WordPress Vulnerability Report

WordPress Vulnerability Report — September 10, 2025

Since last week, 297 new vulnerabilities have emerged in the WordPress ecosystem, including 195 plugins and 102 themes. Of those, 204 remain unpatched, but Solid Security Pro users are protected by virtual patching from Patchstack.

Avatar photo
Sarah Ulmer

In this report, 297 vulnerabilities have been publicly disclosed. Security patches for 93 of these plugins and themes are now available, so please run those updates as soon as possible. If you’re a Solid Security Pro user, the version management tool may have already warned you and updated these plugins, depending on your settings.

Additionally, there are 204 plugin and theme vulnerabilities, and no patch has been available yet. If you’re a Solid Security Pro user, those vulnerabilities are already protected by the Solid Security firewall. Virtual patches from Patchstack will be applied when a vulnerability is considered high or medium risk. If no patch is forthcoming from the vendor or the vulnerable software has been marked “closed” and dropped from the official WordPress repositories, you should deactivate it soon and look for alternative solutions.

Along with poor user account security, vulnerable plugins and themes are among the top reasons why WordPress websites get hacked. Unfortunately, cyberattacks are increasing in volume and sophistication. They’re also increasingly aimed at small to mid-sized businesses.

Our WordPress Vulnerability Report covers the latest emerging WordPress plugin, theme, and core vulnerabilities. Each vulnerability will have a severity rating of LowMediumHigh, or Critical. Responsible disclosure of vulnerabilities is essential to keeping the WordPress community safe. Please share this report to help spread the word and make WordPress — and the web — more secure.

WordPress Core

WordPress 6.8.2 was released on July 15, 2025. This maintenance release includes fixes for 20 Core tickets and 15 Block Editor issues. For a full list of bug fixes, please refer to the release candidate announcement.

No new core vulnerabilities were disclosed this week.

WordPress Plugins — 83 Patched / 112 Unpatched

ARI Fancy Lightbox – Popup for WordPress

Plugin Slug:
ari-fancy-lightbox
Installations
10,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Ray Enterprise Translation

Plugin Slug:
lingotek-translation
Installations
10,000+
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Themify Popup

Plugin Slug:
themify-popup
Installations
9,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Ibtana – Ecommerce Product Addons

Plugin Slug:
ibtana-ecommerce-product-addons
Installations
8,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

License Manager for WooCommerce

Plugin Slug:
license-manager-for-woocommerce
Installations
7,000+
Vulnerability:
SQL Injection
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Authors List

Plugin Slug:
authors-list
Installations
5,000+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Social Sharing Plugin – Kiwi

Plugin Slug:
kiwi-social-share
Installations
5,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Payoneer Checkout

Plugin Slug:
payoneer-checkout
Installations
5,000+
Vulnerability:
Content Spoofing
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Assistant – Every Day Productivity Apps

Plugin Slug:
assistant
Installations
4,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

BCM Duplicate Menu

Plugin Slug:
bcm-duplicate-menu
Installations
4,000+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Elementor Element Condition

Plugin Slug:
ele-conditions
Installations
4,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Notification for Telegram

Plugin Slug:
notification-for-telegram
Installations
4,000+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

SEO Auto Linker

Plugin Slug:
wpa-seo-auto-linker
Installations
4,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

WPB Elementor Addons

Plugin Slug:
wpb-elementor-addons
Installations
4,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Custom WooCommerce Checkout Fields Editor

Plugin Slug:
add-fields-to-checkout-page-woocommerce
Installations
3,000+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Ninja Charts – WordPress Charts and Graphs Plugin

Plugin Slug:
ninja-charts
Installations
3,000+
Vulnerability:
Sensitive Data Exposure
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Responder

Plugin:
Responder
Plugin Slug:
responder
Installations
3,000+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

TrustMate.io – WooCommerce integration

Plugin Slug:
trustmate-io-integration-for-woocommerce
Installations
3,000+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Widgetize Pages Light

Plugin Slug:
widgetize-pages-light
Installations
3,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

WP Email Template

Plugin Slug:
wp-email-template
Installations
3,000+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

WordPress Error Monitoring by Bugsnag

Plugin Slug:
bugsnag
Installations
2,000+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

WordPress prettyPhoto

Plugin Slug:
prettyphoto
Installations
2,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Purge Varnish Cache

Plugin Slug:
purge-varnish
Installations
2,000+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Brilliant Web-to-Lead for Salesforce

Plugin Slug:
salesforce-wordpress-to-lead
Installations
2,000+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.
Plugin Slug:
simple-link-list-widget
Installations
2,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Ultimate Client Dash

Plugin Slug:
ulimate-client-dash
Installations
2,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Aitasi Coming Soon

Plugin Slug:
aitasi-coming-soon
Installations
1,000+
Vulnerability:
Deserialization of untrusted data
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Great Restaurant Menu WP

Plugin Slug:
best-restaurant-menu-by-pricelisto
Installations
1,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Easy Flash Embed

Plugin Slug:
easy-flash-embed
Installations
1,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.
Plugin Slug:
ecommerce-product-carousel-slider-for-elementor
Installations
1,000+
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Low
The vulnerability has not been patched. You should deactivate the plugin.

GoUrl Bitcoin Payment Gateway & Paid Downloads & Membership

Plugin Slug:
gourl-bitcoin-payment-gateway-paid-downloads-membership
Installations
1,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

StagTools

Plugin:
StagTools
Plugin Slug:
stagtools
Installations
1,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Today’s Date Inserter

Plugin Slug:
todays-date-inserter
Installations
1,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.
Plugin Slug:
bulk-featured-image
Installations
900+
Vulnerability:
Arbitrary File Upload
Patched in Version:
No Fix
Severity Score:
Critical
The vulnerability has not been patched. You should deactivate the plugin.

WP Notification Bell

Plugin Slug:
wp-notification-bell
Installations
900+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Developer Tools Blocker

Plugin Slug:
swiftninjapro-inspect-element-console-blocker
Installations
800+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.
Plugin Slug:
carousel
Installations
700+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

WP Mail

Plugin:
WP Mail
Plugin Slug:
wp-mail
Installations
600+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Comment Form WP – Customize Default Comment Form

Plugin Slug:
comment-form-wp
Installations
500+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Get Cash

Plugin:
Get Cash
Plugin Slug:
get-cash
Installations
500+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

???? ???

Plugin:
???? ???
Plugin Slug:
mshop-naver-talktalk
Installations
500+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

WP Publication Archive

Plugin Slug:
wp-publication-archive
Installations
500+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Job Board Manager

Plugin Slug:
job-board-manager
Installations
400+
Vulnerability:
Content Injection
Patched in Version:
No Fix
Severity Score:
Low
The vulnerability has not been patched. You should deactivate the plugin.

Parallax Scrolling Enllax.js

Plugin Slug:
parallax-scrolling-enllax-js
Installations
300+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Parallax Scrolling Enllax.js

Plugin Slug:
parallax-scrolling-enllax-js
Installations
300+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Bonus for Woo

Plugin Slug:
bonus-for-woo
Installations
200+
Vulnerability:
Other Vulnerability Type
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Custom Team Manager

Plugin Slug:
custom-team-manager
Installations
200+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Donation Forms WP by Givecloud

Plugin Slug:
donation-forms-by-givecloud
Installations
200+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

eDS Responsive Menu

Plugin Slug:
eds-responsive-menu
Installations
200+
Vulnerability:
PHP Object Injection
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Invelity MyGLS connect

Plugin Slug:
invelity-mygls-connect
Installations
200+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Media Author

Plugin Slug:
media-author
Installations
200+
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Search by Google

Plugin Slug:
search-google
Installations
200+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Smooth Accordion

Plugin Slug:
smooth-accordion
Installations
200+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

SS Font Awesome Icon

Plugin Slug:
ss-font-awesome-icon
Installations
200+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

short.io

Plugin:
short.io
Plugin Slug:
wp-shortcm
Installations
200+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Add to Feedly

Plugin Slug:
add-to-feedly
Installations
100+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

AP HoneyPot WordPress Plugin

Plugin Slug:
ap-honeypot
Installations
100+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Auto Last Youtube Video

Plugin Slug:
auto-last-youtube-video
Installations
100+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Boxed Content

Plugin Slug:
boxed-content
Installations
100+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Bulk Watermark

Plugin Slug:
bulk-watermark
Installations
100+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

connectDaily Events Calendar Plugin

Plugin Slug:
connect-daily-web-calendar
Installations
100+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Table of content

Plugin Slug:
content-table
Installations
100+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Database to Excel

Plugin Slug:
database-to-excel
Installations
100+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

FW Anker

Plugin:
FW Anker
Plugin Slug:
fw-anker
Installations
100+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Hide Real Download Path

Plugin Slug:
hide-real-download-path
Installations
100+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

MSTW League Manager

Plugin Slug:
mstw-league-manager
Installations
100+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Popping Sidebars and Widgets Light

Plugin Slug:
popping-sidebars-and-widgets-light
Installations
100+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Quick Event Calendar

Plugin Slug:
quick-event-calendar
Installations
100+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Showpass WordPress Extension

Plugin Slug:
showpass
Installations
100+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Ultimate AJAX Login

Plugin Slug:
ultimate-ajax-login
Installations
100+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

WN Flipbox Pro

Plugin Slug:
wn-flipbox-pro
Installations
100+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Woocommerce Notify Updated Product

Plugin Slug:
woocommerce-notify-updated-product
Installations
100+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

WP likes

Plugin:
WP likes
Plugin Slug:
wp-likes
Installations
100+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

WPB Image Widget

Plugin Slug:
wpb-image-widget
Installations
100+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Enable Latex

Plugin Slug:
enable-latex
Installations
90+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Zoomify embed for WP

Plugin Slug:
zoom-image-shortcode
Installations
90+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

???

Plugin:
???
Plugin Slug:
jinshuju
Installations
80+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Compact Admin

Plugin Slug:
compact-admin
Installations
70+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Site Info

Plugin:
Site Info
Plugin Slug:
site-info-dashboard-widget
Installations
70+
Vulnerability:
Sensitive Data Exposure
Patched in Version:
No Fix
Severity Score:
Low
The vulnerability has not been patched. You should deactivate the plugin.

Aparat Video Shortcode

Plugin Slug:
aparat-shortcode
Installations
60+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Easy Download Media Counter

Plugin Slug:
easy-download-media-counter
Installations
60+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Floating Window Music Player

Plugin Slug:
floating-window-music-player
Installations
60+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Master Paper Collapse Toggle

Plugin Slug:
master-paper-collapse-toggle
Installations
60+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

SimaCookie

Plugin:
SimaCookie
Plugin Slug:
simasicher-dsgvo-cookie
Installations
60+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

SimaCookie

Plugin:
SimaCookie
Plugin Slug:
simasicher-dsgvo-cookie
Installations
60+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Pushe Web Push Notification

Plugin Slug:
pushe-webpush
Installations
50+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Simple Price Calculator

Plugin Slug:
simple-price-calculator-basic
Installations
50+
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

WP Github Gist

Plugin Slug:
wp-github-gist
Installations
50+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

WP-GraphViz

Plugin Slug:
wp-graphviz
Installations
50+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

WordPress StoryMap Plugin

Plugin Slug:
wp-storymap
Installations
50+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.
Plugin Slug:
new-simple-gallery
Installations
30+
Vulnerability:
SQL Injection
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Simple Text Slider

Plugin Slug:
simple-text-slider
Installations
30+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Course Booking Platform

Plugin Slug:
course-booking-platform
Installations
10+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Instant Locations

Plugin Slug:
instant-locations
Installations
10+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Constant Contact for WordPress

Plugin:
Constant Contact for WordPress
Plugin Slug:
constant-contact-api
Vulnerability:
PHP Object Injection
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

FAT Event – WordPress Event and Calendar Booking

Plugin:
FAT Event – WordPress Event and Calendar Booking
Plugin Slug:
fat-event
Vulnerability:
Local File Inclusion
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Make, formerly Integromat Connector

Plugin:
Make, formerly Integromat Connector
Plugin Slug:
integromat-connector
Vulnerability:
Arbitrary File Upload
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

PopAd

Plugin:
PopAd
Plugin Slug:
popad
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Recent Posts Widget Extended

Plugin:
Recent Posts Widget Extended
Plugin Slug:
recent-posts-widget-extended
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Search Cloud One

Plugin Slug:
search-cloud-one
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Spirit Framework

Plugin:
Spirit Framework
Plugin Slug:
spirit-framework
Vulnerability:
Local File Inclusion
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Translate This gTranslate Shortcode

Plugin:
Translate This gTranslate Shortcode
Plugin Slug:
translate-this-google-translate-web-element-shortcode
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Uxper Booking

Plugin:
Uxper Booking
Plugin Slug:
uxper-booking
Vulnerability:
SQL Injection
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

vipdrv

Plugin:
vipdrv
Plugin Slug:
vipdrv-vip-test-drive
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Woocommerce Gifts Product

Plugin:
Woocommerce Gifts Product
Plugin Slug:
woo-gift-product
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

WooCommerce Single Page Checkout

Plugin:
WooCommerce Single Page Checkout
Plugin Slug:
woo-single-page-checkout
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

WordPress Helpdesk Integration

Plugin:
WordPress Helpdesk Integration
Plugin Slug:
wp-helpdesk-integration
Vulnerability:
Local File Inclusion
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Admin Menu Editor

Plugin Slug:
admin-menu-editor
Installations
400,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.14.1
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.14.1.

Post SMTP – WP SMTP Plugin with Email Logs and Mobile App for Failure Notifications – Gmail SMTP, Office 365, Brevo, Mailgun, Amazon SES and more

Plugin Slug:
post-smtp
Installations
400,000+
Vulnerability:
Broken Access Control
Patched in Version:
3.4.2
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.4.2.

AI Engine

Plugin:
AI Engine
Plugin Slug:
ai-engine
Installations
100,000+
Vulnerability:
Broken Access Control
Patched in Version:
2.9.6
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.9.6.

Brizy – Page Builder

Plugin Slug:
brizy
Installations
70,000+
Vulnerability:
Broken Access Control
Patched in Version:
2.7.13
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.7.13.

User Registration & Membership – Custom Registration Form Builder, Custom Login Form, User Profile, Content Restriction & Membership Plugin

Plugin Slug:
user-registration
Installations
60,000+
Vulnerability:
SQL Injection
Patched in Version:
4.4.0
Severity Score:
High
The vulnerability has been patched, so you should update to version 4.4.0.

WP-Members Membership Plugin

Plugin Slug:
wp-members
Installations
60,000+
Vulnerability:
Content Injection
Patched in Version:
3.5.4.3
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.5.4.3.

Ditty – Responsive News Tickers, Sliders, and Lists

Plugin Slug:
ditty-news-ticker
Installations
30,000+
Vulnerability:
Server Side Request Forgery (SSRF)
Patched in Version:
3.1.58
Severity Score:
High
The vulnerability has been patched, so you should update to version 3.1.58.

Klarna Order Management for WooCommerce

Plugin Slug:
klarna-order-management-for-woocommerce
Installations
20,000+
Vulnerability:
Sensitive Data Exposure
Patched in Version:
1.9.9
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.9.9.

LA-Studio Element Kit for Elementor

Plugin Slug:
lastudio-element-kit
Installations
20,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.5.5.2
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.5.5.2.

wpForo Forum

Plugin Slug:
wpforo
Installations
20,000+
Vulnerability:
Insecure Direct Object References (IDOR)
Patched in Version:
2.4.7
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.4.7.

Multi Step Form

Plugin Slug:
multi-step-form
Installations
10,000+
Vulnerability:
Arbitrary File Upload
Patched in Version:
1.7.26
Severity Score:
High
The vulnerability has been patched, so you should update to version 1.7.26.

Order Delivery Date for WooCommerce

Plugin Slug:
order-delivery-date-for-woocommerce
Installations
10,000+
Vulnerability:
Broken Access Control
Patched in Version:
4.2.0
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 4.2.0.

Sticky Side Buttons

Plugin Slug:
sticky-side-buttons
Installations
10,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.0.0
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.0.0.

Malcure Malware Scanner — #1 Toolset for Malware Removal

Plugin Slug:
wp-malware-removal
Installations
10,000+
Vulnerability:
Broken Access Control
Patched in Version:
16.9
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 16.9.

If-So Dynamic Content Personalization

Plugin Slug:
if-so
Installations
8,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.9.4.1
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.9.4.1.

aThemes Addons for Elementor

Plugin Slug:
athemes-addons-for-elementor-lite
Installations
7,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.1.3
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.1.3.

Surfer – WordPress Plugin

Plugin Slug:
surferseo
Installations
6,000+
Vulnerability:
Broken Access Control
Patched in Version:
1.6.5.584
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.6.5.584.
Plugin Slug:
cookie-notice-and-consent-banner
Installations
5,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.7.12
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.7.12.

MediaPress

Plugin:
MediaPress
Plugin Slug:
mediapress
Installations
5,000+
Vulnerability:
Local File Inclusion
Patched in Version:
1.6.0
Severity Score:
High
The vulnerability has been patched, so you should update to version 1.6.0.

Latest Post Shortcode

Plugin Slug:
latest-post-shortcode
Installations
4,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
14.10
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 14.10.
Plugin Slug:
photoblocks-grid-gallery
Installations
4,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.3.2
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.3.2.

Posts Table with Search & Sort

Plugin Slug:
posts-data-table
Installations
3,000+
Vulnerability:
Broken Access Control
Patched in Version:
1.4.11
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.4.11.

Property Hive

Plugin Slug:
propertyhive
Installations
3,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.1.6
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.1.6.

Tickera – WordPress Event Ticketing

Plugin Slug:
tickera-event-ticketing-system
Installations
3,000+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
3.5.5.8
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.5.5.8.

Amministrazione Trasparente

Plugin Slug:
amministrazione-trasparente
Installations
1,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
9.1
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 9.1.

Tooltipy (tooltips for WP)

Plugin Slug:
bluet-keywords-tooltip-generator
Installations
1,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
5.5.9
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 5.5.9.

Easy Timer

Plugin:
Easy Timer
Plugin Slug:
easy-timer
Installations
1,000+
Vulnerability:
Remote Code Execution (RCE)
Patched in Version:
4.2.2
Severity Score:
High
The vulnerability has been patched, so you should update to version 4.2.2.

ELEX WooCommerce Google Shopping (Google Product Feed)

Plugin Slug:
elex-woocommerce-google-product-feed-plugin-basic
Installations
1,000+
Vulnerability:
SQL Injection
Patched in Version:
1.4.4
Severity Score:
High
The vulnerability has been patched, so you should update to version 1.4.4.

F4 Media Taxonomies

Plugin Slug:
f4-media-taxonomies
Installations
1,000+
Vulnerability:
Broken Access Control
Patched in Version:
1.1.5
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.1.5.
Plugin Slug:
inpost-gallery
Installations
1,000+
Vulnerability:
Local File Inclusion
Patched in Version:
2.1.4.6
Severity Score:
High
The vulnerability has been patched, so you should update to version 2.1.4.6.

Mobile Contact Line

Plugin Slug:
mobile-contact-line
Installations
1,000+
Vulnerability:
Broken Access Control
Patched in Version:
2.4.1
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.4.1.

PDF for WPForms + Drag and Drop Template Builder

Plugin Slug:
pdf-for-wpforms
Installations
1,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
6.3.0
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 6.3.0.

WordPress Events Calendar Plugin – Pie Calendar

Plugin Slug:
pie-calendar
Installations
1,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.2.9
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.2.9.

PuzzleMe for WordPress

Plugin Slug:
puzzleme
Installations
1,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.2.1
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.2.1.

Quick Paypal Payments

Plugin Slug:
quick-paypal-payments
Installations
1,000+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
5.7.47
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 5.7.47.

Frisbii Pay

Plugin Slug:
reepay-checkout-gateway
Installations
1,000+
Vulnerability:
Broken Access Control
Patched in Version:
1.8.3
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.8.3.

SKT Addons for Elementor

Plugin Slug:
skt-addons-for-elementor
Installations
1,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
3.8
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.8.

Vayu Blocks – Website Builder for the Block Editor

Plugin Slug:
vayu-blocks
Installations
1,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.3.10
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.3.10.

WP Bannerize Pro

Plugin Slug:
wp-bannerize-pro
Installations
1,000+
Vulnerability:
Server Side Request Forgery (SSRF)
Patched in Version:
1.11.0
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.11.0.

WP Flow Plus

Plugin Slug:
wp-imageflow2
Installations
1,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
5.2.6
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 5.2.6.

Show Eventbrite Events – Event Feed for Eventbrite

Plugin Slug:
event-feed-for-eventbrite
Installations
900+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.4.0
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.4.0.

Exchange Rates

Plugin Slug:
exchange-rates
Installations
900+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.3.0
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.3.0.

RumbleTalk Live Group Chat – HTML5

Plugin Slug:
rumbletalk-chat-a-chat-with-themes
Installations
900+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
6.3.6
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 6.3.6.

Simple Matomo Tracking Code

Plugin Slug:
simple-matomo-tracking-code
Installations
900+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.1.1
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.1.1.

Dadevarzan WordPress Common

Plugin Slug:
dadevarzan-common
Installations
700+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.2.3
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.2.3.

IssueM

Plugin:
IssueM
Plugin Slug:
issuem
Installations
700+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.9.1
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.9.1.

Booking Ultra Pro Appointments Booking Calendar Plugin

Plugin Slug:
booking-ultra-pro
Installations
600+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.1.22
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.1.22.

immonex Kickstart

Plugin Slug:
immonex-kickstart
Installations
300+
Vulnerability:
Local File Inclusion
Patched in Version:
1.11.13
Severity Score:
High
The vulnerability has been patched, so you should update to version 1.11.13.

Cloud SAML SSO – Single Sign On Login

Plugin Slug:
cloud-sso-single-sign-on
Installations
100+
Vulnerability:
Broken Access Control
Patched in Version:
1.0.20
Severity Score:
High
The vulnerability has been patched, so you should update to version 1.0.20.

Cloud SAML SSO – Single Sign On Login

Plugin Slug:
cloud-sso-single-sign-on
Installations
100+
Vulnerability:
Broken Access Control
Patched in Version:
1.0.20
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.0.20.

Smart Table Builder

Plugin Slug:
smart-table-builder
Installations
100+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.0.2
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.0.2.

StreamWeasels Kick Integration

Plugin Slug:
streamweasels-kick-integration
Installations
100+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.1.6
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.1.6.

Html Social share buttons

Plugin Slug:
html-social-share-buttons
Installations
90+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.2.0
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.2.0.

Optio Dentistry

Plugin Slug:
optio-dentistry
Installations
80+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.3
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.3.

atec Debug

Plugin:
atec Debug
Plugin Slug:
atec-debug
Installations
40+
Vulnerability:
Arbitrary File Deletion
Patched in Version:
1.2.23
Severity Score:
High
The vulnerability has been patched, so you should update to version 1.2.23.

atec Debug

Plugin:
atec Debug
Plugin Slug:
atec-debug
Installations
40+
Vulnerability:
Remote Code Execution (RCE)
Patched in Version:
1.2.23
Severity Score:
High
The vulnerability has been patched, so you should update to version 1.2.23.

atec Debug

Plugin:
atec Debug
Plugin Slug:
atec-debug
Installations
40+
Vulnerability:
Arbitrary File Download
Patched in Version:
1.2.23
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.2.23.

LTL Freight Quotes – Day & Ross Edition

Plugin Slug:
ltl-freight-quotes-day-ross-edition
Installations
10+
Vulnerability:
PHP Object Injection
Patched in Version:
2.1.12
Severity Score:
High
The vulnerability has been patched, so you should update to version 2.1.12.

ZIP Code Based Content Protection

Plugin Slug:
zip-code-based-content-protection
Installations
10+
Vulnerability:
SQL Injection
Patched in Version:
1.0.1
Severity Score:
High
The vulnerability has been patched, so you should update to version 1.0.1.

Biagiotti Core

Plugin:
Biagiotti Core
Plugin Slug:
biagiotti-core
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.1.4
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.1.4.

Exit Intent Popup

Plugin:
Exit Intent Popup
Plugin Slug:
exitintentpopup
Vulnerability:
Server Side Request Forgery (SSRF)
Patched in Version:
1.0.3
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.0.3.

LTL Freight Quotes – Daylight Edition

Plugin Slug:
ltl-freight-quotes-daylight-edition
Vulnerability:
PHP Object Injection
Patched in Version:
2.2.8
Severity Score:
High
The vulnerability has been patched, so you should update to version 2.2.8.

LTL Freight Quotes – TQL Edition

Plugin Slug:
ltl-freight-quotes-tql-edition
Vulnerability:
PHP Object Injection
Patched in Version:
1.2.7
Severity Score:
High
The vulnerability has been patched, so you should update to version 1.2.7.

Mikado Core

Plugin:
Mikado Core
Plugin Slug:
mikado-core
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.6
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.6.

Wilmer Core

Plugin:
Wilmer Core
Plugin Slug:
wilmer-core
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.4.6
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.4.6.

WordPress Themes — 10 Patched / 92 Unpatched

ConsultStreet

Theme Slug:
consultstreet
Downloads
581,213
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should switch themes.

Shk Corporate

Theme Slug:
shk-corporate
Downloads
105,547
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should switch themes.

SoftMe

Theme:
SoftMe
Theme Slug:
softme
Downloads
155,328
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should switch themes.

Abogado

Theme:
Abogado
Theme Slug:
abogado
Vulnerability:
Local File Inclusion
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should switch themes.

Accalia

Theme:
Accalia
Theme Slug:
accalia
Vulnerability:
Local File Inclusion
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should switch themes.

Adrena

Theme:
Adrena
Theme Slug:
adrena
Vulnerability:
Local File Inclusion
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should switch themes.

Advice

Theme:
Advice
Theme Slug:
advice
Vulnerability:
Local File Inclusion
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should switch themes.

Agora

Theme:
Agora
Theme Slug:
agora
Vulnerability:
Local File Inclusion
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should switch themes.

Alanzo

Theme:
Alanzo
Theme Slug:
alanzo
Vulnerability:
Local File Inclusion
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should switch themes.

Albertino

Theme:
Albertino
Theme Slug:
albertino
Vulnerability:
Local File Inclusion
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should switch themes.

Alhambra

Theme:
Alhambra
Theme Slug:
alhambra
Vulnerability:
Local File Inclusion
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should switch themes.

A.Williams

Theme:
A.Williams
Theme Slug:
alisha-williams
Vulnerability:
Local File Inclusion
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should switch themes.

AlphaColor

Theme:
AlphaColor
Theme Slug:
alpha-color
Vulnerability:
Local File Inclusion
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should switch themes.

Anesta

Theme:
Anesta
Theme Slug:
anesta
Vulnerability:
Local File Inclusion
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should switch themes.

Angela

Theme:
Angela
Theme Slug:
angela
Vulnerability:
Local File Inclusion
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should switch themes.

AI ANN

Theme:
AI ANN
Theme Slug:
ann
Vulnerability:
Local File Inclusion
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should switch themes.

Anubia

Theme:
Anubia
Theme Slug:
anubia
Vulnerability:
Local File Inclusion
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should switch themes.

Artesia

Theme:
Artesia
Theme Slug:
artesia
Vulnerability:
Local File Inclusion
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should switch themes.

Asclepius

Theme:
Asclepius
Theme Slug:
asclepius
Vulnerability:
Local File Inclusion
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should switch themes.

Belicia

Theme:
Belicia
Theme Slug:
belicia
Vulnerability:
Local File Inclusion
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should switch themes.

BeYoga

Theme:
BeYoga
Theme Slug:
beyoga
Vulnerability:
Local File Inclusion
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should switch themes.

Birdily | Travel Agency & Tour Booking WordPress Theme

Theme:
Birdily | Travel Agency & Tour Booking WordPress Theme
Theme Slug:
birdily
Vulnerability:
Local File Inclusion
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should switch themes.

Bonko

Theme:
Bonko
Theme Slug:
bonko
Vulnerability:
Local File Inclusion
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should switch themes.

Booklovers

Theme:
Booklovers
Theme Slug:
booklovers
Vulnerability:
Local File Inclusion
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should switch themes.

Callie Britt

Theme:
Callie Britt
Theme Slug:
callie-britt
Vulnerability:
Local File Inclusion
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should switch themes.

Camelia

Theme:
Camelia
Theme Slug:
camelia
Vulnerability:
Local File Inclusion
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should switch themes.

Carlax

Theme:
Carlax
Theme Slug:
carlax
Vulnerability:
Local File Inclusion
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should switch themes.

Carz

Theme:
Carz
Theme Slug:
carz
Vulnerability:
Local File Inclusion
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should switch themes.

ChainPress

Theme:
ChainPress
Theme Slug:
chainpress
Vulnerability:
Local File Inclusion
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should switch themes.

Chakra

Theme:
Chakra
Theme Slug:
chakra
Vulnerability:
Local File Inclusion
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should switch themes.

Chardonnay

Theme:
Chardonnay
Theme Slug:
chardonnay
Vulnerability:
Local File Inclusion
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should switch themes.

Childy

Theme:
Childy
Theme Slug:
childly
Vulnerability:
Local File Inclusion
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should switch themes.

Chrimson

Theme:
Chrimson
Theme Slug:
chrimson
Vulnerability:
Local File Inclusion
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should switch themes.

City Hostel

Theme:
City Hostel
Theme Slug:
cityhostel
Vulnerability:
Local File Inclusion
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should switch themes.

69 Clothing

Theme:
69 Clothing
Theme Slug:
clothing69
Vulnerability:
Local File Inclusion
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should switch themes.

Corredo

Theme:
Corredo
Theme Slug:
corredo
Vulnerability:
Local File Inclusion
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should switch themes.

Credit Card Experience

Theme:
Credit Card Experience
Theme Slug:
creditcard
Vulnerability:
Local File Inclusion
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should switch themes.

Crework

Theme:
Crework
Theme Slug:
crework
Vulnerability:
Local File Inclusion
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should switch themes.

Custom Made

Theme:
Custom Made
Theme Slug:
custom-made
Vulnerability:
Local File Inclusion
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should switch themes.

Def

Theme:
Def
Theme Slug:
def
Vulnerability:
Local File Inclusion
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should switch themes.

Doccure

Theme:
Doccure
Theme Slug:
doccure
Vulnerability:
Arbitrary File Upload
Patched in Version:
No Fix
Severity Score:
Critical
The vulnerability has not been patched. You should switch themes.

Doccure

Theme:
Doccure
Theme Slug:
doccure
Vulnerability:
Broken Authentication
Patched in Version:
No Fix
Severity Score:
Critical
The vulnerability has not been patched. You should switch themes.

Doccure

Theme:
Doccure
Theme Slug:
doccure
Vulnerability:
Arbitrary File Upload
Patched in Version:
No Fix
Severity Score:
Critical
The vulnerability has not been patched. You should switch themes.

Drone Media

Theme:
Drone Media
Theme Slug:
drone-media
Vulnerability:
Local File Inclusion
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should switch themes.

Edema

Theme:
Edema
Theme Slug:
edema
Vulnerability:
Local File Inclusion
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should switch themes.

Elementra

Theme:
Elementra
Theme Slug:
elementra
Vulnerability:
Local File Inclusion
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should switch themes.

Fortunio

Theme:
Fortunio
Theme Slug:
fortunio
Vulnerability:
Local File Inclusion
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should switch themes.

Good Wine

Theme:
Good Wine
Theme Slug:
good-wine-shop
Vulnerability:
Local File Inclusion
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should switch themes.

Gravity

Theme:
Gravity
Theme Slug:
gravity
Vulnerability:
Local File Inclusion
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should switch themes.

Gutentype

Theme:
Gutentype
Theme Slug:
gutentype
Vulnerability:
Local File Inclusion
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should switch themes.

Hampton

Theme:
Hampton
Theme Slug:
hampton
Vulnerability:
Local File Inclusion
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should switch themes.

Happy Rider

Theme:
Happy Rider
Theme Slug:
happy-rider
Vulnerability:
Local File Inclusion
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should switch themes.

Healthy Blog

Theme:
Healthy Blog
Theme Slug:
healthy-blog
Vulnerability:
Local File Inclusion
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should switch themes.

Heaven11

Theme:
Heaven11
Theme Slug:
heaven11
Vulnerability:
Local File Inclusion
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should switch themes.

Hello Summer

Theme:
Hello Summer
Theme Slug:
hello-summer
Vulnerability:
Local File Inclusion
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should switch themes.

Hogwords

Theme:
Hogwords
Theme Slug:
hogwords
Vulnerability:
Local File Inclusion
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should switch themes.

HotLock

Theme:
HotLock
Theme Slug:
hotlock
Vulnerability:
Local File Inclusion
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should switch themes.

Insurance Ancora

Theme:
Insurance Ancora
Theme Slug:
insurance-ancora
Vulnerability:
Local File Inclusion
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should switch themes.

Juno

Theme:
Juno
Theme Slug:
junotoys
Vulnerability:
Local File Inclusion
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should switch themes.

Kargo

Theme:
Kargo
Theme Slug:
kargo
Vulnerability:
Local File Inclusion
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should switch themes.

Lab

Theme:
Lab
Theme Slug:
lab
Vulnerability:
Local File Inclusion
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should switch themes.

Laundry City

Theme:
Laundry City
Theme Slug:
laundrycity
Vulnerability:
Local File Inclusion
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should switch themes.

MediaFlex

Theme:
MediaFlex
Theme Slug:
mediaflex
Vulnerability:
Local File Inclusion
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should switch themes.

Nazareth

Theme:
Nazareth
Theme Slug:
nazareth
Vulnerability:
Local File Inclusion
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should switch themes.

OldStory

Theme:
OldStory
Theme Slug:
oldstory
Vulnerability:
Local File Inclusion
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should switch themes.

Partiso

Theme:
Partiso
Theme Slug:
partiso
Vulnerability:
Local File Inclusion
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should switch themes.

PathWell

Theme:
PathWell
Theme Slug:
pathwell
Vulnerability:
Local File Inclusion
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should switch themes.

Planet Shakers

Theme:
Planet Shakers
Theme Slug:
planet-shakers
Vulnerability:
Local File Inclusion
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should switch themes.

Plastica

Theme:
Plastica
Theme Slug:
plastica
Vulnerability:
Local File Inclusion
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should switch themes.

Let’s Play

Theme:
Let’s Play
Theme Slug:
playhockey
Vulnerability:
Local File Inclusion
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should switch themes.

Podium

Theme:
Podium
Theme Slug:
podium
Vulnerability:
Local File Inclusion
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should switch themes.

Preston

Theme:
Preston
Theme Slug:
preston
Vulnerability:
Local File Inclusion
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should switch themes.

ProDent

Theme:
ProDent
Theme Slug:
prodent
Vulnerability:
Local File Inclusion
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should switch themes.

ProGuards

Theme:
ProGuards
Theme Slug:
proguards
Vulnerability:
Local File Inclusion
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should switch themes.

ProRange

Theme:
ProRange
Theme Slug:
prorange
Vulnerability:
Local File Inclusion
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should switch themes.

Qwery

Theme:
Qwery
Theme Slug:
qwery
Vulnerability:
Local File Inclusion
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should switch themes.

Samadhi

Theme:
Samadhi
Theme Slug:
samadhi
Vulnerability:
Local File Inclusion
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should switch themes.

Smart Casa

Theme:
Smart Casa
Theme Slug:
smart-casa
Vulnerability:
Local File Inclusion
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should switch themes.

SoccerClub

Theme:
SoccerClub
Theme Slug:
soccerclub
Vulnerability:
Local File Inclusion
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should switch themes.

Softic

Theme:
Softic
Theme Slug:
softic
Vulnerability:
Local File Inclusion
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should switch themes.

Solio

Theme:
Solio
Theme Slug:
solio
Vulnerability:
Local File Inclusion
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should switch themes.

StevenWatkins

Theme:
StevenWatkins
Theme Slug:
steven-watkins
Vulnerability:
Local File Inclusion
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should switch themes.

Stratego

Theme:
Stratego
Theme Slug:
stratego
Vulnerability:
Local File Inclusion
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should switch themes.

Studeon

Theme:
Studeon
Theme Slug:
studeon
Vulnerability:
Local File Inclusion
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should switch themes.

Tantra

Theme:
Tantra
Theme Slug:
tantra
Vulnerability:
Local File Inclusion
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should switch themes.

Tax Help

Theme:
Tax Help
Theme Slug:
tax-help
Vulnerability:
Local File Inclusion
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should switch themes.

Translang

Theme:
Translang
Theme Slug:
translang
Vulnerability:
Local File Inclusion
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should switch themes.

Travesia

Theme:
Travesia
Theme Slug:
travesia
Vulnerability:
Local File Inclusion
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should switch themes.

Vagabonds

Theme:
Vagabonds
Theme Slug:
vagabonds
Vulnerability:
Local File Inclusion
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should switch themes.

Wine House

Theme:
Wine House
Theme Slug:
wine-house
Vulnerability:
Local File Inclusion
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should switch themes.

Wise Move

Theme:
Wise Move
Theme Slug:
wisemove
Vulnerability:
Local File Inclusion
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should switch themes.

WotaHub

Theme:
WotaHub
Theme Slug:
wotahub
Vulnerability:
Local File Inclusion
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should switch themes.

OceanWP

Theme:
OceanWP
Theme Slug:
oceanwp
Downloads
8,786,658
Vulnerability:
Settings Change
Patched in Version:
4.1.2
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 4.1.2.

SaasLauncher

Theme Slug:
saaslauncher
Downloads
67,440
Vulnerability:
Broken Access Control
Patched in Version:
1.3.1
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.3.1.

AdForest

Theme:
AdForest
Theme Slug:
adforest
Vulnerability:
Broken Authentication
Patched in Version:
6.0.10
Severity Score:
Critical
The vulnerability has been patched, so you should update to version 6.0.10.

Flatsome

Theme:
Flatsome
Theme Slug:
flatsome
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
3.20.1
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.20.1.

Goza

Theme:
Goza
Theme Slug:
goza-theme
Vulnerability:
Arbitrary File Deletion
Patched in Version:
3.2.3
Severity Score:
High
The vulnerability has been patched, so you should update to version 3.2.3.

Goza

Theme:
Goza
Theme Slug:
goza-theme
Vulnerability:
Arbitrary File Upload
Patched in Version:
3.2.3
Severity Score:
Critical
The vulnerability has been patched, so you should update to version 3.2.3.

Miraculous

Theme:
Miraculous
Theme Slug:
miraculous
Vulnerability:
SQL Injection
Patched in Version:
2.0.9
Severity Score:
Critical
The vulnerability has been patched, so you should update to version 2.0.9.

Oblo

Theme:
Oblo
Theme Slug:
oblo
Vulnerability:
Local File Inclusion
Patched in Version:
2.2.5
Severity Score:
High
The vulnerability has been patched, so you should update to version 2.2.5.

Rehub

Theme:
Rehub
Theme Slug:
rehub-theme
Vulnerability:
Content Injection
Patched in Version:
19.9.8
Severity Score:
High
The vulnerability has been patched, so you should update to version 19.9.8.

Rehub

Theme:
Rehub
Theme Slug:
rehub-theme
Vulnerability:
Sensitive Data Exposure
Patched in Version:
19.9.8
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 19.9.8.

Solid Security is part of Solid Suite — The best foundation for WordPress websites.

Every WordPress site needs security, backups, and management tools. That’s Solid Suite — an integrated bundle of three plugins: Solid Security, Solid Backups, and Solid Central. You also get access to Solid Academy’s learning resources for WordPress professionals. Build your next WordPress website on a solid foundation with Solid Suite!

Get Solid Security