Line illustration showing a black application window on a dark purple gradient background overlaid with a large exclamation point alert icon and three bugs.

WordPress Vulnerability Report � January 7, 2026

In this report, 333 vulnerabilities have been publicly disclosed. Security patches for 97 of these plugins and themes are now available. Please run these updates as soon as possible. If you’re a Solid Security Pro user, the version management tool may have already warned you and updated these plugins, depending on your settings.

Currently, 236 plugin and theme vulnerabilities remain unpatched. If you’re a Solid Security Pro user, those vulnerabilities are already protected by the Solid Security firewall. Virtual patches from Patchstack will be applied when a vulnerability is considered high or medium risk. If no patch is forthcoming from the vendor or the vulnerable software has been marked “closed” and dropped from the official WordPress repositories, you should deactivate it soon and look for alternative solutions.

WordPress Core

WordPress 6.9 “Gene” was released on December 2, 2025. This release brings major upgrades to how teams collaborate and create. The new Notes feature adds block-level commenting for posts and pages, streamlining editorial reviews, while an expanded Command Palette helps power users navigate and operate across the dashboard even faster. The introduction of the Abilities API delivers a standardized, machine-readable permissions system that lays the groundwork for next-generation AI-powered and automated workflows. WordPress 6.9 also includes notable performance improvements for faster page loads, several new practical blocks, and more visual drag-and-drop tools to help creators build richer, more dynamic content.

Following a major release, you should not update live sites without first taking backups and testing the update in a non-production environment.

WordPress Plugins � 83 Patched / 170 Unpatched

Popup builder with Gamification, Multi-Step Popups, Page-Level Targeting, and WooCommerce Triggers

Plugin Slug:
popup-builder-block

Installations
40,000+

Vulnerability:
Sensitive Data Exposure

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

EasyTest � Simplify A/B Testing

Plugin Slug:
convertpro

Installations
20,000+

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Cookies and Content Security Policy

Plugin Slug:
cookies-and-content-security-policy

Installations
10,000+

Vulnerability:
Sensitive Data Exposure

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Simple Like Page Plugin

Plugin Slug:
simple-facebook-plugin

Installations
10,000+

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.
Plugin Slug:
grand-media

Installations
8,000+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

QuadLayers TikTok Feed

Plugin Slug:
wp-tiktok-feed

Installations
8,000+

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

All in One Accessibility

Plugin Slug:
all-in-one-accessibility

Installations
7,000+

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Tooltips for WordPress

Plugin Slug:
wordpress-tooltips

Installations
6,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Hotel Booking

Plugin Slug:
nd-booking

Installations
5,000+

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Zoho ZeptoMail

Plugin Slug:
transmail

Installations
4,000+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Livemesh Addons for Beaver Builder

Plugin Slug:
addons-for-beaver-builder

Installations
3,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

AnyComment

Plugin Slug:
anycomment

Installations
3,000+

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Cooked � Recipe Management

Plugin Slug:
cooked

Installations
3,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

GS Portfolio for Envato

Plugin Slug:
gs-envato-portfolio

Installations
3,000+

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

WP Attachments

Plugin Slug:
wp-attachments

Installations
3,000+

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.
Plugin Slug:
carousel-horizontal-posts-content-slider

Installations
2,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.
Plugin Slug:
civic-cookie-control-8

Installations
2,000+

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Curator.io

Plugin Slug:
curatorio

Installations
2,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.
Plugin Slug:
featured-image-generator

Installations
2,000+

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Calendar.online / Kalender.digital � Plugin

Plugin Slug:
kalender-digital

Installations
2,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

MAS Videos

Plugin Slug:
masvideos

Installations
2,000+

Vulnerability:
Local File Inclusion

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Menu In Post

Plugin Slug:
menu-in-post

Installations
2,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

MyBookTable Bookstore by Stormhill Media

Plugin Slug:
mybooktable

Installations
2,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Series

Plugin:

Series

Plugin Slug:
series

Installations
2,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

teachPress

Plugin Slug:
teachpress

Installations
2,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

The Moneytizer

Plugin Slug:
the-moneytizer

Installations
2,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

User Specific Content

Plugin Slug:
user-specific-content

Installations
2,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Web and WooCommerce Addons for WPBakery Builder

Plugin Slug:
vc-addons-by-bit14

Installations
2,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Wallet System for WooCommerce � Digital Wallet, Buy Now Pay Later (BNPL), Instant Cashback, Referral program, Partial & Subscription Payments

Plugin Slug:
wallet-system-for-woocommerce

Installations
2,000+

Vulnerability:
Sensitive Data Exposure

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

WebMan Amplifier

Plugin Slug:
webman-amplifier

Installations
2,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.
Plugin Slug:
accordion-slider-gallery

Installations
1,000+

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

AdWords Conversion Tracking Code

Plugin Slug:
adwords-conversion-tracking-code

Installations
1,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

AI Content Writing Assistant

Plugin Slug:
ai-content-writing-assistant

Installations
1,000+

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Payment Gateway Authorize.Net CIM for WooCommerce

Plugin Slug:
authnet-cim-for-woo

Installations
1,000+

Vulnerability:
Arbitrary Content Deletion

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

AweBooking � Hotel Booking System

Plugin Slug:
awebooking

Installations
1,000+

Vulnerability:
Sensitive Data Exposure

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Bootstrap Modals

Plugin Slug:
bootstrap-modals

Installations
1,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Co-marquage service-public.fr

Plugin Slug:
co-marquage-service-public

Installations
1,000+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

CodeColorer

Plugin Slug:
codecolorer

Installations
1,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Core Web Vitals & PageSpeed Booster

Plugin Slug:
core-web-vitals-pagespeed-booster

Installations
1,000+

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Custom Background Changer

Plugin Slug:
custom-background-changer

Installations
1,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.
Plugin Slug:
custom-url-to-featured-image

Installations
1,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

DMCA Protection Badge

Plugin Slug:
dmca-badge

Installations
1,000+

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Download Media Library

Plugin Slug:
download-media-library

Installations
1,000+

Vulnerability:
Sensitive Data Exposure

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

EasyIndex

Plugin Slug:
easyindex

Installations
1,000+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Extra Shortcodes

Plugin Slug:
extra-shortcodes

Installations
1,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

FormFacade � Embed Google Forms in your website

Plugin Slug:
formfacade

Installations
1,000+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.
Plugin Slug:
gallery-portfolio

Installations
1,000+

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

GLS Shipping for WooCommerce

Plugin Slug:
gls-shipping-for-woocommerce

Installations
1,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Hide Plugins

Plugin Slug:
hide-plugins

Installations
1,000+

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Locatoraid Store Locator

Plugin Slug:
locatoraid

Installations
1,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

MX Time Zone Clocks

Plugin Slug:
mx-time-zone-clocks

Installations
1,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Netgsm

Plugin:

Netgsm

Plugin Slug:
netgsm

Installations
1,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Contact Form Widget

Plugin Slug:
new-contact-form-widget

Installations
1,000+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.
Plugin Slug:
owl-carousel-wp

Installations
1,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Page Title Splitter

Plugin Slug:
page-title-splitter

Installations
1,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

?????? ?????? ??????

Plugin Slug:
pardakht-delkhah

Installations
1,000+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Product Delivery Date for WooCommerce � Lite

Plugin Slug:
product-delivery-date-for-woocommerce-lite

Installations
1,000+

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Realbig For WordPress

Plugin Slug:
realbig-media

Installations
1,000+

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

RestroPress � Online Food Ordering System

Plugin Slug:
restropress

Installations
1,000+

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Robots.txt rewrite

Plugin Slug:
robotstxt-rewrite

Installations
1,000+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

SEO Slider

Plugin Slug:
seo-slider

Installations
1,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Slider Templates

Plugin Slug:
slider-templates

Installations
1,000+

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Tasty Recipes Lite

Plugin Slug:
tasty-recipes-lite

Installations
1,000+

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Tasty Recipes Lite

Plugin Slug:
tasty-recipes-lite

Installations
1,000+

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Terms descriptions

Plugin Slug:
terms-descriptions

Installations
1,000+

Vulnerability:
Sensitive Data Exposure

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

OpenHook

Plugin:

OpenHook

Plugin Slug:
thesis-openhook

Installations
1,000+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Trash Duplicate and 301 Redirect

Plugin Slug:
trash-duplicate-and-301-redirect

Installations
1,000+

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Cincopa video and media plug-in

Plugin Slug:
video-playlist-and-gallery-plugin

Installations
1,000+

Vulnerability:
Sensitive Data Exposure

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Cincopa video and media plug-in

Plugin Slug:
video-playlist-and-gallery-plugin

Installations
1,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

WP Gmail SMTP

Plugin Slug:
wp-gmail-smtp

Installations
1,000+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

WP Post Signature

Plugin Slug:
wp-post-signature

Installations
1,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Varnish/Nginx Proxy Caching

Plugin Slug:
vcaching

Installations
900+

Vulnerability:
Sensitive Data Exposure

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Sticky Notes for WP Dashboard

Plugin Slug:
wb-sticky-notes

Installations
900+

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

WP Advanced PDF

Plugin Slug:
wp-advanced-pdf

Installations
900+

Vulnerability:
Other Vulnerability Type

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

iNext Woo Pincode Checker

Plugin Slug:
inext-woo-pincode-checker

Installations
800+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Mergado Pack

Plugin Slug:
mergado-marketing-pack

Installations
800+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Wiremo � Product Reviews for WooCommerce

Plugin Slug:
woo-reviews-by-wiremo

Installations
800+

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

BoomDevs WordPress Coming Soon Plugin

Plugin Slug:
coming-soon-by-boomdevs

Installations
700+

Vulnerability:
Sensitive Data Exposure

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Easy Upload Files During Checkout

Plugin Slug:
easy-upload-files-during-checkout

Installations
600+

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Live Shopping & Shoppable Videos For WooCommerce

Plugin Slug:
live-shopping-video-streams

Installations
600+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Live Shopping & Shoppable Videos For WooCommerce

Plugin Slug:
live-shopping-video-streams

Installations
600+

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Ef� Bank

Plugin Slug:
woo-gerencianet-official

Installations
500+

Vulnerability:
Sensitive Data Exposure

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

WP Export Categories & Taxonomies

Plugin Slug:
wp-export-categories-taxonomies

Installations
500+

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Behance Portfolio Manager

Plugin Slug:
portfolio-manager-powered-by-behance

Installations
400+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Behance Portfolio Manager

Plugin Slug:
portfolio-manager-powered-by-behance

Installations
400+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

WP-CalDav2ICS

Plugin Slug:
wp-caldav2ics

Installations
300+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Audiomack

Plugin Slug:
audiomack

Installations
200+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Content Fetcher

Plugin Slug:
content-fetcher

Installations
200+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Sell Downloads

Plugin Slug:
sell-downloads

Installations
200+

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Accessibility Press

Plugin Slug:
ilogic-accessibility

Installations
100+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Infility Global

Plugin Slug:
infility-global

Installations
100+

Vulnerability:
SQL Injection

Patched in Version:
No Fix

Severity Score:
Critical


The vulnerability has not been patched. You should deactivate the plugin.

MyD Delivery

Plugin Slug:
myd-delivery

Installations
100+

Vulnerability:
Insecure Direct Object References (IDOR)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Orders Chat for WooCommerce

Plugin Slug:
orders-chat-for-woocommerce

Installations
100+

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Simple XML Sitemap

Plugin Slug:
simple-xml-sitemap

Installations
100+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Order Cancellation & Returns for WooCommerce

Plugin Slug:
wc-order-cancellation-return

Installations
100+

Vulnerability:
Insecure Direct Object References (IDOR)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Effect Maker

Plugin Slug:
effect-maker

Installations
80+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Flaming Password Reset

Plugin Slug:
flaming-password-reset

Installations
70+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

PRIMER by chlo�digital

Plugin Slug:
primer-by-chloedigital

Installations
60+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Visitor Stats Widget

Plugin Slug:
visitor-stats-widget

Installations
60+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Custom Style

Plugin Slug:
custom-style

Installations
50+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

e-shops???2

Plugin Slug:
e-shops-cart2

Installations
50+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Noindex by Path

Plugin Slug:
noindex-by-path

Installations
50+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Pinpoll

Plugin:

Pinpoll

Plugin Slug:
pinpoll

Installations
50+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Recent Posts From Each Category

Plugin Slug:
recent-posts-from-each-category

Installations
50+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Scroll rss excerpt

Plugin Slug:
scroll-rss-excerpt

Installations
50+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

SensitiveTagCloud

Plugin Slug:
sensitive-tag-cloud

Installations
50+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Simple Archive Generator

Plugin Slug:
simple-archive-generator

Installations
50+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Social Profilr

Plugin Slug:
social-profilr-display-social-network-profile

Installations
50+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

WP App Bar

Plugin Slug:
wp-app-bar

Installations
50+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

WP-EasyArchives

Plugin Slug:
wp-easyarchives

Installations
50+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Custom Post Status

Plugin Slug:
custom-post-status

Installations
40+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Direct Payments WP

Plugin Slug:
direct-payments-wp

Installations
40+

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Direct Payments WP

Plugin Slug:
direct-payments-wp

Installations
40+

Vulnerability:
Sensitive Data Exposure

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Flowbox

Plugin:

Flowbox

Plugin Slug:
flowbox

Installations
10+

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Dashboard Beacon

Plugin Slug:
wp-dashboard-beacon

Installations
10+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

WPBookit

Plugin:

WPBookit

Plugin Slug:
wpbookit

Installations
10+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Advance WP Query Search Filter

Plugin:

Advance WP Query Search Filter

Plugin Slug:
advance-wp-query-search-filter

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Advance WP Query Search Filter

Plugin:

Advance WP Query Search Filter

Plugin Slug:
advance-wp-query-search-filter

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Appender

Plugin:

Appender

Plugin Slug:
appender

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Appointify

Plugin:

Appointify

Plugin Slug:
appointify

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Appointify

Plugin:

Appointify

Plugin Slug:
appointify

Vulnerability:
SQL Injection

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Wawp

Plugin:

Wawp

Plugin Slug:
automation-web-platform

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

BM Content Builder

Plugin:

BM Content Builder

Plugin Slug:
bm-builder

Vulnerability:
Arbitrary File Download

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Conformer for Elementor

Plugin:

Conformer for Elementor

Plugin Slug:
conformer-elementor

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Countdowner for Elementor

Plugin:

Countdowner for Elementor

Plugin Slug:
countdowner-elementor

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Couponer for Elementor

Plugin:

Couponer for Elementor

Plugin Slug:
couponer-elementor

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Criptopayer for Elementor

Plugin:

Criptopayer for Elementor

Plugin Slug:
criptopayer-elementor

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Dental Care CPT

Plugin:

Dental Care CPT

Plugin Slug:
dentalcare-cpt

Vulnerability:
PHP Object Injection

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Gmaper for Elementor

Plugin:

Gmaper for Elementor

Plugin Slug:
gmaper-elementor

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Select Graphist for Elementor Graphist for Elementor

Plugin:

Select Graphist for Elementor Graphist for Elementor

Plugin Slug:
graphist-elementor

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Headinger for Elementor

Plugin:

Headinger for Elementor

Plugin Slug:
headinger-elementor

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Hotel Listing

Plugin:

Hotel Listing

Plugin Slug:
hotel-listing

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

iRecco Core

Plugin:

iRecco Core

Plugin Slug:
irecco-core

Vulnerability:
Local File Inclusion

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

JobBank

Plugin:

JobBank

Plugin Slug:
jobbank

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

ListingPro Reviews

Plugin:

ListingPro Reviews

Plugin Slug:
listingpro-reviews

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Logger for Elementor

Plugin:

Logger for Elementor

Plugin Slug:
logger-elementor

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

WordPress Movies Bulk Importer

Plugin:

WordPress Movies Bulk Importer

Plugin Slug:
movies importer

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Questionar for Elementor

Plugin:

Questionar for Elementor

Plugin Slug:
questionar-elementor

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Registration & Login with Mobile Phone Number for WooCommerce

Plugin:

Registration & Login with Mobile Phone Number for WooCommerce

Plugin Slug:
registration-login-with-mobile-phone-number

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
Critical


The vulnerability has not been patched. You should deactivate the plugin.

Reuters Direct

Plugin:

Reuters Direct

Plugin Slug:
reuters-direct

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

SearchAzon

Plugin:

SearchAzon

Plugin Slug:
searchazon

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Sermon Manager

Plugin:

Sermon Manager

Plugin Slug:
sermon-manager-for-wordpress

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Sliper for Elementor

Plugin:

Sliper for Elementor

Plugin Slug:
sliper-elementor

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Super Logos Showcase

Plugin:

Super Logos Showcase

Plugin Slug:
superlogoshowcase-wp

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Tech Life CPT

Plugin:

Tech Life CPT

Plugin Slug:
techlife-cpt

Vulnerability:
PHP Object Injection

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

UnGrabber

Plugin:

UnGrabber

Plugin Slug:
ungrabber

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Universal Video Player

Plugin:

Universal Video Player

Plugin Slug:
universal-video-player

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Universal Video Player

Plugin:

Universal Video Player

Plugin Slug:
universal-video-player

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Valenti Engine

Plugin:

Valenti Engine

Plugin Slug:
valenti-engine

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Walker for Elementor

Plugin:

Walker for Elementor

Plugin Slug:
walker-elementor

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Watcher for Elementor

Plugin:

Watcher for Elementor

Plugin Slug:
watcher-elementor

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

WING WordPress Migrator

Plugin:

WING WordPress Migrator

Plugin Slug:
wing-migrator

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
Critical


The vulnerability has not been patched. You should deactivate the plugin.

WooCommerce Parcelas

Plugin:

WooCommerce Parcelas

Plugin Slug:
woocommerce-parcelas

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Worker for Elementor

Plugin:

Worker for Elementor

Plugin Slug:
worker-elementor

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Worker for WPBakery

Plugin:

Worker for WPBakery

Plugin Slug:
worker-wpbakery

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

WordPress & WooCommerce Scraper Plugin, Import Data from Any Site

Plugin:

WordPress & WooCommerce Scraper Plugin, Import Data from Any Site

Plugin Slug:
wp_scraper

Vulnerability:
Server Side Request Forgery (SSRF)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

PixelYourSite � Your smart PIXEL (TAG) & API Manager

Plugin Slug:
pixelyoursite

Installations
500,000+

Vulnerability:
Sensitive Data Exposure

Patched in Version:
11.1.5.1

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 11.1.5.1.

Advanced Ads ��Ad Manager & AdSense

Plugin Slug:
advanced-ads

Installations
100,000+

Vulnerability:
Remote Code Execution (RCE)

Patched in Version:
2.0.15

Severity Score:
Critical


The vulnerability has been patched, so you should update to version 2.0.15.

Aruba HiSpeed Cache

Plugin Slug:
aruba-hispeed-cache

Installations
100,000+

Vulnerability:
Broken Access Control

Patched in Version:
3.0.3

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 3.0.3.

Depicter � Popup & Slider Builder

Plugin Slug:
depicter

Installations
90,000+

Vulnerability:
Broken Access Control

Patched in Version:
4.7.0

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 4.7.0.

Depicter � Popup & Slider Builder

Plugin Slug:
depicter

Installations
90,000+

Vulnerability:
Broken Access Control

Patched in Version:
4.0.5

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 4.0.5.

Strong Testimonials

Plugin Slug:
strong-testimonials

Installations
90,000+

Vulnerability:
Broken Access Control

Patched in Version:
3.2.19

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 3.2.19.

LearnPress � WordPress LMS Plugin

Plugin Slug:
learnpress

Installations
80,000+

Vulnerability:
Broken Access Control

Patched in Version:
4.3.2.1

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 4.3.2.1.

Comments � wpDiscuz

Plugin Slug:
wpdiscuz

Installations
80,000+

Vulnerability:
Privilege Escalation

Patched in Version:
7.6.40

Severity Score:
Critical


The vulnerability has been patched, so you should update to version 7.6.40.

Table Field Add-on for ACF and SCF

Plugin Slug:
advanced-custom-fields-table-field

Installations
50,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.3.31

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.3.31.
Plugin Slug:
link-whisper

Installations
30,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
0.8.9

Severity Score:
High


The vulnerability has been patched, so you should update to version 0.8.9.

Ultimate Post Kit Addons for Elementor

Plugin Slug:
ultimate-post-kit

Installations
30,000+

Vulnerability:
Sensitive Data Exposure

Patched in Version:
4.0.16

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 4.0.16.

WP Custom Admin Interface

Plugin Slug:
wp-custom-admin-interface

Installations
30,000+

Vulnerability:
Broken Access Control

Patched in Version:
7.41

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 7.41.

WP Import � Ultimate CSV XML Importer for WordPress

Plugin Slug:
wp-ultimate-csv-importer

Installations
20,000+

Vulnerability:
Server Side Request Forgery (SSRF)

Patched in Version:
7.36

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 7.36.

AffiliateX � Amazon Affiliate Plugin

Plugin Slug:
affiliatex

Installations
10,000+

Vulnerability:
Broken Access Control

Patched in Version:
1.4.0

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.4.0.

Demo Importer Plus

Plugin Slug:
demo-importer-plus

Installations
10,000+

Vulnerability:
Broken Access Control

Patched in Version:
2.0.9

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.0.9.

Form Vibes � Database Manager for Forms

Plugin Slug:
form-vibes

Installations
10,000+

Vulnerability:
SQL Injection

Patched in Version:
1.5

Severity Score:
High


The vulnerability has been patched, so you should update to version 1.5.

Plugin Organizer

Plugin Slug:
plugin-organizer

Installations
10,000+

Vulnerability:
SQL Injection

Patched in Version:
10.2.4

Severity Score:
High


The vulnerability has been patched, so you should update to version 10.2.4.

Postie

Plugin:

Postie

Plugin Slug:
postie

Installations
10,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.9.74

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.9.74.

Team � Team Members Showcase Plugin

Plugin Slug:
tlp-team

Installations
10,000+

Vulnerability:
SQL Injection

Patched in Version:
5.0.11

Severity Score:
Critical


The vulnerability has been patched, so you should update to version 5.0.11.

YaMaps for WordPress Plugin

Plugin Slug:
yamaps

Installations
10,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
0.6.40

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 0.6.40.

Blog Filter Post Filtering

Plugin Slug:
blog-filter

Installations
8,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.7.4

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.7.4.

Customer Email Verification for WooCommerce

Plugin Slug:
emails-verification-for-woocommerce

Installations
8,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
3.0.3

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 3.0.3.

ShopBuilder � WooCommerce Builder For Elementor

Plugin Slug:
shopbuilder

Installations
7,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
3.2.2

Severity Score:
High


The vulnerability has been patched, so you should update to version 3.2.2.

FlexTable � Data Table Sync with Google Sheets

Plugin Slug:
sheets-to-wp-table-live-sync

Installations
4,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
3.19.2

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 3.19.2.

Spiffy Calendar

Plugin Slug:
spiffy-calendar

Installations
3,000+

Vulnerability:
Broken Access Control

Patched in Version:
5.0.8

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 5.0.8.

BuddyPress Activity Shortcode

Plugin Slug:
bp-activity-shortcode

Installations
2,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.1.9

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.1.9.

Newsletters

Plugin Slug:
newsletters-lite

Installations
2,000+

Vulnerability:
PHP Object Injection

Patched in Version:
4.12

Severity Score:
Critical


The vulnerability has been patched, so you should update to version 4.12.
Plugin Slug:
videographywp

Installations
2,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.0.20

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.0.20.

Wishlist for WooCommerce: Multi Wishlists Per Customer

Plugin Slug:
wish-list-for-woocommerce

Installations
2,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
3.3.1

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 3.3.1.

Combo Offers WooCommerce

Plugin Slug:
woo-combo-offers

Installations
2,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
4.3

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 4.3.

Email Marketing Plugin � WP Email Capture

Plugin Slug:
wp-email-capture

Installations
2,000+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
3.12.6

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 3.12.6.

Yada Wiki

Plugin Slug:
yada-wiki

Installations
2,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
3.6

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 3.6.

Import into Easy Property Listings

Plugin Slug:
easy-property-listings-xml-csv-import

Installations
1,000+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
2.2.2

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.2.2.

Signature Add-On for Gravity Forms

Plugin Slug:
gravity-signature-forms-add-on

Installations
1,000+

Vulnerability:
Broken Access Control

Patched in Version:
1.8.7

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.8.7.

Maximum Products per User for WooCommerce

Plugin Slug:
maximum-products-per-user-for-woocommerce

Installations
1,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
4.4.4

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 4.4.4.

Lucky Wheel for WooCommerce � Spin a Sale

Plugin Slug:
woo-lucky-wheel

Installations
1,000+

Vulnerability:
Remote Code Execution (RCE)

Patched in Version:
1.1.14

Severity Score:
Critical


The vulnerability has been patched, so you should update to version 1.1.14.

WPCal.io � Easy Meeting Scheduler

Plugin Slug:
wpcal

Installations
1,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
0.9.5.10

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 0.9.5.10.

URL Image Importer

Plugin Slug:
url-image-importer

Installations
300+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.0.8

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.0.8.

ilGhera Support System for WooCommerce

Plugin Slug:
wc-support-system

Installations
100+

Vulnerability:
Broken Access Control

Patched in Version:
1.2.7

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.2.7.

Knowband Mobile App Builder

Plugin Slug:
knowband-mobile-app-builder-for-woocommerce

Installations
10+

Vulnerability:
Broken Access Control

Patched in Version:
3.0.0

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 3.0.0.

Page Expire Popup/Redirection for WordPress

Plugin Slug:
page-expire-popup

Installations
10+

Vulnerability:
SQL Injection

Patched in Version:
1.1

Severity Score:
High


The vulnerability has been patched, so you should update to version 1.1.

Automotive Listings

Plugin:

Automotive Listings

Plugin Slug:
automotive

Vulnerability:
SQL Injection

Patched in Version:
18.7

Severity Score:
Critical


The vulnerability has been patched, so you should update to version 18.7.

XStore Core

Plugin:

XStore Core

Plugin Slug:
et-core-plugin

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
5.6

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 5.6.

Follow My Blog Post

Plugin:

Follow My Blog Post

Plugin Slug:
follow-my-blog-post

Vulnerability:
Arbitrary Content Deletion

Patched in Version:
2.4.1

Severity Score:
High


The vulnerability has been patched, so you should update to version 2.4.1.

FooEvents for WooCommerce

Plugin:

FooEvents for WooCommerce

Plugin Slug:
fooevents

Vulnerability:
SQL Injection

Patched in Version:
1.20.5

Severity Score:
High


The vulnerability has been patched, so you should update to version 1.20.5.
Plugin:

WP Cookie Notice for GDPR, CCPA & ePrivacy Consent

Plugin Slug:
gdpr-cookie-consent

Vulnerability:
Broken Access Control

Patched in Version:
4.0.4

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 4.0.4.

JetBlog

Plugin:

JetBlog

Plugin Slug:
jet-blog

Vulnerability:
Broken Access Control

Patched in Version:
2.4.7.1

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.4.7.1.

JetEngine

Plugin:

JetEngine

Plugin Slug:
jet-engine

Vulnerability:
Broken Access Control

Patched in Version:
3.8.1.2

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 3.8.1.2.

JetEngine

Plugin:

JetEngine

Plugin Slug:
jet-engine

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
3.7.8

Severity Score:
High


The vulnerability has been patched, so you should update to version 3.7.8.

JetPopup

Plugin:

JetPopup

Plugin Slug:
jet-popup

Vulnerability:
Insecure Direct Object References (IDOR)

Patched in Version:
2.0.20.2

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.0.20.2.

JetSearch

Plugin:

JetSearch

Plugin Slug:
jet-search

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
3.5.16.1

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 3.5.16.1.

JetTabs

Plugin:

JetTabs

Plugin Slug:
jet-tabs

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.2.12.1

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.2.12.1.

JetTabs

Plugin:

JetTabs

Plugin Slug:
jet-tabs

Vulnerability:
Broken Access Control

Patched in Version:
2.2.12.1

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.2.12.1.

WBC907 Core

Plugin:

WBC907 Core

Plugin Slug:
wbc907-core

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
3.4.2

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 3.4.2.

WeDesignTech Ultimate Booking Addon

Plugin:

WeDesignTech Ultimate Booking Addon

Plugin Slug:
wedesigntech-ultimate-booking-addon

Vulnerability:
Broken Access Control

Patched in Version:
1.0.4

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.0.4.

Woffice Core

Plugin:

Woffice Core

Plugin Slug:
woffice-core

Vulnerability:
Insecure Direct Object References (IDOR)

Patched in Version:
5.4.31

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 5.4.31.

WordPress Themes � 14 Patched / 66 Unpatched

Black Rider

Theme Slug:
black-rider

Downloads
45,140

Vulnerability:
Sensitive Data Exposure

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should switch themes.

Consulting

Theme Slug:
consulting

Downloads
428,660

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should switch themes.

Melos

Theme:

Melos

Theme Slug:
melos

Downloads
438,193

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should switch themes.

Minamaze

Theme Slug:
minamaze

Downloads
1,015,028

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should switch themes.

Shuttle

Theme:

Shuttle

Theme Slug:
shuttle

Downloads
555,266

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should switch themes.

Vireo

Theme:

Vireo

Theme Slug:
vireo

Downloads
23,014

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should switch themes.

Arcane

Theme:

Arcane

Theme Slug:
arcane

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should switch themes.

Arlo

Theme:

Arlo

Theme Slug:
arlo

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should switch themes.

Backpack Traveler

Theme:

Backpack Traveler

Theme Slug:
backpacktraveler

Vulnerability:
Insecure Direct Object References (IDOR)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should switch themes.

Bailly

Theme:

Bailly

Theme Slug:
bailly

Vulnerability:
Local File Inclusion

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should switch themes.

Bfres

Theme:

Bfres

Theme Slug:
bfres

Vulnerability:
Local File Inclusion

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should switch themes.

Hope

Theme:

Hope

Theme Slug:
charity-is-hope

Vulnerability:
Local File Inclusion

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should switch themes.

Cocco

Theme:

Cocco

Theme Slug:
cocco

Vulnerability:
Insecure Direct Object References (IDOR)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should switch themes.

Curly

Theme:

Curly

Theme Slug:
curly

Vulnerability:
Insecure Direct Object References (IDOR)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should switch themes.

Dekoro

Theme:

Dekoro

Theme Slug:
dekoro

Vulnerability:
Local File Inclusion

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should switch themes.

DiveIt

Theme:

DiveIt

Theme Slug:
diveit

Vulnerability:
Local File Inclusion

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should switch themes.

Dolcino

Theme:

Dolcino

Theme Slug:
dolcino

Vulnerability:
Insecure Direct Object References (IDOR)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should switch themes.

Eldon

Theme:

Eldon

Theme Slug:
eldon

Vulnerability:
Local File Inclusion

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should switch themes.

Electrician – Electrical Service WordPress

Theme:

Electrician – Electrical Service WordPress

Theme Slug:
electrician

Vulnerability:
Server Side Request Forgery (SSRF)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should switch themes.

Fiorello

Theme:

Fiorello

Theme Slug:
fiorello

Vulnerability:
Insecure Direct Object References (IDOR)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should switch themes.

FiveStar

Theme:

FiveStar

Theme Slug:
fivestar

Vulnerability:
Insecure Direct Object References (IDOR)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should switch themes.

Fleur

Theme:

Fleur

Theme Slug:
fleur

Vulnerability:
Insecure Direct Object References (IDOR)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should switch themes.

Frapp�

Theme:

Frapp�

Theme Slug:
frappe

Vulnerability:
Local File Inclusion

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should switch themes.

FreeAgent

Theme:

FreeAgent

Theme Slug:
freeagent

Vulnerability:
Local File Inclusion

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should switch themes.

Freshio

Theme:

Freshio

Theme Slug:
freshio

Vulnerability:
Local File Inclusion

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should switch themes.

Gecko

Theme:

Gecko

Theme Slug:
gecko

Vulnerability:
Local File Inclusion

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should switch themes.

Genemy

Theme:

Genemy

Theme Slug:
genemy

Vulnerability:
Server Side Request Forgery (SSRF)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should switch themes.

Hobo

Theme:

Hobo

Theme Slug:
hobo

Vulnerability:
Local File Inclusion

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should switch themes.

Holmes

Theme:

Holmes

Theme Slug:
holmes

Vulnerability:
Insecure Direct Object References (IDOR)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should switch themes.

Hyori

Theme:

Hyori

Theme Slug:
hyori

Vulnerability:
Local File Inclusion

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should switch themes.

Indoor Plants

Theme:

Indoor Plants

Theme Slug:
indoor-plants

Vulnerability:
Local File Inclusion

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should switch themes.

Innovio

Theme:

Innovio

Theme Slug:
innovio

Vulnerability:
Insecure Direct Object References (IDOR)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should switch themes.

Issabella

Theme:

Issabella

Theme Slug:
issabella

Vulnerability:
Local File Inclusion

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should switch themes.

Justicia

Theme:

Justicia

Theme Slug:
justicia

Vulnerability:
Insecure Direct Object References (IDOR)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should switch themes.

Lekker

Theme:

Lekker

Theme Slug:
lekker

Vulnerability:
Local File Inclusion

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should switch themes.

Lindo

Theme:

Lindo

Theme Slug:
lindo

Vulnerability:
Local File Inclusion

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should switch themes.

Malta

Theme:

Malta

Theme Slug:
malta

Vulnerability:
Local File Inclusion

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should switch themes.

Modern Housewife

Theme:

Modern Housewife

Theme Slug:
modernhousewife

Vulnerability:
Local File Inclusion

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should switch themes.

MoveMe

Theme:

MoveMe

Theme Slug:
moveme

Vulnerability:
Local File Inclusion

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should switch themes.

Muji

Theme:

Muji

Theme Slug:
muji

Vulnerability:
Local File Inclusion

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should switch themes.

Sound | Musical Instruments Online Store

Theme:

Sound | Musical Instruments Online Store

Theme Slug:
musicplace

Vulnerability:
Deserialization of untrusted data

Patched in Version:
No Fix

Severity Score:
Critical


The vulnerability has not been patched. You should switch themes.

Overton

Theme:

Overton

Theme Slug:
overton

Vulnerability:
Insecure Direct Object References (IDOR)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should switch themes.

Overworld

Theme:

Overworld

Theme Slug:
overworld

Vulnerability:
Local File Inclusion

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should switch themes.

PartyMaker

Theme:

PartyMaker

Theme Slug:
partymaker

Vulnerability:
Local File Inclusion

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should switch themes.

PawFriends – Pet Shop and Veterinary WordPress Theme

Theme:

PawFriends – Pet Shop and Veterinary WordPress Theme

Theme Slug:
pawfriends

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should switch themes.

Pearson Specter

Theme:

Pearson Specter

Theme Slug:
pearsonspecter

Vulnerability:
Local File Inclusion

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should switch themes.

Pets Land

Theme:

Pets Land

Theme Slug:
petsland

Vulnerability:
Local File Inclusion

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should switch themes.

Pippo

Theme:

Pippo

Theme Slug:
pippo

Vulnerability:
Local File Inclusion

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should switch themes.

Piqes

Theme:

Piqes

Theme Slug:
piqes

Vulnerability:
Local File Inclusion

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should switch themes.

Prider

Theme:

Prider

Theme Slug:
prider

Vulnerability:
Local File Inclusion

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should switch themes.

Rashy

Theme:

Rashy

Theme Slug:
rashy

Vulnerability:
Local File Inclusion

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should switch themes.

Roam

Theme:

Roam

Theme Slug:
roam

Vulnerability:
Insecure Direct Object References (IDOR)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should switch themes.

Snow Mountain

Theme:

Snow Mountain

Theme Slug:
snowmountain

Vulnerability:
Local File Inclusion

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should switch themes.

Struktur

Theme:

Struktur

Theme Slug:
struktur

Vulnerability:
Insecure Direct Object References (IDOR)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should switch themes.

MaxShop

Theme:

MaxShop

Theme Slug:
sw_maxshop

Vulnerability:
Local File Inclusion

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should switch themes.

Sweet Jane

Theme:

Sweet Jane

Theme Slug:
sweetjane

Vulnerability:
Insecure Direct Object References (IDOR)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should switch themes.

Tails

Theme:

Tails

Theme Slug:
tails

Vulnerability:
Local File Inclusion

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should switch themes.

TanTum

Theme:

TanTum

Theme Slug:
tantum

Vulnerability:
Local File Inclusion

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should switch themes.

T�bel

Theme:

T�bel

Theme Slug:
tobel

Vulnerability:
Local File Inclusion

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should switch themes.

Tornados

Theme:

Tornados

Theme Slug:
tornados

Vulnerability:
Local File Inclusion

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should switch themes.

Triply

Theme:

Triply

Theme Slug:
triply

Vulnerability:
Local File Inclusion

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should switch themes.

uReach

Theme:

uReach

Theme Slug:
ureach

Vulnerability:
Local File Inclusion

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should switch themes.

Vango

Theme:

Vango

Theme Slug:
vango

Vulnerability:
Local File Inclusion

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should switch themes.

Verdure

Theme:

Verdure

Theme Slug:
verdure

Vulnerability:
Insecure Direct Object References (IDOR)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should switch themes.

Weedles

Theme:

Weedles

Theme Slug:
weedles

Vulnerability:
Local File Inclusion

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should switch themes.

Yolox

Theme:

Yolox

Theme Slug:
yolox

Vulnerability:
Local File Inclusion

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should switch themes.

Oneline Lite

Theme Slug:
oneline-lite

Downloads
411,275

Vulnerability:
Broken Access Control

Patched in Version:
6.7

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 6.7.

Phlox

Theme:

Phlox

Theme Slug:
phlox

Downloads
1,709,830

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.17.11

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.17.11.

Bookory

Theme:

Bookory

Theme Slug:
bookory

Vulnerability:
Local File Inclusion

Patched in Version:
2.2.8

Severity Score:
High


The vulnerability has been patched, so you should update to version 2.2.8.

Calafate

Theme:

Calafate

Theme Slug:
calafate

Vulnerability:
Local File Inclusion

Patched in Version:
1.7.8

Severity Score:
High


The vulnerability has been patched, so you should update to version 1.7.8.

Corpkit

Theme:

Corpkit

Theme Slug:
corpkit

Vulnerability:
Local File Inclusion

Patched in Version:
2.0.1

Severity Score:
High


The vulnerability has been patched, so you should update to version 2.0.1.

Corpkit

Theme:

Corpkit

Theme Slug:
corpkit

Vulnerability:
Arbitrary File Upload

Patched in Version:
2.0.1

Severity Score:
Critical


The vulnerability has been patched, so you should update to version 2.0.1.

Grand Restaurant

Theme:

Grand Restaurant

Theme Slug:
grandrestaurant

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
7.0.9

Severity Score:
High


The vulnerability has been patched, so you should update to version 7.0.9.

Jobify

Theme:

Jobify

Theme Slug:
jobify

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
4.3.1

Severity Score:
High


The vulnerability has been patched, so you should update to version 4.3.1.

Lobo

Theme:

Lobo

Theme Slug:
lobo

Vulnerability:
SQL Injection

Patched in Version:
2.8.6

Severity Score:
High


The vulnerability has been patched, so you should update to version 2.8.6.

Neo Ocular

Theme:

Neo Ocular

Theme Slug:
neoocular

Vulnerability:
Local File Inclusion

Patched in Version:
1.2

Severity Score:
High


The vulnerability has been patched, so you should update to version 1.2.

Photography

Theme:

Photography

Theme Slug:
photography

Vulnerability:
Local File Inclusion

Patched in Version:
7.7.5

Severity Score:
High


The vulnerability has been patched, so you should update to version 7.7.5.

Traveler

Theme:

Traveler

Theme Slug:
traveler

Vulnerability:
Broken Access Control

Patched in Version:
3.2.7

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 3.2.7.

VidMov

Theme:

VidMov

Theme Slug:
vidmov

Vulnerability:
Path Traversal

Patched in Version:
2.3.9

Severity Score:
High


The vulnerability has been patched, so you should update to version 2.3.9.

Woffice

Theme:

Woffice

Theme Slug:
woffice

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
5.4.31

Severity Score:
High


The vulnerability has been patched, so you should update to version 5.4.31.

Related articles

Wait! Get exclusive hosting insights

Subscribe to our newsletter and stay ahead of the competition with expert advice from our hosting pros.

Loading form…