
WP JobHunt
Plugin Slug:
wp-jobhunt
Vulnerability:
Broken Authentication
Patched in Version:
7.7
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 7.7.

WP JobHunt

Plugin:
WP JobHunt
Plugin Slug:
wp-jobhunt
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
7.7
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 7.7.

WordPress Themes — 3 Patched / 0 Unpatched

Newsup

Theme:
Newsup
Theme Slug:
newsup
Downloads
2,613,735
Vulnerability:
Broken Access Control
Patched in Version:
5.0.11
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 5.0.11.

Betheme

Theme:
Betheme
Theme Slug:
betheme
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
28.1.7
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 28.1.7.

Search & Go

Theme:
Search & Go
Theme Slug:
search-and-go
Vulnerability:
Privilege Escalation
Patched in Version:
2.8
Severity Score:
Critical
The vulnerability has been patched, so you should update to version 2.8.

Solid Security is part of Solid Suite — The best foundation for WordPress websites.

Every WordPress site needs security, backups, and management tools. That’s Solid Suite — an integrated bundle of three plugins: Solid Security, Solid Backups, and Solid Central. You also get access to Solid Academy’s learning resources for WordPress professionals. Build your next WordPress website on a solid foundation with Solid Suite!

Get Solid Security