Line illustration showing a black application window on a blue gradient background overlaid with a large exclamation point alert icon and three bugs.

WordPress Vulnerability Report � February 19, 2025

In this report, 230 vulnerabilities have been publicly disclosed. Security patches for 135 of these plugins and themes are available now, so run those updates as soon as possible. If you’re a Solid Security Pro user, the version management tool may have already warned you and updated these plugins, depending on your settings.

Additionally, there are 95 plugin and theme vulnerabilities with no patch available yet. If you’re a Solid Security Pro user, those vulnerabilities are already protected by the Solid Security firewall. Virtual patches from Patchstack will be applied when a vulnerability is considered high or medium risk. If no patch is forthcoming from the vendor or the vulnerable software has been marked “closed” and dropped from the official WordPress repositories, you should deactivate it soon and look for alternative solutions.

WordPress Core

WordPress 6.7.2 is now available! This minor release includes 35 bug fixes, addressing issues affecting multiple components including the block editor, HTML API, and Customize.

WordPress Plugins � 123 Patched / 91 Unpatched

Easy MLS Listings Import

Plugin Slug:
easy-mls-listings-import

Installations
100+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Gumlet Video

Plugin Slug:
gumlet-video

Installations
90+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Actionwear products sync

Plugin Slug:
actionwear-products-sync

Installations
50+

Vulnerability:
Sensitive Data Exposure

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Filled In

Plugin Slug:
filled-in

Installations
50+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

1 Click WordPress Migration

Plugin:

1 Click WordPress Migration

Plugin Slug:
1-click-migration

Vulnerability:
Sensitive Data Exposure

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

1 Click WordPress Migration

Plugin:

1 Click WordPress Migration

Plugin Slug:
1-click-migration

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Aparat Responsive

Plugin:

Aparat Responsive

Plugin Slug:
aparat-responsive

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Apus Framework

Plugin:

Apus Framework

Plugin Slug:
apus-framework

Vulnerability:
Settings Change

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Naver Syndication V2

Plugin:

Naver Syndication V2

Plugin Slug:
badr-naver-syndication

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

BigBuy Dropshipping Connector for WooCommerce

Plugin:

BigBuy Dropshipping Connector for WooCommerce

Plugin Slug:
bigbuy-wc-dropshipping-connector

Vulnerability:
Sensitive Data Exposure

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Book a Room

Plugin:

Book a Room

Plugin Slug:
book-a-room

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Bootstrap collapse

Plugin:

Bootstrap collapse

Plugin Slug:
bootstrap-collapse

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

WooODT Lite

Plugin:

WooODT Lite

Plugin Slug:
byconsole-woo-order-delivery-time

Vulnerability:
Sensitive Data Exposure

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

CalendApp

Plugin:

CalendApp

Plugin Slug:
calendapp

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

CATS Job Listings

Plugin:

CATS Job Listings

Plugin Slug:
cats-job-listings

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Chalet-Montagne.com Tools

Plugin:

Chalet-Montagne.com Tools

Plugin Slug:
chalet-montagne-com-tools

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Simple Documentation

Plugin:

Simple Documentation

Plugin Slug:
client-documentation

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

DL Leadback

Plugin:

DL Leadback

Plugin Slug:
dl-leadback

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

DX-auto-publish

Plugin:

DX-auto-publish

Plugin Slug:
dx-auto-publish

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Easy Amazon Product Information

Plugin:

Easy Amazon Product Information

Plugin Slug:
easy-amazon-product-information

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Ebook Downloader

Plugin:

Ebook Downloader

Plugin Slug:
ebook-downloader

Vulnerability:
SQL Injection

Patched in Version:
No Fix

Severity Score:
Critical


The vulnerability has not been patched. You should deactivate the plugin.

Embed Google Map

Plugin:

Embed Google Map

Plugin Slug:
embed-google-map

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Events Planner

Plugin:

Events Planner

Plugin Slug:
events-planner

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Font Awesome WP

Plugin:

Font Awesome WP

Plugin Slug:
font-awesome-wp

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

WP-FormAssembly

Plugin:

WP-FormAssembly

Plugin Slug:
formassembly-web-forms

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

GetBookingsWP

Plugin:

GetBookingsWP

Plugin Slug:
get-bookings-wp

Vulnerability:
Privilege Escalation

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Glance That

Plugin:

Glance That

Plugin Slug:
glance-that

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Global Meta Keyword & Description

Plugin:

Global Meta Keyword & Description

Plugin Slug:
global-meta-keyword-and-description

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Google Drive WP Media

Plugin:

Google Drive WP Media

Plugin Slug:
google-drive-wp-media

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

IE CSS3 Support

Plugin:

IE CSS3 Support

Plugin Slug:
ie-css3-support

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Keap Official Opt-in Forms

Plugin:

Keap Official Opt-in Forms

Plugin Slug:
infusionsoft-official-opt-in-forms

Vulnerability:
Local File Inclusion

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Library Bookshelves

Plugin:

Library Bookshelves

Plugin Slug:
library-bookshelves

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

magayo Lottery Results

Plugin:

magayo Lottery Results

Plugin Slug:
magayo-lottery-results

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Mortgage Calculator / Loan Calculator

Plugin:

Mortgage Calculator / Loan Calculator

Plugin Slug:
mortgage-loan-calculator

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

My Login Logout Plugin

Plugin:

My Login Logout Plugin

Plugin Slug:
my-loginlogout

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Easy Quiz Maker

Plugin:

Easy Quiz Maker

Plugin Slug:
n-media-wp-simple-quiz

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Open Hours

Plugin:

Open Hours

Plugin Slug:
open-hours

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Option Editor

Plugin:

Option Editor

Plugin Slug:
option-editor

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Page/Post Specific Social Share Buttons

Plugin:

Page/Post Specific Social Share Buttons

Plugin Slug:
pagepost-specific-social-share-buttons

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Pallet Packaging for WooCommerce

Plugin:

Pallet Packaging for WooCommerce

Plugin Slug:
pallet-packaging-for-woocommerce

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

WP PHPList

Plugin:

WP PHPList

Plugin Slug:
phplist-form-integration

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Post Sync

Plugin:

Post Sync

Plugin Slug:
post-sync

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Post Thumbs

Plugin:

Post Thumbs

Plugin Slug:
post-thumbs

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Prezi Embedder

Plugin:

Prezi Embedder

Plugin Slug:
prezi-embedder

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

pushBIZ

Plugin:

pushBIZ

Plugin Slug:
pushbiz

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

R3W InstaFeed

Plugin:

R3W InstaFeed

Plugin Slug:
r3w-instafeed

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Rapid Cache

Plugin:

Rapid Cache

Plugin Slug:
rapid-cache

Vulnerability:
Content Spoofing

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Reaction Buttons

Plugin:

Reaction Buttons

Plugin Slug:
reaction-buttons

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.
Plugin:

Related Posts Line-up-Exactly by Milliard

Plugin Slug:
related-posts-line-up-exactry-by-milliard

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Reset

Plugin:

Reset

Plugin Slug:
reset

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Rise Blocks

Plugin:

Rise Blocks

Plugin Slug:
rise-blocks

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Mobile

Plugin:

Mobile

Plugin Slug:
rocket-wp-mobile

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

RSS Filter

Plugin:

RSS Filter

Plugin Slug:
rss-filter

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Sensly Online Presence

Plugin:

Sensly Online Presence

Plugin Slug:
sensly-online-presence

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

ShipEngine Shipping Quotes

Plugin:

ShipEngine Shipping Quotes

Plugin Slug:
shipengine-shipping-quotes

Vulnerability:
SQL Injection

Patched in Version:
No Fix

Severity Score:
Critical


The vulnerability has not been patched. You should deactivate the plugin.

sidebarTabs

Plugin:

sidebarTabs

Plugin Slug:
sidebartabs

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Simple catalogue

Plugin:

Simple catalogue

Plugin Slug:
simple-catalogue

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Simple Charts

Plugin:

Simple Charts

Plugin Slug:
simple-charts

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Simple Pricing Tables For WPBakery Page Builder

Plugin:

Simple Pricing Tables For WPBakery Page Builder

Plugin Slug:
simple-pricing-tables-vc-extension

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Simple Responsive Menu

Plugin:

Simple Responsive Menu

Plugin Slug:
simple-responsive-menu

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Simple Signup Form

Plugin:

Simple Signup Form

Plugin Slug:
simple-signup-form

Vulnerability:
SQL Injection

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Simple Video Management System

Plugin:

Simple Video Management System

Plugin Slug:
simple-video-management-system

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Small Package Quotes � Purolator Edition

Plugin:

Small Package Quotes � Purolator Edition

Plugin Slug:
small-package-quotes-purolator-edition

Vulnerability:
SQL Injection

Patched in Version:
No Fix

Severity Score:
Critical


The vulnerability has not been patched. You should deactivate the plugin.

Spiritual Gifts Survey

Plugin:

Spiritual Gifts Survey

Plugin Slug:
spiritual-gifts-survey

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Stray Random Quotes

Plugin:

Stray Random Quotes

Plugin Slug:
stray-quotes

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Themes Coder

Plugin:

Themes Coder

Plugin Slug:
tc-ecommerce

Vulnerability:
SQL Injection

Patched in Version:
No Fix

Severity Score:
Critical


The vulnerability has not been patched. You should deactivate the plugin.

Team Builder

Plugin:

Team Builder

Plugin Slug:
team-display

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

TinyMCE Advanced qTranslate fix editor problems

Plugin:

TinyMCE Advanced qTranslate fix editor problems

Plugin Slug:
tinymce-advanced-qtranslate-fix-editor-problems

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Track Logins

Plugin:

Track Logins

Plugin Slug:
track-logins

Vulnerability:
SQL Injection

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

TTT Crop

Plugin:

TTT Crop

Plugin Slug:
ttt-crop

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Tube Video Ads Lite

Plugin:

Tube Video Ads Lite

Plugin Slug:
tube-video-ads-lite

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

VR-Frases

Plugin:

VR-Frases

Plugin Slug:
vr-frases

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Wibiya Toolbar

Plugin:

Wibiya Toolbar

Plugin Slug:
wibiya

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Wise Forms

Plugin:

Wise Forms

Plugin Slug:
wise-forms

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

File Uploads Addon for WooCommerce

Plugin:

File Uploads Addon for WooCommerce

Plugin Slug:
woo-addon-uploads

Vulnerability:
Sensitive Data Exposure

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

WordPress Activity-o-meter

Plugin:

WordPress Activity-o-meter

Plugin Slug:
wordpress-activity-o-meter

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

WP-Asambleas

Plugin:

WP-Asambleas

Plugin Slug:
wp-asambleas

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

WP-BibTeX

Plugin:

WP-BibTeX

Plugin Slug:
wp-bibtex

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

WP Extra Fields

Plugin:

WP Extra Fields

Plugin Slug:
wp-extra-fields

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

FoodBakery

Plugin:

FoodBakery

Plugin Slug:
wp-foodbakery

Vulnerability:
Privilege Escalation

Patched in Version:
No Fix

Severity Score:
Critical


The vulnerability has not been patched. You should deactivate the plugin.

FoodBakery

Plugin:

FoodBakery

Plugin Slug:
wp-foodbakery

Vulnerability:
Privilege Escalation

Patched in Version:
No Fix

Severity Score:
Critical


The vulnerability has not been patched. You should deactivate the plugin.

FoodBakery

Plugin:

FoodBakery

Plugin Slug:
wp-foodbakery

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

FoodBakery

Plugin:

FoodBakery

Plugin Slug:
wp-foodbakery

Vulnerability:
Arbitrary File Upload

Patched in Version:
No Fix

Severity Score:
Critical


The vulnerability has not been patched. You should deactivate the plugin.

WP Html Page Sitemap

Plugin:

WP Html Page Sitemap

Plugin Slug:
wp-html-page-sitemap

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

WP Job Board Pro

Plugin:

WP Job Board Pro

Plugin Slug:
wp-job-board-pro

Vulnerability:
Privilege Escalation

Patched in Version:
No Fix

Severity Score:
Critical


The vulnerability has not been patched. You should deactivate the plugin.

WP Pricing Table

Plugin:

WP Pricing Table

Plugin Slug:
wp-pricing-table

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.
Plugin:

OWL Carousel Slider

Plugin Slug:
wp-touch-slider

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

WPMovieLibrary

Plugin:

WPMovieLibrary

Plugin Slug:
wpmovielibrary

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Mortgage Lead Capture System

Plugin:

Mortgage Lead Capture System

Plugin Slug:
wprequal

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Elfsight Yottie Lite

Plugin:

Elfsight Yottie Lite

Plugin Slug:
yottie-lite

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Zarinpal Paid Download

Plugin:

Zarinpal Paid Download

Plugin Slug:
zarinpal-paid-downloads

Vulnerability:
Arbitrary File Upload

Patched in Version:
No Fix

Severity Score:
Critical


The vulnerability has not been patched. You should deactivate the plugin.

Rank Math SEO � AI SEO Tools to Dominate SEO Rankings

Plugin Slug:
seo-by-rank-math

Installations
3,000,000+

Vulnerability:
Broken Access Control

Patched in Version:
1.0.236

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.0.236.

Rank Math SEO � AI SEO Tools to Dominate SEO Rankings

Plugin Slug:
seo-by-rank-math

Installations
3,000,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.0.236

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.0.236.

ElementsKit Elementor addons

Plugin Slug:
elementskit-lite

Installations
1,000,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
3.4.1

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 3.4.1.

Post SMTP � WordPress SMTP Plugin with Email Logs and Mobile App for Failure Notifications � Gmail SMTP, Office 365, Brevo, Mailgun, Amazon SES and more

Plugin Slug:
post-smtp

Installations
400,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
3.1.0

Severity Score:
High


The vulnerability has been patched, so you should update to version 3.1.0.

WP Ghost (Hide My WP Ghost) � Security & Firewall

Plugin Slug:
hide-my-wp

Installations
200,000+

Vulnerability:
Bypass Vulnerability

Patched in Version:
5.4.01

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 5.4.01.

WP Activity Log

Plugin Slug:
wp-security-audit-log

Installations
200,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
5.3.0

Severity Score:
High


The vulnerability has been patched, so you should update to version 5.3.0.

HT Mega � Absolute Addons For Elementor

Plugin Slug:
ht-mega-for-elementor

Installations
90,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.8.2

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.8.2.

Brizy � Page Builder

Plugin Slug:
brizy

Installations
80,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.6.9

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.6.9.

Brizy � Page Builder

Plugin Slug:
brizy

Installations
80,000+

Vulnerability:
Arbitrary File Upload

Patched in Version:
2.6.5

Severity Score:
Critical


The vulnerability has been patched, so you should update to version 2.6.5.

Stream

Plugin:

Stream

Plugin Slug:
stream

Installations
70,000+

Vulnerability:
Server Side Request Forgery (SSRF)

Patched in Version:
4.1.0

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 4.1.0.

Spotlight Social Feeds � Block, Shortcode, and Widget

Plugin Slug:
spotlight-social-photo-feeds

Installations
60,000+

Vulnerability:
Sensitive Data Exposure

Patched in Version:
1.7.2

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.7.2.

WP Booking Calendar

Plugin Slug:
booking

Installations
50,000+

Vulnerability:
Broken Access Control

Patched in Version:
10.10.1

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 10.10.1.

DethemeKit for Elementor

Plugin Slug:
dethemekit-for-elementor

Installations
40,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.1.9

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.1.9.

DethemeKit for Elementor

Plugin Slug:
dethemekit-for-elementor

Installations
40,000+

Vulnerability:
Insecure Direct Object References (IDOR)

Patched in Version:
2.1.9

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.1.9.

FULL � Cliente

Plugin Slug:
full-customer

Installations
40,000+

Vulnerability:
Local File Inclusion

Patched in Version:
3.1.27

Severity Score:
High


The vulnerability has been patched, so you should update to version 3.1.27.

Security & Malware scan by CleanTalk

Plugin Slug:
security-malware-firewall

Installations
30,000+

Vulnerability:
Arbitrary File Upload

Patched in Version:
2.150

Severity Score:
Critical


The vulnerability has been patched, so you should update to version 2.150.

Ecwid by Lightspeed Ecommerce Shopping Cart

Plugin Slug:
ecwid-shopping-cart

Installations
20,000+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
6.12.28

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 6.12.28.

Read More & Accordion

Plugin Slug:
expand-maker

Installations
20,000+

Vulnerability:
Broken Access Control

Patched in Version:
3.4.3

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 3.4.3.

Custom Block Builder � Lazy Blocks

Plugin Slug:
lazy-blocks

Installations
20,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
3.8.3

Severity Score:
High


The vulnerability has been patched, so you should update to version 3.8.3.

Welcart e-Commerce

Plugin Slug:
usc-e-shop

Installations
20,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.11.10

Severity Score:
High


The vulnerability has been patched, so you should update to version 2.11.10.

Media Library Folders

Plugin Slug:
media-library-plus

Installations
10,000+

Vulnerability:
Broken Access Control

Patched in Version:
8.3.1

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 8.3.1.

Qubely � Advanced Gutenberg Blocks

Plugin Slug:
qubely

Installations
10,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.8.13

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.8.13.

Team � Team Members Showcase Plugin

Plugin Slug:
tlp-team

Installations
10,000+

Vulnerability:
Broken Access Control

Patched in Version:
5.0.0

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 5.0.0.

Export All Posts, Products, Orders, Refunds & Users

Plugin Slug:
wp-ultimate-exporter

Installations
10,000+

Vulnerability:
Sensitive Data Exposure

Patched in Version:
2.10

Severity Score:
High


The vulnerability has been patched, so you should update to version 2.10.

Customer Email Verification for WooCommerce

Plugin Slug:
emails-verification-for-woocommerce

Installations
7,000+

Vulnerability:
Sensitive Data Exposure

Patched in Version:
2.9.5

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.9.5.

Customer Email Verification for WooCommerce

Plugin Slug:
emails-verification-for-woocommerce

Installations
7,000+

Vulnerability:
Broken Authentication

Patched in Version:
2.9.6

Severity Score:
High


The vulnerability has been patched, so you should update to version 2.9.6.

ProfileGrid � User Profiles, Groups and Communities

Plugin Slug:
profilegrid-user-profiles-groups-and-communities

Installations
7,000+

Vulnerability:
Insecure Direct Object References (IDOR)

Patched in Version:
5.9.4.3

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 5.9.4.3.

ProfileGrid � User Profiles, Groups and Communities

Plugin Slug:
profilegrid-user-profiles-groups-and-communities

Installations
7,000+

Vulnerability:
Server Side Request Forgery (SSRF)

Patched in Version:
5.9.4.3

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 5.9.4.3.

Super Testimonials

Plugin Slug:
super-testimonial

Installations
3,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
4.0.2

Severity Score:
High


The vulnerability has been patched, so you should update to version 4.0.2.

Leyka

Plugin:

Leyka

Plugin Slug:
leyka

Installations
2,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
3.31.9

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 3.31.9.

SKT Blocks � Gutenberg based Page Builder

Plugin Slug:
skt-blocks

Installations
2,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.8

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.8.

Timeline Block � Timeline block plugin for WordPress

Plugin Slug:
timeline-block-block

Installations
2,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.1.3

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.1.3.

WP Airbnb Review Slider

Plugin Slug:
wp-airbnb-review-slider

Installations
2,000+

Vulnerability:
SQL Injection

Patched in Version:
4.0

Severity Score:
High


The vulnerability has been patched, so you should update to version 4.0.

Calculator Builder � Create an Online Calculator

Plugin Slug:
calculator-builder

Installations
1,000+

Vulnerability:
Local File Inclusion

Patched in Version:
1.6.3

Severity Score:
High


The vulnerability has been patched, so you should update to version 1.6.3.

DirectoryPress Frontend

Plugin Slug:
directorypress-frontend

Installations
1,000+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
2.8.0

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.8.0.

iNET Webkit

Plugin Slug:
inet-webkit

Installations
1,000+

Vulnerability:
Broken Access Control

Patched in Version:
1.2.3

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.2.3.

Oliver POS � A WooCommerce Point of Sale (POS)

Plugin Slug:
oliver-pos

Installations
1,000+

Vulnerability:
Privilege Escalation

Patched in Version:
2.4.2.4

Severity Score:
Critical


The vulnerability has been patched, so you should update to version 2.4.2.4.

Simple Google Calendar Outlook Events Widget

Plugin Slug:
simple-google-icalendar-widget

Installations
1,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.6.0

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.6.0.

SuperSaaS � online appointment scheduling

Plugin Slug:
supersaas-appointment-scheduling

Installations
1,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.1.13

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.1.13.

The Ultimate WordPress Toolkit � WP Extended

Plugin Slug:
wpextended

Installations
1,000+

Vulnerability:
Broken Access Control

Patched in Version:
3.0.14

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 3.0.14.

aBlocks � WordPress Gutenberg Blocks

Plugin Slug:
ablocks

Installations
900+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.6.2

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.6.2.

Marketing Automation

Plugin Slug:
marketing-automation

Installations
800+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.2.6.9

Severity Score:
High


The vulnerability has been patched, so you should update to version 1.2.6.9.

Waymark

Plugin:

Waymark

Plugin Slug:
waymark

Installations
800+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.5.1

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.5.1.

Give � Divi Donation Modules

Plugin Slug:
give-donation-modules-for-divi

Installations
600+

Vulnerability:
Sensitive Data Exposure

Patched in Version:
2.0.1

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.0.1.

Houzez Property Feed

Plugin Slug:
houzez-property-feed

Installations
600+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
2.4.22

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.4.22.
Plugin Slug:
ngg-smart-image-search

Installations
500+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
3.3.2

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 3.3.2.

aDirectory � WordPress Directory Listing Plugin

Plugin Slug:
adirectory

Installations
400+

Vulnerability:
Broken Access Control

Patched in Version:
2.3.5

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.3.5.

AForms Eats

Plugin Slug:
aforms-eats

Installations
400+

Vulnerability:
Sensitive Data Exposure

Patched in Version:
1.3.2

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.3.2.

Keep Backup Daily

Plugin Slug:
keep-backup-daily

Installations
400+

Vulnerability:
Arbitrary File Download

Patched in Version:
2.1.1

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.1.1.

SpeedSize Image & Video AI-Optimizer

Plugin Slug:
speedsize-ai-image-optimizer

Installations
400+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
1.5.2

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.5.2.

Easy Elementor Addons

Plugin Slug:
easy-elementor-addons

Installations
300+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.1.6

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.1.6.

Web Stories Enhancer � Level Up Your Web Stories

Plugin Slug:
web-stories-enhancer

Installations
300+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.4

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.4.

WooCommerce Pricing � Product Pricing

Plugin Slug:
woo-pricing-table

Installations
300+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.1.0

Severity Score:
High


The vulnerability has been patched, so you should update to version 1.1.0.

WP Abstracts

Plugin Slug:
wp-abstracts-manuscripts-manager

Installations
300+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
2.7.4

Severity Score:
High


The vulnerability has been patched, so you should update to version 2.7.4.

what3words Address Field

Plugin Slug:
3-word-address-validation-field

Installations
200+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
4.0.16

Severity Score:
High


The vulnerability has been patched, so you should update to version 4.0.16.

Content Snippet Manager

Plugin Slug:
content-snippet-manager

Installations
200+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
1.1.6

Severity Score:
High


The vulnerability has been patched, so you should update to version 1.1.6.

Threepress

Plugin Slug:
threepress

Installations
200+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.7.2

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.7.2.

Admire Extra

Plugin Slug:
admire-extra

Installations
100+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.7

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.7.

Distance Based Shipping Calculator

Plugin Slug:
distance-based-shipping-calculator

Installations
100+

Vulnerability:
Settings Change

Patched in Version:
2.0.23

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.0.23.

Distance Based Shipping Calculator

Plugin Slug:
distance-based-shipping-calculator

Installations
100+

Vulnerability:
Broken Access Control

Patched in Version:
2.0.23

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.0.23.

LTL Freight Quotes � Worldwide Express Edition

Plugin Slug:
ltl-freight-quotes-worldwide-express-edition

Installations
100+

Vulnerability:
Broken Access Control

Patched in Version:
5.0.21

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 5.0.21.

LTL Freight Quotes � Worldwide Express Edition

Plugin Slug:
ltl-freight-quotes-worldwide-express-edition

Installations
100+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
5.0.22

Severity Score:
High


The vulnerability has been patched, so you should update to version 5.0.22.

Magic the Gathering Card Tooltips

Plugin Slug:
magic-the-gathering-card-tooltips

Installations
100+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
3.6.0

Severity Score:
High


The vulnerability has been patched, so you should update to version 3.6.0.

StaffList

Plugin Slug:
stafflist

Installations
100+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
3.2.4

Severity Score:
High


The vulnerability has been patched, so you should update to version 3.2.4.

Liveticker (by stklcode)

Plugin Slug:
stklcode-liveticker

Installations
100+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.2.3

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.2.3.

FuseDesk

Plugin:

FuseDesk

Plugin Slug:
fusedesk

Installations
70+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
6.7

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 6.7.

LTL Freight Quotes � FreightQuote Edition

Plugin Slug:
ltl-freight-quotes-freightquote-edition

Installations
60+

Vulnerability:
Broken Access Control

Patched in Version:
2.3.12

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.3.12.

LTL Freight Quotes � FreightQuote Edition

Plugin Slug:
ltl-freight-quotes-freightquote-edition

Installations
60+

Vulnerability:
SQL Injection

Patched in Version:
2.3.12

Severity Score:
Critical


The vulnerability has been patched, so you should update to version 2.3.12.

MemorialDay

Plugin Slug:
memorialday

Installations
60+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
1.1.0

Severity Score:
High


The vulnerability has been patched, so you should update to version 1.1.0.

Vertex Addons for Elementor

Plugin Slug:
addons-for-elementor-builder

Installations
50+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.3.0

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.3.0.

LTL Freight Quotes � Estes Edition

Plugin Slug:
ltl-freight-quotes-estes-edition

Installations
40+

Vulnerability:
SQL Injection

Patched in Version:
3.3.8

Severity Score:
Critical


The vulnerability has been patched, so you should update to version 3.3.8.

LTL Freight Quotes � XPO Edition

Plugin Slug:
ltl-freight-quotes-xpo-edition

Installations
40+

Vulnerability:
SQL Injection

Patched in Version:
4.3.8

Severity Score:
Critical


The vulnerability has been patched, so you should update to version 4.3.8.

Small Package Quotes � UPS Edition

Plugin Slug:
small-package-quotes-ups-edition

Installations
30+

Vulnerability:
SQL Injection

Patched in Version:
4.5.17

Severity Score:
Critical


The vulnerability has been patched, so you should update to version 4.5.17.

LTL Freight Quotes � For Customers of FedEx Freight

Plugin Slug:
ltl-freight-quotes-fedex-freight-edition

Installations
20+

Vulnerability:
SQL Injection

Patched in Version:
3.4.2

Severity Score:
Critical


The vulnerability has been patched, so you should update to version 3.4.2.

Simple Certain Time to Show Content

Plugin Slug:
simple-certain-time-to-show-content

Installations
20+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.3.1

Severity Score:
High


The vulnerability has been patched, so you should update to version 1.3.1.

Chaty Pro

Plugin:

Chaty Pro

Plugin Slug:
chaty-pro

Vulnerability:
Arbitrary File Upload

Patched in Version:
3.3.4

Severity Score:
Critical


The vulnerability has been patched, so you should update to version 3.3.4.

ConvertPlus

Plugin:

ConvertPlus

Plugin Slug:
convertplug

Vulnerability:
Broken Access Control

Patched in Version:
3.5.31

Severity Score:
High


The vulnerability has been patched, so you should update to version 3.5.31.

Fusion Builder

Plugin:

Fusion Builder

Plugin Slug:
fusion-builder

Vulnerability:
Remote Code Execution (RCE)

Patched in Version:
3.11.14

Severity Score:
High


The vulnerability has been patched, so you should update to version 3.11.14.
Plugin:

Gallery

Plugin Slug:
gallery

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.2.2

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.2.2.
Plugin:

Global Gallery – WordPress Responsive Gallery

Plugin Slug:
global-gallery

Vulnerability:
Remote Code Execution (RCE)

Patched in Version:
9.1.6

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 9.1.6.

K Elements

Plugin:

K Elements

Plugin Slug:
k-elements

Vulnerability:
Privilege Escalation

Patched in Version:
5.4.0

Severity Score:
Critical


The vulnerability has been patched, so you should update to version 5.4.0.

LTL Freight Quotes � Unishippers Edition

Plugin:

LTL Freight Quotes � Unishippers Edition

Plugin Slug:
ltl-freight-quotes-unishippers-edition

Vulnerability:
SQL Injection

Patched in Version:
2.5.9

Severity Score:
Critical


The vulnerability has been patched, so you should update to version 2.5.9.

LTL Freight Quotes � Unishippers Edition

Plugin:

LTL Freight Quotes � Unishippers Edition

Plugin Slug:
ltl-freight-quotes-unishippers-edition

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.5.9

Severity Score:
High


The vulnerability has been patched, so you should update to version 2.5.9.

LTL Freight Quotes � Unishippers Edition

Plugin:

LTL Freight Quotes � Unishippers Edition

Plugin Slug:
ltl-freight-quotes-unishippers-edition

Vulnerability:
Broken Access Control

Patched in Version:
2.5.9

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.5.9.

Notif Bell

Plugin Slug:
notif-bell

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
0.9.9

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 0.9.9.

Tourmaster

Plugin:

Tourmaster

Plugin Slug:
tourmaster

Vulnerability:
SQL Injection

Patched in Version:
5.3.7

Severity Score:
High


The vulnerability has been patched, so you should update to version 5.3.7.

Uncode Core

Plugin:

Uncode Core

Plugin Slug:
uncode-core

Vulnerability:
Content Injection

Patched in Version:
2.9.1.7

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.9.1.7.

WP Table Manager

Plugin:

WP Table Manager

Plugin Slug:
wp-table-manager

Vulnerability:
Directory Traversal

Patched in Version:
4.1.4

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 4.1.4.

WordPress Themes � 12 Patched / 4 Unpatched

Campress

Theme:

Campress

Theme Slug:
campress

Vulnerability:
Local File Inclusion

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should switch themes.

Puzzles

Theme:

Puzzles

Theme Slug:
puzzles

Vulnerability:
PHP Object Injection

Patched in Version:
No Fix

Severity Score:
Critical


The vulnerability has not been patched. You should switch themes.

Puzzles

Theme:

Puzzles

Theme Slug:
puzzles

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should switch themes.

Puzzles

Theme:

Puzzles

Theme Slug:
puzzles

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should switch themes.

Uncode

Theme:

Uncode

Theme Slug:
uncode

Downloads
2,247

Vulnerability:
Arbitrary File Download

Patched in Version:
2.9.1.7

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.9.1.7.

Uncode

Theme:

Uncode

Theme Slug:
uncode

Downloads
2,247

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.9.1.7

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.9.1.7.

Uncode

Theme:

Uncode

Theme Slug:
uncode

Downloads
2,247

Vulnerability:
Arbitrary File Download

Patched in Version:
2.9.1.7

Severity Score:
High


The vulnerability has been patched, so you should update to version 2.9.1.7.

Avada

Theme:

Avada

Theme Slug:
avada

Vulnerability:
Remote Code Execution (RCE)

Patched in Version:
7.11.14

Severity Score:
High


The vulnerability has been patched, so you should update to version 7.11.14.

CarSpot

Theme:

CarSpot

Theme Slug:
carspot

Vulnerability:
Broken Authentication

Patched in Version:
2.4.4

Severity Score:
Critical


The vulnerability has been patched, so you should update to version 2.4.4.

Click Mag

Theme:

Click Mag

Theme Slug:
click-mag

Vulnerability:
Broken Access Control

Patched in Version:
3.7.0

Severity Score:
High


The vulnerability has been patched, so you should update to version 3.7.0.

Listivo – Classified Ads

Theme:

Listivo – Classified Ads

Theme Slug:
listivo

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.3.68

Severity Score:
High


The vulnerability has been patched, so you should update to version 2.3.68.

PressMart

Theme:

PressMart

Theme Slug:
pressmart

Vulnerability:
Content Injection

Patched in Version:
1.2.17

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.2.17.

Real Estate 7

Theme:

Real Estate 7

Theme Slug:
realestate-7

Vulnerability:
Privilege Escalation

Patched in Version:
3.5.1

Severity Score:
Critical


The vulnerability has been patched, so you should update to version 3.5.1.

Zox News

Theme:

Zox News

Theme Slug:
zox-news

Vulnerability:
Broken Access Control

Patched in Version:
3.17.1

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 3.17.1.

ZoxPress

Theme:

ZoxPress

Theme Slug:
zoxpress

Vulnerability:
Broken Access Control

Patched in Version:
2.12.1

Severity Score:
High


The vulnerability has been patched, so you should update to version 2.12.1.

ZoxPress

Theme:

ZoxPress

Theme Slug:
zoxpress

Vulnerability:
Broken Access Control

Patched in Version:
2.12.1

Severity Score:
High


The vulnerability has been patched, so you should update to version 2.12.1.

Related articles

Wait! Get exclusive hosting insights

Subscribe to our newsletter and stay ahead of the competition with expert advice from our hosting pros.

Loading form…