Line illustration showing a black application window on a dark black to purple gradient background overlaid with a large exclamation point alert icon and three bugs.

WordPress Vulnerability Report � January 8, 2025

In this report, 228 vulnerabilities have been publicly disclosed. Security patches for 97 of these plugins and themes are available now, so run those updates as soon as possible. If you’re a Solid Security Pro user, the version management tool may have already warned you and updated these plugins, depending on your settings.

Additionally, there are 131 plugin and theme vulnerabilities with no patch available yet. If you’re a Solid Security Pro user, those vulnerabilities are already protected by the Solid Security firewall. Virtual patches from Patchstack will be applied when a vulnerability is considered high or medium risk. If no patch is forthcoming from the vendor or the vulnerable software has been marked “closed” and dropped from the official WordPress repositories, you should deactivate it soon and look for alternative solutions.

WordPress Core

WordPress 6.7.1 is available! This minor release features 16 bug fixes throughout Core and the Block Editor.

WordPress Plugins � 95 Patched / 110 Unpatched

Smart Custom Fields

Plugin Slug:
smart-custom-fields

Installations
50,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Gutentor � Gutenberg Blocks � Page Builder for Gutenberg Editor

Plugin Slug:
gutentor

Installations
40,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.
Plugin Slug:
link-whisper

Installations
30,000+

Vulnerability:
Sensitive Data Exposure

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

WP Visitor Statistics (Real Time Traffic)

Plugin Slug:
wp-stats-manager

Installations
30,000+

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Thim Elementor Kit

Plugin Slug:
thim-elementor-kit

Installations
20,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

TemplatesNext ToolKit

Plugin Slug:
templatesnext-toolkit

Installations
10,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

WP FullCalendar

Plugin Slug:
wp-fullcalendar

Installations
10,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Hash Elements

Plugin Slug:
hash-elements

Installations
6,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

CubeWP Forms � All-in-One Form Builder

Plugin Slug:
cubewp-forms

Installations
4,000+

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

SpeakOut! Email Petitions

Plugin Slug:
speakout

Installations
3,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

DynamicTags

Plugin Slug:
dynamictags

Installations
2,000+

Vulnerability:
SQL Injection

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

BSK Forms Blacklist

Plugin Slug:
bsk-gravityforms-blacklist

Installations
1,000+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Hero Banner Ultimate

Plugin Slug:
hero-banner-ultimate

Installations
1,000+

Vulnerability:
Local File Inclusion

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Typing Text

Plugin Slug:
typing-text

Installations
1,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Custom Field For WP Job Manager

Plugin Slug:
custom-field-for-wp-job-manager

Installations
900+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Build App Online

Plugin Slug:
build-app-online

Installations
700+

Vulnerability:
Local File Inclusion

Patched in Version:
No Fix

Severity Score:
Critical


The vulnerability has not been patched. You should deactivate the plugin.

WordLift � AI powered SEO � Schema

Plugin Slug:
wordlift

Installations
600+

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

SMSA Shipping (official)

Plugin Slug:
smsa-shipping-official

Installations
500+

Vulnerability:
Arbitrary File Deletion

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.
Plugin Slug:
wp-youtube-gallery

Installations
500+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

NAVER Analytics

Plugin Slug:
naver-analytics

Installations
400+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

ThePerfectWedding.nl Widget

Plugin Slug:
theperfectweddingnl-widget

Installations
400+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Hide Category by User Role for WooCommerce

Plugin Slug:
hide-category-by-user-role-for-woocommerce

Installations
200+

Vulnerability:
Arbitrary Content Deletion

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Rezgo Online Booking

Plugin Slug:
rezgo

Installations
200+

Vulnerability:
Local File Inclusion

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Standard Box Sizes � for WooCommerce

Plugin Slug:
standard-box-sizes

Installations
100+

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

ARS Affiliate Page Plugin

Plugin Slug:
ars-affiliate-page

Installations
70+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

ProductDyno

Plugin Slug:
productdyno

Installations
70+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

SSL Wireless SMS Notification

Plugin Slug:
ssl-wireless-sms-notification

Installations
70+

Vulnerability:
SQL Injection

Patched in Version:
No Fix

Severity Score:
Critical


The vulnerability has not been patched. You should deactivate the plugin.

Image Hover Effects for Elementor

Plugin Slug:
image-hover-effects-elementor-addon

Installations
60+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

WP SecureSubmit

Plugin Slug:
securesubmit

Installations
60+

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

WP SecureSubmit

Plugin Slug:
securesubmit

Installations
60+

Vulnerability:
Sensitive Data Exposure

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Chative Live chat and Chatbot

Plugin Slug:
chative-live-chat-and-chatbot

Installations
50+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

EO4WP: EmailOctopus for WordPress

Plugin Slug:
fw-integration-for-emailoctopus

Installations
30+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

5centsCDN � WordPress CDN Plugin

Plugin Slug:
5centscdn

Installations
10+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

ACH Invoicing Plugin

Plugin Slug:
ach-invoice-app

Vulnerability:
Local File Inclusion

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Contact Form 7 Database � CFDB7

Plugin:

Contact Form 7 Database � CFDB7

Plugin Slug:
advanced-cf7-database

Vulnerability:
SQL Injection

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Wp advertising management

Plugin:

Wp advertising management

Plugin Slug:
advertising-management

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

AHAthat

Plugin:

AHAthat

Plugin Slug:
ahathat

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Allada T-shirt Designer for Woocommerce

Plugin:

Allada T-shirt Designer for Woocommerce

Plugin Slug:
allada-tshirt-designer-for-woocommerce

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

ARPrice

Plugin:

ARPrice

Plugin Slug:
arprice

Vulnerability:
SQL Injection

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

ARPrice

Plugin:

ARPrice

Plugin Slug:
arprice

Vulnerability:
SQL Injection

Patched in Version:
No Fix

Severity Score:
Critical


The vulnerability has not been patched. You should deactivate the plugin.

ARPrice

Plugin:

ARPrice

Plugin Slug:
arprice

Vulnerability:
PHP Object Injection

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

ARPrice

Plugin:

ARPrice

Plugin Slug:
arprice

Vulnerability:
PHP Object Injection

Patched in Version:
No Fix

Severity Score:
Critical


The vulnerability has not been patched. You should deactivate the plugin.

Autocompleter

Plugin:

Autocompleter

Plugin Slug:
autocompleter

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Bizapp for WooCommerce

Plugin:

Bizapp for WooCommerce

Plugin Slug:
bizapp-for-woocommerce

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.
Plugin:

BVD Easy Gallery Manager

Plugin Slug:
bvd-easy-gallery-manager

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Candifly

Plugin:

Candifly

Plugin Slug:
candifly

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Chatroll Live Chat

Plugin:

Chatroll Live Chat

Plugin Slug:
chatroll-live-chat

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

ClickDesigns

Plugin:

ClickDesigns

Plugin Slug:
clickdesigns

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Common Ninja

Plugin:

Common Ninja

Plugin Slug:
common-ninja

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Duplicate Post, Page and Any Custom Post

Plugin:

Duplicate Post, Page and Any Custom Post

Plugin Slug:
duplicate-pp

Vulnerability:
Sensitive Data Exposure

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Elevio

Plugin:

Elevio

Plugin Slug:
elevio

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

EMC2 Alert Boxes

Plugin:

EMC2 Alert Boxes

Plugin Slug:
emc2-alert-boxes

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Enable Accessibility

Plugin:

Enable Accessibility

Plugin Slug:
enable-accessibility

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Fancy Product Designer

Plugin:

Fancy Product Designer

Plugin Slug:
fancy-product-designer

Vulnerability:
SQL Injection

Patched in Version:
No Fix

Severity Score:
Critical


The vulnerability has not been patched. You should deactivate the plugin.

Fancy Product Designer

Plugin:

Fancy Product Designer

Plugin Slug:
fancy-product-designer

Vulnerability:
Arbitrary File Upload

Patched in Version:
No Fix

Severity Score:
Critical


The vulnerability has not been patched. You should deactivate the plugin.

Formaloo Form Maker

Plugin:

Formaloo Form Maker

Plugin Slug:
formaloo-form-builder

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

GDY Modular Content

Plugin:

GDY Modular Content

Plugin Slug:
gdy-modular-content

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Geo Content

Plugin:

Geo Content

Plugin Slug:
geo-targetly-geo-content

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Hero Mega Menu – Responsive WordPress Menu Plugin

Plugin:

Hero Mega Menu – Responsive WordPress Menu Plugin

Plugin Slug:
hmenu

Vulnerability:
SQL Injection

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Hero Mega Menu – Responsive WordPress Menu Plugin

Plugin:

Hero Mega Menu – Responsive WordPress Menu Plugin

Plugin Slug:
hmenu

Vulnerability:
SQL Injection

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Host PHP Info

Plugin:

Host PHP Info

Plugin Slug:
host-php-info

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Ultimate Learning Pro

Plugin:

Ultimate Learning Pro

Plugin Slug:
indeed-learning-pro

Vulnerability:
SQL Injection

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

LazyLoad Background Images

Plugin:

LazyLoad Background Images

Plugin Slug:
lazyload-background-images

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Marketplace Items

Plugin:

Marketplace Items

Plugin Slug:
marketplace-items

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Meteor Slides

Plugin:

Meteor Slides

Plugin Slug:
meteor-slides

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

MG Parallax Slider

Plugin:

MG Parallax Slider

Plugin Slug:
mg-parallax-slider

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Opencart Product in WP

Plugin:

Opencart Product in WP

Plugin Slug:
opencart-product-in-wp

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

OZ Canonical

Plugin:

OZ Canonical

Plugin Slug:
oz-canonical

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

PayGreen Payment Gateway

Plugin:

PayGreen Payment Gateway

Plugin Slug:
paygreen-payment-gateway

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

RightMessage WP

Plugin:

RightMessage WP

Plugin Slug:
rightmessage

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Kikx Simple Post Author Filter

Plugin:

Kikx Simple Post Author Filter

Plugin Slug:
sa-post-author-filter

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

School Management System � SakolaWP

Plugin:

School Management System � SakolaWP

Plugin Slug:
sakolawp-lite

Vulnerability:
Privilege Escalation

Patched in Version:
No Fix

Severity Score:
Critical


The vulnerability has not been patched. You should deactivate the plugin.

Sell Media

Plugin:

Sell Media

Plugin Slug:
sell-media

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Sellsy

Plugin:

Sellsy

Plugin Slug:
sellsy

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

SEO LAT Auto Post

Plugin:

SEO LAT Auto Post

Plugin Slug:
seo-beginner-auto-post

Vulnerability:
Remote Code Execution (RCE)

Patched in Version:
No Fix

Severity Score:
Critical


The vulnerability has not been patched. You should deactivate the plugin.

Simple Add Pages or Posts

Plugin:

Simple Add Pages or Posts

Plugin Slug:
simple-add-pages-or-posts

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Slider Pro Lite

Plugin:

Slider Pro Lite

Plugin Slug:
slider-pro-lite

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Social Rocket

Plugin:

Social Rocket

Plugin Slug:
social-rocket

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Social Rocket

Plugin:

Social Rocket

Plugin Slug:
social-rocket

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Spacer

Plugin:

Spacer

Plugin Slug:
spacer

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
Low


The vulnerability has not been patched. You should deactivate the plugin.

SweepWidget Contests, Giveaways, Photo Contests, Competitions

Plugin:

SweepWidget Contests, Giveaways, Photo Contests, Competitions

Plugin Slug:
sweepwidget

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

SyncFields

Plugin:

SyncFields

Plugin Slug:
syncfields

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

WP-tagMaker

Plugin:

WP-tagMaker

Plugin Slug:
tagmaker

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Target Notifications

Plugin:

Target Notifications

Plugin Slug:
target-notifications

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Themes Coder

Plugin:

Themes Coder

Plugin Slug:
tc-ecommerce

Vulnerability:
Insecure Direct Object References (IDOR)

Patched in Version:
No Fix

Severity Score:
Critical


The vulnerability has not been patched. You should deactivate the plugin.

Timeline Designer

Plugin:

Timeline Designer

Plugin Slug:
timeline-designer

Vulnerability:
SQL Injection

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Transporters.io

Plugin:

Transporters.io

Plugin Slug:
transportersio

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Private Messages for UserPro

Plugin:

Private Messages for UserPro

Plugin Slug:
userpro-messaging

Vulnerability:
Local File Inclusion

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

ViewMedica 9

Plugin:

ViewMedica 9

Plugin Slug:
viewmedica

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

ViewMedica 9

Plugin:

ViewMedica 9

Plugin Slug:
viewmedica

Vulnerability:
SQL Injection

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

WC1C

Plugin:

WC1C

Plugin Slug:
wc1c-main

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Wizhi Multi Filters by Wenprise

Plugin:

Wizhi Multi Filters by Wenprise

Plugin Slug:
wizhi-multi-filters

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Binary MLM Woocommerce

Plugin:

Binary MLM Woocommerce

Plugin Slug:
woo-binary-mlm

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Woo Ukrposhta

Plugin:

Woo Ukrposhta

Plugin Slug:
woo-ukrposhta

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

WooCommerce Digital Content Delivery (incl. DRM) � FlickRocket

Plugin:

WooCommerce Digital Content Delivery (incl. DRM) � FlickRocket

Plugin Slug:
woocommerce-digital-content-delivery-with-drm-flickrocket

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Live Sales Notification for Woocommerce – Woomotiv

Plugin:

Live Sales Notification for Woocommerce – Woomotiv

Plugin Slug:
woomotiv

Vulnerability:
SQL Injection

Patched in Version:
No Fix

Severity Score:
Critical


The vulnerability has not been patched. You should deactivate the plugin.

WordPress Auction Plugin

Plugin:

WordPress Auction Plugin

Plugin Slug:
wp-auctions

Vulnerability:
SQL Injection

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

WP Simple Sitemap

Plugin:

WP Simple Sitemap

Plugin Slug:
wp-simple-sitemap

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

WPAchievements Free

Plugin:

WPAchievements Free

Plugin Slug:
wpachievements-free

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

wpSOL

Plugin:

wpSOL

Plugin Slug:
wpsol

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Custom Product Tabs for WooCommerce

Plugin:

Custom Product Tabs for WooCommerce

Plugin Slug:
yikes-inc-easy-custom-woocommerce-product-tabs

Vulnerability:
PHP Object Injection

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

UpdraftPlus: WP Backup & Migration Plugin

Plugin Slug:
updraftplus

Installations
3,000,000+

Vulnerability:
PHP Object Injection

Patched in Version:
1.24.12

Severity Score:
High


The vulnerability has been patched, so you should update to version 1.24.12.

Envato Elements � Photos & Elementor Templates

Plugin Slug:
envato-elements

Installations
1,000,000+

Vulnerability:
Server Side Request Forgery (SSRF)

Patched in Version:
2.0.15

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.0.15.

PixelYourSite � Your smart PIXEL (TAG) & API Manager

Plugin Slug:
pixelyoursite

Installations
500,000+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
10.0.2

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 10.0.2.

Astra Widgets

Plugin Slug:
astra-widgets

Installations
200,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.2.16

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.2.16.

Pods � Custom Content Types and Fields

Plugin Slug:
pods

Installations
100,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
3.2.8.1

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 3.2.8.1.
Plugin Slug:
wordpress-popular-posts

Installations
100,000+

Vulnerability:
Arbitrary Code Execution

Patched in Version:
7.2.0

Severity Score:
High


The vulnerability has been patched, so you should update to version 7.2.0.

Backup Migration

Plugin Slug:
backup-backup

Installations
80,000+

Vulnerability:
PHP Object Injection

Patched in Version:
1.4.6.1

Severity Score:
Critical


The vulnerability has been patched, so you should update to version 1.4.6.1.

Media Library Assistant

Plugin Slug:
media-library-assistant

Installations
70,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
3.24

Severity Score:
High


The vulnerability has been patched, so you should update to version 3.24.

Piotnet Addons For Elementor

Plugin Slug:
piotnet-addons-for-elementor

Installations
40,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.4.32

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.4.32.

Compact WP Audio Player

Plugin Slug:
compact-wp-audio-player

Installations
30,000+

Vulnerability:
Server Side Request Forgery (SSRF)

Patched in Version:
1.9.15

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.9.15.

Data Tables Generator by Supsystic

Plugin Slug:
data-tables-generator-by-supsystic

Installations
20,000+

Vulnerability:
Broken Access Control

Patched in Version:
1.10.37

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.10.37.

Post Grid Elementor Addon

Plugin Slug:
post-grid-elementor-addon

Installations
20,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.0.19

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.0.19.

AFI � The Easiest Integration Plugin

Plugin Slug:
advanced-form-integration

Installations
10,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.97.0

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.97.0.

AyeCode Connect

Plugin Slug:
ayecode-connect

Installations
10,000+

Vulnerability:
Broken Access Control

Patched in Version:
1.3.9

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.3.9.

Export Import Menus

Plugin Slug:
export-import-menus

Installations
10,000+

Vulnerability:
Broken Access Control

Patched in Version:
1.9.2

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.9.2.

Mang Board WP

Plugin Slug:
mangboard

Installations
10,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.8.5

Severity Score:
High


The vulnerability has been patched, so you should update to version 1.8.5.

WP Post Author � Boost Your Blog’s Engagement with Author Box, Social Links, Co-Authors, Guest Authors, Post Rating System, and Custom User Registration Form Builder

Plugin Slug:
wp-post-author

Installations
10,000+

Vulnerability:
SQL Injection

Patched in Version:
3.8.3

Severity Score:
High


The vulnerability has been patched, so you should update to version 3.8.3.

Export All Posts, Products, Orders, Refunds & Users

Plugin Slug:
wp-ultimate-exporter

Installations
10,000+

Vulnerability:
Remote Code Execution (RCE)

Patched in Version:
2.9.2

Severity Score:
Critical


The vulnerability has been patched, so you should update to version 2.9.2.

WP Compress � Instant Performance & Speed Optimization

Plugin Slug:
wp-compress-image-optimizer

Installations
7,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
6.30.04

Severity Score:
High


The vulnerability has been patched, so you should update to version 6.30.04.

Arconix Shortcodes

Plugin Slug:
arconix-shortcodes

Installations
5,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.1.15

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.1.15.

WPKoi Templates for Elementor

Plugin Slug:
wpkoi-templates-for-elementor

Installations
5,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
3.1.4

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 3.1.4.

Ashe Extra

Plugin Slug:
ashe-extra

Installations
3,000+

Vulnerability:
Broken Access Control

Patched in Version:
1.3

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.3.

Move Addons for Elementor

Plugin Slug:
move-addons

Installations
3,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.3.7

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.3.7.

Classic Addons � WPBakery Page Builder

Plugin Slug:
classic-addons-wpbakery-page-builder-addons

Installations
2,000+

Vulnerability:
Local File Inclusion

Patched in Version:
3.1

Severity Score:
High


The vulnerability has been patched, so you should update to version 3.1.

MyBookTable Bookstore by Stormhill Media

Plugin Slug:
mybooktable

Installations
2,000+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
3.5.4

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 3.5.4.

Premium Blocks � Gutenberg Blocks for WordPress

Plugin Slug:
premium-blocks-for-gutenberg

Installations
2,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.1.43

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.1.43.

Pronamic Google Maps

Plugin Slug:
pronamic-google-maps

Installations
2,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.3.3

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.3.3.

WPBITS Addons For Elementor Page Builder

Plugin Slug:
wpbits-addons-for-elementor

Installations
2,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.6

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.6.

WPBITS Addons For Elementor Page Builder

Plugin Slug:
wpbits-addons-for-elementor

Installations
2,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.6

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.6.

WP Wand � AI Writer, AI Content Generator & AI Assistant by ChatGPT, OpenAI | Generate SEO Friendly AI Blog Post & Article with 20X Speed

Plugin Slug:
ai-content-generation

Installations
1,000+

Vulnerability:
Broken Access Control

Patched in Version:
1.2.6

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.2.6.

Accessibility by AllAccessible

Plugin Slug:
allaccessible

Installations
1,000+

Vulnerability:
Privilege Escalation

Patched in Version:
1.3.5

Severity Score:
High


The vulnerability has been patched, so you should update to version 1.3.5.

Locatoraid Store Locator

Plugin Slug:
locatoraid

Installations
1,000+

Vulnerability:
PHP Object Injection

Patched in Version:
3.9.51

Severity Score:
High


The vulnerability has been patched, so you should update to version 3.9.51.

????? ?? ???? � ???? ?? ????

Plugin Slug:
pgall-for-woocommerce

Installations
1,000+

Vulnerability:
Local File Inclusion

Patched in Version:
5.2.2

Severity Score:
High


The vulnerability has been patched, so you should update to version 5.2.2.

Themify Audio Dock

Plugin Slug:
themify-audio-dock

Installations
1,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.0.5

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.0.5.

WP Docs

Plugin:

WP Docs

Plugin Slug:
wp-docs

Installations
1,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.2.2

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.2.2.
Plugin Slug:
wp-responsive-photo-gallery

Installations
1,000+

Vulnerability:
Server Side Request Forgery (SSRF)

Patched in Version:
1.0.16

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.0.16.

WP Smart Import : Import any XML File to WordPress

Plugin Slug:
wp-smart-import

Installations
1,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.1.3

Severity Score:
High


The vulnerability has been patched, so you should update to version 1.1.3.

ConvertCalculator for WordPress

Plugin Slug:
convertcalculator

Installations
900+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.1.2

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.1.2.

Event Espresso � Event Registration & Ticketing Sales

Plugin Slug:
event-espresso-decaf

Installations
900+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
5.0.31.decaf

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 5.0.31.decaf.

WP Social AutoConnect

Plugin Slug:
wp-fb-autoconnect

Installations
900+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
4.6.3

Severity Score:
High


The vulnerability has been patched, so you should update to version 4.6.3.

Hestia Nginx Cache

Plugin Slug:
hestia-nginx-cache

Installations
800+

Vulnerability:
Broken Access Control

Patched in Version:
2.4.1

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.4.1.

Dynamics 365 Integration

Plugin Slug:
integration-dynamics

Installations
800+

Vulnerability:
Remote Code Execution (RCE)

Patched in Version:
1.3.24

Severity Score:
Critical


The vulnerability has been patched, so you should update to version 1.3.24.

Just Writing Statistics

Plugin Slug:
just-writing-statistics

Installations
800+

Vulnerability:
SQL Injection

Patched in Version:
4.8

Severity Score:
High


The vulnerability has been patched, so you should update to version 4.8.

WP jQuery DataTable

Plugin Slug:
wp-jquery-datatable

Installations
800+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
4.1.0

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 4.1.0.

One to one user Chat by WPGuppy

Plugin Slug:
wpguppy-lite

Installations
800+

Vulnerability:
Privilege Escalation

Patched in Version:
1.1.1

Severity Score:
High


The vulnerability has been patched, so you should update to version 1.1.1.

One to one user Chat by WPGuppy

Plugin Slug:
wpguppy-lite

Installations
800+

Vulnerability:
PHP Object Injection

Patched in Version:
1.1.1

Severity Score:
Critical


The vulnerability has been patched, so you should update to version 1.1.1.

WPMasterToolKit (WPMTK) � All in one plugin

Plugin Slug:
wpmastertoolkit

Installations
800+

Vulnerability:
Arbitrary File Upload

Patched in Version:
1.14.0

Severity Score:
Critical


The vulnerability has been patched, so you should update to version 1.14.0.

WPMasterToolKit (WPMTK) � All in one plugin

Plugin Slug:
wpmastertoolkit

Installations
800+

Vulnerability:
Arbitrary File Download

Patched in Version:
1.14.0

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.14.0.

Service Box

Plugin Slug:
service-boxs

Installations
400+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.0

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.0.

WP Multi Store Locator

Plugin Slug:
wp-multi-store-locator

Installations
400+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.4.6

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.4.6.

WP Mailster

Plugin Slug:
wp-mailster

Installations
300+

Vulnerability:
Sensitive Data Exposure

Patched in Version:
1.8.18.0

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.8.18.0.

ACF City Selector

Plugin Slug:
acf-city-selector

Installations
200+

Vulnerability:
Arbitrary File Upload

Patched in Version:
1.15.0

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.15.0.

CC Canadian Mortgage Calculator

Plugin Slug:
cc-canadian-mortgage-calculator

Installations
200+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.1.1

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.1.1.

Multiple Shipping And Billing Address For Woocommerce

Plugin Slug:
different-shipping-and-billing-address-for-woocommerce

Installations
200+

Vulnerability:
SQL Injection

Patched in Version:
1.3

Severity Score:
Critical


The vulnerability has been patched, so you should update to version 1.3.

Email Reminders

Plugin Slug:
email-reminders

Installations
200+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.0.6

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.0.6.

Turnkey bbPress by WeaverTheme

Plugin Slug:
weaver-for-bbpress

Installations
200+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.7.1

Severity Score:
High


The vulnerability has been patched, so you should update to version 1.7.1.

Interactive UK Map

Plugin Slug:
interactive-uk-map

Installations
100+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
3.4.9

Severity Score:
High


The vulnerability has been patched, so you should update to version 3.4.9.

JobBoard Job listing plugin

Plugin Slug:
job-board-light

Installations
100+

Vulnerability:
Arbitrary File Upload

Patched in Version:
1.2.7

Severity Score:
Critical


The vulnerability has been patched, so you should update to version 1.2.7.

Pretty Simple Popup Builder

Plugin Slug:
pretty-simple-popup-builder

Installations
100+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.0.10

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.0.10.

PlainInventory � Inventory Management Plugin

Plugin Slug:
z-inventory-manager

Installations
100+

Vulnerability:
PHP Object Injection

Patched in Version:
3.1.7

Severity Score:
High


The vulnerability has been patched, so you should update to version 3.1.7.

Notify Odoo

Plugin Slug:
notify-odoo

Installations
90+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
1.0.1

Severity Score:
High


The vulnerability has been patched, so you should update to version 1.0.1.

Error Log Viewer By WP Guru

Plugin Slug:
error-log-viewer-wp

Installations
80+

Vulnerability:
Arbitrary File Download

Patched in Version:
1.0.4

Severity Score:
High


The vulnerability has been patched, so you should update to version 1.0.4.

GS Shots for Dribbble

Plugin Slug:
gs-dribbble-portfolio

Installations
30+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.2.1

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.2.1.

Highlight Sitewide Notice, Text, Button Menu

Plugin Slug:
highlight

Installations
20+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.0.6

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.0.6.

GS Coaches

Plugin Slug:
gs-coach

Installations
10+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.1.1

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.1.1.

WPMozo Addons Lite for Elementor

Plugin Slug:
wpmozo-addons-lite-for-elementor

Installations
10+

Vulnerability:
Local File Inclusion

Patched in Version:
1.1.1

Severity Score:
High


The vulnerability has been patched, so you should update to version 1.1.1.

Coins MarketCap

Plugin:

Coins MarketCap

Plugin Slug:
coins-marketcap

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
5.5.9

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 5.5.9.

Floating Action Buttons

Plugin Slug:
floating-action-buttons

Vulnerability:
Broken Access Control

Patched in Version:
1.0.1

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.0.1.

Goodlayers Core

Plugin:

Goodlayers Core

Plugin Slug:
goodlayers-core

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.0.10

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.0.10.

ShopElement

Plugin Slug:
shopelement

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.1.0

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.1.0.

Tourmaster

Plugin:

Tourmaster

Plugin Slug:
tourmaster

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
5.3.4

Severity Score:
High


The vulnerability has been patched, so you should update to version 5.3.4.

WordPress Themes � 2 Patched / 21 Unpatched

Store Commerce

Theme Slug:
store-commerce

Downloads
50,956

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should switch themes.

Aports – Single Property WordPress Theme

Theme:

Aports – Single Property WordPress Theme

Theme Slug:
aports

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should switch themes.

Boliin – Resort & Hotel Booking WordPress Theme

Theme:

Boliin – Resort & Hotel Booking WordPress Theme

Theme Slug:
boliin

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should switch themes.

Constix – Construction Factory & Industrial WordPress Theme

Theme:

Constix – Construction Factory & Industrial WordPress Theme

Theme Slug:
constix

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should switch themes.

Conult – Consulting Business WordPress Themes

Theme:

Conult – Consulting Business WordPress Themes

Theme Slug:
conult

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should switch themes.

Digi Store

Theme:

Digi Store

Theme Slug:
digi-store

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should switch themes.

Education LMS

Theme:

Education LMS

Theme Slug:
education-lms

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should switch themes.

Fioxen

Theme:

Fioxen

Theme Slug:
fioxen

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should switch themes.

TheFude – Crowdfunding & Charity WordPress Theme

Theme:

TheFude – Crowdfunding & Charity WordPress Theme

Theme Slug:
fude

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should switch themes.

Gowilds – Travel & Tour Booking WordPress Theme

Theme:

Gowilds – Travel & Tour Booking WordPress Theme

Theme Slug:
gowilds

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should switch themes.

Halpes

Theme:

Halpes

Theme Slug:
halpes

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should switch themes.

Lestin – Directory Listing WordPress Theme

Theme:

Lestin – Directory Listing WordPress Theme

Theme Slug:
lestin

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should switch themes.

Modins – Insurance & Finance WordPress Theme

Theme:

Modins – Insurance & Finance WordPress Theme

Theme Slug:
modins

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should switch themes.

Orgarium – Agriculture & Organic Farm WordPress Theme

Theme:

Orgarium – Agriculture & Organic Farm WordPress Theme

Theme Slug:
orgarium

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should switch themes.

Paroti

Theme:

Paroti

Theme Slug:
paroti

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should switch themes.

Pisole – Digital Creative Agency WordPress Theme

Theme:

Pisole – Digital Creative Agency WordPress Theme

Theme Slug:
pisole

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should switch themes.

Qempo

Theme:

Qempo

Theme Slug:
qempo

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should switch themes.

Qizon – Crowdfunding & Charity WordPress Theme

Theme:

Qizon – Crowdfunding & Charity WordPress Theme

Theme Slug:
qizon

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should switch themes.

Sominx – Creative Business Agency WordPress Theme

Theme:

Sominx – Creative Business Agency WordPress Theme

Theme Slug:
sominx

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should switch themes.

Tevily – Travel & Tour Booking WordPress Theme

Theme:

Tevily – Travel & Tour Booking WordPress Theme

Theme Slug:
tevily

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should switch themes.

welowe

Theme:

welowe

Theme Slug:
welowe

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should switch themes.

SimpleCharm

Theme Slug:
simplecharm

Downloads
1,014

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.4.4

Severity Score:
High


The vulnerability has been patched, so you should update to version 1.4.4.

Aurum

Theme:

Aurum

Theme Slug:
aurum-minimalist-shopping-theme

Vulnerability:
Broken Access Control

Patched in Version:
4.0.3

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 4.0.3.

Related articles

Wait! Get exclusive hosting insights

Subscribe to our newsletter and stay ahead of the competition with expert advice from our hosting pros.

Loading form…