Line illustration showing a black application window on a dark black to purple gradient background overlaid with a large exclamation point alert icon and three bugs.

WordPress Vulnerability Report � February 4, 2026

In this report, 661 vulnerabilities have been publicly disclosed. Security patches for 497 of these plugins and themes are now available. Please run these updates as soon as possible. If you’re a Solid Security Pro user, the version management tool may have already warned you and updated these plugins, depending on your settings.

Currently, 164 plugin and theme vulnerabilities remain unpatched. If you’re a Solid Security Pro user, those vulnerabilities are already protected by the Solid Security firewall. Virtual patches from Patchstack will be applied when a vulnerability is considered high or medium risk. If no patch is forthcoming from the vendor or the vulnerable software has been marked “closed” and dropped from the official WordPress repositories, you should deactivate it soon and look for alternative solutions.

WordPress Core

WordPress 6.9.1 was released on February 3, 2026, as a short-cycle maintenance update, addressing 49 bugs across WordPress Core and the Block Editor, including fixes affecting the editor, mail functionality, and classic themes. Sites with automatic background updates may already be updated. We recommend reviewing the details and updating as part of your regular maintenance cycle.

The next major WordPress release, version 7.0, is scheduled for April 9, 2026, during WordCamp Asia.

WordPress Plugins � 488 Patched / 150 Unpatched

WP Shortcodes Plugin � Shortcodes Ultimate

Plugin Slug:
shortcodes-ultimate

Installations
400,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Master Slider � Responsive Touch Slider

Plugin Slug:
master-slider

Installations
60,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Piotnet Addons For Elementor

Plugin Slug:
piotnet-addons-for-elementor

Installations
30,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Kama Thumbnail

Plugin Slug:
kama-thumbnail

Installations
10,000+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Leadpages

Plugin Slug:
leadpages

Installations
10,000+

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Shiprocket

Plugin Slug:
shiprocket

Installations
10,000+

Vulnerability:
Insecure Direct Object References (IDOR)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

NextMove Lite � Thank You Page for WooCommerce

Plugin Slug:
woo-thank-you-page-nextmove-lite

Installations
10,000+

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

CLP Varnish Cache

Plugin Slug:
clp-varnish-cache

Installations
9,000+

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

WP FullCalendar

Plugin Slug:
wp-fullcalendar

Installations
9,000+

Vulnerability:
Sensitive Data Exposure

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

WP Subscribe

Plugin Slug:
wp-subscribe

Installations
9,000+

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Travelpayouts

Plugin Slug:
travelpayouts

Installations
7,000+

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

?????? ????? ???? ?? ???? ?? ?? ??

Plugin Slug:
farazsms

Installations
3,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Frontend File Manager Plugin

Plugin Slug:
nmedia-user-file-uploader

Installations
1,000+

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Nova Blocks by Pixelgrade

Plugin Slug:
nova-blocks

Installations
900+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Email Inquiry & Cart Options for WooCommerce

Plugin Slug:
woocommerce-email-inquiry-cart-options

Installations
900+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Generic Elements

Plugin Slug:
generic-elements-for-elementor

Installations
600+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Quick Restaurant Reservations

Plugin Slug:
quick-restaurant-reservations

Installations
600+

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Easy Hotel Booking � Powerful Hotel Booking

Plugin Slug:
easy-hotel

Installations
500+

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

SurveyJS: Drag & Drop Form Builder

Plugin Slug:
surveyjs

Installations
500+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

SurveyJS: Drag & Drop Form Builder

Plugin Slug:
surveyjs

Installations
500+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

SurveyJS: Drag & Drop Form Builder

Plugin Slug:
surveyjs

Installations
500+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Sendy

Plugin:

Sendy

Plugin Slug:
sendy

Installations
400+

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Asynchronous Javascript

Plugin Slug:
asynchronous-javascript

Installations
200+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

eDS Responsive Menu

Plugin Slug:
eds-responsive-menu

Installations
200+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

FeedWordPress Advanced Filters

Plugin Slug:
faf

Installations
200+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Membee Login

Plugin Slug:
membees-member-login-widget

Installations
200+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Widget Logic Visual

Plugin Slug:
widget-logic-visual

Installations
200+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

ID Arrays

Plugin Slug:
id-arrays

Installations
100+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

iSape

Plugin:

iSape

Plugin Slug:
isape

Installations
100+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

JobBoard Job listing plugin

Plugin Slug:
job-board-light

Installations
100+

Vulnerability:
Sensitive Data Exposure

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Mopinion Feedback Form

Plugin Slug:
mopinion-feedback-form

Installations
100+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

JavaScript Notifier

Plugin Slug:
javascript-notifier

Installations
50+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Simple Archive Generator

Plugin Slug:
simple-archive-generator

Installations
50+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Aardvark Plugin

Plugin:

Aardvark Plugin

Plugin Slug:
aardvark-plugin

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

ABC Notation

Plugin:

ABC Notation

Plugin Slug:
abc-notation

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

AhaChat Messenger Marketing

Plugin:

AhaChat Messenger Marketing

Plugin Slug:
ahachat-messenger-marketing

Vulnerability:
Broken Authentication

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

AhaChat Messenger Marketing

Plugin:

AhaChat Messenger Marketing

Plugin Slug:
ahachat-messenger-marketing

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

AHAthat

Plugin:

AHAthat

Plugin Slug:
ahathat

Vulnerability:
SQL Injection

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Allmart

Plugin:

Allmart

Plugin Slug:
allmart-core

Vulnerability:
SQL Injection

Patched in Version:
No Fix

Severity Score:
Critical


The vulnerability has not been patched. You should deactivate the plugin.

Anber Elementor Addon

Plugin:

Anber Elementor Addon

Plugin Slug:
anber-elementor-addon

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Aoa Downloadable

Plugin:

Aoa Downloadable

Plugin Slug:
aoa-downloadable

Vulnerability:
Arbitrary File Download

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Aoa Downloadable

Plugin:

Aoa Downloadable

Plugin Slug:
aoa-downloadable

Vulnerability:
Server Side Request Forgery (SSRF)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Ads Pro

Plugin:

Ads Pro

Plugin Slug:
ap-plugin-scripteo

Vulnerability:
SQL Injection

Patched in Version:
No Fix

Severity Score:
Critical


The vulnerability has not been patched. You should deactivate the plugin.

Ads Pro

Plugin:

Ads Pro

Plugin Slug:
ap-plugin-scripteo

Vulnerability:
SQL Injection

Patched in Version:
No Fix

Severity Score:
Critical


The vulnerability has not been patched. You should deactivate the plugin.

Ads Pro

Plugin:

Ads Pro

Plugin Slug:
ap-plugin-scripteo

Vulnerability:
SQL Injection

Patched in Version:
No Fix

Severity Score:
Critical


The vulnerability has not been patched. You should deactivate the plugin.

ArielBrailovsky-ViralAd

Plugin:

ArielBrailovsky-ViralAd

Plugin Slug:
arielbrailovsky-viralad

Vulnerability:
SQL Injection

Patched in Version:
No Fix

Severity Score:
Critical


The vulnerability has not been patched. You should deactivate the plugin.

Auto Thickbox

Plugin:

Auto Thickbox

Plugin Slug:
auto-thickbox

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Bitcoin Donate Button

Plugin:

Bitcoin Donate Button

Plugin Slug:
bitcoin-donate-button

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

BlockArt Blocks

Plugin:

BlockArt Blocks

Plugin Slug:
blockart-blocks

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

BlossomThemes Social Feed

Plugin:

BlossomThemes Social Feed

Plugin Slug:
blossomthemes-instagram-feed

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Booked

Plugin:

Booked

Plugin Slug:
booked

Vulnerability:
Broken Authentication

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Business Card

Plugin:

Business Card

Plugin Slug:
business-card-by-esterox-100

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Business Card

Plugin:

Business Card

Plugin Slug:
business-card-by-esterox-100

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Business Card

Plugin:

Business Card

Plugin Slug:
business-card-by-esterox-100

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Buttons Shortcode and Widget

Plugin:

Buttons Shortcode and Widget

Plugin Slug:
buttons-shortcode-and-widget

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Change WP URL

Plugin:

Change WP URL

Plugin Slug:
change-wp-url

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

cits-support-svg-webp-media-upload

Plugin:

cits-support-svg-webp-media-upload

Plugin Slug:
cits-support-svg-webp-media-upload

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Crete Core

Plugin:

Crete Core

Plugin Slug:
crete-core

Vulnerability:
SQL Injection

Patched in Version:
No Fix

Severity Score:
Critical


The vulnerability has not been patched. You should deactivate the plugin.

CRM Memberships

Plugin:

CRM Memberships

Plugin Slug:
crm-memberships

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

CRM Memberships

Plugin:

CRM Memberships

Plugin Slug:
crm-memberships

Vulnerability:
Broken Authentication

Patched in Version:
No Fix

Severity Score:
Critical


The vulnerability has not been patched. You should deactivate the plugin.

DesignThemes Core Features

Plugin:

DesignThemes Core Features

Plugin Slug:
designthemes-core-features

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Pixter Right Click Protect Images for WordPress

Plugin:

Pixter Right Click Protect Images for WordPress

Plugin Slug:
disable-right-click-powered-by-pixterme

Vulnerability:
Backdoor

Patched in Version:
No Fix

Severity Score:
Critical


The vulnerability has not been patched. You should deactivate the plugin.

Dyn Business Panel

Plugin:

Dyn Business Panel

Plugin Slug:
dyn-business-panel

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.
Plugin:

Easy Jump Links Menus

Plugin Slug:
easy-jump-links-menus

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Electio Core

Plugin:

Electio Core

Plugin Slug:
electio-core

Vulnerability:
SQL Injection

Patched in Version:
No Fix

Severity Score:
Critical


The vulnerability has not been patched. You should deactivate the plugin.

Elegant Addons for elementor

Plugin:

Elegant Addons for elementor

Plugin Slug:
elegant-addons-for-elementor

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Emerce Core

Plugin:

Emerce Core

Plugin Slug:
emerce-core

Vulnerability:
SQL Injection

Patched in Version:
No Fix

Severity Score:
Critical


The vulnerability has not been patched. You should deactivate the plugin.

Eyewear prescription form

Plugin:

Eyewear prescription form

Plugin Slug:
eyewear-prescription-form

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Feedback Modal for Website

Plugin:

Feedback Modal for Website

Plugin Slug:
feedback-modal-for-website

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Fintelligence Calculator

Plugin:

Fintelligence Calculator

Plugin Slug:
fintelligence-calculator

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Font Farsi

Plugin:

Font Farsi

Plugin Slug:
font-farsi

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Frontend Checklist

Plugin:

Frontend Checklist

Plugin Slug:
frontend-checklist

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

GoZen Forms

Plugin:

GoZen Forms

Plugin Slug:
gozen-forms

Vulnerability:
SQL Injection

Patched in Version:
No Fix

Severity Score:
Critical


The vulnerability has not been patched. You should deactivate the plugin.

Hide Categories Or Products On Shop Page

Plugin:

Hide Categories Or Products On Shop Page

Plugin Slug:
hide-categories-or-products-on-shop-page

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

HL Twitter

Plugin:

HL Twitter

Plugin Slug:
hl-twitter

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.
Plugin:

Image Hover Effects – Caption Hover with Carousel

Plugin Slug:
image-hover-effects-with-carousel

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Image Optimizer by wps.sk

Plugin:

Image Optimizer by wps.sk

Plugin Slug:
image-optimizer-wpssk

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

imwptip

Plugin:

imwptip

Plugin Slug:
imwptip

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Likes and Dislikes

Plugin:

Likes and Dislikes

Plugin Slug:
inprosysmedia-likes-dislikes-post

Vulnerability:
SQL Injection

Patched in Version:
No Fix

Severity Score:
Critical


The vulnerability has not been patched. You should deactivate the plugin.
Plugin:

Internal Link Builder

Plugin Slug:
internal-link-builder

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Joy Of Text Lite

Plugin:

Joy Of Text Lite

Plugin Slug:
joy-of-text

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

JustClick registration plugin

Plugin:

JustClick registration plugin

Plugin Slug:
justclick-subscriber

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Kalrav AI Agent

Plugin:

Kalrav AI Agent

Plugin Slug:
kalrav-ai-agent

Vulnerability:
Arbitrary File Upload

Patched in Version:
No Fix

Severity Score:
Critical


The vulnerability has not been patched. You should deactivate the plugin.

KiotViet Sync

Plugin:

KiotViet Sync

Plugin Slug:
kiotvietsync

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.
Plugin:

Kona Gallery Block

Plugin Slug:
kona-instagram-feed-for-gutenberg

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Light Poll

Plugin:

Light Poll

Plugin Slug:
light-poll

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Login Logout Register Menu

Plugin:

Login Logout Register Menu

Plugin Slug:
login-logout-register-menu

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Marketplace Items

Plugin:

Marketplace Items

Plugin Slug:
marketplace-items

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Medinik Core

Plugin:

Medinik Core

Plugin Slug:
medinik-core

Vulnerability:
SQL Injection

Patched in Version:
No Fix

Severity Score:
Critical


The vulnerability has not been patched. You should deactivate the plugin.

Meta-box GalleryMeta

Plugin Slug:
meta-box-gallerymeta

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
Low


The vulnerability has not been patched. You should deactivate the plugin.

Meta-box GalleryMeta

Plugin Slug:
meta-box-gallerymeta

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Search Atlas SEO

Plugin:

Search Atlas SEO

Plugin Slug:
metasync

Vulnerability:
Broken Authentication

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

ModelTheme Framework

Plugin:

ModelTheme Framework

Plugin Slug:
modeltheme-framework

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Takeads

Plugin:

Takeads

Plugin Slug:
monetize-link

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Nestbyte Core

Plugin:

Nestbyte Core

Plugin Slug:
nestbyte-core

Vulnerability:
SQL Injection

Patched in Version:
No Fix

Severity Score:
Critical


The vulnerability has not been patched. You should deactivate the plugin.

Newsletter Popup

Plugin:

Newsletter Popup

Plugin Slug:
newsletter-popup

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Newsletter Popup

Plugin:

Newsletter Popup

Plugin Slug:
newsletter-popup

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Newsletter Popup

Plugin:

Newsletter Popup

Plugin Slug:
newsletter-popup

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Norby AI

Plugin:

Norby AI

Plugin Slug:
norby-ai

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

PayPal Pay Now, Buy Now, Donation and Cart Buttons Shortcode

Plugin:

PayPal Pay Now, Buy Now, Donation and Cart Buttons Shortcode

Plugin Slug:
paypal-pay-buy-donation-and-cart-buttons-shortcode

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Pet Manager

Plugin:

Pet Manager

Plugin Slug:
pet-manager

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Image License and Protection

Plugin:

Image License and Protection

Plugin Slug:
pixter-image-digital-license

Vulnerability:
Backdoor

Patched in Version:
No Fix

Severity Score:
Critical


The vulnerability has not been patched. You should deactivate the plugin.

Postalicious

Plugin:

Postalicious

Plugin Slug:
postalicious

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Premmerce Brands for WooCommerce

Plugin:

Premmerce Brands for WooCommerce

Plugin Slug:
premmerce-woocommerce-brands

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Recooty

Plugin:

Recooty

Plugin Slug:
recooty

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Responsive Header

Plugin:

Responsive Header

Plugin Slug:
responsive-header

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Rupantorpay

Plugin:

Rupantorpay

Plugin Slug:
rupantorpay

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Saasplate Core

Plugin:

Saasplate Core

Plugin Slug:
saasplate-core

Vulnerability:
SQL Injection

Patched in Version:
No Fix

Severity Score:
Critical


The vulnerability has not been patched. You should deactivate the plugin.

SendPress Newsletters

Plugin:

SendPress Newsletters

Plugin Slug:
sendpress

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

SendPress Newsletters

Plugin:

SendPress Newsletters

Plugin Slug:
sendpress

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.
Plugin:

SEO Links Interlinking

Plugin Slug:
seo-links-interlinking

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Sermon Manager

Plugin:

Sermon Manager

Plugin Slug:
sermon-manager-for-wordpress

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Smart PopUp Blaster

Plugin:

Smart PopUp Blaster

Plugin Slug:
smart-popup-blaster

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Solidres � Hotel booking plugin

Plugin:

Solidres � Hotel booking plugin

Plugin Slug:
solidres

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

SP Project & Document Manager

Plugin:

SP Project & Document Manager

Plugin Slug:
sp-client-document-manager

Vulnerability:
Arbitrary File Download

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

SSP Debug

Plugin:

SSP Debug

Plugin Slug:
ssp-debugging

Vulnerability:
Sensitive Data Exposure

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

SVS Pricing Tables

Plugin:

SVS Pricing Tables

Plugin Slug:
svs-pricing-tables

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Testimonials Widget

Plugin:

Testimonials Widget

Plugin Slug:
testimonials-widget

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Top Comments

Plugin:

Top Comments

Plugin Slug:
top-comments

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Translate This gTranslate Shortcode

Plugin:

Translate This gTranslate Shortcode

Plugin Slug:
translate-this-google-translate-web-element-shortcode

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Quantic Social Image Hover

Plugin:

Quantic Social Image Hover

Plugin Slug:
tw-image-hover-share

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Twitter Bootstrap Collapse aka Accordian Shortcode

Plugin:

Twitter Bootstrap Collapse aka Accordian Shortcode

Plugin Slug:
twitter-bootstrap-collapse-aka-accordian-shortcode

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Uroan Core

Plugin:

Uroan Core

Plugin Slug:
uroan-core

Vulnerability:
SQL Injection

Patched in Version:
No Fix

Severity Score:
Critical


The vulnerability has not been patched. You should deactivate the plugin.

Vzaar Media Management

Plugin:

Vzaar Media Management

Plugin Slug:
vzaar-media-management

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Widget4Call

Plugin:

Widget4Call

Plugin Slug:
widget4call

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Woodly Core

Plugin:

Woodly Core

Plugin Slug:
woodly-core

Vulnerability:
SQL Injection

Patched in Version:
No Fix

Severity Score:
Critical


The vulnerability has not been patched. You should deactivate the plugin.

WoWPth

Plugin:

WoWPth

Plugin Slug:
wowpth

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

WordPress Auction Plugin

Plugin:

WordPress Auction Plugin

Plugin Slug:
wp-auctions

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

WP Easy FAQs

Plugin:

WP Easy FAQs

Plugin Slug:
wp-easy-faqs

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

WP Featherlight

Plugin:

WP Featherlight

Plugin Slug:
wp-featherlight

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

WP Google Ad Manager

Plugin:

WP Google Ad Manager

Plugin Slug:
wp-google-ad-manager-plugin

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

WP Logs Book

Plugin:

WP Logs Book

Plugin Slug:
wp-logs-book

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

WP MultiTasking

Plugin:

WP MultiTasking

Plugin Slug:
wp-multitasking

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

WP MultiTasking

Plugin:

WP MultiTasking

Plugin Slug:
wp-multitasking

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

WP MultiTasking

Plugin:

WP MultiTasking

Plugin Slug:
wp-multitasking

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

WP MultiTasking

Plugin:

WP MultiTasking

Plugin Slug:
wp-multitasking

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

WP MultiTasking

Plugin:

WP MultiTasking

Plugin Slug:
wp-multitasking

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

WP Online Users Stats

Plugin:

WP Online Users Stats

Plugin Slug:
wp-online-users-stats

Vulnerability:
SQL Injection

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

WP Prayer

Plugin:

WP Prayer

Plugin Slug:
wp-prayer

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

WP Prayer

Plugin:

WP Prayer

Plugin Slug:
wp-prayer

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

WP-Revive Adserver

Plugin:

WP-Revive Adserver

Plugin Slug:
wp-revive-adserver

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

WordPress Survey & Poll

Plugin:

WordPress Survey & Poll

Plugin Slug:
wp-survey-and-poll

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

YouTube Embed, Playlist and Popup by WpDevArt

Plugin:

YouTube Embed, Playlist and Popup by WpDevArt

Plugin Slug:
youtube-video-player

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

ElementsKit Elementor Addons and Templates

Plugin Slug:
elementskit-lite

Installations
1,000,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
3.5.3

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 3.5.3.
Plugin Slug:
cookie-notice

Installations
900,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.5.9

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.5.9.

Ocean Extra

Plugin Slug:
ocean-extra

Installations
500,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.4.7

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.4.7.

Happy Addons for Elementor

Plugin Slug:
happy-elementor-addons

Installations
400,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
3.20.8

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 3.20.8.

Happy Addons for Elementor

Plugin Slug:
happy-elementor-addons

Installations
400,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
3.10.4

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 3.10.4.

Happy Addons for Elementor

Plugin Slug:
happy-elementor-addons

Installations
400,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
3.12.3

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 3.12.3.

Happy Addons for Elementor

Plugin Slug:
happy-elementor-addons

Installations
400,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
3.10.5

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 3.10.5.

Happy Addons for Elementor

Plugin Slug:
happy-elementor-addons

Installations
400,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
3.10.5

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 3.10.5.

Happy Addons for Elementor

Plugin Slug:
happy-elementor-addons

Installations
400,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
3.10.5

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 3.10.5.

Happy Addons for Elementor

Plugin Slug:
happy-elementor-addons

Installations
400,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
3.10.5

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 3.10.5.

Happy Addons for Elementor

Plugin Slug:
happy-elementor-addons

Installations
400,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
3.10.5

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 3.10.5.

Happy Addons for Elementor

Plugin Slug:
happy-elementor-addons

Installations
400,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
3.10.8

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 3.10.8.

Happy Addons for Elementor

Plugin Slug:
happy-elementor-addons

Installations
400,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
3.11.0

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 3.11.0.

Happy Addons for Elementor

Plugin Slug:
happy-elementor-addons

Installations
400,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
3.10.9

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 3.10.9.

WP Shortcodes Plugin � Shortcodes Ultimate

Plugin Slug:
shortcodes-ultimate

Installations
400,000+

Vulnerability:
Server Side Request Forgery (SSRF)

Patched in Version:
7.4.6

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 7.4.6.

Unlimited Elements For Elementor

Plugin Slug:
unlimited-elements-for-elementor

Installations
300,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.5.136

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.5.136.

Unlimited Elements For Elementor

Plugin Slug:
unlimited-elements-for-elementor

Installations
300,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.0.2

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.0.2.

Unlimited Elements For Elementor

Plugin Slug:
unlimited-elements-for-elementor

Installations
300,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.5.113

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.5.113.

WP Go Maps (formerly WP Google Maps)

Plugin Slug:
wp-google-maps

Installations
300,000+

Vulnerability:
Broken Access Control

Patched in Version:
10.0.05

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 10.0.05.

Advanced Google reCAPTCHA

Plugin Slug:
advanced-google-recaptcha

Installations
200,000+

Vulnerability:
SQL Injection

Patched in Version:
1.30

Severity Score:
High


The vulnerability has been patched, so you should update to version 1.30.

FileOrganizer � WordPress File Manager

Plugin Slug:
fileorganizer

Installations
200,000+

Vulnerability:
Sensitive Data Exposure

Patched in Version:
1.0.8

Severity Score:
High


The vulnerability has been patched, so you should update to version 1.0.8.

Redirection for Contact Form 7

Plugin Slug:
wpcf7-redirect

Installations
200,000+

Vulnerability:
Arbitrary File Upload

Patched in Version:
3.2.8

Severity Score:
High


The vulnerability has been patched, so you should update to version 3.2.8.

Ivory Search � WordPress Search Plugin

Plugin Slug:
add-search-to-menu

Installations
100,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
5.5.14

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 5.5.14.

AI Engine � The Chatbot and AI Framework for WordPress

Plugin Slug:
ai-engine

Installations
100,000+

Vulnerability:
Server Side Request Forgery (SSRF)

Patched in Version:
3.3.3

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 3.3.3.

Element Pack Addons for Elementor

Plugin Slug:
bdthemes-element-pack-lite

Installations
100,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
5.6.1

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 5.6.1.

Element Pack Addons for Elementor

Plugin Slug:
bdthemes-element-pack-lite

Installations
100,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
5.6.1

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 5.6.1.

Element Pack Addons for Elementor

Plugin Slug:
bdthemes-element-pack-lite

Installations
100,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
5.6.12

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 5.6.12.

Element Pack Addons for Elementor

Plugin Slug:
bdthemes-element-pack-lite

Installations
100,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
5.10.3

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 5.10.3.

Element Pack Addons for Elementor

Plugin Slug:
bdthemes-element-pack-lite

Installations
100,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
5.10.3

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 5.10.3.

Prime Slider � Addons for Elementor

Plugin Slug:
bdthemes-prime-slider-lite

Installations
100,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
3.14.2

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 3.14.2.

Lightbox & Modal Popup WordPress Plugin � FooBox

Plugin Slug:
foobox-image-lightbox

Installations
100,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.7.35

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.7.35.
Plugin Slug:
foogallery

Installations
100,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.4.15

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.4.15.

GiveWP � Donation Plugin and Fundraising Platform

Plugin Slug:
give

Installations
100,000+

Vulnerability:
PHP Object Injection

Patched in Version:
3.14.2

Severity Score:
Critical


The vulnerability has been patched, so you should update to version 3.14.2.

WP Ghost (Hide My WP Ghost) � Security & Firewall

Plugin Slug:
hide-my-wp

Installations
100,000+

Vulnerability:
Arbitrary File Download

Patched in Version:
5.4.02

Severity Score:
High


The vulnerability has been patched, so you should update to version 5.4.02.
Plugin Slug:
modula-best-grid-gallery

Installations
100,000+

Vulnerability:
Broken Access Control

Patched in Version:
2.13.4

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.13.4.
Plugin Slug:
relevanssi

Installations
100,000+

Vulnerability:
Broken Access Control

Patched in Version:
4.22.1

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 4.22.1.
Plugin Slug:
relevanssi

Installations
100,000+

Vulnerability:
SQL Injection

Patched in Version:
4.26.0

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 4.26.0.
Plugin Slug:
responsive-lightbox

Installations
100,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.4.8

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.4.8.

Tutor LMS � eLearning and online course solution

Plugin Slug:
tutor

Installations
100,000+

Vulnerability:
Sensitive Data Exposure

Patched in Version:
3.9.6

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 3.9.6.

VK All in One Expansion Unit

Plugin Slug:
vk-all-in-one-expansion-unit

Installations
100,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
9.112.2

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 9.112.2.

Addon Elements for Elementor (formerly Elementor Addon Elements)

Plugin Slug:
addon-elements-for-elementor-page-builder

Installations
90,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.13.3

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.13.3.

Addon Elements for Elementor (formerly Elementor Addon Elements)

Plugin Slug:
addon-elements-for-elementor-page-builder

Installations
90,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.13.4

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.13.4.

Addon Elements for Elementor (formerly Elementor Addon Elements)

Plugin Slug:
addon-elements-for-elementor-page-builder

Installations
90,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.13.6

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.13.6.

Addon Elements for Elementor (formerly Elementor Addon Elements)

Plugin Slug:
addon-elements-for-elementor-page-builder

Installations
90,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.13.6

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.13.6.

Addon Elements for Elementor (formerly Elementor Addon Elements)

Plugin Slug:
addon-elements-for-elementor-page-builder

Installations
90,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.13.7

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.13.7.

Shortcodes and extra features for Phlox theme

Plugin Slug:
auxin-elements

Installations
90,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.17.3

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.17.3.

Shortcodes and extra features for Phlox theme

Plugin Slug:
auxin-elements

Installations
90,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.15.8

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.15.8.

Shortcodes and extra features for Phlox theme

Plugin Slug:
auxin-elements

Installations
90,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.15.8

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.15.8.

Shortcodes and extra features for Phlox theme

Plugin Slug:
auxin-elements

Installations
90,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.15.8

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.15.8.

Shortcodes and extra features for Phlox theme

Plugin Slug:
auxin-elements

Installations
90,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.15.8

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.15.8.

Shortcodes and extra features for Phlox theme

Plugin Slug:
auxin-elements

Installations
90,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.15.8

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.15.8.

Shortcodes and extra features for Phlox theme

Plugin Slug:
auxin-elements

Installations
90,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.17.1

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.17.1.

Shortcodes and extra features for Phlox theme

Plugin Slug:
auxin-elements

Installations
90,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.17.14

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.17.14.

Shortcodes and extra features for Phlox theme

Plugin Slug:
auxin-elements

Installations
90,000+

Vulnerability:
Sensitive Data Exposure

Patched in Version:
2.17.14

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.17.14.

Colibri Page Builder

Plugin Slug:
colibri-page-builder

Installations
90,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.0.274

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.0.274.

Colibri Page Builder

Plugin Slug:
colibri-page-builder

Installations
90,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.0.277

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.0.277.

JetFormBuilder � Dynamic Blocks Form Builder

Plugin Slug:
jetformbuilder

Installations
90,000+

Vulnerability:
Broken Access Control

Patched in Version:
3.5.4

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 3.5.4.

Custom Login Page Customizer

Plugin Slug:
login-customizer

Installations
90,000+

Vulnerability:
Privilege Escalation

Patched in Version:
2.5.4

Severity Score:
Critical


The vulnerability has been patched, so you should update to version 2.5.4.

HT Mega � Absolute Addons For Elementor

Plugin Slug:
ht-mega-for-elementor

Installations
80,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.4.7

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.4.7.

HT Mega � Absolute Addons For Elementor

Plugin Slug:
ht-mega-for-elementor

Installations
80,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.5.0

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.5.0.

HT Mega � Absolute Addons For Elementor

Plugin Slug:
ht-mega-for-elementor

Installations
80,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.5.1

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.5.1.

HT Mega � Absolute Addons For Elementor

Plugin Slug:
ht-mega-for-elementor

Installations
80,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.5.6

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.5.6.

Import and export users and customers

Plugin Slug:
import-users-from-csv-with-meta

Installations
80,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.26.7

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.26.7.

MaxButtons � Create buttons

Plugin Slug:
maxbuttons

Installations
80,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
9.8.1

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 9.8.1.

SlimStat Analytics

Plugin Slug:
wp-slimstat

Installations
80,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
5.3.3

Severity Score:
High


The vulnerability has been patched, so you should update to version 5.3.3.

Advanced Contact form 7 DB

Plugin Slug:
advanced-cf7-db

Installations
70,000+

Vulnerability:
Sensitive Data Exposure

Patched in Version:
2.0.3

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.0.3.

Brizy � Page Builder

Plugin Slug:
brizy

Installations
70,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.4.41

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.4.41.

Brizy � Page Builder

Plugin Slug:
brizy

Installations
70,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.4.42

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.4.42.

Database for Contact Form 7, WPforms, Elementor forms

Plugin Slug:
contact-form-entries

Installations
70,000+

Vulnerability:
Arbitrary File Deletion

Patched in Version:
1.4.4

Severity Score:
High


The vulnerability has been patched, so you should update to version 1.4.4.

Database for Contact Form 7, WPforms, Elementor forms

Plugin Slug:
contact-form-entries

Installations
70,000+

Vulnerability:
Broken Access Control

Patched in Version:
1.4.6

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.4.6.
Plugin Slug:
featured-image-from-url

Installations
70,000+

Vulnerability:
SQL Injection

Patched in Version:
5.2.8

Severity Score:
High


The vulnerability has been patched, so you should update to version 5.2.8.
Plugin Slug:
featured-image-from-url

Installations
70,000+

Vulnerability:
Server Side Request Forgery (SSRF)

Patched in Version:
5.3.2

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 5.3.2.

Exclusive Addons for Elementor

Plugin Slug:
exclusive-addons-for-elementor

Installations
60,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.6.9.3

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.6.9.3.

Exclusive Addons for Elementor

Plugin Slug:
exclusive-addons-for-elementor

Installations
60,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.6.9.5

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.6.9.5.

Master Slider � Responsive Touch Slider

Plugin Slug:
master-slider

Installations
60,000+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
3.10.0

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 3.10.0.

Qi Blocks

Plugin Slug:
qi-blocks

Installations
60,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.4

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.4.

Qi Blocks

Plugin Slug:
qi-blocks

Installations
60,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.4

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.4.

Ultimate Dashboard � Custom WordPress Dashboard

Plugin Slug:
ultimate-dashboard

Installations
60,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
3.8.6

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 3.8.6.

Ultimate Dashboard � Custom WordPress Dashboard

Plugin Slug:
ultimate-dashboard

Installations
60,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
3.8.6

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 3.8.6.

Bold Page Builder

Plugin Slug:
bold-page-builder

Installations
50,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
5.1.3

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 5.1.3.

Bold Page Builder

Plugin Slug:
bold-page-builder

Installations
50,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
4.8.9

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 4.8.9.

Bold Page Builder

Plugin Slug:
bold-page-builder

Installations
50,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
5.3.6

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 5.3.6.

Booking Calendar

Plugin Slug:
booking

Installations
50,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
10.14.7

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 10.14.7.

Booking Calendar

Plugin Slug:
booking

Installations
50,000+

Vulnerability:
Broken Access Control

Patched in Version:
10.14.14

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 10.14.14.

Booking Calendar

Plugin Slug:
booking

Installations
50,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
10.6.5

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 10.6.5.

Getwid � Gutenberg Blocks

Plugin Slug:
getwid

Installations
50,000+

Vulnerability:
Broken Access Control

Patched in Version:
2.0.11

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.0.11.

Search Exclude

Plugin Slug:
search-exclude

Installations
50,000+

Vulnerability:
Broken Access Control

Patched in Version:
2.5.0

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.5.0.

Sina Extension for Elementor

Plugin Slug:
sina-extension-for-elementor

Installations
50,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
3.5.4

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 3.5.4.

Themesflat Addons For Elementor

Plugin Slug:
themesflat-addons-for-elementor

Installations
50,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.1.3

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.1.3.

Themesflat Addons For Elementor

Plugin Slug:
themesflat-addons-for-elementor

Installations
50,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.1.3

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.1.3.

Themesflat Addons For Elementor

Plugin Slug:
themesflat-addons-for-elementor

Installations
50,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.1.3

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.1.3.

Themesflat Addons For Elementor

Plugin Slug:
themesflat-addons-for-elementor

Installations
50,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.1.3

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.1.3.

WP Recipe Maker

Plugin Slug:
wp-recipe-maker

Installations
50,000+

Vulnerability:
Broken Access Control

Patched in Version:
10.3.0

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 10.3.0.

Livemesh Addons by Elementor

Plugin Slug:
addons-for-elementor

Installations
40,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
8.3.6

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 8.3.6.

Livemesh Addons by Elementor

Plugin Slug:
addons-for-elementor

Installations
40,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
8.3.6

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 8.3.6.

Livemesh Addons by Elementor

Plugin Slug:
addons-for-elementor

Installations
40,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
8.3.6

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 8.3.6.

Livemesh Addons by Elementor

Plugin Slug:
addons-for-elementor

Installations
40,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
8.3.6

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 8.3.6.

Livemesh Addons by Elementor

Plugin Slug:
addons-for-elementor

Installations
40,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
8.3.6

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 8.3.6.

Livemesh Addons by Elementor

Plugin Slug:
addons-for-elementor

Installations
40,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
8.4

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 8.4.

Livemesh Addons by Elementor

Plugin Slug:
addons-for-elementor

Installations
40,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
8.4

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 8.4.

Advanced iFrame

Plugin Slug:
advanced-iframe

Installations
40,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2025.0

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2025.0.

Calculated Fields Form

Plugin Slug:
calculated-fields-form

Installations
40,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
5.2.62

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 5.2.62.
Plugin Slug:
carousel-slider

Installations
40,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.2.15

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.2.15.

FunnelKit � Funnel Builder for WooCommerce Checkout

Plugin Slug:
funnel-builder

Installations
40,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
3.13.1.3

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 3.13.1.3.

Genesis Blocks

Plugin Slug:
genesis-blocks

Installations
40,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
3.1.3

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 3.1.3.

Genesis Blocks

Plugin Slug:
genesis-blocks

Installations
40,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
3.1.4

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 3.1.4.
Plugin Slug:
robo-gallery

Installations
40,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
3.2.23

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 3.2.23.
Plugin Slug:
yith-woocommerce-ajax-search

Installations
40,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.7.1

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.7.1.

Ditty � Responsive News Tickers, Sliders, and Lists

Plugin Slug:
ditty-news-ticker

Installations
30,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
3.1.46

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 3.1.46.

Piotnet Addons For Elementor

Plugin Slug:
piotnet-addons-for-elementor

Installations
30,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.4.29

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.4.29.

Post Grid

Plugin Slug:
post-grid

Installations
30,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.2.81

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.2.81.

Post Grid

Plugin Slug:
post-grid

Installations
30,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.2.81

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.2.81.

SEO Plugin by Squirrly SEO

Plugin Slug:
squirrly-seo

Installations
30,000+

Vulnerability:
SQL Injection

Patched in Version:
12.3.20

Severity Score:
High


The vulnerability has been patched, so you should update to version 12.3.20.

Stop Spammers Classic

Plugin Slug:
stop-spammer-registrations-plugin

Installations
30,000+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
2026.2

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2026.2.

Stratum Widgets for Elementor

Plugin Slug:
stratum

Installations
30,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.6.1

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.6.1.

Tutor LMS Elementor Addons

Plugin Slug:
tutor-lms-elementor-addons

Installations
30,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.1.5

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.1.5.

WP Video Lightbox

Plugin Slug:
wp-post-447778 wp-video-lightbox

Installations
30,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.9.12

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.9.12.

Xpro Addons � 140+ Widgets for Elementor

Plugin Slug:
xpro-elementor-addons

Installations
30,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.4.8

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.4.8.
Plugin Slug:
final-tiles-grid-gallery-lite

Installations
20,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
3.6.9

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 3.6.9.

New User Approve

Plugin Slug:
new-user-approve

Installations
20,000+

Vulnerability:
Broken Access Control

Patched in Version:
3.2.3

Severity Score:
High


The vulnerability has been patched, so you should update to version 3.2.3.

Secure Copy Content Protection and Content Locking

Plugin Slug:
secure-copy-content-protection

Installations
20,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
4.1.7

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 4.1.7.

Snow Monkey Forms

Plugin Slug:
snow-monkey-forms

Installations
20,000+

Vulnerability:
Arbitrary File Deletion

Patched in Version:
12.0.4

Severity Score:
High


The vulnerability has been patched, so you should update to version 12.0.4.

Ultimate Addons for Beaver Builder � Lite

Plugin Slug:
ultimate-addons-for-beaver-builder-lite

Installations
20,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.5.8

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.5.8.

Ultimate Addons for Beaver Builder � Lite

Plugin Slug:
ultimate-addons-for-beaver-builder-lite

Installations
20,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.5.8

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.5.8.

Ultimate Addons for Beaver Builder � Lite

Plugin Slug:
ultimate-addons-for-beaver-builder-lite

Installations
20,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.5.8

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.5.8.

Ultimate Addons for Beaver Builder � Lite

Plugin Slug:
ultimate-addons-for-beaver-builder-lite

Installations
20,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.5.8

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.5.8.

Welcart e-Commerce

Plugin Slug:
usc-e-shop

Installations
20,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.11.21

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.11.21.

Appointment Hour Booking � Booking Calendar

Plugin Slug:
appointment-hour-booking

Installations
10,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.5.61

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.5.61.

Bold Timeline Lite

Plugin Slug:
bold-timeline-lite

Installations
10,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.2.8

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.2.8.

Passster � Password Protect Pages and Content

Plugin Slug:
content-protector

Installations
10,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
4.2.25

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 4.2.25.

Crelly Slider

Plugin Slug:
crelly-slider

Installations
10,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.4.7

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.4.7.

Content Blocks (Custom Post Widget)

Plugin Slug:
custom-post-widget

Installations
10,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
3.3.1

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 3.3.1.

Content Blocks (Custom Post Widget)

Plugin Slug:
custom-post-widget

Installations
10,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
3.3.6

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 3.3.6.

WP Customer Area

Plugin Slug:
customer-area

Installations
10,000+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
8.2.5

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 8.2.5.

LA-Studio Element Kit for Elementor

Plugin Slug:
lastudio-element-kit

Installations
10,000+

Vulnerability:
Local File Inclusion

Patched in Version:
1.3.9

Severity Score:
High


The vulnerability has been patched, so you should update to version 1.3.9.

LA-Studio Element Kit for Elementor

Plugin Slug:
lastudio-element-kit

Installations
10,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.5.0

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.5.0.

Motors � Car Dealership & Classified Listings Plugin

Plugin Slug:
motors-car-dealership-classified-listings

Installations
10,000+

Vulnerability:
Broken Access Control

Patched in Version:
1.4.58

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.4.58.

Child Theme Creator by Orbisius

Plugin Slug:
orbisius-child-theme-creator

Installations
10,000+

Vulnerability:
Broken Access Control

Patched in Version:
1.5.6

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.5.6.

Order Minimum/Maximum Amount Limits for WooCommerce

Plugin Slug:
order-minimum-amount-for-woocommerce

Installations
10,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
4.6.9

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 4.6.9.

OSM � OpenStreetMap

Plugin Slug:
osm

Installations
10,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
6.0.4

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 6.0.4.

Recipe Card Blocks Lite

Plugin Slug:
recipe-card-blocks-by-wpzoom

Installations
10,000+

Vulnerability:
SQL Injection

Patched in Version:
3.4.13

Severity Score:
High


The vulnerability has been patched, so you should update to version 3.4.13.

SupportCandy � Helpdesk & Customer Support Ticket System

Plugin Slug:
supportcandy

Installations
10,000+

Vulnerability:
Insecure Direct Object References (IDOR)

Patched in Version:
3.4.5

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 3.4.5.
Plugin Slug:
testimonials-carousel-elementor

Installations
10,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
10.2.0

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 10.2.0.

Countdown Timer � Widget Countdown

Plugin Slug:
widget-countdown

Installations
10,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.7.8

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.7.8.

Simple Shopping Cart

Plugin Slug:
wordpress-simple-paypal-shopping-cart

Installations
10,000+

Vulnerability:
Insecure Direct Object References (IDOR)

Patched in Version:
5.1.4

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 5.1.4.

Backup, Restore and Migrate your sites with XCloner

Plugin Slug:
xcloner-backup-and-restore

Installations
10,000+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
4.8.3

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 4.8.3.

Prisna GWT � Google Website Translator

Plugin Slug:
google-website-translator

Installations
9,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.4.14

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.4.14.

Qubely � Advanced Gutenberg Blocks

Plugin Slug:
qubely

Installations
9,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.8.13

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.8.13.

Ultimate Coming Soon & Maintenance

Plugin Slug:
ultimate-coming-soon

Installations
9,000+

Vulnerability:
Broken Access Control

Patched in Version:
1.1.0

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.1.0.

Ultimate Coming Soon & Maintenance

Plugin Slug:
ultimate-coming-soon

Installations
9,000+

Vulnerability:
Broken Access Control

Patched in Version:
1.1.0

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.1.0.

VikBooking Hotel Booking Engine & PMS

Plugin Slug:
vikbooking

Installations
9,000+

Vulnerability:
Broken Access Control

Patched in Version:
1.6.8

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.6.8.

NEX-Forms � Ultimate Forms Plugin for WordPress

Plugin Slug:
nex-forms-express-wp-form-builder

Installations
8,000+

Vulnerability:
Broken Access Control

Patched in Version:
9.1.9

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 9.1.9.

EventPrime � Events Calendar, Bookings and Tickets

Plugin Slug:
eventprime-event-calendar-management

Installations
7,000+

Vulnerability:
Broken Access Control

Patched in Version:
3.4.3

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 3.4.3.

EventPrime � Events Calendar, Bookings and Tickets

Plugin Slug:
eventprime-event-calendar-management

Installations
7,000+

Vulnerability:
Sensitive Data Exposure

Patched in Version:
4.2.8.0

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 4.2.8.0.

EventPrime � Events Calendar, Bookings and Tickets

Plugin Slug:
eventprime-event-calendar-management

Installations
7,000+

Vulnerability:
Broken Access Control

Patched in Version:
4.2.8.1

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 4.2.8.1.

EventON � Events Calendar

Plugin Slug:
eventon-lite

Installations
6,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.2.8

Severity Score:
High


The vulnerability has been patched, so you should update to version 2.2.8.

EventON � Events Calendar

Plugin Slug:
eventon-lite

Installations
6,000+

Vulnerability:
Sensitive Data Exposure

Patched in Version:
2.2.8

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.2.8.

EventON � Events Calendar

Plugin Slug:
eventon-lite

Installations
6,000+

Vulnerability:
Broken Access Control

Patched in Version:
2.2.8

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.2.8.

EventON � Events Calendar

Plugin Slug:
eventon-lite

Installations
6,000+

Vulnerability:
Broken Access Control

Patched in Version:
2.2.9

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.2.9.

EventON � Events Calendar

Plugin Slug:
eventon-lite

Installations
6,000+

Vulnerability:
Broken Access Control

Patched in Version:
2.2.8

Severity Score:
High


The vulnerability has been patched, so you should update to version 2.2.8.

Hunk Companion

Plugin Slug:
hunk-companion

Installations
6,000+

Vulnerability:
Broken Access Control

Patched in Version:
1.9.0

Severity Score:
Critical


The vulnerability has been patched, so you should update to version 1.9.0.

Pearl � Header Builder

Plugin Slug:
pearl-header-builder

Installations
6,000+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
1.3.9

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.3.9.

ProfileGrid � User Profiles, Groups and Communities

Plugin Slug:
profilegrid-user-profiles-groups-and-communities

Installations
6,000+

Vulnerability:
PHP Object Injection

Patched in Version:
5.9.4.6

Severity Score:
High


The vulnerability has been patched, so you should update to version 5.9.4.6.

ProfileGrid � User Profiles, Groups and Communities

Plugin Slug:
profilegrid-user-profiles-groups-and-communities

Installations
6,000+

Vulnerability:
Broken Access Control

Patched in Version:
5.9.4.5

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 5.9.4.5.

Survey Maker

Plugin Slug:
survey-maker

Installations
6,000+

Vulnerability:
Broken Access Control

Patched in Version:
5.1.9.5

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 5.1.9.5.

Booking Calendar | Appointment Booking | Bookit

Plugin Slug:
bookit

Installations
5,000+

Vulnerability:
Broken Access Control

Patched in Version:
2.5.1

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.5.1.
Plugin Slug:
easy-image-gallery

Installations
5,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.5.3

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.5.3.

Return Refund and Exchange For WooCommerce

Plugin Slug:
woo-refund-and-exchange-lite

Installations
5,000+

Vulnerability:
Insecure Direct Object References (IDOR)

Patched in Version:
4.5.6

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 4.5.6.

CubeWP Framework

Plugin Slug:
cubewp-framework

Installations
4,000+

Vulnerability:
Sensitive Data Exposure

Patched in Version:
1.1.28

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.1.28.

CubeWP Framework

Plugin Slug:
cubewp-framework

Installations
4,000+

Vulnerability:
Broken Access Control

Patched in Version:
1.1.28

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.1.28.

CubeWP Framework

Plugin Slug:
cubewp-framework

Installations
4,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.1.27

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.1.27.

ELEX WooCommerce Bulk Edit Products, Prices & Attributes (Basic)

Plugin Slug:
elex-bulk-edit-products-prices-attributes-for-woocommerce-basic

Installations
4,000+

Vulnerability:
SQL Injection

Patched in Version:
1.5.0

Severity Score:
High


The vulnerability has been patched, so you should update to version 1.5.0.

HelloAsso

Plugin Slug:
helloasso

Installations
4,000+

Vulnerability:
Broken Access Control

Patched in Version:
1.1.11

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.1.11.

MediaPress

Plugin Slug:
mediapress

Installations
4,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.6.2

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.6.2.

WPZOOM Addons for Beaver Builder

Plugin Slug:
wpzoom-addons-for-beaver-builder

Installations
4,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.3.5

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.3.5.

WPZOOM Addons for Beaver Builder

Plugin Slug:
wpzoom-addons-for-beaver-builder

Installations
4,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.3.5

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.3.5.

WPZOOM Addons for Beaver Builder

Plugin Slug:
wpzoom-addons-for-beaver-builder

Installations
4,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.3.5

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.3.5.

WPZOOM Addons for Beaver Builder

Plugin Slug:
wpzoom-addons-for-beaver-builder

Installations
4,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.3.5

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.3.5.

AVIF Uploader

Plugin Slug:
avif-support

Installations
3,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.1.1

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.1.1.
Plugin Slug:
photoblocks-grid-gallery

Installations
3,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.3.3

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.3.3.

Tickera � Sell Tickets & Manage Events

Plugin Slug:
tickera-event-ticketing-system

Installations
3,000+

Vulnerability:
Sensitive Data Exposure

Patched in Version:
3.5.4.9

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 3.5.4.9.

WP-DownloadManager

Plugin Slug:
wp-downloadmanager

Installations
3,000+

Vulnerability:
Arbitrary File Deletion

Patched in Version:
1.68.11

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.68.11.

WP-WebAuthn

Plugin Slug:
wp-webauthn

Installations
3,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.3.4

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.3.4.

WP Directory Kit

Plugin Slug:
wpdirectorykit

Installations
3,000+

Vulnerability:
Sensitive Data Exposure

Patched in Version:
1.5.0

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.5.0.

KiviCare � Clinic & Patient Management System (EHR)

Plugin Slug:
kivicare-clinic-management-system

Installations
2,000+

Vulnerability:
SQL Injection

Patched in Version:
4.0.0

Severity Score:
High


The vulnerability has been patched, so you should update to version 4.0.0.

Markup Markdown

Plugin Slug:
markup-markdown

Installations
2,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
3.20.10

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 3.20.10.

Melapress Login Security

Plugin Slug:
melapress-login-security

Installations
2,000+

Vulnerability:
Broken Access Control

Patched in Version:
2.1.1

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.1.1.

RSS Feed Widget

Plugin Slug:
rss-feed-widget

Installations
2,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
3.0.0

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 3.0.0.

WPBITS Addons For Elementor Page Builder

Plugin Slug:
wpbits-addons-for-elementor

Installations
2,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.5

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.5.

WPBITS Addons For Elementor Page Builder

Plugin Slug:
wpbits-addons-for-elementor

Installations
2,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.8.1

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.8.1.

Geo Controller

Plugin Slug:
cf-geoplugin

Installations
1,000+

Vulnerability:
Content Injection

Patched in Version:
8.7.0

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 8.7.0.

Smart Online Order for Clover

Plugin Slug:
clover-online-orders

Installations
1,000+

Vulnerability:
Broken Access Control

Patched in Version:
1.5.7

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.5.7.

Web3 Crypto Payments by DePay for WooCommerce

Plugin Slug:
depay-payments-for-woocommerce

Installations
1,000+

Vulnerability:
Broken Access Control

Patched in Version:
2.12.18

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.12.18.

Double the Donation � A workplace giving tool

Plugin Slug:
double-the-donation

Installations
1,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
3.1.0

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 3.1.0.

Educare � Students & Result Management System

Plugin Slug:
educare

Installations
1,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.6.2

Severity Score:
High


The vulnerability has been patched, so you should update to version 1.6.2.

EPROLO-Dropshipping

Plugin Slug:
eprolo-dropshipping

Installations
1,000+

Vulnerability:
Broken Access Control

Patched in Version:
2.4.0

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.4.0.

Flamix: Bitrix24 and Contact Form 7 integrations

Plugin Slug:
flamix-bitrix24-and-contact-forms-7-integrations

Installations
1,000+

Vulnerability:
Sensitive Data Exposure

Patched in Version:
3.2.0

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 3.2.0.

Friendly Functions for Welcart

Plugin Slug:
friendly-functions-for-welcart

Installations
1,000+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
1.2.6

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.2.6.

Mizan Demo Importer

Plugin Slug:
mizan-demo-importer

Installations
1,000+

Vulnerability:
Broken Access Control

Patched in Version:
0.1.4

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 0.1.4.

Nelio Popups

Plugin Slug:
nelio-popups

Installations
1,000+

Vulnerability:
Broken Access Control

Patched in Version:
1.3.6

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.3.6.

Frontend File Manager Plugin

Plugin Slug:
nmedia-user-file-uploader

Installations
1,000+

Vulnerability:
Arbitrary File Deletion

Patched in Version:
23.5

Severity Score:
High


The vulnerability has been patched, so you should update to version 23.5.

PDF Generator Addon for Elementor Page Builder

Plugin Slug:
pdf-generator-addon-for-elementor-page-builder

Installations
1,000+

Vulnerability:
Arbitrary File Download

Patched in Version:
2.0.1

Severity Score:
High


The vulnerability has been patched, so you should update to version 2.0.1.

Private Google Calendars

Plugin Slug:
private-google-calendars

Installations
1,000+

Vulnerability:
Broken Access Control

Patched in Version:
20251128

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 20251128.

Save as PDF Plugin by PDFCrowd

Plugin Slug:
save-as-pdf-by-pdfcrowd

Installations
1,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
4.5.6

Severity Score:
High


The vulnerability has been patched, so you should update to version 4.5.6.

Simple Popup Plugin

Plugin Slug:
simple-popup-plugin

Installations
1,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
4.6

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 4.6.

Squelch Tabs and Accordions Shortcodes

Plugin Slug:
squelch-tabs-and-accordions-shortcodes

Installations
1,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
0.4.4

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 0.4.4.

Subscriptions & Memberships for PayPal

Plugin Slug:
subscriptions-memberships-for-paypal

Installations
1,000+

Vulnerability:
Broken Access Control

Patched in Version:
1.1.8

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.1.8.

Tainacan

Plugin:

Tainacan

Plugin Slug:
tainacan

Installations
1,000+

Vulnerability:
Broken Access Control

Patched in Version:
1.0.2

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.0.2.

Tutor LMS � Migration Tool

Plugin Slug:
tutor-lms-migration-tool

Installations
1,000+

Vulnerability:
Broken Access Control

Patched in Version:
2.2.1

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.2.1.

WC Builder � WooCommerce Page Builder for WPBakery

Plugin Slug:
wc-builder

Installations
1,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.2.1

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.2.1.

WishSuite � Wishlist for WooCommerce

Plugin Slug:
wishsuite

Installations
1,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.5.2

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.5.2.

Easy 3D Viewer

Plugin Slug:
woo-3d-viewer

Installations
1,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.8.6.7

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.8.6.7.

WP Sync for Notion � Notion to WordPress

Plugin Slug:
wp-sync-for-notion

Installations
1,000+

Vulnerability:
Broken Access Control

Patched in Version:
1.7.1

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.7.1.

Zephyr Project Manager

Plugin Slug:
zephyr-project-manager

Installations
1,000+

Vulnerability:
Privilege Escalation

Patched in Version:
3.3.102

Severity Score:
High


The vulnerability has been patched, so you should update to version 3.3.102.

CBX Map for Google Map & OpenStreetMap

Plugin Slug:
cbxgooglemap

Installations
900+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.0.2

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.0.2.

ContentStudio

Plugin Slug:
contentstudio

Installations
900+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
1.4.0

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.4.0.

Ebook Store

Plugin Slug:
ebook-store

Installations
900+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
5.8015

Severity Score:
High


The vulnerability has been patched, so you should update to version 5.8015.

Omnipress

Plugin Slug:
omnipress

Installations
900+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.6.6

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.6.6.

3DPrint Lite

Plugin Slug:
3dprint-lite

Installations
800+

Vulnerability:
SQL Injection

Patched in Version:
2.1.3.7

Severity Score:
High


The vulnerability has been patched, so you should update to version 2.1.3.7.

3DPrint Lite

Plugin Slug:
3dprint-lite

Installations
800+

Vulnerability:
SQL Injection

Patched in Version:
2.1.3.7

Severity Score:
High


The vulnerability has been patched, so you should update to version 2.1.3.7.

3DPrint Lite

Plugin Slug:
3dprint-lite

Installations
800+

Vulnerability:
SQL Injection

Patched in Version:
2.1.3.7

Severity Score:
High


The vulnerability has been patched, so you should update to version 2.1.3.7.

Frontis Blocks � Block Library for the Block Editor

Plugin Slug:
frontis-blocks

Installations
800+

Vulnerability:
Server Side Request Forgery (SSRF)

Patched in Version:
1.1.7

Severity Score:
High


The vulnerability has been patched, so you should update to version 1.1.7.

Confetti Fall Animation

Plugin Slug:
confetti-fall-animation

Installations
600+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.3.2

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.3.2.

Frontend Dashboard

Plugin Slug:
frontend-dashboard

Installations
600+

Vulnerability:
Privilege Escalation

Patched in Version:
2.2.8

Severity Score:
High


The vulnerability has been patched, so you should update to version 2.2.8.

Simplebooklet PDF Viewer and Embedder

Plugin Slug:
simplebooklet

Installations
600+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.1.3

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.1.3.

eMagicOne Store Manager for WooCommerce

Plugin Slug:
store-manager-connector

Installations
600+

Vulnerability:
Arbitrary File Upload

Patched in Version:
1.3.0

Severity Score:
Critical


The vulnerability has been patched, so you should update to version 1.3.0.

Polls CP

Plugin:

Polls CP

Plugin Slug:
cp-polls

Installations
500+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.0.77

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.0.77.

Dynamic AJAX Product Filters for WooCommerce

Plugin Slug:
dynamic-ajax-product-filters-for-woocommerce

Installations
500+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.3.8

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.3.8.

Easy Replace Image

Plugin Slug:
easy-replace-image

Installations
500+

Vulnerability:
Broken Access Control

Patched in Version:
3.5.3

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 3.5.3.

EZ SQL Reports Shortcode Widget and DB Backup

Plugin Slug:
elisqlreports

Installations
500+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
5.25.25

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 5.25.25.

g-FFL Cockpit

Plugin Slug:
g-ffl-cockpit

Installations
500+

Vulnerability:
Broken Access Control

Patched in Version:
1.8.0

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.8.0.

Simple calendar for Elementor

Plugin Slug:
simple-calendar-for-elementor

Installations
500+

Vulnerability:
Broken Access Control

Patched in Version:
1.6.7

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.6.7.

SurveyJS: Drag & Drop Form Builder

Plugin Slug:
surveyjs

Installations
500+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
1.20.27

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.20.27.

VidShop � Shoppable Videos for WooCommerce

Plugin Slug:
vidshop-for-woocommerce

Installations
400+

Vulnerability:
SQL Injection

Patched in Version:
1.1.5

Severity Score:
Critical


The vulnerability has been patched, so you should update to version 1.1.5.

CYAN Backup

Plugin Slug:
cyan-backup

Installations
300+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.5.3

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.5.3.

DeBounce Email Validator

Plugin Slug:
debounce-io-email-validator

Installations
300+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
5.8.1

Severity Score:
High


The vulnerability has been patched, so you should update to version 5.8.1.

ELEX WordPress HelpDesk & Customer Ticketing System

Plugin Slug:
elex-helpdesk-customer-support-ticket-system

Installations
300+

Vulnerability:
Broken Access Control

Patched in Version:
3.3.2

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 3.3.2.

ELEX WordPress HelpDesk & Customer Ticketing System

Plugin Slug:
elex-helpdesk-customer-support-ticket-system

Installations
300+

Vulnerability:
Broken Access Control

Patched in Version:
3.3.2

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 3.3.2.

ELEX WordPress HelpDesk & Customer Ticketing System

Plugin Slug:
elex-helpdesk-customer-support-ticket-system

Installations
300+

Vulnerability:
Broken Access Control

Patched in Version:
3.3.2

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 3.3.2.

ELEX WordPress HelpDesk & Customer Ticketing System

Plugin Slug:
elex-helpdesk-customer-support-ticket-system

Installations
300+

Vulnerability:
Broken Access Control

Patched in Version:
3.3.6

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 3.3.6.

TableOn � WordPress Posts Table Filterable�

Plugin Slug:
posts-table-filterable

Installations
300+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.0.4.2

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.0.4.2.

Photo Contest | Competition | Video Contest

Plugin Slug:
totalcontest-lite

Installations
300+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.9.0

Severity Score:
High


The vulnerability has been patched, so you should update to version 2.9.0.

Webcake � Landing Page Builder

Plugin Slug:
webcake

Installations
300+

Vulnerability:
Broken Access Control

Patched in Version:
1.2

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.2.

Accept Stripe Payments Using Contact Form 7

Plugin Slug:
accept-stripe-payments-using-contact-form-7

Installations
200+

Vulnerability:
Sensitive Data Exposure

Patched in Version:
2.6

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.6.

Autoship Cloud for WooCommerce Subscription Products

Plugin Slug:
autoship-cloud

Installations
200+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.8.1

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.8.1.

Site.pro for WooCommerce

Plugin Slug:
b1-accounting

Installations
200+

Vulnerability:
SQL Injection

Patched in Version:
2.2.57

Severity Score:
High


The vulnerability has been patched, so you should update to version 2.2.57.
Plugin Slug:
header-footer-code

Installations
200+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.2

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.2.
Plugin Slug:
invoice-payment-for-woocommerce

Installations
200+

Vulnerability:
Broken Access Control

Patched in Version:
2.8.1

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.8.1.

Premmerce Wishlist for WooCommerce

Plugin Slug:
premmerce-woocommerce-wishlist

Installations
200+

Vulnerability:
Broken Access Control

Patched in Version:
1.1.11

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.1.11.

Simple User Registration

Plugin Slug:
wp-registration

Installations
200+

Vulnerability:
Privilege Escalation

Patched in Version:
6.4

Severity Score:
Critical


The vulnerability has been patched, so you should update to version 6.4.

Zigaform � Price Calculator & Cost Estimation Form Builder Lite

Plugin Slug:
zigaform-calculator-cost-estimation-form-builder-lite

Installations
200+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
7.4.8

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 7.4.8.

Run Contests, Raffles, and Giveaways with ContestsWP

Plugin Slug:
contest-code-checker

Installations
100+

Vulnerability:
Sensitive Data Exposure

Patched in Version:
2.1.1

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.1.1.

Course Booking System

Plugin Slug:
course-booking-system

Installations
100+

Vulnerability:
Broken Access Control

Patched in Version:
6.1.6

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 6.1.6.

Feedify � Web Push Notifications

Plugin Slug:
push-notification-by-feedify

Installations
100+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.4.6

Severity Score:
High


The vulnerability has been patched, so you should update to version 2.4.6.

Chatbot with ChatGPT WordPress

Plugin Slug:
smartsearchwp

Installations
100+

Vulnerability:
Broken Access Control

Patched in Version:
2.4.5

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.4.5.

Uptodown APK Download Widget

Plugin Slug:
uptodown-apk-download-widget

Installations
100+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
0.1.11

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 0.1.11.

WP To Do

Plugin:

WP To Do

Plugin Slug:
wp-todo

Installations
100+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.0.1

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.0.1.

WP To Do

Plugin:

WP To Do

Plugin Slug:
wp-todo

Installations
100+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
2.0.1

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.0.1.

WP To Do

Plugin:

WP To Do

Plugin Slug:
wp-todo

Installations
100+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
2.0.1

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.0.1.

Pdf & Print to Post � Custom Post Type and Pages

Plugin Slug:
post-to-pdf

Installations
90+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.1

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.1.

Ganohrs Toggle Shortcode

Plugin Slug:
ganohrs-toggle-shortcode

Installations
80+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
0.2.5

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 0.2.5.

Linear

Plugin:

Linear

Plugin Slug:
linear

Installations
80+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.8.0

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.8.0.

GeoDataSource Country Region DropDown

Plugin Slug:
geodatasource-country-region-dropdown

Installations
70+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.0.2

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.0.2.

Zigaform � Form Builder Lite

Plugin Slug:
zigaform-form-builder-lite

Installations
70+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
7.4.8

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 7.4.8.

Target Video Easy Publish

Plugin Slug:
brid-video-easy-publish

Installations
60+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
3.8.9

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 3.8.9.

IRM Newsroom

Plugin Slug:
irm-newsroom

Installations
60+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.2.20

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.2.20.

IRM Newsroom

Plugin Slug:
irm-newsroom

Installations
60+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.2.20

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.2.20.

Binary MLM Plan

Plugin Slug:
binary-mlm-plan

Installations
50+

Vulnerability:
Privilege Escalation

Patched in Version:
5.0

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 5.0.

ConvertForce Popup Builder

Plugin Slug:
convertforce-popup-builder

Installations
40+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
0.0.8

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 0.0.8.

Bread & Butter: Content Gating for Verified Leads

Plugin Slug:
bread-butter

Installations
30+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
8.0.1398

Severity Score:
Critical


The vulnerability has been patched, so you should update to version 8.0.1398.

Community Events

Plugin Slug:
community-events

Installations
30+

Vulnerability:
SQL Injection

Patched in Version:
1.5.2

Severity Score:
Critical


The vulnerability has been patched, so you should update to version 1.5.2.

Forms Bridge � Infinite integrations

Plugin Slug:
forms-bridge

Installations
30+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
4.3.0

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 4.3.0.

Magic Buttons for Elementor

Plugin Slug:
magic-buttons-for-elementor

Installations
30+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.1

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.1.

EKC Tournament Manager

Plugin Slug:
ekc-tournament-manager

Installations
20+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
2.2.2

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.2.2.

Ultimate Classified Listings

Plugin Slug:
ultimate-classified-listings

Installations
20+

Vulnerability:
Local File Inclusion

Patched in Version:
1.7

Severity Score:
High


The vulnerability has been patched, so you should update to version 1.7.

Buy Now Plus � Payments with Stripe

Plugin Slug:
buy-now-plus

Installations
10+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.0.3

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.0.3.

coreActivity: Activity Logging for WordPress

Plugin Slug:
coreactivity

Installations
10+

Vulnerability:
Content Spoofing

Patched in Version:
2.1

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.1.

HAPPY � Helpdesk Support Ticket System

Plugin Slug:
happy-helpdesk-support-ticket-system

Installations
10+

Vulnerability:
Broken Access Control

Patched in Version:
1.0.9

Severity Score:
High


The vulnerability has been patched, so you should update to version 1.0.9.

Simple Folio

Plugin Slug:
simple-folio

Installations
10+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.1.2

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.1.2.

WPBookit

Plugin:

WPBookit

Plugin Slug:
wpbookit

Installations
10+

Vulnerability:
Privilege Escalation

Patched in Version:
1.0.3

Severity Score:
Critical


The vulnerability has been patched, so you should update to version 1.0.3.

ARMember Premium

Plugin:

ARMember Premium

Plugin Slug:
armember

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
6.7.1

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 6.7.1.

Beaver Builder Plugin (Starter Version)

Plugin:

Beaver Builder Plugin (Starter Version)

Plugin Slug:
bb-plugin

Vulnerability:
Arbitrary File Upload

Patched in Version:
2.9.1.1

Severity Score:
High


The vulnerability has been patched, so you should update to version 2.9.1.1.

BM Content Builder

Plugin:

BM Content Builder

Plugin Slug:
bm-builder

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
3.16.3

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 3.16.3.

bodi0�s Easy Cache

Plugin:

bodi0�s Easy Cache

Plugin Slug:
bodi0s-easy-cache

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
0.9

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 0.9.

Bridge Core

Plugin:

Bridge Core

Plugin Slug:
bridge-core

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
3.3

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 3.3.

Buddyboss Platform

Plugin:

Buddyboss Platform

Plugin Slug:
buddyboss-platform

Vulnerability:
Insecure Direct Object References (IDOR)

Patched in Version:
2.6.0

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.6.0.

Divi Builder

Plugin:

Divi Builder

Plugin Slug:
divi-builder

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
4.27.2

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 4.27.2.

Elementor Pro

Plugin:

Elementor Pro

Plugin Slug:
elementor-pro

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
3.29.1

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 3.29.1.

EventON

Plugin:

EventON

Plugin Slug:
eventon

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
4.5.5

Severity Score:
High


The vulnerability has been patched, so you should update to version 4.5.5.

EventON

Plugin:

EventON

Plugin Slug:
eventon

Vulnerability:
Sensitive Data Exposure

Patched in Version:
4.5.5

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 4.5.5.

EventON

Plugin:

EventON

Plugin Slug:
eventon

Vulnerability:
Broken Access Control

Patched in Version:
4.5.5

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 4.5.5.

EventON

Plugin:

EventON

Plugin Slug:
eventon

Vulnerability:
Broken Access Control

Patched in Version:
4.5.9

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 4.5.9.

EventON

Plugin:

EventON

Plugin Slug:
eventon

Vulnerability:
Broken Access Control

Patched in Version:
4.5.6

Severity Score:
High


The vulnerability has been patched, so you should update to version 4.5.6.

Favicon Generator

Plugin:

Favicon Generator

Plugin Slug:
favicon-generator

Vulnerability:
Arbitrary File Deletion

Patched in Version:
2.1

Severity Score:
High


The vulnerability has been patched, so you should update to version 2.1.

Gyan Elements

Plugin:

Gyan Elements

Plugin Slug:
gyan-elements

Vulnerability:
Local File Inclusion

Patched in Version:
2.2.2

Severity Score:
High


The vulnerability has been patched, so you should update to version 2.2.2.

WPGYM

Plugin:

WPGYM

Plugin Slug:
gym-management

Vulnerability:
SQL Injection

Patched in Version:
67.8.0

Severity Score:
Critical


The vulnerability has been patched, so you should update to version 67.8.0.

WPBakery Page Builder

Plugin:

WPBakery Page Builder

Plugin Slug:
js_composer

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
7.6

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 7.6.

WPBakery Page Builder

Plugin:

WPBakery Page Builder

Plugin Slug:
js_composer

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
7.6

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 7.6.

WPBakery Page Builder

Plugin:

WPBakery Page Builder

Plugin Slug:
js_composer

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
7.7

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 7.7.

MelaPress Login Security Premium

Plugin:

MelaPress Login Security Premium

Plugin Slug:
melapress-login-security-premium

Vulnerability:
Broken Access Control

Patched in Version:
2.1.1

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.1.1.

Memberlite Shortcodes

Plugin:

Memberlite Shortcodes

Plugin Slug:
memberlite-shortcodes

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.4.1

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.4.1.

ModelTheme Addons for WPBakery and Elementor

Plugin:

ModelTheme Addons for WPBakery and Elementor

Plugin Slug:
modeltheme-addons-for-wpbakery

Vulnerability:
PHP Object Injection

Patched in Version:
1.5.6

Severity Score:
High


The vulnerability has been patched, so you should update to version 1.5.6.

Paid Memberships Pro

Plugin:

Paid Memberships Pro

Plugin Slug:
paid-memberships-pro

Vulnerability:
Broken Access Control

Patched in Version:
2.12.9

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.12.9.

Community by PeepSo

Plugin:

Community by PeepSo

Plugin Slug:
peepso-core

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
6.4.6.0

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 6.4.6.0.

Community by PeepSo

Plugin:

Community by PeepSo

Plugin Slug:
peepso-core

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
6.3.1.2

Severity Score:
High


The vulnerability has been patched, so you should update to version 6.3.1.2.

Porto Theme – Functionality

Plugin:

Porto Theme – Functionality

Plugin Slug:
porto-functionality

Vulnerability:
Local File Inclusion

Patched in Version:
3.1.0

Severity Score:
High


The vulnerability has been patched, so you should update to version 3.1.0.

Prague

Plugin:

Prague

Plugin Slug:
prague-plugins

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.2.9

Severity Score:
High


The vulnerability has been patched, so you should update to version 2.2.9.

Premium Addons PRO

Plugin:

Premium Addons PRO

Plugin Slug:
premium-addons-pro

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.9.13

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.9.13.

Premium Addons PRO

Plugin:

Premium Addons PRO

Plugin Slug:
premium-addons-pro

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.9.13

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.9.13.

Premium Addons PRO

Plugin:

Premium Addons PRO

Plugin Slug:
premium-addons-pro

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.9.13

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.9.13.

Premium Addons PRO

Plugin:

Premium Addons PRO

Plugin Slug:
premium-addons-pro

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.9.13

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.9.13.

Premium Addons PRO

Plugin:

Premium Addons PRO

Plugin Slug:
premium-addons-pro

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.9.13

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.9.13.

Relevanssi Premium

Plugin:

Relevanssi Premium

Plugin Slug:
relevanssi-premium

Vulnerability:
Broken Access Control

Patched in Version:
2.25.1

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.25.1.

Relevanssi Premium

Plugin:

Relevanssi Premium

Plugin Slug:
relevanssi-premium

Vulnerability:
SQL Injection

Patched in Version:
2.29.0

Severity Score:
High


The vulnerability has been patched, so you should update to version 2.29.0.

Slider Revolution

Plugin:

Slider Revolution

Plugin Slug:
revslider

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
6.7.11

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 6.7.11.

Slider Revolution

Plugin:

Slider Revolution

Plugin Slug:
revslider

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
6.7.11

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 6.7.11.

Salient Core

Plugin:

Salient Core

Plugin Slug:
salient-core

Vulnerability:
Local File Inclusion

Patched in Version:
2.0.8

Severity Score:
High


The vulnerability has been patched, so you should update to version 2.0.8.

Salient Shortcodes

Plugin:

Salient Shortcodes

Plugin Slug:
salient-shortcodes

Vulnerability:
Local File Inclusion

Patched in Version:
1.5.4

Severity Score:
High


The vulnerability has been patched, so you should update to version 1.5.4.

Salient Shortcodes

Plugin:

Salient Shortcodes

Plugin Slug:
salient-shortcodes

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.5.4

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.5.4.

Schedula � Smart Appointment Booking

Plugin Slug:
schedula-smart-appointment-booking

Vulnerability:
Broken Access Control

Patched in Version:
1.1

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.1.

Service Finder Booking

Plugin:

Service Finder Booking

Plugin Slug:
sf-booking

Vulnerability:
Privilege Escalation

Patched in Version:
6.1

Severity Score:
High


The vulnerability has been patched, so you should update to version 6.1.

Service Finder Booking

Plugin:

Service Finder Booking

Plugin Slug:
sf-booking

Vulnerability:
Privilege Escalation

Patched in Version:
6.1

Severity Score:
High


The vulnerability has been patched, so you should update to version 6.1.

Simple Locator

Plugin:

Simple Locator

Plugin Slug:
simple-locator

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.0.4

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.0.4.

The Grid

Plugin:

The Grid

Plugin Slug:
the-grid

Vulnerability:
Broken Access Control

Patched in Version:
2.8.0

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.8.0.

Ultimate Addons for WPBakery Page Builder

Plugin:

Ultimate Addons for WPBakery Page Builder

Plugin Slug:
ultimate_vc_addons

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
3.19.20.1

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 3.19.20.1.

Ultimate Addons for WPBakery Page Builder

Plugin:

Ultimate Addons for WPBakery Page Builder

Plugin Slug:
ultimate_vc_addons

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
3.19.20.1

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 3.19.20.1.

Ultimate Addons for WPBakery Page Builder

Plugin:

Ultimate Addons for WPBakery Page Builder

Plugin Slug:
ultimate_vc_addons

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
3.19.20.1

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 3.19.20.1.

Ultimate Addons for WPBakery Page Builder

Plugin:

Ultimate Addons for WPBakery Page Builder

Plugin Slug:
ultimate_vc_addons

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
3.19.20.1

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 3.19.20.1.

Web to SugarCRM Lead

Plugin Slug:
web-to-sugarcrm-lead

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
1.0.1

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.0.1.

WooCommerce Social Login

Plugin:

WooCommerce Social Login

Plugin Slug:
woo-social-login

Vulnerability:
Broken Authentication

Patched in Version:
2.7.4

Severity Score:
High


The vulnerability has been patched, so you should update to version 2.7.4.

WooCommerce Social Login

Plugin:

WooCommerce Social Login

Plugin Slug:
woo-social-login

Vulnerability:
Privilege Escalation

Patched in Version:
2.7.4

Severity Score:
Critical


The vulnerability has been patched, so you should update to version 2.7.4.

WooCommerce Social Login

Plugin:

WooCommerce Social Login

Plugin Slug:
woo-social-login

Vulnerability:
Privilege Escalation

Patched in Version:
2.7.4

Severity Score:
High


The vulnerability has been patched, so you should update to version 2.7.4.

WooCommerce Customers Manager

Plugin:

WooCommerce Customers Manager

Plugin Slug:
woocommerce-customers-manager

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
30.1

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 30.1.

WooCommerce PDF Vouchers

Plugin:

WooCommerce PDF Vouchers

Plugin Slug:
woocommerce-pdf-vouchers

Vulnerability:
Broken Authentication

Patched in Version:
4.9.4

Severity Score:
High


The vulnerability has been patched, so you should update to version 4.9.4.

Affiliate Manager

Plugin:

Affiliate Manager

Plugin Slug:
wp-affiliate-platform

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
6.5.1

Severity Score:
High


The vulnerability has been patched, so you should update to version 6.5.1.

Affiliate Manager

Plugin:

Affiliate Manager

Plugin Slug:
wp-affiliate-platform

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
6.5.1

Severity Score:
High


The vulnerability has been patched, so you should update to version 6.5.1.

Affiliate Manager

Plugin:

Affiliate Manager

Plugin Slug:
wp-affiliate-platform

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
6.5.1

Severity Score:
High


The vulnerability has been patched, so you should update to version 6.5.1.

Affiliate Manager

Plugin:

Affiliate Manager

Plugin Slug:
wp-affiliate-platform

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
6.5.1

Severity Score:
High


The vulnerability has been patched, so you should update to version 6.5.1.

WP eStore

Plugin:

WP eStore

Plugin Slug:
wp-cart-for-digital-products

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
8.5.5

Severity Score:
High


The vulnerability has been patched, so you should update to version 8.5.5.

WP eStore

Plugin:

WP eStore

Plugin Slug:
wp-cart-for-digital-products

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
8.5.5

Severity Score:
High


The vulnerability has been patched, so you should update to version 8.5.5.

WP eStore

Plugin:

WP eStore

Plugin Slug:
wp-cart-for-digital-products

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
8.5.5

Severity Score:
High


The vulnerability has been patched, so you should update to version 8.5.5.

WP eStore

Plugin:

WP eStore

Plugin Slug:
wp-cart-for-digital-products

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
8.5.6

Severity Score:
High


The vulnerability has been patched, so you should update to version 8.5.6.

WP eMember

Plugin:

WP eMember

Plugin Slug:
wp-eMember

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
10.6.6

Severity Score:
High


The vulnerability has been patched, so you should update to version 10.6.6.

WordPress Themes � 9 Patched / 14 Unpatched

Oxygen

Theme:

Oxygen

Theme Slug:
oxygen

Downloads
403,132

Vulnerability:
Server Side Request Forgery (SSRF)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should switch themes.

Aardvark

Theme:

Aardvark

Theme Slug:
aardvark

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should switch themes.

Capella

Theme:

Capella

Theme Slug:
capella

Vulnerability:
PHP Object Injection

Patched in Version:
No Fix

Severity Score:
Critical


The vulnerability has not been patched. You should switch themes.

Cas

Theme:

Cas

Theme Slug:
cas

Vulnerability:
Arbitrary File Download

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should switch themes.

Cas

Theme:

Cas

Theme Slug:
cas

Vulnerability:
Server Side Request Forgery (SSRF)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should switch themes.

Gauge

Theme:

Gauge

Theme Slug:
gauge

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should switch themes.

KindlyCare

Theme:

KindlyCare

Theme Slug:
kindlycare

Vulnerability:
PHP Object Injection

Patched in Version:
No Fix

Severity Score:
Critical


The vulnerability has not been patched. You should switch themes.

Outdoor

Theme:

Outdoor

Theme Slug:
outdoor

Vulnerability:
SQL Injection

Patched in Version:
No Fix

Severity Score:
Critical


The vulnerability has not been patched. You should switch themes.

Oyster – Photography WordPress Theme

Theme:

Oyster – Photography WordPress Theme

Theme Slug:
oyster

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should switch themes.

PhotoMe

Theme:

PhotoMe

Theme Slug:
photome

Vulnerability:
PHP Object Injection

Patched in Version:
No Fix

Severity Score:
Critical


The vulnerability has not been patched. You should switch themes.

SOHO – Photography WordPress Theme

Theme:

SOHO – Photography WordPress Theme

Theme Slug:
soho

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should switch themes.

The Wound

Theme:

The Wound

Theme Slug:
the-wound

Vulnerability:
Local File Inclusion

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should switch themes.

WPJobster

Theme:

WPJobster

Theme Slug:
wpjobster

Vulnerability:
SQL Injection

Patched in Version:
No Fix

Severity Score:
Critical


The vulnerability has not been patched. You should switch themes.

WPJobster

Theme:

WPJobster

Theme Slug:
wpjobster

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should switch themes.

OceanWP

Theme:

OceanWP

Theme Slug:
oceanwp

Downloads
9,187,846

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
3.6.1

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 3.6.1.

Divi

Theme:

Divi

Theme Slug:
divi

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
4.27.2

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 4.27.2.

Himer

Theme:

Himer

Theme Slug:
himer

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
2.1.1

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.1.1.

Himer

Theme:

Himer

Theme Slug:
himer

Vulnerability:
Insecure Direct Object References (IDOR)

Patched in Version:
2.1.1

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.1.1.

Himer

Theme:

Himer

Theme Slug:
himer

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
2.1.3

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.1.3.

Himer

Theme:

Himer

Theme Slug:
himer

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
2.1.1

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.1.1.

Jobify

Theme:

Jobify

Theme Slug:
jobify

Vulnerability:
Broken Access Control

Patched in Version:
4.2.8

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 4.2.8.

Konte

Theme:

Konte

Theme Slug:
konte

Vulnerability:
Broken Access Control

Patched in Version:
2.4.7

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.4.7.

Travel Tour

Theme:

Travel Tour

Theme Slug:
traveltour

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
5.2.4

Severity Score:
High


The vulnerability has been patched, so you should update to version 5.2.4.

Related articles

Wait! Get exclusive hosting insights

Subscribe to our newsletter and stay ahead of the competition with expert advice from our hosting pros.

Loading form…