WordPress Vulnerability Report

WordPress Vulnerability Report — September 17, 2025

Since last week, 199 new vulnerabilities have emerged in the WordPress ecosystem, including 97 plugins and 102 themes. Of those, 149 remain unpatched, but Solid Security Pro users are protected by virtual patching from Patchstack.

Avatar photo
Sarah Ulmer

In this report, 199 vulnerabilities have been publicly disclosed. Security patches for 50 of these plugins and themes are now available, so please run those updates as soon as possible. If you’re a Solid Security Pro user, the version management tool may have already warned you and updated these plugins, depending on your settings.

Additionally, there are 149 plugin and theme vulnerabilities, and no patch has been available yet. If you’re a Solid Security Pro user, those vulnerabilities are already protected by the Solid Security firewall. Virtual patches from Patchstack will be applied when a vulnerability is considered high or medium risk. If no patch is forthcoming from the vendor or the vulnerable software has been marked “closed” and dropped from the official WordPress repositories, you should deactivate it soon and look for alternative solutions.

Along with poor user account security, vulnerable plugins and themes are among the top reasons why WordPress websites get hacked. Unfortunately, cyberattacks are increasing in volume and sophistication. They’re also increasingly aimed at small to mid-sized businesses.

Our WordPress Vulnerability Report covers the latest emerging WordPress plugin, theme, and core vulnerabilities. Each vulnerability will have a severity rating of LowMediumHigh, or Critical. Responsible disclosure of vulnerabilities is essential to keeping the WordPress community safe. Please share this report to help spread the word and make WordPress — and the web — more secure.

WordPress Core

WordPress 6.8.2 was released on July 15, 2025. This maintenance release includes fixes for 20 Core tickets and 15 Block Editor issues. For a full list of bug fixes, please refer to the release candidate announcement.

No new core vulnerabilities were disclosed this week.

WordPress Plugins — 47 Patched / 50 Unpatched

Duplicate Page and Post

Plugin Slug:
duplicate-wp-page-post
Installations
90,000+
Vulnerability:
SQL Injection
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

WP Mailgun SMTP

Plugin Slug:
wp-mailgun-smtp
Installations
1,000+
Vulnerability:
Sensitive Data Exposure
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

WP SendGrid SMTP

Plugin Slug:
wp-sendgrid-smtp
Installations
1,000+
Vulnerability:
Sensitive Data Exposure
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

All in one Minifier

Plugin Slug:
all-in-one-minifier
Installations
10+
Vulnerability:
SQL Injection
Patched in Version:
No Fix
Severity Score:
Critical
The vulnerability has not been patched. You should deactivate the plugin.

Ultimate Classified Listings

Plugin Slug:
ultimate-classified-listings
Installations
10+
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Admin in English with Switch

Plugin:
Admin in English with Switch
Plugin Slug:
admin-in-english-with-switch
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Analytics Reduce Bounce Rate

Plugin:
Analytics Reduce Bounce Rate
Plugin Slug:
analytics-unbounce
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Auto Save Remote Images (Drafts)

Plugin:
Auto Save Remote Images (Drafts)
Plugin Slug:
auto-save-remote-images-drafts
Vulnerability:
Server Side Request Forgery (SSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

AutoCatSet

Plugin:
AutoCatSet
Plugin Slug:
autocatset
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

azurecurve BBCode

Plugin:
azurecurve BBCode
Plugin Slug:
azurecurve-bbcode
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

BeyondCart Connector

Plugin:
BeyondCart Connector
Plugin Slug:
beyondcart
Vulnerability:
Privilege Escalation
Patched in Version:
No Fix
Severity Score:
Critical
The vulnerability has not been patched. You should deactivate the plugin.

Blog Designer For Elementor

Plugin:
Blog Designer For Elementor
Plugin Slug:
blog-designer-for-elementor
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Certifica WP

Plugin:
Certifica WP
Plugin Slug:
certifica-wp
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Contact Form 7 reCAPTCHA

Plugin:
Contact Form 7 reCAPTCHA
Plugin Slug:
contact-form-7-recaptcha
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Countdown Timer for Elementor

Plugin:
Countdown Timer for Elementor
Plugin Slug:
countdown-timer-for-elementor
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Coupon API

Plugin:
Coupon API
Plugin Slug:
couponapi
Vulnerability:
SQL Injection
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Digital Events Calendar

Plugin:
Digital Events Calendar
Plugin Slug:
digital-events-calendar
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Elements Plus!

Plugin:
Elements Plus!
Plugin Slug:
elements-plus
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Embed Google Datastudio

Plugin:
Embed Google Datastudio
Plugin Slug:
embed-google-data-studio
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Enhanced BibliPlug

Plugin:
Enhanced BibliPlug
Plugin Slug:
enhanced-bibliplug
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Evenium

Plugin:
Evenium
Plugin Slug:
evenium
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

WPGYM

Plugin:
WPGYM
Plugin Slug:
gym-management
Vulnerability:
Privilege Escalation
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

IndiaNIC Testimonial

Plugin:
IndiaNIC Testimonial
Plugin Slug:
indianic-testimonial
Vulnerability:
SQL Injection
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Catalog Importer, Scraper & Crawler

Plugin:
Catalog Importer, Scraper & Crawler
Plugin Slug:
intelligent-importer
Vulnerability:
Remote Code Execution (RCE)
Patched in Version:
No Fix
Severity Score:
Critical
The vulnerability has not been patched. You should deactivate the plugin.

jQuery Colorbox

Plugin:
jQuery Colorbox
Plugin Slug:
jquery-colorbox
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

The integration of the AMO.CRM

Plugin:
The integration of the AMO.CRM
Plugin Slug:
leads-for-amo-crm
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

LH Signing

Plugin:
LH Signing
Plugin Slug:
lh-signing
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Mitfahrgelegenheit

Plugin:
Mitfahrgelegenheit
Plugin Slug:
mitfahrgelegenheit
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Mixtape

Plugin:
Mixtape
Plugin Slug:
mixtape
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

My WP Translate

Plugin:
My WP Translate
Plugin Slug:
my-wp-translate
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

My WP Translate

Plugin:
My WP Translate
Plugin Slug:
my-wp-translate
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

PhpList Subber

Plugin:
PhpList Subber
Plugin Slug:
phpls
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Plugin updates blocker

Plugin:
Plugin updates blocker
Plugin Slug:
plugin-update-blocker
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Propovoice CRM

Plugin:
Propovoice CRM
Plugin Slug:
propovoice
Vulnerability:
Arbitrary File Download
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Publish Approval

Plugin:
Publish Approval
Plugin Slug:
publish-approval
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Resideo Plugin for Resideo

Plugin:
Resideo Plugin for Resideo
Plugin Slug:
resideo-plugin
Vulnerability:
Privilege Escalation
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Responsive Addons for Elementor

Plugin:
Responsive Addons for Elementor
Plugin Slug:
responsive-addons-for-elementor
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Run Log

Plugin:
Run Log
Plugin Slug:
run-log
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Salon booking system

Plugin:
Salon booking system
Plugin Slug:
salon-booking-system
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Seo Monster

Plugin:
Seo Monster
Plugin Slug:
seo-monster
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Side Slide Responsive Menu

Plugin:
Side Slide Responsive Menu
Plugin Slug:
side-slide-responsive-menu
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

eID Easy

Plugin:
eID Easy
Plugin Slug:
smart-id
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Smartcat Translator for WPML

Plugin:
Smartcat Translator for WPML
Plugin Slug:
smartcat-wpml
Vulnerability:
SQL Injection
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Spotify Embed Creator

Plugin:
Spotify Embed Creator
Plugin Slug:
spotify-embed-creator
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

ThemeLoom Widgets

Plugin:
ThemeLoom Widgets
Plugin Slug:
themeloom-widgets
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Ultimate Blogroll

Plugin:
Ultimate Blogroll
Plugin Slug:
ultimate-blogroll
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

User Meta

Plugin:
User Meta
Plugin Slug:
user-meta
Vulnerability:
Arbitrary File Deletion
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

WP Scriptcase

Plugin:
WP Scriptcase
Plugin Slug:
wp-scriptcase
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Workable Api

Plugin:
Workable Api
Plugin Slug:
wrapper-for-workable-api
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

The Events Calendar

Plugin Slug:
the-events-calendar
Installations
700,000+
Vulnerability:
Broken Access Control
Patched in Version:
6.15.3
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 6.15.3.

The Events Calendar

Plugin Slug:
the-events-calendar
Installations
700,000+
Vulnerability:
SQL Injection
Patched in Version:
6.15.1.1
Severity Score:
Critical
The vulnerability has been patched, so you should update to version 6.15.1.1.

Tutor LMS – eLearning and online course solution

Plugin Slug:
tutor
Installations
100,000+
Vulnerability:
SQL Injection
Patched in Version:
3.8.0
Severity Score:
High
The vulnerability has been patched, so you should update to version 3.8.0.

Import any XML, CSV or Excel File to WordPress

Plugin Slug:
wp-all-import
Installations
100,000+
Vulnerability:
Arbitrary File Upload
Patched in Version:
3.9.4
Severity Score:
High
The vulnerability has been patched, so you should update to version 3.9.4.

WP-Members Membership Plugin

Plugin Slug:
wp-members
Installations
60,000+
Vulnerability:
Content Injection
Patched in Version:
3.5.4.3
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.5.4.3.

Maspik – Ultimate Spam Protection

Plugin Slug:
contact-forms-anti-spam
Installations
30,000+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
2.5.7
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.5.7.

Maspik – Ultimate Spam Protection

Plugin Slug:
contact-forms-anti-spam
Installations
30,000+
Vulnerability:
Broken Access Control
Patched in Version:
2.5.7
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.5.7.

Ditty – Responsive News Tickers, Sliders, and Lists

Plugin Slug:
ditty-news-ticker
Installations
30,000+
Vulnerability:
Server Side Request Forgery (SSRF)
Patched in Version:
3.1.58
Severity Score:
High
The vulnerability has been patched, so you should update to version 3.1.58.

Welcart e-Commerce

Plugin Slug:
usc-e-shop
Installations
20,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.11.21
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.11.21.

WP Import – Ultimate CSV XML Importer for WordPress

Plugin Slug:
wp-ultimate-csv-importer
Installations
20,000+
Vulnerability:
Sensitive Data Exposure
Patched in Version:
7.28
Severity Score:
High
The vulnerability has been patched, so you should update to version 7.28.

LWS Cleaner

Plugin Slug:
lws-cleaner
Installations
10,000+
Vulnerability:
Arbitrary File Deletion
Patched in Version:
2.4.2
Severity Score:
High
The vulnerability has been patched, so you should update to version 2.4.2.

AI ChatBot for WordPress – WPBot

Plugin Slug:
chatbot
Installations
7,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
7.1.0
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 7.1.0.

Export WP Page to Static HTML & PDF

Plugin Slug:
export-wp-page-to-static-html
Installations
5,000+
Vulnerability:
Broken Access Control
Patched in Version:
4.2.0
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 4.2.0.

Include Me

Plugin:
Include Me
Plugin Slug:
include-me
Installations
4,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.3.3
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.3.3.

PagBank / PagSeguro Connect para WooCommerce

Plugin Slug:
pagbank-connect
Installations
4,000+
Vulnerability:
SQL Injection
Patched in Version:
4.44.4
Severity Score:
High
The vulnerability has been patched, so you should update to version 4.44.4.

PDF Generator for WordPress

Plugin Slug:
pdf-generator-for-wp
Installations
2,000+
Vulnerability:
Broken Access Control
Patched in Version:
1.5.5
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.5.5.

Responsive Filterable Portfolio

Plugin Slug:
responsive-filterable-portfolio
Installations
2,000+
Vulnerability:
Arbitrary File Upload
Patched in Version:
1.0.25
Severity Score:
Critical
The vulnerability has been patched, so you should update to version 1.0.25.

Dynamic Text Field For Contact Form 7

Plugin Slug:
dynamic-text-field-for-contact-form-7
Installations
1,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.1
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.1.

Falang multilanguage for WordPress

Plugin Slug:
falang
Installations
1,000+
Vulnerability:
PHP Object Injection
Patched in Version:
1.3.66
Severity Score:
High
The vulnerability has been patched, so you should update to version 1.3.66.

WP eBay Product Feeds

Plugin Slug:
ebay-feeds-for-wordpress
Installations
900+
Vulnerability:
Server Side Request Forgery (SSRF)
Patched in Version:
3.4.9
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.4.9.

Pixeline’s Email Protector

Plugin Slug:
pixelines-email-protector
Installations
900+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.4.0
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.4.0.

Football Pool

Plugin Slug:
football-pool
Installations
800+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.13.0
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.13.0.

My Tickets – Accessible Event Ticketing

Plugin Slug:
my-tickets
Installations
800+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.0.23
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.0.23.

Additional Custom Product Tabs for WooCommerce

Plugin Slug:
product-tabs-for-woocommerce
Installations
500+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.7.4
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.7.4.

The Hack Repair Guy’s Plugin Archiver

Plugin Slug:
hackrepair-plugin-archiver
Installations
400+
Vulnerability:
Arbitrary File Deletion
Patched in Version:
3.1.1
Severity Score:
High
The vulnerability has been patched, so you should update to version 3.1.1.

Advanced Settings 3

Plugin Slug:
advanced-settings
Installations
200+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
3.2.0
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.2.0.

Time Tracker

Plugin Slug:
time-tracker
Installations
60+
Vulnerability:
Broken Access Control
Patched in Version:
3.2.0
Severity Score:
High
The vulnerability has been patched, so you should update to version 3.2.0.

WP Blast | SEO & Performance Booster

Plugin Slug:
wpblast
Installations
40+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
1.8.7
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.8.7.

Heateor Login – Social Login Plugin

Plugin Slug:
heateor-login
Installations
30+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.1.10
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.1.10.

MyBrain Utilities

Plugin Slug:
mybrain-utilities
Installations
20+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.1.0
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.1.0.

Compress & Upload

Plugin Slug:
compress-then-upload
Installations
10+
Vulnerability:
Arbitrary File Upload
Patched in Version:
1.0.5
Severity Score:
Critical
The vulnerability has been patched, so you should update to version 1.0.5.

Mikado Core

Plugin:
Mikado Core
Plugin Slug:
mikado-core
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.6
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.6.

Wilmer Core

Plugin:
Wilmer Core
Plugin Slug:
wilmer-core
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.4.6
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.4.6.

WooCommerce Booking Bundle Hours

Plugin:
WooCommerce Booking Bundle Hours
Plugin Slug:
woo-booking-bundle-hours
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
0.7.5
Severity Score:
High
The vulnerability has been patched, so you should update to version 0.7.5.

WordPress Themes — 3 Patched / 99 Unpatched

ButterBelly

Theme Slug:
butterbelly
Downloads
70,694
Vulnerability:
Sensitive Data Exposure
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should switch themes.

Cloriato Lite

Theme Slug:
cloriato-lite
Downloads
111,776
Vulnerability:
Sensitive Data Exposure
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should switch themes.

ColorWay

Theme:
ColorWay
Theme Slug:
colorway
Downloads
1,314,146
Vulnerability:
Sensitive Data Exposure
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should switch themes.

Compass

Theme:
Compass
Theme Slug:
compass
Downloads
65,712
Vulnerability:
Sensitive Data Exposure
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should switch themes.

Dzonia Lite

Theme Slug:
dzonia-lite
Downloads
114,483
Vulnerability:
Sensitive Data Exposure
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should switch themes.

Poloray

Theme:
Poloray
Theme Slug:
poloray
Downloads
71,063
Vulnerability:
Sensitive Data Exposure
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should switch themes.

Rethink

Theme:
Rethink
Theme Slug:
rethink
Downloads
42,070
Vulnerability:
Sensitive Data Exposure
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should switch themes.

Road Fighter

Theme Slug:
road-fighter
Downloads
82,748
Vulnerability:
Sensitive Data Exposure
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should switch themes.

Themia Lite

Theme Slug:
themia-lite
Downloads
194,918
Vulnerability:
Sensitive Data Exposure
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should switch themes.

Abogado

Theme:
Abogado
Theme Slug:
abogado
Vulnerability:
Local File Inclusion
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should switch themes.

Accalia

Theme:
Accalia
Theme Slug:
accalia
Vulnerability:
Local File Inclusion
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should switch themes.

Adrena

Theme:
Adrena
Theme Slug:
adrena
Vulnerability:
Local File Inclusion
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should switch themes.

Advice

Theme:
Advice
Theme Slug:
advice
Vulnerability:
Local File Inclusion
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should switch themes.

Agora

Theme:
Agora
Theme Slug:
agora
Vulnerability:
Local File Inclusion
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should switch themes.

Alanzo

Theme:
Alanzo
Theme Slug:
alanzo
Vulnerability:
Local File Inclusion
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should switch themes.

Albertino

Theme:
Albertino
Theme Slug:
albertino
Vulnerability:
Local File Inclusion
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should switch themes.

Alhambra

Theme:
Alhambra
Theme Slug:
alhambra
Vulnerability:
Local File Inclusion
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should switch themes.

A.Williams

Theme:
A.Williams
Theme Slug:
alisha-williams
Vulnerability:
Local File Inclusion
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should switch themes.

AlphaColor

Theme:
AlphaColor
Theme Slug:
alpha-color
Vulnerability:
Local File Inclusion
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should switch themes.

Anesta

Theme:
Anesta
Theme Slug:
anesta
Vulnerability:
Local File Inclusion
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should switch themes.

Angela

Theme:
Angela
Theme Slug:
angela
Vulnerability:
Local File Inclusion
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should switch themes.

AI ANN

Theme:
AI ANN
Theme Slug:
ann
Vulnerability:
Local File Inclusion
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should switch themes.

Anubia

Theme:
Anubia
Theme Slug:
anubia
Vulnerability:
Local File Inclusion
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should switch themes.

Artesia

Theme:
Artesia
Theme Slug:
artesia
Vulnerability:
Local File Inclusion
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should switch themes.

Asclepius

Theme:
Asclepius
Theme Slug:
asclepius
Vulnerability:
Local File Inclusion
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should switch themes.

Belicia

Theme:
Belicia
Theme Slug:
belicia
Vulnerability:
Local File Inclusion
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should switch themes.

BeYoga

Theme:
BeYoga
Theme Slug:
beyoga
Vulnerability:
Local File Inclusion
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should switch themes.

Birdily | Travel Agency & Tour Booking WordPress Theme

Theme:
Birdily | Travel Agency & Tour Booking WordPress Theme
Theme Slug:
birdily
Vulnerability:
Local File Inclusion
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should switch themes.

Bonko

Theme:
Bonko
Theme Slug:
bonko
Vulnerability:
Local File Inclusion
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should switch themes.

Booklovers

Theme:
Booklovers
Theme Slug:
booklovers
Vulnerability:
Local File Inclusion
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should switch themes.

Callie Britt

Theme:
Callie Britt
Theme Slug:
callie-britt
Vulnerability:
Local File Inclusion
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should switch themes.

Camelia

Theme:
Camelia
Theme Slug:
camelia
Vulnerability:
Local File Inclusion
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should switch themes.

Carlax

Theme:
Carlax
Theme Slug:
carlax
Vulnerability:
Local File Inclusion
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should switch themes.

Carz

Theme:
Carz
Theme Slug:
carz
Vulnerability:
Local File Inclusion
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should switch themes.

ChainPress

Theme:
ChainPress
Theme Slug:
chainpress
Vulnerability:
Local File Inclusion
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should switch themes.

Chakra

Theme:
Chakra
Theme Slug:
chakra
Vulnerability:
Local File Inclusion
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should switch themes.

Chardonnay

Theme:
Chardonnay
Theme Slug:
chardonnay
Vulnerability:
Local File Inclusion
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should switch themes.

Childy

Theme:
Childy
Theme Slug:
childly
Vulnerability:
Local File Inclusion
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should switch themes.

Chrimson

Theme:
Chrimson
Theme Slug:
chrimson
Vulnerability:
Local File Inclusion
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should switch themes.

City Hostel

Theme:
City Hostel
Theme Slug:
cityhostel
Vulnerability:
Local File Inclusion
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should switch themes.

69 Clothing

Theme:
69 Clothing
Theme Slug:
clothing69
Vulnerability:
Local File Inclusion
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should switch themes.

Corredo

Theme:
Corredo
Theme Slug:
corredo
Vulnerability:
Local File Inclusion
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should switch themes.

Credit Card Experience

Theme:
Credit Card Experience
Theme Slug:
creditcard
Vulnerability:
Local File Inclusion
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should switch themes.

Crework

Theme:
Crework
Theme Slug:
crework
Vulnerability:
Local File Inclusion
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should switch themes.

Custom Made

Theme:
Custom Made
Theme Slug:
custom-made
Vulnerability:
Local File Inclusion
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should switch themes.

Def

Theme:
Def
Theme Slug:
def
Vulnerability:
Local File Inclusion
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should switch themes.

Doccure

Theme:
Doccure
Theme Slug:
doccure
Vulnerability:
Arbitrary File Upload
Patched in Version:
No Fix
Severity Score:
Critical
The vulnerability has not been patched. You should switch themes.

Doccure

Theme:
Doccure
Theme Slug:
doccure
Vulnerability:
Broken Authentication
Patched in Version:
No Fix
Severity Score:
Critical
The vulnerability has not been patched. You should switch themes.

Doccure

Theme:
Doccure
Theme Slug:
doccure
Vulnerability:
Arbitrary File Upload
Patched in Version:
No Fix
Severity Score:
Critical
The vulnerability has not been patched. You should switch themes.

Drone Media

Theme:
Drone Media
Theme Slug:
drone-media
Vulnerability:
Local File Inclusion
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should switch themes.

Edema

Theme:
Edema
Theme Slug:
edema
Vulnerability:
Local File Inclusion
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should switch themes.

Elementra

Theme:
Elementra
Theme Slug:
elementra
Vulnerability:
Local File Inclusion
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should switch themes.

Fortunio

Theme:
Fortunio
Theme Slug:
fortunio
Vulnerability:
Local File Inclusion
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should switch themes.

Good Wine

Theme:
Good Wine
Theme Slug:
good-wine-shop
Vulnerability:
Local File Inclusion
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should switch themes.

Gravity

Theme:
Gravity
Theme Slug:
gravity
Vulnerability:
Local File Inclusion
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should switch themes.

Gutentype

Theme:
Gutentype
Theme Slug:
gutentype
Vulnerability:
Local File Inclusion
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should switch themes.

Hampton

Theme:
Hampton
Theme Slug:
hampton
Vulnerability:
Local File Inclusion
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should switch themes.

Happy Rider

Theme:
Happy Rider
Theme Slug:
happy-rider
Vulnerability:
Local File Inclusion
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should switch themes.

Healthy Blog

Theme:
Healthy Blog
Theme Slug:
healthy-blog
Vulnerability:
Local File Inclusion
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should switch themes.

Heaven11

Theme:
Heaven11
Theme Slug:
heaven11
Vulnerability:
Local File Inclusion
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should switch themes.

Hello Summer

Theme:
Hello Summer
Theme Slug:
hello-summer
Vulnerability:
Local File Inclusion
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should switch themes.

Hogwords

Theme:
Hogwords
Theme Slug:
hogwords
Vulnerability:
Local File Inclusion
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should switch themes.

HotLock

Theme:
HotLock
Theme Slug:
hotlock
Vulnerability:
Local File Inclusion
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should switch themes.

Insurance Ancora

Theme:
Insurance Ancora
Theme Slug:
insurance-ancora
Vulnerability:
Local File Inclusion
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should switch themes.

Jobify – Job Board WordPress Theme

Theme:
Jobify – Job Board WordPress Theme
Theme Slug:
jobify
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should switch themes.

Juno

Theme:
Juno
Theme Slug:
junotoys
Vulnerability:
Local File Inclusion
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should switch themes.

Kargo

Theme:
Kargo
Theme Slug:
kargo
Vulnerability:
Local File Inclusion
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should switch themes.

Lab

Theme:
Lab
Theme Slug:
lab
Vulnerability:
Local File Inclusion
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should switch themes.

Laundry City

Theme:
Laundry City
Theme Slug:
laundrycity
Vulnerability:
Local File Inclusion
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should switch themes.

MediaFlex

Theme:
MediaFlex
Theme Slug:
mediaflex
Vulnerability:
Local File Inclusion
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should switch themes.

Nazareth

Theme:
Nazareth
Theme Slug:
nazareth
Vulnerability:
Local File Inclusion
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should switch themes.

OldStory

Theme:
OldStory
Theme Slug:
oldstory
Vulnerability:
Local File Inclusion
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should switch themes.

Partiso

Theme:
Partiso
Theme Slug:
partiso
Vulnerability:
Local File Inclusion
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should switch themes.

PathWell

Theme:
PathWell
Theme Slug:
pathwell
Vulnerability:
Local File Inclusion
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should switch themes.

Planet Shakers

Theme:
Planet Shakers
Theme Slug:
planet-shakers
Vulnerability:
Local File Inclusion
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should switch themes.

Plastica

Theme:
Plastica
Theme Slug:
plastica
Vulnerability:
Local File Inclusion
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should switch themes.

Let’s Play

Theme:
Let’s Play
Theme Slug:
playhockey
Vulnerability:
Local File Inclusion
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should switch themes.

Podium

Theme:
Podium
Theme Slug:
podium
Vulnerability:
Local File Inclusion
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should switch themes.

Preston

Theme:
Preston
Theme Slug:
preston
Vulnerability:
Local File Inclusion
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should switch themes.

ProDent

Theme:
ProDent
Theme Slug:
prodent
Vulnerability:
Local File Inclusion
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should switch themes.

ProGuards

Theme:
ProGuards
Theme Slug:
proguards
Vulnerability:
Local File Inclusion
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should switch themes.

ProRange

Theme:
ProRange
Theme Slug:
prorange
Vulnerability:
Local File Inclusion
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should switch themes.

Qwery

Theme:
Qwery
Theme Slug:
qwery
Vulnerability:
Local File Inclusion
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should switch themes.

Samadhi

Theme:
Samadhi
Theme Slug:
samadhi
Vulnerability:
Local File Inclusion
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should switch themes.

Smart Casa

Theme:
Smart Casa
Theme Slug:
smart-casa
Vulnerability:
Local File Inclusion
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should switch themes.

SoccerClub

Theme:
SoccerClub
Theme Slug:
soccerclub
Vulnerability:
Local File Inclusion
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should switch themes.

Softic

Theme:
Softic
Theme Slug:
softic
Vulnerability:
Local File Inclusion
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should switch themes.

Solio

Theme:
Solio
Theme Slug:
solio
Vulnerability:
Local File Inclusion
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should switch themes.

StevenWatkins

Theme:
StevenWatkins
Theme Slug:
steven-watkins
Vulnerability:
Local File Inclusion
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should switch themes.

Stratego

Theme:
Stratego
Theme Slug:
stratego
Vulnerability:
Local File Inclusion
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should switch themes.

Studeon

Theme:
Studeon
Theme Slug:
studeon
Vulnerability:
Local File Inclusion
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should switch themes.

Tantra

Theme:
Tantra
Theme Slug:
tantra
Vulnerability:
Local File Inclusion
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should switch themes.

Tax Help

Theme:
Tax Help
Theme Slug:
tax-help
Vulnerability:
Local File Inclusion
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should switch themes.

Translang

Theme:
Translang
Theme Slug:
translang
Vulnerability:
Local File Inclusion
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should switch themes.

Travesia

Theme:
Travesia
Theme Slug:
travesia
Vulnerability:
Local File Inclusion
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should switch themes.

Vagabonds

Theme:
Vagabonds
Theme Slug:
vagabonds
Vulnerability:
Local File Inclusion
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should switch themes.

Wine House

Theme:
Wine House
Theme Slug:
wine-house
Vulnerability:
Local File Inclusion
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should switch themes.

Wise Move

Theme:
Wise Move
Theme Slug:
wisemove
Vulnerability:
Local File Inclusion
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should switch themes.

WotaHub

Theme:
WotaHub
Theme Slug:
wotahub
Vulnerability:
Local File Inclusion
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should switch themes.

Goza

Theme:
Goza
Theme Slug:
goza-theme
Vulnerability:
Arbitrary File Deletion
Patched in Version:
3.2.3
Severity Score:
High
The vulnerability has been patched, so you should update to version 3.2.3.

Goza

Theme:
Goza
Theme Slug:
goza-theme
Vulnerability:
Arbitrary File Upload
Patched in Version:
3.2.3
Severity Score:
Critical
The vulnerability has been patched, so you should update to version 3.2.3.

Mow

Theme:
Mow
Theme Slug:
mow
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
4.11
Severity Score:
Critical
The vulnerability has been patched, so you should update to version 4.11.

Solid Security is part of Solid Suite — The best foundation for WordPress websites.

Every WordPress site needs security, backups, and management tools. That’s Solid Suite — an integrated bundle of three plugins: Solid Security, Solid Backups, and Solid Central. You also get access to Solid Academy’s learning resources for WordPress professionals. Build your next WordPress website on a solid foundation with Solid Suite!

Get Solid Security