Line illustration showing a black application window on a dark orange to black gradient background overlaid with a large exclamation point alert icon and three bugs.

WordPress Vulnerability Report � February 11, 2026

In this report, 467 vulnerabilities have been publicly disclosed. Security patches for 386 of these plugins and themes are now available. Please run these updates as soon as possible. If you’re a Solid Security Pro user, the version management tool may have already warned you and updated these plugins, depending on your settings.

Currently, 81 plugin and theme vulnerabilities remain unpatched. If you’re a Solid Security Pro user, those vulnerabilities are already protected by the Solid Security firewall. Virtual patches from Patchstack will be applied when a vulnerability is considered high or medium risk. If no patch is forthcoming from the vendor or the vulnerable software has been marked “closed” and dropped from the official WordPress repositories, you should deactivate it soon and look for alternative solutions.

WordPress Core

WordPress 6.9.1 was released on February 3, 2026, as a short-cycle maintenance update, addressing 49 bugs across WordPress Core and the Block Editor, including fixes affecting the editor, mail functionality, and classic themes. Sites with automatic background updates may already be updated. We recommend reviewing the details and updating as part of your regular maintenance cycle.

The next major WordPress release, version 7.0, is scheduled for April 9, 2026, during WordCamp Asia.

WordPress Plugins � 372 Patched / 76 Unpatched

Bold Page Builder

Plugin Slug:
bold-page-builder

Installations
50,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Bold Page Builder

Plugin Slug:
bold-page-builder

Installations
50,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Bold Page Builder

Plugin Slug:
bold-page-builder

Installations
50,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Bold Page Builder

Plugin Slug:
bold-page-builder

Installations
50,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

SportsPress � Sports Club & League Manager

Plugin Slug:
sportspress

Installations
10,000+

Vulnerability:
Local File Inclusion

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Advanced Country Blocker

Plugin Slug:
advanced-country-blocker

Installations
2,000+

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Plugin BlueX for WooCommerce

Plugin Slug:
bluex-for-woocommerce

Installations
2,000+

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Cliengo � Chatbot

Plugin Slug:
cliengo

Installations
2,000+

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

GA4WP � Analytics Dashboard for the Website

Plugin Slug:
ga-for-wp

Installations
2,000+

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Addonify � Compare Products For WooCommerce

Plugin Slug:
addonify-compare-products

Installations
1,000+

Vulnerability:
Settings Change

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Addonify Floating Cart For WooCommerce

Plugin Slug:
addonify-floating-cart

Installations
1,000+

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Addonify � WooCommerce Wishlist

Plugin Slug:
addonify-wishlist

Installations
1,000+

Vulnerability:
Settings Change

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

WP Duplicate � WordPress Migration Plugin

Plugin Slug:
local-sync

Installations
200+

Vulnerability:
Arbitrary File Upload

Patched in Version:
No Fix

Severity Score:
Critical


The vulnerability has not been patched. You should deactivate the plugin.

Contact Manager

Plugin Slug:
contact-manager

Installations
100+

Vulnerability:
PHP Object Injection

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

RVCFDI para Woocommerce

Plugin Slug:
rvcfdi-para-woocommerce

Installations
100+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Simple Retail Menus

Plugin Slug:
simple-retail-menus

Installations
90+

Vulnerability:
Local File Inclusion

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

iContact for Gravity Forms

Plugin Slug:
gravity-forms-icontact

Installations
80+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Optimize More! � Images

Plugin Slug:
optimize-more-images

Installations
80+

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

WPshop 2 � E-Commerce

Plugin Slug:
wpshop

Installations
70+

Vulnerability:
Local File Inclusion

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

All push notification for WP

Plugin:

All push notification for WP

Plugin Slug:
all-push-notification

Vulnerability:
SQL Injection

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Bulk Edit Post Titles

Plugin:

Bulk Edit Post Titles

Plugin Slug:
bulk-edit-post-titles

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Buy one click WooCommerce

Plugin:

Buy one click WooCommerce

Plugin Slug:
buy-one-click-woocommerce

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Buy one click WooCommerce

Plugin:

Buy one click WooCommerce

Plugin Slug:
buy-one-click-woocommerce

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Catch Popup

Plugin:

Catch Popup

Plugin Slug:
catch-popup

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Chapa Payment Gateway Plugin for WooCommerce

Plugin:

Chapa Payment Gateway Plugin for WooCommerce

Plugin Slug:
chapa-payment-gateway-for-woocommerce

Vulnerability:
Sensitive Data Exposure

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Code Explorer

Plugin:

Code Explorer

Plugin Slug:
code-explorer

Vulnerability:
Arbitrary File Download

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

CommentTweets

Plugin:

CommentTweets

Plugin Slug:
commenttweets

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Eleblog � Elementor Blog And Magazine Addons

Plugin:

Eleblog � Elementor Blog And Magazine Addons

Plugin Slug:
ele-blog

Vulnerability:
Local File Inclusion

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Elegant Addons for elementor

Plugin:

Elegant Addons for elementor

Plugin Slug:
elegant-addons-for-elementor

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Extended Random Number Generator

Plugin:

Extended Random Number Generator

Plugin Slug:
extended-random-number-generator

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Font Farsi

Plugin:

Font Farsi

Plugin Slug:
font-farsi

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Fortis for WooCommerce

Plugin:

Fortis for WooCommerce

Plugin Slug:
fortis-for-woocommerce

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.
Plugin:

Image Hover Effects – Caption Hover with Carousel

Plugin Slug:
image-hover-effects-with-carousel

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Infility Global

Plugin:

Infility Global

Plugin Slug:
infility-global

Vulnerability:
SQL Injection

Patched in Version:
No Fix

Severity Score:
Critical


The vulnerability has not been patched. You should deactivate the plugin.

Login Logout Register Menu

Plugin:

Login Logout Register Menu

Plugin Slug:
login-logout-register-menu

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

SEO Flow by LupsOnline

Plugin:

SEO Flow by LupsOnline

Plugin Slug:
lupsonline-link-netwerk

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Magic Import Document Extractor

Plugin Slug:
magic-import-document-extractor

Vulnerability:
Sensitive Data Exposure

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Magic Import Document Extractor

Plugin Slug:
magic-import-document-extractor

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Newsletter Popup

Plugin:

Newsletter Popup

Plugin Slug:
newsletter-popup

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Okay Toolkit

Plugin:

Okay Toolkit

Plugin Slug:
okay-toolkit

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

OMIGO

Plugin:

OMIGO

Plugin Slug:
omigo

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Product Filter for WooCommerce

Plugin:

Product Filter for WooCommerce

Plugin Slug:
prdctfltr

Vulnerability:
Privilege Escalation

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Redirects

Plugin:

Redirects

Plugin Slug:
redirects

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

SIBS woocommerce payment gateway

Plugin:

SIBS woocommerce payment gateway

Plugin Slug:
sibs-woocommerce

Vulnerability:
SQL Injection

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Simple Bible Verse via Shortcode

Plugin:

Simple Bible Verse via Shortcode

Plugin Slug:
simple-bible-verse-via-shortcode

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Smart PopUp Blaster

Plugin:

Smart PopUp Blaster

Plugin Slug:
smart-popup-blaster

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

SP Project & Document Manager

Plugin:

SP Project & Document Manager

Plugin Slug:
sp-client-document-manager

Vulnerability:
Arbitrary File Download

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Store Locator

Plugin:

Store Locator

Plugin Slug:
store-locator

Vulnerability:
Local File Inclusion

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

SVS Pricing Tables

Plugin:

SVS Pricing Tables

Plugin Slug:
svs-pricing-tables

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Portfolio Builder

Plugin:

Portfolio Builder

Plugin Slug:
swp-portfolio

Vulnerability:
Local File Inclusion

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Tabs Maker

Plugin:

Tabs Maker

Plugin Slug:
tabs-maker

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Testimonials Widget

Plugin:

Testimonials Widget

Plugin Slug:
testimonials-widget

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

The Bucketlister

Plugin:

The Bucketlister

Plugin Slug:
the-bucketlister

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

The Bucketlister

Plugin:

The Bucketlister

Plugin Slug:
the-bucketlister

Vulnerability:
SQL Injection

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Themesflat Elementor

Plugin:

Themesflat Elementor

Plugin Slug:
themesflat-elementor

Vulnerability:
PHP Object Injection

Patched in Version:
No Fix

Severity Score:
Critical


The vulnerability has not been patched. You should deactivate the plugin.

Timeline Event History

Plugin:

Timeline Event History

Plugin Slug:
timeline-event-history

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

TITLE ANIMATOR

Plugin:

TITLE ANIMATOR

Plugin Slug:
title-animator

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

WordPress form builder plugin for contact forms, surveys and quizzes � Tripetto

Plugin:

WordPress form builder plugin for contact forms, surveys and quizzes � Tripetto

Plugin Slug:
tripetto

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

UserPlus

Plugin:

UserPlus

Plugin Slug:
userplus

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Video Onclick

Plugin:

Video Onclick

Plugin Slug:
video-onclick

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

WebPurify Profanity Filter

Plugin:

WebPurify Profanity Filter

Plugin Slug:
webpurifytextreplace

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Wikiloops Track Player

Plugin:

Wikiloops Track Player

Plugin Slug:
wikiloops-track-player

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Wonka Slide

Plugin:

Wonka Slide

Plugin Slug:
wonka-slide

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Woo File Dropzone

Plugin:

Woo File Dropzone

Plugin Slug:
woo-file-dropzone

Vulnerability:
Arbitrary File Deletion

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Xendit Payment

Plugin:

Xendit Payment

Plugin Slug:
woo-xendit-virtual-accounts

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

WooCommerce Bulk Product Editor

Plugin:

WooCommerce Bulk Product Editor

Plugin Slug:
woocommerce-quick-product-editor

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

MyRewards

Plugin:

MyRewards

Plugin Slug:
woorewards

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

WP Content Permission

Plugin:

WP Content Permission

Plugin Slug:
wp-content-permission

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

WP-Revive Adserver

Plugin:

WP-Revive Adserver

Plugin Slug:
wp-revive-adserver

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Upload Files Anywhere

Plugin:

Upload Files Anywhere

Plugin Slug:
wp-upload-files-anywhere

Vulnerability:
Arbitrary File Download

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Upload Files Anywhere

Plugin:

Upload Files Anywhere

Plugin Slug:
wp-upload-files-anywhere

Vulnerability:
Arbitrary File Deletion

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

User Extra Fields

Plugin:

User Extra Fields

Plugin Slug:
wp-user-extra-fields

Vulnerability:
Arbitrary File Deletion

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

User Extra Fields

Plugin:

User Extra Fields

Plugin Slug:
wp-user-extra-fields

Vulnerability:
Arbitrary File Deletion

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Code Snippets

Plugin Slug:
code-snippets

Installations
1,000,000+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
3.9.5

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 3.9.5.

Happy Addons for Elementor

Plugin Slug:
happy-elementor-addons

Installations
400,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
3.20.8

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 3.20.8.

Happy Addons for Elementor

Plugin Slug:
happy-elementor-addons

Installations
400,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
3.10.4

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 3.10.4.

Happy Addons for Elementor

Plugin Slug:
happy-elementor-addons

Installations
400,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
3.10.5

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 3.10.5.

Happy Addons for Elementor

Plugin Slug:
happy-elementor-addons

Installations
400,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
3.10.5

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 3.10.5.

Happy Addons for Elementor

Plugin Slug:
happy-elementor-addons

Installations
400,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
3.10.5

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 3.10.5.

Happy Addons for Elementor

Plugin Slug:
happy-elementor-addons

Installations
400,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
3.10.5

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 3.10.5.

Happy Addons for Elementor

Plugin Slug:
happy-elementor-addons

Installations
400,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
3.10.5

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 3.10.5.

Happy Addons for Elementor

Plugin Slug:
happy-elementor-addons

Installations
400,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
3.10.8

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 3.10.8.

Happy Addons for Elementor

Plugin Slug:
happy-elementor-addons

Installations
400,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
3.11.0

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 3.11.0.

Happy Addons for Elementor

Plugin Slug:
happy-elementor-addons

Installations
400,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
3.10.9

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 3.10.9.

Unlimited Elements For Elementor

Plugin Slug:
unlimited-elements-for-elementor

Installations
300,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.0.2

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.0.2.

Unlimited Elements For Elementor

Plugin Slug:
unlimited-elements-for-elementor

Installations
300,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.5.113

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.5.113.

SEOPress � On-site SEO & Analytics

Plugin Slug:
wp-seopress

Installations
300,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
7.6

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 7.6.

FileOrganizer � WordPress File Manager

Plugin Slug:
fileorganizer

Installations
200,000+

Vulnerability:
Sensitive Data Exposure

Patched in Version:
1.0.8

Severity Score:
High


The vulnerability has been patched, so you should update to version 1.0.8.

Element Pack Addons for Elementor

Plugin Slug:
bdthemes-element-pack-lite

Installations
100,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
5.10.2

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 5.10.2.

Element Pack Addons for Elementor

Plugin Slug:
bdthemes-element-pack-lite

Installations
100,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
5.6.1

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 5.6.1.

Element Pack Addons for Elementor

Plugin Slug:
bdthemes-element-pack-lite

Installations
100,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
5.6.1

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 5.6.1.

Element Pack Addons for Elementor

Plugin Slug:
bdthemes-element-pack-lite

Installations
100,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
5.6.12

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 5.6.12.

Element Pack Addons for Elementor

Plugin Slug:
bdthemes-element-pack-lite

Installations
100,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
5.10.3

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 5.10.3.

Prime Slider � Addons for Elementor

Plugin Slug:
bdthemes-prime-slider-lite

Installations
100,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
3.14.2

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 3.14.2.

Beaver Builder Page Builder � Drag and Drop Website Builder

Plugin Slug:
beaver-builder-lite-version

Installations
100,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.7.4.3

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.7.4.3.
Plugin Slug:
foogallery

Installations
100,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.4.15

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.4.15.

GiveWP � Donation Plugin and Fundraising Platform

Plugin Slug:
give

Installations
100,000+

Vulnerability:
PHP Object Injection

Patched in Version:
3.14.2

Severity Score:
Critical


The vulnerability has been patched, so you should update to version 3.14.2.

Menu Icons by ThemeIsle

Plugin Slug:
menu-icons

Installations
100,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
0.13.21

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 0.13.21.
Plugin Slug:
modula-best-grid-gallery

Installations
100,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.13.5

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.13.5.

WebSub (FKA. PubSubHubbub)

Plugin Slug:
pubsubhubbub

Installations
100,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
3.2.0

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 3.2.0.
Plugin Slug:
relevanssi

Installations
100,000+

Vulnerability:
Insecure Direct Object References (IDOR)

Patched in Version:
4.22.0

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 4.22.0.
Plugin Slug:
relevanssi

Installations
100,000+

Vulnerability:
Broken Access Control

Patched in Version:
4.22.1

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 4.22.1.

Tutor LMS � eLearning and online course solution

Plugin Slug:
tutor

Installations
100,000+

Vulnerability:
Insecure Direct Object References (IDOR)

Patched in Version:
3.9.6

Severity Score:
High


The vulnerability has been patched, so you should update to version 3.9.6.

Tutor LMS � eLearning and online course solution

Plugin Slug:
tutor

Installations
100,000+

Vulnerability:
Sensitive Data Exposure

Patched in Version:
3.9.6

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 3.9.6.

Addon Elements for Elementor (formerly Elementor Addon Elements)

Plugin Slug:
addon-elements-for-elementor-page-builder

Installations
90,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.13.3

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.13.3.

Addon Elements for Elementor (formerly Elementor Addon Elements)

Plugin Slug:
addon-elements-for-elementor-page-builder

Installations
90,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.13.4

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.13.4.

Addon Elements for Elementor (formerly Elementor Addon Elements)

Plugin Slug:
addon-elements-for-elementor-page-builder

Installations
90,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.13.6

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.13.6.

Addon Elements for Elementor (formerly Elementor Addon Elements)

Plugin Slug:
addon-elements-for-elementor-page-builder

Installations
90,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.13.6

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.13.6.

Addon Elements for Elementor (formerly Elementor Addon Elements)

Plugin Slug:
addon-elements-for-elementor-page-builder

Installations
90,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.13.7

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.13.7.

Shortcodes and extra features for Phlox theme

Plugin Slug:
auxin-elements

Installations
90,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.17.3

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.17.3.

Shortcodes and extra features for Phlox theme

Plugin Slug:
auxin-elements

Installations
90,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.15.8

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.15.8.

Shortcodes and extra features for Phlox theme

Plugin Slug:
auxin-elements

Installations
90,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.15.8

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.15.8.

Shortcodes and extra features for Phlox theme

Plugin Slug:
auxin-elements

Installations
90,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.15.8

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.15.8.

Shortcodes and extra features for Phlox theme

Plugin Slug:
auxin-elements

Installations
90,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.15.8

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.15.8.

Shortcodes and extra features for Phlox theme

Plugin Slug:
auxin-elements

Installations
90,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.15.8

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.15.8.

Shortcodes and extra features for Phlox theme

Plugin Slug:
auxin-elements

Installations
90,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.17.1

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.17.1.

Colibri Page Builder

Plugin Slug:
colibri-page-builder

Installations
90,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.0.274

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.0.274.

Colibri Page Builder

Plugin Slug:
colibri-page-builder

Installations
90,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.0.277

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.0.277.

HT Mega � Absolute Addons For Elementor

Plugin Slug:
ht-mega-for-elementor

Installations
80,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.4.7

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.4.7.

HT Mega � Absolute Addons For Elementor

Plugin Slug:
ht-mega-for-elementor

Installations
80,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.5.0

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.5.0.

HT Mega � Absolute Addons For Elementor

Plugin Slug:
ht-mega-for-elementor

Installations
80,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.5.1

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.5.1.

HT Mega � Absolute Addons For Elementor

Plugin Slug:
ht-mega-for-elementor

Installations
80,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.5.6

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.5.6.

Import and export users and customers

Plugin Slug:
import-users-from-csv-with-meta

Installations
80,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.26.7

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.26.7.

Advanced Contact form 7 DB

Plugin Slug:
advanced-cf7-db

Installations
70,000+

Vulnerability:
Sensitive Data Exposure

Patched in Version:
2.0.3

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.0.3.

Brizy � Page Builder

Plugin Slug:
brizy

Installations
70,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.4.44

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.4.44.

Brizy � Page Builder

Plugin Slug:
brizy

Installations
70,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.4.44

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.4.44.

Brizy � Page Builder

Plugin Slug:
brizy

Installations
70,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.4.41

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.4.41.

Brizy � Page Builder

Plugin Slug:
brizy

Installations
70,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.4.42

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.4.42.

Exclusive Addons for Elementor

Plugin Slug:
exclusive-addons-for-elementor

Installations
60,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.6.9.3

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.6.9.3.

Exclusive Addons for Elementor

Plugin Slug:
exclusive-addons-for-elementor

Installations
60,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.6.9.5

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.6.9.5.

Greenshift � animation and page builder blocks

Plugin Slug:
greenshift-animation-and-page-builder-blocks

Installations
60,000+

Vulnerability:
Sensitive Data Exposure

Patched in Version:
12.6

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 12.6.

Bold Page Builder

Plugin Slug:
bold-page-builder

Installations
50,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
4.8.9

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 4.8.9.

Getwid � Gutenberg Blocks

Plugin Slug:
getwid

Installations
50,000+

Vulnerability:
Broken Access Control

Patched in Version:
2.0.11

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.0.11.

?????? ????? ??????? Persian WooCommerce SMS

Plugin Slug:
persian-woocommerce-sms

Installations
50,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
7.0.6

Severity Score:
High


The vulnerability has been patched, so you should update to version 7.0.6.

Sina Extension for Elementor

Plugin Slug:
sina-extension-for-elementor

Installations
50,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
3.5.4

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 3.5.4.

Themesflat Addons For Elementor

Plugin Slug:
themesflat-addons-for-elementor

Installations
50,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.1.3

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.1.3.

Themesflat Addons For Elementor

Plugin Slug:
themesflat-addons-for-elementor

Installations
50,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.1.3

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.1.3.

Themesflat Addons For Elementor

Plugin Slug:
themesflat-addons-for-elementor

Installations
50,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.1.3

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.1.3.

Themesflat Addons For Elementor

Plugin Slug:
themesflat-addons-for-elementor

Installations
50,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.1.3

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.1.3.

WP Recipe Maker

Plugin Slug:
wp-recipe-maker

Installations
50,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
9.1.1

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 9.1.1.

WP Recipe Maker

Plugin Slug:
wp-recipe-maker

Installations
50,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
9.1.1

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 9.1.1.

Livemesh Addons by Elementor

Plugin Slug:
addons-for-elementor

Installations
40,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
8.3.6

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 8.3.6.

Livemesh Addons by Elementor

Plugin Slug:
addons-for-elementor

Installations
40,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
8.3.6

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 8.3.6.

Livemesh Addons by Elementor

Plugin Slug:
addons-for-elementor

Installations
40,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
8.3.6

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 8.3.6.

Livemesh Addons by Elementor

Plugin Slug:
addons-for-elementor

Installations
40,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
8.3.6

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 8.3.6.

Livemesh Addons by Elementor

Plugin Slug:
addons-for-elementor

Installations
40,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
8.3.6

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 8.3.6.

Livemesh Addons by Elementor

Plugin Slug:
addons-for-elementor

Installations
40,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
8.4

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 8.4.

Livemesh Addons by Elementor

Plugin Slug:
addons-for-elementor

Installations
40,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
8.4

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 8.4.

SEO Plugin by Squirrly SEO

Plugin Slug:
squirrly-seo

Installations
40,000+

Vulnerability:
SQL Injection

Patched in Version:
12.3.20

Severity Score:
High


The vulnerability has been patched, so you should update to version 12.3.20.

ACF Quick Edit Fields

Plugin Slug:
acf-quickedit-fields

Installations
30,000+

Vulnerability:
Insecure Direct Object References (IDOR)

Patched in Version:
3.2.3

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 3.2.3.

Piotnet Addons For Elementor

Plugin Slug:
piotnet-addons-for-elementor

Installations
30,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.4.29

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.4.29.

Post Grid

Plugin Slug:
post-grid

Installations
30,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.2.81

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.2.81.

Post Grid

Plugin Slug:
post-grid

Installations
30,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.2.81

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.2.81.

Tutor LMS Elementor Addons

Plugin Slug:
tutor-lms-elementor-addons

Installations
30,000+

Vulnerability:
Broken Access Control

Patched in Version:
2.1.6

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.1.6.

Tutor LMS Elementor Addons

Plugin Slug:
tutor-lms-elementor-addons

Installations
30,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.1.5

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.1.5.

Print Invoice & Delivery Notes for WooCommerce

Plugin Slug:
woocommerce-delivery-notes

Installations
30,000+

Vulnerability:
Broken Access Control

Patched in Version:
5.9.0

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 5.9.0.
Plugin Slug:
all-in-one-video-gallery

Installations
20,000+

Vulnerability:
Arbitrary File Upload

Patched in Version:
4.6.4

Severity Score:
Critical


The vulnerability has been patched, so you should update to version 4.6.4.

The Events Calendar Shortcode & Block

Plugin Slug:
the-events-calendar-shortcode

Installations
20,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
3.1.3

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 3.1.3.

The Events Calendar Shortcode & Block

Plugin Slug:
the-events-calendar-shortcode

Installations
20,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
3.1.2

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 3.1.2.

Ultimate Addons for Beaver Builder � Lite

Plugin Slug:
ultimate-addons-for-beaver-builder-lite

Installations
20,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.5.8

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.5.8.

Ultimate Addons for Beaver Builder � Lite

Plugin Slug:
ultimate-addons-for-beaver-builder-lite

Installations
20,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.5.8

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.5.8.

Ultimate Addons for Beaver Builder � Lite

Plugin Slug:
ultimate-addons-for-beaver-builder-lite

Installations
20,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.5.8

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.5.8.

Ultimate Addons for Beaver Builder � Lite

Plugin Slug:
ultimate-addons-for-beaver-builder-lite

Installations
20,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.5.8

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.5.8.

WCFM Marketplace � Multivendor Marketplace for WooCommerce

Plugin Slug:
wc-multivendor-marketplace

Installations
20,000+

Vulnerability:
Insecure Direct Object References (IDOR)

Patched in Version:
3.7.1

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 3.7.1.

Frontend Admin by DynamiApps

Plugin Slug:
acf-frontend-form-element

Installations
10,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
3.25.1

Severity Score:
High


The vulnerability has been patched, so you should update to version 3.25.1.

Frontend Admin by DynamiApps

Plugin Slug:
acf-frontend-form-element

Installations
10,000+

Vulnerability:
Privilege Escalation

Patched in Version:
3.25.1

Severity Score:
High


The vulnerability has been patched, so you should update to version 3.25.1.

Content Blocks (Custom Post Widget)

Plugin Slug:
custom-post-widget

Installations
10,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
3.3.1

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 3.3.1.

WP Customer Area

Plugin Slug:
customer-area

Installations
10,000+

Vulnerability:
Broken Access Control

Patched in Version:
8.2.1

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 8.2.1.

Essential Widgets

Plugin Slug:
essential-widgets

Installations
10,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
3.0.1

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 3.0.1.

LA-Studio Element Kit for Elementor

Plugin Slug:
lastudio-element-kit

Installations
10,000+

Vulnerability:
Local File Inclusion

Patched in Version:
1.3.9

Severity Score:
High


The vulnerability has been patched, so you should update to version 1.3.9.

Child Theme Creator by Orbisius

Plugin Slug:
orbisius-child-theme-creator

Installations
10,000+

Vulnerability:
Broken Access Control

Patched in Version:
1.5.6

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.5.6.

OSM � OpenStreetMap

Plugin Slug:
osm

Installations
10,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
6.0.4

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 6.0.4.
Plugin Slug:
testimonials-carousel-elementor

Installations
10,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
10.2.0

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 10.2.0.

Ultimate Maps by Supsystic

Plugin Slug:
ultimate-maps-by-supsystic

Installations
10,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.2.16

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.2.16.

Ultimate Coming Soon & Maintenance

Plugin Slug:
ultimate-coming-soon

Installations
9,000+

Vulnerability:
Broken Access Control

Patched in Version:
1.1.0

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.1.0.

Ultimate Coming Soon & Maintenance

Plugin Slug:
ultimate-coming-soon

Installations
9,000+

Vulnerability:
Broken Access Control

Patched in Version:
1.1.0

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.1.0.

NEX-Forms � Ultimate Forms Plugin for WordPress

Plugin Slug:
nex-forms-express-wp-form-builder

Installations
8,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
9.1.8

Severity Score:
High


The vulnerability has been patched, so you should update to version 9.1.8.

NEX-Forms � Ultimate Forms Plugin for WordPress

Plugin Slug:
nex-forms-express-wp-form-builder

Installations
8,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
9.1.8

Severity Score:
High


The vulnerability has been patched, so you should update to version 9.1.8.

NEX-Forms � Ultimate Forms Plugin for WordPress

Plugin Slug:
nex-forms-express-wp-form-builder

Installations
8,000+

Vulnerability:
Broken Access Control

Patched in Version:
8.5.7

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 8.5.7.

NEX-Forms � Ultimate Forms Plugin for WordPress

Plugin Slug:
nex-forms-express-wp-form-builder

Installations
8,000+

Vulnerability:
Broken Access Control

Patched in Version:
8.5.7

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 8.5.7.

EventPrime � Events Calendar, Bookings and Tickets

Plugin Slug:
eventprime-event-calendar-management

Installations
7,000+

Vulnerability:
Broken Access Control

Patched in Version:
3.4.4

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 3.4.4.

EventPrime � Events Calendar, Bookings and Tickets

Plugin Slug:
eventprime-event-calendar-management

Installations
7,000+

Vulnerability:
Broken Access Control

Patched in Version:
3.4.2

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 3.4.2.

EventPrime � Events Calendar, Bookings and Tickets

Plugin Slug:
eventprime-event-calendar-management

Installations
7,000+

Vulnerability:
Broken Access Control

Patched in Version:
3.4.3

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 3.4.3.

LottieFiles

Plugin Slug:
lottiefiles

Installations
7,000+

Vulnerability:
Broken Access Control

Patched in Version:
3.1.0

Severity Score:
High


The vulnerability has been patched, so you should update to version 3.1.0.

OAuth Single Sign On � SSO (OAuth Client)

Plugin Slug:
miniorange-login-with-eve-online-google-facebook

Installations
7,000+

Vulnerability:
Broken Access Control

Patched in Version:
6.26.15

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 6.26.15.

Schema App Structured Data

Plugin Slug:
schema-app-structured-data-for-schemaorg

Installations
7,000+

Vulnerability:
Broken Access Control

Patched in Version:
2.2.1

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.2.1.

Schema App Structured Data

Plugin Slug:
schema-app-structured-data-for-schemaorg

Installations
7,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.2.5

Severity Score:
High


The vulnerability has been patched, so you should update to version 2.2.5.

YayCurrency � WooCommerce Multi-Currency Switcher

Plugin Slug:
yaycurrency

Installations
7,000+

Vulnerability:
Arbitrary Content Deletion

Patched in Version:
3.3.1

Severity Score:
High


The vulnerability has been patched, so you should update to version 3.3.1.

Export Media URLs

Plugin Slug:
export-media-urls

Installations
6,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.3

Severity Score:
High


The vulnerability has been patched, so you should update to version 2.3.

ProfileGrid � User Profiles, Groups and Communities

Plugin Slug:
profilegrid-user-profiles-groups-and-communities

Installations
6,000+

Vulnerability:
Insecure Direct Object References (IDOR)

Patched in Version:
5.9.7.3

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 5.9.7.3.

ProfileGrid � User Profiles, Groups and Communities

Plugin Slug:
profilegrid-user-profiles-groups-and-communities

Installations
6,000+

Vulnerability:
Broken Access Control

Patched in Version:
5.9.7.3

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 5.9.7.3.

Contact Form 7 Connector

Plugin Slug:
ari-cf7-connector

Installations
5,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.2.3

Severity Score:
High


The vulnerability has been patched, so you should update to version 1.2.3.

Shortcodes for Elementor

Plugin Slug:
shortcode-elementor

Installations
5,000+

Vulnerability:
Sensitive Data Exposure

Patched in Version:
1.0.5

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.0.5.

Simple File List

Plugin Slug:
simple-file-list

Installations
5,000+

Vulnerability:
Arbitrary File Download

Patched in Version:
6.1.16

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 6.1.16.

ElementInvader Addons for Elementor

Plugin Slug:
elementinvader-addons-for-elementor

Installations
4,000+

Vulnerability:
Broken Access Control

Patched in Version:
1.3.2

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.3.2.

ElementInvader Addons for Elementor

Plugin Slug:
elementinvader-addons-for-elementor

Installations
4,000+

Vulnerability:
Broken Access Control

Patched in Version:
1.4.2

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.4.2.

HelloAsso

Plugin Slug:
helloasso

Installations
4,000+

Vulnerability:
Broken Access Control

Patched in Version:
1.1.11

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.1.11.

Snippet Shortcodes

Plugin Slug:
shortcode-variables

Installations
4,000+

Vulnerability:
Broken Access Control

Patched in Version:
4.1.7

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 4.1.7.

Payment Button for PayPal

Plugin Slug:
wp-paypal

Installations
4,000+

Vulnerability:
Broken Access Control

Patched in Version:
1.2.3.42

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.2.3.42.

WPZOOM Addons for Beaver Builder

Plugin Slug:
wpzoom-addons-for-beaver-builder

Installations
4,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.3.5

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.3.5.

WPZOOM Addons for Beaver Builder

Plugin Slug:
wpzoom-addons-for-beaver-builder

Installations
4,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.3.5

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.3.5.

WPZOOM Addons for Beaver Builder

Plugin Slug:
wpzoom-addons-for-beaver-builder

Installations
4,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.3.5

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.3.5.

WPZOOM Addons for Beaver Builder

Plugin Slug:
wpzoom-addons-for-beaver-builder

Installations
4,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.3.5

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.3.5.

Classic Addons � WPBakery Page Builder

Plugin Slug:
classic-addons-wpbakery-page-builder-addons

Installations
3,000+

Vulnerability:
Local File Inclusion

Patched in Version:
3.1

Severity Score:
High


The vulnerability has been patched, so you should update to version 3.1.

Product Enquiry for WooCommerce

Plugin Slug:
gm-woocommerce-quote-popup

Installations
3,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
3.1

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 3.1.

Salon Booking System � Free Version

Plugin Slug:
salon-booking-system

Installations
3,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
9.6.3

Severity Score:
High


The vulnerability has been patched, so you should update to version 9.6.3.

Tickera � Sell Tickets & Manage Events

Plugin Slug:
tickera-event-ticketing-system

Installations
3,000+

Vulnerability:
Sensitive Data Exposure

Patched in Version:
3.5.4.9

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 3.5.4.9.

WP-WebAuthn

Plugin Slug:
wp-webauthn

Installations
3,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.3.4

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.3.4.

PeproDev WooCommerce Receipt Uploader

Plugin Slug:
pepro-bacs-receipt-upload-for-woocommerce

Installations
2,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.7.0

Severity Score:
High


The vulnerability has been patched, so you should update to version 2.7.0.

WPBITS Addons For Elementor Page Builder

Plugin Slug:
wpbits-addons-for-elementor

Installations
2,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.5

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.5.

Geo Controller

Plugin Slug:
cf-geoplugin

Installations
1,000+

Vulnerability:
Content Injection

Patched in Version:
8.7.0

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 8.7.0.

Message Filter for Contact Form 7

Plugin Slug:
cf7-message-filter

Installations
1,000+

Vulnerability:
Broken Access Control

Patched in Version:
1.6.3.1

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.6.3.1.

Smart Online Order for Clover

Plugin Slug:
clover-online-orders

Installations
1,000+

Vulnerability:
Broken Access Control

Patched in Version:
1.5.7

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.5.7.

Web3 Crypto Payments by DePay for WooCommerce

Plugin Slug:
depay-payments-for-woocommerce

Installations
1,000+

Vulnerability:
Broken Access Control

Patched in Version:
2.12.18

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.12.18.

Flamix: Bitrix24 and Contact Form 7 integrations

Plugin Slug:
flamix-bitrix24-and-contact-forms-7-integrations

Installations
1,000+

Vulnerability:
Sensitive Data Exposure

Patched in Version:
3.2.0

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 3.2.0.

Gestpay for WooCommerce

Plugin Slug:
gestpay-for-woocommerce

Installations
1,000+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
20240307

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 20240307.

Gestpay for WooCommerce

Plugin Slug:
gestpay-for-woocommerce

Installations
1,000+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
20240307

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 20240307.

Connector Wizard (formerly LC Wizard)

Plugin Slug:
ghl-wizard

Installations
1,000+

Vulnerability:
Settings Change

Patched in Version:
2.1.2

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.1.2.

Keap Official Opt-in Forms

Plugin Slug:
infusionsoft-official-opt-in-forms

Installations
1,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.0.12

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.0.12.

PDF Generator for WordPress Elementor

Plugin Slug:
pdf-generator-addon-for-elementor-page-builder

Installations
1,000+

Vulnerability:
Arbitrary File Download

Patched in Version:
2.0.1

Severity Score:
High


The vulnerability has been patched, so you should update to version 2.0.1.

Simple Popup Plugin

Plugin Slug:
simple-popup-plugin

Installations
1,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
4.6

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 4.6.

Squelch Tabs and Accordions Shortcodes

Plugin Slug:
squelch-tabs-and-accordions-shortcodes

Installations
1,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
0.4.4

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 0.4.4.

Tutor LMS � Migration Tool

Plugin Slug:
tutor-lms-migration-tool

Installations
1,000+

Vulnerability:
Broken Access Control

Patched in Version:
2.2.1

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.2.1.

WP AdCenter � Ad Manager & Adsense Ads

Plugin Slug:
wpadcenter

Installations
1,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.5.8

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.5.8.

Zephyr Project Manager

Plugin Slug:
zephyr-project-manager

Installations
1,000+

Vulnerability:
Privilege Escalation

Patched in Version:
3.3.102

Severity Score:
High


The vulnerability has been patched, so you should update to version 3.3.102.

Checkout Gateway for IRIS

Plugin Slug:
checkout-gateway-iris

Installations
900+

Vulnerability:
Broken Access Control

Patched in Version:
1.4

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.4.

Ebook Store

Plugin Slug:
ebook-store

Installations
900+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
5.8002

Severity Score:
High


The vulnerability has been patched, so you should update to version 5.8002.

ForumWP � Forum & Discussion Board

Plugin Slug:
forumwp

Installations
900+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.1.3

Severity Score:
High


The vulnerability has been patched, so you should update to version 2.1.3.

IdeaPush

Plugin:

IdeaPush

Plugin Slug:
ideapush

Installations
800+

Vulnerability:
Broken Access Control

Patched in Version:
8.72

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 8.72.

Confetti Fall Animation

Plugin Slug:
confetti-fall-animation

Installations
600+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.3.2

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.3.2.

Integrate Firebase

Plugin Slug:
integrate-firebase

Installations
600+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
0.10.0

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 0.10.0.

PowerBI Embed Reports

Plugin Slug:
embed-power-bi-reports

Installations
500+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.1.8

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.1.8.

Dynamic Widget Content

Plugin Slug:
dynamic-widget-content

Installations
400+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.3.7

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.3.7.

Library Viewer

Plugin Slug:
library-viewer

Installations
400+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
3.2.0

Severity Score:
High


The vulnerability has been patched, so you should update to version 3.2.0.

SmartAgenda � Prise de rendez-vous en ligne

Plugin Slug:
smart-agenda-prise-de-rendez-vous-en-ligne

Installations
400+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
4.7

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 4.7.

WaveSurfer-WP

Plugin Slug:
wavesurfer-wp

Installations
400+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.8.4

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.8.4.

JSM file_get_contents() Shortcode

Plugin Slug:
wp-file-get-contents

Installations
400+

Vulnerability:
Server Side Request Forgery (SSRF)

Patched in Version:
2.7.1

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.7.1.

WP Mailster

Plugin Slug:
wp-mailster

Installations
400+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.8.18.0

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.8.18.0.

ELEX WordPress HelpDesk & Customer Ticketing System

Plugin Slug:
elex-helpdesk-customer-support-ticket-system

Installations
300+

Vulnerability:
Broken Access Control

Patched in Version:
3.3.6

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 3.3.6.

Accept Stripe Payments Using Contact Form 7

Plugin Slug:
accept-stripe-payments-using-contact-form-7

Installations
200+

Vulnerability:
Sensitive Data Exposure

Patched in Version:
2.6

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.6.

Arena.IM � Live Blogging for real-time events

Plugin Slug:
arena-liveblog-and-chat-tool

Installations
200+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
0.4.0

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 0.4.0.

Bukza

Plugin:

Bukza

Plugin Slug:
bukza

Installations
200+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.0.1

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.0.1.

Eveeno

Plugin:

Eveeno

Plugin Slug:
eveeno

Installations
200+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.8

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.8.

OS DataHub Maps

Plugin Slug:
os-datahub-maps

Installations
200+

Vulnerability:
Arbitrary File Upload

Patched in Version:
1.8.4

Severity Score:
Critical


The vulnerability has been patched, so you should update to version 1.8.4.

Password for WP

Plugin Slug:
password-for-wp

Installations
200+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
1.6

Severity Score:
High


The vulnerability has been patched, so you should update to version 1.6.

Plezi

Plugin:

Plezi

Plugin Slug:
plezi

Installations
200+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.0.7

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.0.7.

WP GeoNames

Plugin Slug:
wp-geonames

Installations
200+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.9.1

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.9.1.

Add infos to The Events Calendar

Plugin Slug:
add-infos-to-the-events-calendar

Installations
100+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.5.0

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.5.0.

Run Contests, Raffles, and Giveaways with ContestsWP

Plugin Slug:
contest-code-checker

Installations
100+

Vulnerability:
Sensitive Data Exposure

Patched in Version:
2.1.1

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.1.1.

IMS Countdown

Plugin Slug:
ims-countdown

Installations
100+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.3.6

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.3.6.
Plugin Slug:
my-idx-home-search

Installations
100+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.1.2

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.1.2.

Primer MyData for Woocommerce

Plugin Slug:
primer-mydata

Installations
100+

Vulnerability:
Path Traversal

Patched in Version:
4.2.9

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 4.2.9.

WP To Do

Plugin:

WP To Do

Plugin Slug:
wp-todo

Installations
100+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.0.1

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.0.1.

WP To Do

Plugin:

WP To Do

Plugin Slug:
wp-todo

Installations
100+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
2.0.1

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.0.1.

WP To Do

Plugin:

WP To Do

Plugin Slug:
wp-todo

Installations
100+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
2.0.1

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.0.1.

ONLYOFFICE DocSpace

Plugin Slug:
onlyoffice-docspace

Installations
90+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.1.2

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.1.2.

Pdf & Print to Post � Custom Post Type and Pages

Plugin Slug:
post-to-pdf

Installations
90+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.1

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.1.

Ganohrs Toggle Shortcode

Plugin Slug:
ganohrs-toggle-shortcode

Installations
80+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
0.2.5

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 0.2.5.

Events Listing Widget

Plugin Slug:
events-listing-widget

Installations
60+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.3.5

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.3.5.

GeoDataSource Country Region DropDown

Plugin Slug:
geodatasource-country-region-dropdown

Installations
60+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.0.2

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.0.2.

NPS computy

Plugin Slug:
nps-computy

Installations
50+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.8.3

Severity Score:
High


The vulnerability has been patched, so you should update to version 2.8.3.

Social Media Shortcodes

Plugin Slug:
social-media-shortcodes

Installations
50+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.3.1

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.3.1.

Employee Directory � Staff Directory and Listing

Plugin Slug:
employee-staff-directory

Installations
20+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.2.2

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.2.2.

Sell BTC � Cryptocurrency Selling Calculator

Plugin Slug:
sell-btc-by-hayyatapps

Installations
20+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.6

Severity Score:
High


The vulnerability has been patched, so you should update to version 1.6.

Docus � YouTube Video Playlist

Plugin Slug:
docus

Installations
10+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.0.7

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.0.7.

Orange Comfort+ accessibility toolbar for WordPress

Plugin Slug:
orange-confort-plus

Installations
10+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
0.7.1

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 0.7.1.

Peter�s Date Countdown

Plugin Slug:
peters-date-countdown

Installations
10+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.0.1

Severity Score:
High


The vulnerability has been patched, so you should update to version 2.0.1.

WP FOFT Loader

Plugin Slug:
wp-foft-loader

Installations
10+

Vulnerability:
Arbitrary File Upload

Patched in Version:
2.1.40

Severity Score:
High


The vulnerability has been patched, so you should update to version 2.1.40.

Aiomatic

Plugin:

Aiomatic

Plugin Slug:
aiomatic-automatic-ai-content-writer

Vulnerability:
Broken Access Control

Patched in Version:
2.0.6

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.0.6.

ARMember Premium

Plugin:

ARMember Premium

Plugin Slug:
armember

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
6.7.1

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 6.7.1.

Bit Form

Plugin:

Bit Form

Plugin Slug:
bit-form

Vulnerability:
SQL Injection

Patched in Version:
2.13.10

Severity Score:
High


The vulnerability has been patched, so you should update to version 2.13.10.

bodi0�s Easy Cache

Plugin:

bodi0�s Easy Cache

Plugin Slug:
bodi0s-easy-cache

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
0.9

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 0.9.

Bridge Core

Plugin:

Bridge Core

Plugin Slug:
bridge-core

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
3.3

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 3.3.

EventON-RSVP

Plugin:

EventON-RSVP

Plugin Slug:
eventon-rsvp

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.9.5

Severity Score:
High


The vulnerability has been patched, so you should update to version 2.9.5.

Fluent Forms Pro Add On Pack

Plugin:

Fluent Forms Pro Add On Pack

Plugin Slug:
fluentformpro

Vulnerability:
Server Side Request Forgery (SSRF)

Patched in Version:
6.1.13

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 6.1.13.

Integrate Google Drive

Plugin:

Integrate Google Drive

Plugin Slug:
integrate-google-drive

Vulnerability:
Broken Access Control

Patched in Version:
1.3.9

Severity Score:
Critical


The vulnerability has been patched, so you should update to version 1.3.9.

WPBakery Page Builder

Plugin:

WPBakery Page Builder

Plugin Slug:
js_composer

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
7.6

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 7.6.

WPBakery Page Builder

Plugin:

WPBakery Page Builder

Plugin Slug:
js_composer

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
7.6

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 7.6.

WPBakery Page Builder

Plugin:

WPBakery Page Builder

Plugin Slug:
js_composer

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
7.7

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 7.7.

Paid Memberships Pro

Plugin:

Paid Memberships Pro

Plugin Slug:
paid-memberships-pro

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
2.12.8

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.12.8.

Community by PeepSo

Plugin:

Community by PeepSo

Plugin Slug:
peepso-core

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
6.3.1.2

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 6.3.1.2.

Community by PeepSo

Plugin:

Community by PeepSo

Plugin Slug:
peepso-core

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
6.4.6.0

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 6.4.6.0.

Porto Theme – Functionality

Plugin:

Porto Theme – Functionality

Plugin Slug:
porto-functionality

Vulnerability:
Local File Inclusion

Patched in Version:
3.1.0

Severity Score:
High


The vulnerability has been patched, so you should update to version 3.1.0.

Premium Addons PRO

Plugin:

Premium Addons PRO

Plugin Slug:
premium-addons-pro

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.9.13

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.9.13.

Premium Addons PRO

Plugin:

Premium Addons PRO

Plugin Slug:
premium-addons-pro

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.9.13

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.9.13.

Premium Addons PRO

Plugin:

Premium Addons PRO

Plugin Slug:
premium-addons-pro

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.9.13

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.9.13.

Premium Addons PRO

Plugin:

Premium Addons PRO

Plugin Slug:
premium-addons-pro

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.9.13

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.9.13.

Premium Addons PRO

Plugin:

Premium Addons PRO

Plugin Slug:
premium-addons-pro

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.9.13

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.9.13.

Reflector

Plugin:

Reflector

Plugin Slug:
reflector-plugins

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.2.3

Severity Score:
High


The vulnerability has been patched, so you should update to version 1.2.3.

Relevanssi Premium

Plugin:

Relevanssi Premium

Plugin Slug:
relevanssi-premium

Vulnerability:
Insecure Direct Object References (IDOR)

Patched in Version:
2.25.0

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.25.0.

Relevanssi Premium

Plugin:

Relevanssi Premium

Plugin Slug:
relevanssi-premium

Vulnerability:
Broken Access Control

Patched in Version:
2.25.1

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.25.1.

Slider Revolution

Plugin:

Slider Revolution

Plugin Slug:
revslider

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
6.7.11

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 6.7.11.

Slider Revolution

Plugin:

Slider Revolution

Plugin Slug:
revslider

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
6.7.11

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 6.7.11.

Salient Core

Plugin:

Salient Core

Plugin Slug:
salient-core

Vulnerability:
Local File Inclusion

Patched in Version:
2.0.8

Severity Score:
High


The vulnerability has been patched, so you should update to version 2.0.8.

Salient Shortcodes

Plugin:

Salient Shortcodes

Plugin Slug:
salient-shortcodes

Vulnerability:
Local File Inclusion

Patched in Version:
1.5.4

Severity Score:
High


The vulnerability has been patched, so you should update to version 1.5.4.

Salient Shortcodes

Plugin:

Salient Shortcodes

Plugin Slug:
salient-shortcodes

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.5.4

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.5.4.

School Management

Plugin:

School Management

Plugin Slug:
school-management

Vulnerability:
Arbitrary File Upload

Patched in Version:
92.0.0

Severity Score:
Critical


The vulnerability has been patched, so you should update to version 92.0.0.

Simple Locator

Plugin:

Simple Locator

Plugin Slug:
simple-locator

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.0.4

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.0.4.

Smart Appointment & Booking

Plugin Slug:
smart-appointment-booking

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.0.8

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.0.8.

Ultimate Addons for WPBakery Page Builder

Plugin:

Ultimate Addons for WPBakery Page Builder

Plugin Slug:
ultimate_vc_addons

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
3.19.20.1

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 3.19.20.1.

Ultimate Addons for WPBakery Page Builder

Plugin:

Ultimate Addons for WPBakery Page Builder

Plugin Slug:
ultimate_vc_addons

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
3.19.20.1

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 3.19.20.1.

Ultimate Addons for WPBakery Page Builder

Plugin:

Ultimate Addons for WPBakery Page Builder

Plugin Slug:
ultimate_vc_addons

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
3.19.20.1

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 3.19.20.1.

Ultimate Addons for WPBakery Page Builder

Plugin:

Ultimate Addons for WPBakery Page Builder

Plugin Slug:
ultimate_vc_addons

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
3.19.20.1

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 3.19.20.1.

Whizz Plugins

Plugin:

Whizz Plugins

Plugin Slug:
whizz-plugins

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.0.0

Severity Score:
High


The vulnerability has been patched, so you should update to version 2.0.0.

WooCommerce Social Login

Plugin:

WooCommerce Social Login

Plugin Slug:
woo-social-login

Vulnerability:
Broken Authentication

Patched in Version:
2.7.4

Severity Score:
High


The vulnerability has been patched, so you should update to version 2.7.4.

WooCommerce Social Login

Plugin:

WooCommerce Social Login

Plugin Slug:
woo-social-login

Vulnerability:
Privilege Escalation

Patched in Version:
2.7.4

Severity Score:
Critical


The vulnerability has been patched, so you should update to version 2.7.4.

WooCommerce Social Login

Plugin:

WooCommerce Social Login

Plugin Slug:
woo-social-login

Vulnerability:
Privilege Escalation

Patched in Version:
2.7.4

Severity Score:
High


The vulnerability has been patched, so you should update to version 2.7.4.

WooCommerce PDF Vouchers

Plugin:

WooCommerce PDF Vouchers

Plugin Slug:
woocommerce-pdf-vouchers

Vulnerability:
Broken Authentication

Patched in Version:
4.9.4

Severity Score:
High


The vulnerability has been patched, so you should update to version 4.9.4.

WooCommerce Support Ticket System

Plugin:

WooCommerce Support Ticket System

Plugin Slug:
woocommerce-support-ticket-system

Vulnerability:
Arbitrary File Deletion

Patched in Version:
17.8

Severity Score:
High


The vulnerability has been patched, so you should update to version 17.8.

Affiliate Manager

Plugin:

Affiliate Manager

Plugin Slug:
wp-affiliate-platform

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
6.5.1

Severity Score:
High


The vulnerability has been patched, so you should update to version 6.5.1.

Affiliate Manager

Plugin:

Affiliate Manager

Plugin Slug:
wp-affiliate-platform

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
6.5.1

Severity Score:
High


The vulnerability has been patched, so you should update to version 6.5.1.

Affiliate Manager

Plugin:

Affiliate Manager

Plugin Slug:
wp-affiliate-platform

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
6.5.1

Severity Score:
High


The vulnerability has been patched, so you should update to version 6.5.1.

Affiliate Manager

Plugin:

Affiliate Manager

Plugin Slug:
wp-affiliate-platform

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
6.5.1

Severity Score:
High


The vulnerability has been patched, so you should update to version 6.5.1.

WP eStore

Plugin:

WP eStore

Plugin Slug:
wp-cart-for-digital-products

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
8.5.5

Severity Score:
High


The vulnerability has been patched, so you should update to version 8.5.5.

WP eStore

Plugin:

WP eStore

Plugin Slug:
wp-cart-for-digital-products

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
8.5.5

Severity Score:
High


The vulnerability has been patched, so you should update to version 8.5.5.

WP eStore

Plugin:

WP eStore

Plugin Slug:
wp-cart-for-digital-products

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
8.5.5

Severity Score:
High


The vulnerability has been patched, so you should update to version 8.5.5.

WP eStore

Plugin:

WP eStore

Plugin Slug:
wp-cart-for-digital-products

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
8.5.6

Severity Score:
High


The vulnerability has been patched, so you should update to version 8.5.6.

WP eMember

Plugin:

WP eMember

Plugin Slug:
wp-eMember

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
10.6.6

Severity Score:
High


The vulnerability has been patched, so you should update to version 10.6.6.

WP eMember

Plugin:

WP eMember

Plugin Slug:
wp-eMember

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
10.6.7

Severity Score:
High


The vulnerability has been patched, so you should update to version 10.6.7.

User Extra Fields

Plugin:

User Extra Fields

Plugin Slug:
wp-user-extra-fields

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
16.9

Severity Score:
High


The vulnerability has been patched, so you should update to version 16.9.

WPB Show Core

Plugin:

WPB Show Core

Plugin Slug:
wpb-show-core

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.7

Severity Score:
High


The vulnerability has been patched, so you should update to version 2.7.

WordPress Themes � 14 Patched / 5 Unpatched

WordPress Dating Theme

Theme:

WordPress Dating Theme

Theme Slug:
DA10

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should switch themes.

Cartify – WooCommerce Gutenberg WordPress Theme

Theme:

Cartify – WooCommerce Gutenberg WordPress Theme

Theme Slug:
cartify

Vulnerability:
Arbitrary Content Deletion

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should switch themes.

Meris

Theme:

Meris

Theme Slug:
meris

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should switch themes.

SevenHills

Theme:

SevenHills

Theme Slug:
sevenhills

Vulnerability:
PHP Object Injection

Patched in Version:
No Fix

Severity Score:
Critical


The vulnerability has not been patched. You should switch themes.

VidoRev

Theme:

VidoRev

Theme Slug:
vidorev

Vulnerability:
Local File Inclusion

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should switch themes.

Royal Elementor Kit

Theme Slug:
royal-elementor-kit

Downloads
986,469

Vulnerability:
Broken Access Control

Patched in Version:
1.0.117

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.0.117.

Besa

Theme:

Besa

Theme Slug:
besa

Vulnerability:
Local File Inclusion

Patched in Version:
2.3.16

Severity Score:
High


The vulnerability has been patched, so you should update to version 2.3.16.

CozyStay

Theme:

CozyStay

Theme Slug:
cozystay

Vulnerability:
Local File Inclusion

Patched in Version:
1.9.1

Severity Score:
High


The vulnerability has been patched, so you should update to version 1.9.1.

Golo

Theme:

Golo

Theme Slug:
golo

Vulnerability:
Broken Access Control

Patched in Version:
1.7.5

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.7.5.

Golo

Theme:

Golo

Theme Slug:
golo

Vulnerability:
Local File Inclusion

Patched in Version:
1.7.5

Severity Score:
High


The vulnerability has been patched, so you should update to version 1.7.5.

Grand Conference

Theme:

Grand Conference

Theme Slug:
grandconference

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
5.3.5

Severity Score:
High


The vulnerability has been patched, so you should update to version 5.3.5.

Hara

Theme:

Hara

Theme Slug:
hara

Vulnerability:
Local File Inclusion

Patched in Version:
1.2.18

Severity Score:
High


The vulnerability has been patched, so you should update to version 1.2.18.

Nestin

Theme:

Nestin

Theme Slug:
nestin

Vulnerability:
PHP Object Injection

Patched in Version:
1.2.6

Severity Score:
Critical


The vulnerability has been patched, so you should update to version 1.2.6.

PatioTime

Theme:

PatioTime

Theme Slug:
patiotime

Vulnerability:
PHP Object Injection

Patched in Version:
2.1

Severity Score:
Critical


The vulnerability has been patched, so you should update to version 2.1.

PatioTime

Theme:

PatioTime

Theme Slug:
patiotime

Vulnerability:
Local File Inclusion

Patched in Version:
2.1

Severity Score:
High


The vulnerability has been patched, so you should update to version 2.1.

PhotoMe

Theme:

PhotoMe

Theme Slug:
photome

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
5.7.2

Severity Score:
High


The vulnerability has been patched, so you should update to version 5.7.2.

Travelicious

Theme:

Travelicious

Theme Slug:
travelicious

Vulnerability:
PHP Object Injection

Patched in Version:
1.6.7

Severity Score:
Critical


The vulnerability has been patched, so you should update to version 1.6.7.

Unicamp

Theme:

Unicamp

Theme Slug:
unicamp

Vulnerability:
Local File Inclusion

Patched in Version:
2.7.2

Severity Score:
High


The vulnerability has been patched, so you should update to version 2.7.2.

Urna

Theme:

Urna

Theme Slug:
urna

Vulnerability:
Local File Inclusion

Patched in Version:
2.5.13

Severity Score:
High


The vulnerability has been patched, so you should update to version 2.5.13.

Related articles

Wait! Get exclusive hosting insights

Subscribe to our newsletter and stay ahead of the competition with expert advice from our hosting pros.

Loading form…