WordPress Vulnerability Report

WordPress Vulnerability Report — October 22, 2025

Since last week, 139 new vulnerabilities have emerged in the WordPress ecosystem, including 129 plugins and 10 themes. Of those, 52 remain unpatched, but Solid Security Pro users are protected by virtual patching from Patchstack.

Avatar photo
Sarah Ulmer

In this report, 139 vulnerabilities have been publicly disclosed. Security patches for 87 of these plugins and themes are now available. Please run these updates as soon as possible. If you’re a Solid Security Pro user, the version management tool may have already warned you and updated these plugins, depending on your settings.

Currently, 52 plugin and theme vulnerabilities remain unpatched. If you’re a Solid Security Pro user, those vulnerabilities are already protected by the Solid Security firewall. Virtual patches from Patchstack will be applied when a vulnerability is considered high or medium risk. If no patch is forthcoming from the vendor or the vulnerable software has been marked “closed” and dropped from the official WordPress repositories, you should deactivate it soon and look for alternative solutions.

Along with poor user account security, vulnerable plugins and themes are among the top reasons why WordPress websites get hacked. Unfortunately, cyberattacks are increasing in volume and sophistication. They’re also increasingly aimed at small to mid-sized businesses.

Our WordPress Vulnerability Report covers the latest emerging WordPress plugin, theme, and core vulnerabilities. Each vulnerability will have a severity rating of LowMediumHigh, or Critical. Responsible disclosure of vulnerabilities is essential to keeping the WordPress community safe. Please share this report to help spread the word and make WordPress — and the web — more secure.

WordPress Core

WordPress 6.8.3 was released on September 30, 2025! This is a security release that features two fixes. As this is a security release, we recommend updating your sites immediately. For more information on WordPress 6.8.3, please visit the version page on the HelpHub site.

No new core vulnerabilities were disclosed this week.

WordPress Plugins — 79 Patched / 50 Unpatched

Binary MLM Plan

Plugin Slug:
binary-mlm-plan
Installations
80+
Vulnerability:
Insecure Direct Object References (IDOR)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Block Country

Plugin Slug:
block-country
Installations
70+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Simple Stripe

Plugin Slug:
simple-stripe
Installations
70+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Stock History & Reports Manager for WooCommerce

Plugin Slug:
stock-snapshot-for-woocommerce
Installations
70+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

replyMail

Plugin:
replyMail
Plugin Slug:
replymail
Installations
60+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Slick Google Map

Plugin Slug:
slick-google-map
Installations
60+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

wpNamedUsers

Plugin Slug:
wpnamedusers
Installations
60+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

WP BookWidgets

Plugin Slug:
wp-bookwidgets
Installations
50+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Woocommerce Category and Products Accordion Panel

Plugin:
Woocommerce Category and Products Accordion Panel
Plugin Slug:
accordion-panel-for-category-and-products
Vulnerability:
Local File Inclusion
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Code Quality Control Tool

Plugin:
Code Quality Control Tool
Plugin Slug:
code-quality-control-tool
Vulnerability:
Sensitive Data Exposure
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Course Redirects for Learndash

Plugin:
Course Redirects for Learndash
Plugin Slug:
course-redirects-for-learndash
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Custom 404 Pro

Plugin:
Custom 404 Pro
Plugin Slug:
custom-404-pro
Vulnerability:
SQL Injection
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Demo Import Kit

Plugin:
Demo Import Kit
Plugin Slug:
demo-import-kit
Vulnerability:
Arbitrary File Upload
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Dhivehi Text

Plugin:
Dhivehi Text
Plugin Slug:
dhivehi-text
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Digiseller

Plugin:
Digiseller
Plugin Slug:
digiseller
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

DocoDoco Store Locator

Plugin:
DocoDoco Store Locator
Plugin Slug:
docodoco-store-locator
Vulnerability:
Arbitrary File Upload
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Dynamically Display Posts

Plugin:
Dynamically Display Posts
Plugin Slug:
dynamically-display-posts
Vulnerability:
SQL Injection
Patched in Version:
No Fix
Severity Score:
Critical
The vulnerability has not been patched. You should deactivate the plugin.

External Login

Plugin:
External Login
Plugin Slug:
external-login
Vulnerability:
SQL Injection
Patched in Version:
No Fix
Severity Score:
Critical
The vulnerability has not been patched. You should deactivate the plugin.

External Login

Plugin:
External Login
Plugin Slug:
external-login
Vulnerability:
Sensitive Data Exposure
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Find And Replace content for WordPress

Plugin:
Find And Replace content for WordPress
Plugin Slug:
find-and-replace-content
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

FunKItools

Plugin:
FunKItools
Plugin Slug:
funkitools
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Keyy Two Factor Authentication (like Clef)

Plugin:
Keyy Two Factor Authentication (like Clef)
Plugin Slug:
keyy
Vulnerability:
Privilege Escalation
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Library Management System

Plugin:
Library Management System
Plugin Slug:
library-management-system
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

YourMembership Single Sign On

Plugin:
YourMembership Single Sign On
Plugin Slug:
login-with-yourmembership
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Memberlite Shortcodes

Plugin:
Memberlite Shortcodes
Plugin Slug:
memberlite-shortcodes
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Oceanpayment CreditCard Gateway

Plugin:
Oceanpayment CreditCard Gateway
Plugin Slug:
oceanpayment-creditcard-gateway
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

onOffice for WP-Websites

Plugin:
onOffice for WP-Websites
Plugin Slug:
onoffice-for-wp-websites
Vulnerability:
SQL Injection
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Orion SMS OTP Verification

Plugin:
Orion SMS OTP Verification
Plugin Slug:
orion-sms-otp-verification
Vulnerability:
Broken Authentication
Patched in Version:
No Fix
Severity Score:
Critical
The vulnerability has not been patched. You should deactivate the plugin.

OwnID Passwordless Login

Plugin:
OwnID Passwordless Login
Plugin Slug:
ownid-passwordless-login
Vulnerability:
Broken Authentication
Patched in Version:
No Fix
Severity Score:
Critical
The vulnerability has not been patched. You should deactivate the plugin.

Page Blocks

Plugin:
Page Blocks
Plugin Slug:
page-blocks
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Quick Social Login

Plugin:
Quick Social Login
Plugin Slug:
quick-login
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.
Plugin:
Related Posts Lite
Plugin Slug:
related-posts-lite
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Shortcode Button

Plugin:
Shortcode Button
Plugin Slug:
shortcode-button
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

TARIFFUXX

Plugin:
TARIFFUXX
Plugin Slug:
tariffuxx
Vulnerability:
SQL Injection
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Task Scheduler

Plugin:
Task Scheduler
Plugin Slug:
task-scheduler
Vulnerability:
Server Side Request Forgery (SSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Theme Importer

Plugin:
Theme Importer
Plugin Slug:
theme-importer
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

TopBar

Plugin:
TopBar
Plugin Slug:
topbar
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Truelysell Core

Plugin:
Truelysell Core
Plugin Slug:
truelysell-core
Vulnerability:
Broken Authentication
Patched in Version:
No Fix
Severity Score:
Critical
The vulnerability has not been patched. You should deactivate the plugin.

TwentyFourth WP Scraper

Plugin:
TwentyFourth WP Scraper
Plugin Slug:
twentyfourth-wp-scraper
Vulnerability:
Server Side Request Forgery (SSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

URLYar URL Shortner

Plugin:
URLYar URL Shortner
Plugin Slug:
urlyar
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

WooCommerce Designer Pro

Plugin:
WooCommerce Designer Pro
Plugin Slug:
wc-designer-pro
Vulnerability:
Arbitrary File Deletion
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

WidgetPack Comment System

Plugin:
WidgetPack Comment System
Plugin Slug:
widgetpack-comment-system
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

WP Dashboard Chat

Plugin:
WP Dashboard Chat
Plugin Slug:
wp-dashboard-chat
Vulnerability:
SQL Injection
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

WP Easy Toggles

Plugin:
WP Easy Toggles
Plugin Slug:
wp-easy-toggles
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

WP Google Map

Plugin:
WP Google Map
Plugin Slug:
wp-google-map
Vulnerability:
SQL Injection
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

WP jQuery Pager

Plugin:
WP jQuery Pager
Plugin Slug:
wp-jquery-pdf-paged
Vulnerability:
SQL Injection
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

WP Private Content Plus

Plugin:
WP Private Content Plus
Plugin Slug:
wp-private-content-plus
Vulnerability:
Broken Authentication
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

WordPress Live Webcam Widget & Shortcode

Plugin:
WordPress Live Webcam Widget & Shortcode
Plugin Slug:
wp-webcam-widget-shortcode
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Zip Attachments

Plugin:
Zip Attachments
Plugin Slug:
zip-attachments
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Zip Attachments

Plugin:
Zip Attachments
Plugin Slug:
zip-attachments
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Ally – Web Accessibility & Usability

Plugin Slug:
pojo-accessibility
Installations
400,000+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
3.8.1
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.8.1.

WP Go Maps (formerly WP Google Maps)

Plugin Slug:
wp-google-maps
Installations
300,000+
Vulnerability:
Content Injection
Patched in Version:
9.0.49
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 9.0.49.

Redirection for Contact Form 7

Plugin Slug:
wpcf7-redirect
Installations
300,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
3.2.7
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.2.7.

Element Pack Addons for Elementor

Plugin Slug:
bdthemes-element-pack-lite
Installations
100,000+
Vulnerability:
Server Side Request Forgery (SSRF)
Patched in Version:
8.2.6
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 8.2.6.

Colibri Page Builder

Plugin Slug:
colibri-page-builder
Installations
100,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.0.335
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.0.335.

WPC Smart Quick View for WooCommerce

Plugin Slug:
woo-smart-quick-view
Installations
100,000+
Vulnerability:
Insecure Direct Object References (IDOR)
Patched in Version:
4.2.6
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 4.2.6.

WPC Smart Wishlist for WooCommerce

Plugin Slug:
woo-smart-wishlist
Installations
100,000+
Vulnerability:
Broken Access Control
Patched in Version:
5.0.5
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 5.0.5.

Event Tickets and Registration

Plugin Slug:
event-tickets
Installations
90,000+
Vulnerability:
Broken Authentication
Patched in Version:
5.26.6
Severity Score:
High
The vulnerability has been patched, so you should update to version 5.26.6.

Event Tickets and Registration

Plugin Slug:
event-tickets
Installations
90,000+
Vulnerability:
Broken Access Control
Patched in Version:
5.26.4
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 5.26.4.

LearnPress – WordPress LMS Plugin

Plugin Slug:
learnpress
Installations
80,000+
Vulnerability:
Broken Access Control
Patched in Version:
4.2.9.4
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 4.2.9.4.

Media Library Assistant

Plugin Slug:
media-library-assistant
Installations
70,000+
Vulnerability:
Arbitrary File Download
Patched in Version:
3.30
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.30.
Plugin Slug:
quick-featured-images
Installations
50,000+
Vulnerability:
Insecure Direct Object References (IDOR)
Patched in Version:
13.7.3
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 13.7.3.

Theme Editor

Plugin Slug:
theme-editor
Installations
50,000+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
3.1
Severity Score:
High
The vulnerability has been patched, so you should update to version 3.1.

Advanced Coupons – WooCommerce Coupons & Store Credit

Plugin Slug:
advanced-coupons-for-woocommerce-free
Installations
20,000+
Vulnerability:
SQL Injection
Patched in Version:
4.6.9
Severity Score:
High
The vulnerability has been patched, so you should update to version 4.6.9.

One Page Express Companion

Plugin Slug:
one-page-express-companion
Installations
20,000+
Vulnerability:
Broken Access Control
Patched in Version:
1.6.44
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.6.44.

Pz-LinkCard

Plugin Slug:
pz-linkcard
Installations
20,000+
Vulnerability:
Server Side Request Forgery (SSRF)
Patched in Version:
2.5.7
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.5.7.

SmartCrawl SEO checker, analyzer & optimizer

Plugin Slug:
smartcrawl-seo
Installations
20,000+
Vulnerability:
Broken Access Control
Patched in Version:
3.14.4
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.14.4.

PPOM – Product Addons & Custom Fields for WooCommerce

Plugin Slug:
woocommerce-product-addon
Installations
20,000+
Vulnerability:
SQL Injection
Patched in Version:
33.0.16
Severity Score:
Critical
The vulnerability has been patched, so you should update to version 33.0.16.

PPOM – Product Addons & Custom Fields for WooCommerce

Plugin Slug:
woocommerce-product-addon
Installations
20,000+
Vulnerability:
Arbitrary File Upload
Patched in Version:
33.0.16
Severity Score:
Critical
The vulnerability has been patched, so you should update to version 33.0.16.

Web Accessibility by accessiBe

Plugin Slug:
accessibe
Installations
10,000+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
2.11
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.11.

Simple SEO

Plugin:
Simple SEO
Plugin Slug:
cds-simple-seo
Installations
10,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.0.32
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.0.32.

E2Pdf – Export Pdf Tool for WordPress

Plugin Slug:
e2pdf
Installations
10,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.28.10
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.28.10.

Simple Job Board

Plugin Slug:
simple-job-board
Installations
10,000+
Vulnerability:
Sensitive Data Exposure
Patched in Version:
2.13.8
Severity Score:
High
The vulnerability has been patched, so you should update to version 2.13.8.

Error Log Viewer by BestWebSoft

Plugin Slug:
error-log-viewer
Installations
6,000+
Vulnerability:
Arbitrary File Download
Patched in Version:
1.1.7
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.1.7.

GSpeech TTS – WordPress Text To Speech Plugin

Plugin Slug:
gspeech
Installations
3,000+
Vulnerability:
SQL Injection
Patched in Version:
3.18.0
Severity Score:
High
The vulnerability has been patched, so you should update to version 3.18.0.

Kognetiks Chatbot

Plugin Slug:
chatbot-chatgpt
Installations
1,000+
Vulnerability:
Broken Access Control
Patched in Version:
2.3.6
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.3.6.

Event post

Plugin:
Event post
Plugin Slug:
event-post
Installations
1,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
5.10.4
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 5.10.4.

GSheetConnector For Gravity Forms

Plugin Slug:
gsheetconnector-gravity-forms
Installations
1,000+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
1.3.24
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.3.24.

GSheetConnector For Gravity Forms

Plugin Slug:
gsheetconnector-gravity-forms
Installations
1,000+
Vulnerability:
Broken Access Control
Patched in Version:
1.3.28
Severity Score:
High
The vulnerability has been patched, so you should update to version 1.3.28.

Events Calendar Made Simple – Pie Calendar

Plugin Slug:
pie-calendar
Installations
1,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.3.0
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.3.0.

Product Catalog Simple

Plugin Slug:
post-type-x
Installations
1,000+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
1.8.5
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.8.5.

Reviews Widgets for Google & 45+ platforms by Repuso

Plugin Slug:
social-testimonials-and-reviews-widget
Installations
1,000+
Vulnerability:
Broken Access Control
Patched in Version:
5.30
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 5.30.

Tab Ultimate

Plugin Slug:
tabs-pro
Installations
1,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.9
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.9.

MDTF – Meta Data and Taxonomies Filter

Plugin Slug:
wp-meta-data-filter-and-taxonomy-filter
Installations
1,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.3.3.9
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.3.3.9.

WP Travel Gutenberg Blocks

Plugin Slug:
wp-travel-blocks
Installations
1,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
3.9.3
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.9.3.

WPC Countdown Timer for WooCommerce

Plugin Slug:
wpc-countdown-timer
Installations
1,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
3.1.5
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.1.5.

WPCasa

Plugin:
WPCasa
Plugin Slug:
wpcasa
Installations
1,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.4.2
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.4.2.

Product Table For WooCommerce

Plugin Slug:
product-table-for-woocommerce
Installations
600+
Vulnerability:
PHP Object Injection
Patched in Version:
1.2.5
Severity Score:
High
The vulnerability has been patched, so you should update to version 1.2.5.

PowerBI Embed Reports

Plugin Slug:
embed-power-bi-reports
Installations
500+
Vulnerability:
Sensitive Data Exposure
Patched in Version:
1.2.1
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.2.1.

Front End Users

Plugin Slug:
front-end-only-users
Installations
500+
Vulnerability:
Broken Access Control
Patched in Version:
3.2.34
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.2.34.

UPC/EAN/GTIN Barcode Generator/Importer

Plugin Slug:
upc-ean-barcode-generator
Installations
500+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
2.0.3
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.0.3.

Content Writer

Plugin Slug:
content-writer
Installations
300+
Vulnerability:
Sensitive Data Exposure
Patched in Version:
3.6.9
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.6.9.

Acknowledgify

Plugin Slug:
acknowledgify
Installations
100+
Vulnerability:
Broken Access Control
Patched in Version:
1.1.4
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.1.4.
Plugin Slug:
create-temporary-login
Installations
40+
Vulnerability:
Broken Access Control
Patched in Version:
1.0.8
Severity Score:
Critical
The vulnerability has been patched, so you should update to version 1.0.8.

XX2WP Integration Tools

Plugin Slug:
fb2wp-integration-tools
Installations
30+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.0.0
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.0.0.

Flex QR Code Generator

Plugin Slug:
flex-qr-code-generator
Installations
30+
Vulnerability:
Arbitrary File Upload
Patched in Version:
1.2.6
Severity Score:
Critical
The vulnerability has been patched, so you should update to version 1.2.6.

Voice Feedback – Voice Recorder for Audio Feedback

Plugin Slug:
voice-feedback
Installations
10+
Vulnerability:
Privilege Escalation
Patched in Version:
2.0.0
Severity Score:
High
The vulnerability has been patched, so you should update to version 2.0.0.

BlindMatrix e-Commerce

Plugin Slug:
window-blinds-solution
Installations
10+
Vulnerability:
Local File Inclusion
Patched in Version:
3.1
Severity Score:
High
The vulnerability has been patched, so you should update to version 3.1.

Felan Framework

Plugin:
Felan Framework
Plugin Slug:
felan-framework
Vulnerability:
Broken Access Control
Patched in Version:
1.1.5
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.1.5.

Felan Framework

Plugin:
Felan Framework
Plugin Slug:
felan-framework
Vulnerability:
Broken Authentication
Patched in Version:
1.1.5
Severity Score:
Critical
The vulnerability has been patched, so you should update to version 1.1.5.

Houzez Theme – Functionality

Plugin:
Houzez Theme – Functionality
Plugin Slug:
houzez-theme-functionality
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
4.2.0
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 4.2.0.

Houzez Theme – Functionality

Plugin:
Houzez Theme – Functionality
Plugin Slug:
houzez-theme-functionality
Vulnerability:
Local File Inclusion
Patched in Version:
4.2.0
Severity Score:
High
The vulnerability has been patched, so you should update to version 4.2.0.

WPBakery Page Builder

Plugin:
WPBakery Page Builder
Plugin Slug:
js_composer
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
8.7
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 8.7.

WPBakery Page Builder

Plugin:
WPBakery Page Builder
Plugin Slug:
js_composer
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
8.7
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 8.7.

WPBakery Page Builder

Plugin:
WPBakery Page Builder
Plugin Slug:
js_composer
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
8.7
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 8.7.

Lisfinity Core

Plugin:
Lisfinity Core
Plugin Slug:
lisfinity-core
Vulnerability:
Privilege Escalation
Patched in Version:
1.5.0
Severity Score:
High
The vulnerability has been patched, so you should update to version 1.5.0.

Ova Advent

Plugin:
Ova Advent
Plugin Slug:
ova-advent
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.1.8
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.1.8.

SUMO Memberships for WooCommerce

Plugin:
SUMO Memberships for WooCommerce
Plugin Slug:
sumomemberships
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
7.8.0
Severity Score:
High
The vulnerability has been patched, so you should update to version 7.8.0.

tagDiv Cloud Library

Plugin:
tagDiv Cloud Library
Plugin Slug:
td-cloud-library
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
4.0
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 4.0.

tagDiv Composer

Plugin:
tagDiv Composer
Plugin Slug:
td-composer
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
5.4.2
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 5.4.2.

TheGem Theme Elements (for WPBakery)

Plugin:
TheGem Theme Elements (for WPBakery)
Plugin Slug:
thegem-elements
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
5.10.5.2
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 5.10.5.2.

UDesign Core

Plugin:
UDesign Core
Plugin Slug:
u-design-core
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
4.14.2
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 4.14.2.

WordPress Themes — 8 Patched / 2 Unpatched

ClassifiedPro

Theme:
ClassifiedPro
Theme Slug:
classified-pro
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should switch themes.

Rich Snippet Site Report

Theme:
Rich Snippet Site Report
Theme Slug:
easysnippet
Vulnerability:
SQL Injection
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should switch themes.

HomeLancer

Theme Slug:
homelancer
Downloads
3,788
Vulnerability:
Broken Access Control
Patched in Version:
1.0.2
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.0.2.

Newsup

Theme:
Newsup
Theme Slug:
newsup
Downloads
2,628,569
Vulnerability:
Broken Access Control
Patched in Version:
5.0.11
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 5.0.11.

Education WordPress Theme | HiStudy

Theme:
Education WordPress Theme | HiStudy
Theme Slug:
histudy
Vulnerability:
SQL Injection
Patched in Version:
3.1.0
Severity Score:
Critical
The vulnerability has been patched, so you should update to version 3.1.0.

Kallyas

Theme:
Kallyas
Theme Slug:
kallyas
Vulnerability:
Broken Access Control
Patched in Version:
4.23.0
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 4.23.0.

Kallyas

Theme:
Kallyas
Theme Slug:
kallyas
Vulnerability:
Broken Access Control
Patched in Version:
4.23.0
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 4.23.0.

Salient

Theme:
Salient
Theme Slug:
salient
Vulnerability:
Broken Access Control
Patched in Version:
17.4.0
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 17.4.0.

WoodMart

Theme:
WoodMart
Theme Slug:
woodmart
Vulnerability:
Local File Inclusion
Patched in Version:
8.3.2
Severity Score:
High
The vulnerability has been patched, so you should update to version 8.3.2.

XStore

Theme:
XStore
Theme Slug:
xstore
Vulnerability:
Local File Inclusion
Patched in Version:
9.6
Severity Score:
High
The vulnerability has been patched, so you should update to version 9.6.

Solid Security is part of Solid Suite — The best foundation for WordPress websites.

Every WordPress site needs security, backups, and management tools. That’s Solid Suite — an integrated bundle of three plugins: Solid Security, Solid Backups, and Solid Central. You also get access to Solid Academy’s learning resources for WordPress professionals. Build your next WordPress website on a solid foundation with Solid Suite!

Get Solid Security