Line illustration showing a black application window on a dark blue gradient background overlaid with a large exclamation point alert icon and three bugs.

WordPress Vulnerability Report � March 26, 2025

In this report, 240 vulnerabilities have been publicly disclosed. Security patches for 51 of these plugins and themes are available now, so run those updates as soon as possible. If you’re a Solid Security Pro user, the version management tool may have already warned you and updated these plugins, depending on your settings.

Additionally, there are 189 plugin and theme vulnerabilities with no patch available yet. If you’re a Solid Security Pro user, those vulnerabilities are already protected by the Solid Security firewall. Virtual patches from Patchstack will be applied when a vulnerability is considered high or medium risk. If no patch is forthcoming from the vendor or the vulnerable software has been marked “closed” and dropped from the official WordPress repositories, you should deactivate it soon and look for alternative solutions.

WordPress Core

WordPress 6.8 Release Candidate 1 is ready for download and testing! This version of the WordPress software is under development. Please do not install, run, or test this version of WordPress on production or mission-critical websites. Instead, it�s recommended that you evaluate RC1 on a test server and site.

WordPress Plugins � 46 Patched / 180 Unpatched

teachPress

Plugin Slug:
teachpress

Installations
2,000+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

GlobalPayments WooCommerce

Plugin Slug:
global-payments-woocommerce

Installations
600+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

EZ SQL Reports Shortcode Widget and DB Backup

Plugin Slug:
elisqlreports

Installations
500+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
Critical


The vulnerability has not been patched. You should deactivate the plugin.

WP Email Delivery

Plugin Slug:
wp-email-delivery

Installations
100+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

AdSense Privacy Policy

Plugin:

AdSense Privacy Policy

Plugin Slug:
adsense-privacy-policy

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Advanced Dewplayer

Plugin:

Advanced Dewplayer

Plugin Slug:
advanced-dewplayer

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

AHAthat

Plugin:

AHAthat

Plugin Slug:
ahathat

Vulnerability:
SQL Injection

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

AI Preloader

Plugin:

AI Preloader

Plugin Slug:
ai-preloader

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Alert Box Block � Display notice/alerts in the front end

Plugin:

Alert Box Block � Display notice/alerts in the front end

Plugin Slug:
alert-box-block

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

AlphaOmega Captcha & Anti-Spam Filter

Plugin:

AlphaOmega Captcha & Anti-Spam Filter

Plugin Slug:
alphaomega-captcha-anti-spam

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

ANAC XML Render

Plugin:

ANAC XML Render

Plugin Slug:
anac-xml-render

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Arrow Maps

Plugin:

Arrow Maps

Plugin Slug:
ap-google-maps

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

AppExperts � WordPress to Mobile App � WooCommerce to iOs and Android Apps

Plugin:

AppExperts � WordPress to Mobile App � WooCommerce to iOs and Android Apps

Plugin Slug:
appexperts

Vulnerability:
Sensitive Data Exposure

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

AppReview

Plugin:

AppReview

Plugin Slug:
appreview

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Are you robot google recaptcha for wordpress

Plugin:

Are you robot google recaptcha for wordpress

Plugin Slug:
are-you-robot-recaptcha

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

ARPrice

Plugin:

ARPrice

Plugin Slug:
arprice

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

AuMenu

Plugin:

AuMenu

Plugin Slug:
aumenu

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Auto Load Next Post

Plugin:

Auto Load Next Post

Plugin Slug:
auto-load-next-post

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

AvaiBook

Plugin:

AvaiBook

Plugin Slug:
avaibook

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Awesome Logos

Plugin:

Awesome Logos

Plugin Slug:
awesome-logos

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
Critical


The vulnerability has not been patched. You should deactivate the plugin.

banner-manager

Plugin:

banner-manager

Plugin Slug:
banner-manager

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.
Plugin:

Beautiful Link Preview

Plugin Slug:
beautiful-link-preview

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Block Logic

Plugin:

Block Logic

Plugin Slug:
block-logic

Vulnerability:
Remote Code Execution (RCE)

Patched in Version:
No Fix

Severity Score:
Critical


The vulnerability has not been patched. You should deactivate the plugin.

Blue Captcha

Plugin:

Blue Captcha

Plugin Slug:
blue-captcha

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

BMo Expo

Plugin:

BMo Expo

Plugin Slug:
bmo-expo

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Browser Address Bar Color

Plugin:

Browser Address Bar Color

Plugin Slug:
browser-address-bar-color

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Cackle

Plugin:

Cackle

Plugin Slug:
cackle

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

CallPhone’r

Plugin:

CallPhone’r

Plugin Slug:
callphoner

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

CAS Maestro

Plugin:

CAS Maestro

Plugin Slug:
cas-maestro

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Cazamba

Plugin:

Cazamba

Plugin Slug:
cazamba

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Contact Form 7 Material Design

Plugin:

Contact Form 7 Material Design

Plugin Slug:
cf7-material-design

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

UTM tags tracking for Contact Form 7

Plugin:

UTM tags tracking for Contact Form 7

Plugin Slug:
cf7-utm-tracking

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

cits-support-svg-webp-media-upload

Plugin:

cits-support-svg-webp-media-upload

Plugin Slug:
cits-support-svg-webp-media-upload

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.
Plugin:

Clink

Plugin Slug:
clink

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Code Clone

Plugin:

Code Clone

Plugin Slug:
code-clone

Vulnerability:
SQL Injection

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

CG Button

Plugin:

CG Button

Plugin Slug:
content-glass-button

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Cookies Pro

Plugin:

Cookies Pro

Plugin Slug:
cookies-pro

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.
Plugin:

CopyLink

Plugin Slug:
copy-link

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Menu Duplicator

Plugin:

Menu Duplicator

Plugin Slug:
copy-menu

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

CryoKey

Plugin:

CryoKey

Plugin Slug:
cryokey

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

CSV to Responsive Tables

Plugin:

CSV to Responsive Tables

Plugin Slug:
csv-to-webpage-plugin

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

cTabs

Plugin:

cTabs

Plugin Slug:
ctabs

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

custom-field-list-widget

Plugin:

custom-field-list-widget

Plugin Slug:
custom-field-list-widget

Vulnerability:
Local File Inclusion

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Custom Product Stickers for Woocommerce

Plugin:

Custom Product Stickers for Woocommerce

Plugin Slug:
custom-product-stickers-for-woocommerce

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Custom Script Integration

Plugin:

Custom Script Integration

Plugin Slug:
custom-script-integration

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Custom Smilies

Plugin:

Custom Smilies

Plugin Slug:
custom-smilies-se

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Management-screen-droptiles

Plugin:

Management-screen-droptiles

Plugin Slug:
cxc-sawa

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

WP Database Audit

Plugin:

WP Database Audit

Plugin Slug:
database-audit

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Driving Directions

Plugin:

Driving Directions

Plugin Slug:
ddirections

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

DesignThemes Core Features

Plugin:

DesignThemes Core Features

Plugin Slug:
designthemes-core-features

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Display Post Meta

Plugin:

Display Post Meta

Plugin Slug:
display-post-meta

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Docpro

Plugin:

Docpro

Plugin Slug:
docpro

Vulnerability:
Local File Inclusion

Patched in Version:
No Fix

Severity Score:
Critical


The vulnerability has not been patched. You should deactivate the plugin.

????? ???? ??????? ????

Plugin:

????? ???? ??????? ????

Plugin Slug:
dokme

Vulnerability:
SQL Injection

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Easy Custom Admin Bar

Plugin:

Easy Custom Admin Bar

Plugin Slug:
easy-custom-admin-bar

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Easy Page Transition

Plugin:

Easy Page Transition

Plugin Slug:
easy-page-transition

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

En Masse

Plugin:

En Masse

Plugin Slug:
en-masse-wp

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

External image replace

Plugin:

External image replace

Plugin Slug:
external-image-replace

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Secret Meta

Plugin:

Secret Meta

Plugin Slug:
facebook-secret-meta

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Fancybox Plus

Plugin:

Fancybox Plus

Plugin Slug:
fancybox-plus

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

File Away

Plugin:

File Away

Plugin Slug:
file-away

Vulnerability:
Arbitrary File Download

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

File Away

Plugin:

File Away

Plugin Slug:
file-away

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
Critical


The vulnerability has not been patched. You should deactivate the plugin.
Plugin:

Fiverr.com Official Search Box

Plugin Slug:
fiverr-official-search-box

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Fix Rss Feeds

Plugin:

Fix Rss Feeds

Plugin Slug:
fix-rss-feed

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Flickr set slideshows

Plugin:

Flickr set slideshows

Plugin Slug:
flickr-set-slideshows

Vulnerability:
SQL Injection

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Flipdish Ordering System

Plugin:

Flipdish Ordering System

Plugin Slug:
flipdish-ordering-system

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

FOMO Pay Chinese Payment Solution

Plugin:

FOMO Pay Chinese Payment Solution

Plugin Slug:
fomo-payment-gateway-for-woocommerce

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Frndzk Expandable Bottom Bar

Plugin:

Frndzk Expandable Bottom Bar

Plugin Slug:
frndzk-expandable-bottom-bar

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

custom-post-edit

Plugin:

custom-post-edit

Plugin Slug:
front-end-post-edit

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Frontend Post Submission

Plugin:

Frontend Post Submission

Plugin Slug:
frontend-post-submission

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

GDPR Tools

Plugin:

GDPR Tools

Plugin Slug:
gdpr-tools

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Generate Post Thumbnails

Plugin:

Generate Post Thumbnails

Plugin Slug:
generate-post-thumbnails

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

GetShop ecommerce

Plugin:

GetShop ecommerce

Plugin Slug:
getshop-ecommerce

Vulnerability:
Local File Inclusion

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Gravity 2 PDF

Plugin:

Gravity 2 PDF

Plugin Slug:
gf2pdf

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

GMO Font Agent

Plugin:

GMO Font Agent

Plugin Slug:
gmo-font-agent

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Google Plus

Plugin:

Google Plus

Plugin Slug:
google-plus-google

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Gotcha

Plugin:

Gotcha

Plugin Slug:
gotcha-gesture-based-captcha

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

GP Back To Top

Plugin:

GP Back To Top

Plugin Slug:
gp-back-to-top

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Hacklog Remote Image Autosave

Plugin:

Hacklog Remote Image Autosave

Plugin Slug:
hacklog-remote-image-autosave

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

IG Shortcodes

Plugin:

IG Shortcodes

Plugin Slug:
ig-shortcodes

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Image Captcha

Plugin:

Image Captcha

Plugin Slug:
image-captcha

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Image Slider / Slideshow Pearlbells

Plugin:

Image Slider / Slideshow Pearlbells

Plugin Slug:
image-slider-pearlbells

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Improve My City

Plugin:

Improve My City

Plugin Slug:
improve-my-city

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

include-file

Plugin:

include-file

Plugin Slug:
include-file

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Include URL

Plugin:

Include URL

Plugin Slug:
include-url

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Info Boxes Shortcode and Widget

Plugin:

Info Boxes Shortcode and Widget

Plugin Slug:
info-boxes-shortcode-and-widget

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Infugrator

Plugin:

Infugrator

Plugin Slug:
infugrator

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Instant Appointment

Plugin:

Instant Appointment

Plugin Slug:
instant-appointment

Vulnerability:
Arbitrary File Upload

Patched in Version:
No Fix

Severity Score:
Critical


The vulnerability has not been patched. You should deactivate the plugin.

issuuPress

Plugin:

issuuPress

Plugin Slug:
issuupress

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

JiangQie Official Website Mini Program

Plugin:

JiangQie Official Website Mini Program

Plugin Slug:
jiangqie-official-website-mini-program

Vulnerability:
SQL Injection

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

jQuery Dropdown Menu

Plugin:

jQuery Dropdown Menu

Plugin Slug:
jquery-drop-down-menu-plugin

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Key4ce osTicket Bridge

Plugin:

Key4ce osTicket Bridge

Plugin Slug:
key4ce-osticket-bridge

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

LH OGP Meta

Plugin:

LH OGP Meta

Plugin Slug:
lh-ogp-meta-tags

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Lightview Plus

Plugin:

Lightview Plus

Plugin Slug:
lightview-plus

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

LinkedIn Lite

Plugin:

LinkedIn Lite

Plugin Slug:
linkedin-lite

Vulnerability:
Local File Inclusion

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

LIVE TV

Plugin:

LIVE TV

Plugin Slug:
live-tv

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Login Redirect

Plugin:

Login Redirect

Plugin Slug:
login-redirect

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Map Contact

Plugin:

Map Contact

Plugin Slug:
map-contact

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Message ticker

Plugin:

Message ticker

Plugin Slug:
message-ticker

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Mobile Navigation

Plugin:

Mobile Navigation

Plugin Slug:
mobile-navigation

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Multi Video Box

Plugin:

Multi Video Box

Plugin Slug:
multi-video-box

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Music Press Pro

Plugin:

Music Press Pro

Plugin Slug:
music-press-pro

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

My Bootstrap Menu

Plugin:

My Bootstrap Menu

Plugin Slug:
my-bootstrap-menu

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

My Default Post Content

Plugin:

My Default Post Content

Plugin Slug:
my-default-post-content

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Narnoo Operator

Plugin:

Narnoo Operator

Plugin Slug:
narnoo-shortcodes

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.
Plugin:

NextGEN Gallery Voting

Plugin Slug:
nextgen-gallery-voting

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

NS Simple Intro Loader

Plugin:

NS Simple Intro Loader

Plugin Slug:
ns-simple-intro-loader

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Easy 301 Redirects

Plugin:

Easy 301 Redirects

Plugin Slug:
odihost-easy-redirect-301

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Off Page SEO

Plugin:

Off Page SEO

Plugin Slug:
off-page-seo

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Omnify

Plugin:

Omnify

Plugin Slug:
omnify-widget

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

OSS Upload

Plugin:

OSS Upload

Plugin Slug:
oss-upload

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Pixobe Cartography

Plugin:

Pixobe Cartography

Plugin Slug:
pixobe-cartography

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.
Plugin:

Pretty file links

Plugin Slug:
pretty-file-links

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Product Puller

Plugin:

Product Puller

Plugin Slug:
product-puller

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Pro Rank Tracker

Plugin:

Pro Rank Tracker

Plugin Slug:
proranktracker

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Random Quotes

Plugin:

Random Quotes

Plugin Slug:
random-quotes

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

RDP inGroups+

Plugin:

RDP inGroups+

Plugin Slug:
rdp-ingroups

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

RDP Linkedin Login

Plugin:

RDP Linkedin Login

Plugin Slug:
rdp-linkedin-login

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.
Plugin:

Related Posts via Categories

Plugin Slug:
related-posts-via-categories

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Replace Default Words

Plugin:

Replace Default Words

Plugin Slug:
replace-default-words

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Rewrite

Plugin:

Rewrite

Plugin Slug:
rewrite

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Rizzi Guestbook

Plugin:

Rizzi Guestbook

Plugin Slug:
rizzi-guestbook

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

RWS Enquiry And Lead Follow-up

Plugin:

RWS Enquiry And Lead Follow-up

Plugin Slug:
rws-enquiry

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

s2Member Pro

Plugin:

s2Member Pro

Plugin Slug:
s2member-pro

Vulnerability:
Local File Inclusion

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Schedule

Plugin:

Schedule

Plugin Slug:
schedule

Vulnerability:
SQL Injection

Patched in Version:
No Fix

Severity Score:
Critical


The vulnerability has not been patched. You should deactivate the plugin.

Shuffle

Plugin:

Shuffle

Plugin Slug:
shuffle

Vulnerability:
SQL Injection

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Simple Optimizer

Plugin:

Simple Optimizer

Plugin Slug:
simple-optimizer

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Simple Post Series

Plugin:

Simple Post Series

Plugin Slug:
simple-post-series

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Simple Rating

Plugin:

Simple Rating

Plugin Slug:
simple-rating

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Site Editor Google Map

Plugin:

Site Editor Google Map

Plugin Slug:
site-editor-google-map

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Sleekplan

Plugin:

Sleekplan

Plugin Slug:
sleekplan

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

SoundCloud Ultimate

Plugin:

SoundCloud Ultimate

Plugin Slug:
soundcloud-ultimate

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

sourceplay-navermap

Plugin:

sourceplay-navermap

Plugin Slug:
sourceplay-navermap

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

SpatialMatch IDX

Plugin:

SpatialMatch IDX

Plugin Slug:
spatialmatch-free-lifestyle-search

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

SpeakPipe

Plugin:

SpeakPipe

Plugin Slug:
speakpipe-voicemail-for-websites

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

STEdb Forms

Plugin:

STEdb Forms

Plugin Slug:
stedb-forms

Vulnerability:
SQL Injection

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Stencies

Plugin:

Stencies

Plugin Slug:
stencies

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Super Simple Subscriptions

Plugin:

Super Simple Subscriptions

Plugin Slug:
super-simple-subscriptions

Vulnerability:
SQL Injection

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

SUPER RESPONSIVE SLIDER

Plugin:

SUPER RESPONSIVE SLIDER

Plugin Slug:
super-slider

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Super Static Cache

Plugin:

Super Static Cache

Plugin Slug:
super-static-cache

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Teleport

Plugin:

Teleport

Plugin Slug:
teleport

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Translator

Plugin:

Translator

Plugin Slug:
translator

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Trust Payments Gateway for WooCommerce

Plugin:

Trust Payments Gateway for WooCommerce

Plugin Slug:
trust-payments-hosted-payment-pages-integration

Vulnerability:
SQL Injection

Patched in Version:
No Fix

Severity Score:
Critical


The vulnerability has not been patched. You should deactivate the plugin.

Typekit plugin for WordPress

Plugin:

Typekit plugin for WordPress

Plugin Slug:
typekit

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Top Bar

Plugin:

Top Bar

Plugin Slug:
ultimate-bar

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.
Plugin:

ULTIMATE VIDEO GALLERY

Plugin Slug:
ultimate-gallery

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Upload Quota per User

Plugin:

Upload Quota per User

Plugin Slug:
upload-quota-per-user

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Visual Text Editor

Plugin:

Visual Text Editor

Plugin Slug:
visual-text-editor

Vulnerability:
Remote Code Execution (RCE)

Patched in Version:
No Fix

Severity Score:
Critical


The vulnerability has not been patched. You should deactivate the plugin.

wA11y � The Web Accessibility Toolbox

Plugin:

wA11y � The Web Accessibility Toolbox

Plugin Slug:
wa11y

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

J�-J� Pagamentos for WooCommerce

Plugin:

J�-J� Pagamentos for WooCommerce

Plugin Slug:
wc-ja-ja-pagamentos-multicaixa-express

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

WooCommerce Multivendor Marketplace � REST API

Plugin:

WooCommerce Multivendor Marketplace � REST API

Plugin Slug:
wcfm-marketplace-rest-api

Vulnerability:
SQL Injection

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Weather Layer

Plugin:

Weather Layer

Plugin Slug:
weather-layer

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Bitcoin / AltCoin Payment Gateway for WooCommerce

Plugin:

Bitcoin / AltCoin Payment Gateway for WooCommerce

Plugin Slug:
woo-altcoin-payment-gateway

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

WordPress Admin Bar Improved

Plugin:

WordPress Admin Bar Improved

Plugin Slug:
wordpress-admin-bar-improved

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Secure Invites

Plugin:

Secure Invites

Plugin Slug:
wordpress-mu-secure-invites

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

WordPress SQL Backup

Plugin:

WordPress SQL Backup

Plugin Slug:
wordpress-sql-backup

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Theme Demo Bar

Plugin:

Theme Demo Bar

Plugin Slug:
wordpress-theme-demo-bar

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Ads24 Lite

Plugin:

Ads24 Lite

Plugin Slug:
wp-ad-management

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

WP Azure offload

Plugin:

WP Azure offload

Plugin Slug:
wp-azure-offload

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

WP Colorful Tag Cloud

Plugin:

WP Colorful Tag Cloud

Plugin Slug:
wp-colorful-tag-cloud

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

WP Contact Form III

Plugin:

WP Contact Form III

Plugin Slug:
wp-contact-form-iii

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

WP e-Commerce Style Email

Plugin:

WP e-Commerce Style Email

Plugin Slug:
wp-e-commerce-style-email

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
Critical


The vulnerability has not been patched. You should deactivate the plugin.
Plugin:

WP Featured Entries

Plugin Slug:
wp-featured-entries

Vulnerability:
SQL Injection

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

FoodBakery

Plugin:

FoodBakery

Plugin Slug:
wp-foodbakery

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

WP Google Calendar Manager

Plugin:

WP Google Calendar Manager

Plugin Slug:
wp-gcalendar

Vulnerability:
SQL Injection

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

WP Hotjar

Plugin:

WP Hotjar

Plugin Slug:
wp-hotjar

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

WP Multistore Locator

Plugin:

WP Multistore Locator

Plugin Slug:
wp-multi-store-locator

Vulnerability:
SQL Injection

Patched in Version:
No Fix

Severity Score:
Critical


The vulnerability has not been patched. You should deactivate the plugin.

WP Odoo Form Integrator

Plugin:

WP Odoo Form Integrator

Plugin Slug:
wp-odoo-form-integrator

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

WP Parallax Content Slider

Plugin:

WP Parallax Content Slider

Plugin Slug:
wp-parallax-content-slider

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

WP Profitshare

Plugin:

WP Profitshare

Plugin Slug:
wp-profitshare

Vulnerability:
SQL Injection

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

WP Ride Booking

Plugin:

WP Ride Booking

Plugin Slug:
wp-ride-booking

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

WP Social Widget

Plugin:

WP Social Widget

Plugin Slug:
wp-social-widget

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

WordPres ????

Plugin:

WordPres ????

Plugin Slug:
wp2wb

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

WP Event Ticketing

Plugin:

WP Event Ticketing

Plugin Slug:
wpeventticketing

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Your Lightbox

Plugin:

Your Lightbox

Plugin Slug:
your-lightbox

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Yummly Rich Recipes

Plugin:

Yummly Rich Recipes

Plugin Slug:
yummly-rich-recipes

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Zalo Live Chat

Plugin:

Zalo Live Chat

Plugin Slug:
zalo-live-chat

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

ZD Scribd iPaper

Plugin:

ZD Scribd iPaper

Plugin Slug:
zd-scribd-ipaper

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

ZenphotoPress

Plugin:

ZenphotoPress

Plugin Slug:
zenphotopress

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

ZhinaTwitterWidget

Plugin:

ZhinaTwitterWidget

Plugin Slug:
zhina-twitter-widget

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.
Plugin:

Zielke Design Project Gallery

Plugin Slug:
zielke-design-project-gallery

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

WP Ghost (Hide My WP Ghost) � Security & Firewall

Plugin Slug:
hide-my-wp

Installations
200,000+

Vulnerability:
Local File Inclusion

Patched in Version:
5.4.02

Severity Score:
Critical


The vulnerability has been patched, so you should update to version 5.4.02.

Custom Twitter Feeds � A Tweets Widget or X Feed Widget

Plugin Slug:
custom-twitter-feeds

Installations
100,000+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
2.3.0

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.3.0.

GiveWP � Donation Plugin and Fundraising Platform

Plugin Slug:
give

Installations
100,000+

Vulnerability:
Broken Access Control

Patched in Version:
3.22.2

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 3.22.2.

GiveWP � Donation Plugin and Fundraising Platform

Plugin Slug:
give

Installations
100,000+

Vulnerability:
Broken Access Control

Patched in Version:
3.22.1

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 3.22.1.

Pods � Custom Content Types and Fields

Plugin Slug:
pods

Installations
100,000+

Vulnerability:
SQL Injection

Patched in Version:
3.2.8.2

Severity Score:
High


The vulnerability has been patched, so you should update to version 3.2.8.2.

HT Mega � Absolute Addons For Elementor

Plugin Slug:
ht-mega-for-elementor

Installations
90,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.8.4

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.8.4.

Nested Pages

Plugin Slug:
wp-nested-pages

Installations
90,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
3.2.13

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 3.2.13.

Site Reviews

Plugin Slug:
site-reviews

Installations
60,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
7.2.5

Severity Score:
High


The vulnerability has been patched, so you should update to version 7.2.5.

Export and Import Users and Customers

Plugin Slug:
users-customers-import-export-for-wp-woocommerce

Installations
60,000+

Vulnerability:
Arbitrary File Download

Patched in Version:
2.6.3

Severity Score:
Low


The vulnerability has been patched, so you should update to version 2.6.3.

Export and Import Users and Customers

Plugin Slug:
users-customers-import-export-for-wp-woocommerce

Installations
60,000+

Vulnerability:
PHP Object Injection

Patched in Version:
2.6.3

Severity Score:
High


The vulnerability has been patched, so you should update to version 2.6.3.

Export and Import Users and Customers

Plugin Slug:
users-customers-import-export-for-wp-woocommerce

Installations
60,000+

Vulnerability:
Arbitrary File Deletion

Patched in Version:
2.6.3

Severity Score:
Low


The vulnerability has been patched, so you should update to version 2.6.3.

Export and Import Users and Customers

Plugin Slug:
users-customers-import-export-for-wp-woocommerce

Installations
60,000+

Vulnerability:
Server Side Request Forgery (SSRF)

Patched in Version:
2.6.3

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.6.3.

Order Export & Order Import for WooCommerce

Plugin Slug:
order-import-export-for-woocommerce

Installations
50,000+

Vulnerability:
Arbitrary File Download

Patched in Version:
2.6.1

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.6.1.

Order Export & Order Import for WooCommerce

Plugin Slug:
order-import-export-for-woocommerce

Installations
50,000+

Vulnerability:
PHP Object Injection

Patched in Version:
2.6.1

Severity Score:
High


The vulnerability has been patched, so you should update to version 2.6.1.

Order Export & Order Import for WooCommerce

Plugin Slug:
order-import-export-for-woocommerce

Installations
50,000+

Vulnerability:
Arbitrary File Deletion

Patched in Version:
2.6.1

Severity Score:
Low


The vulnerability has been patched, so you should update to version 2.6.1.

Order Export & Order Import for WooCommerce

Plugin Slug:
order-import-export-for-woocommerce

Installations
50,000+

Vulnerability:
Server Side Request Forgery (SSRF)

Patched in Version:
2.6.1

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.6.1.

Age Gate

Plugin:

Age Gate

Plugin Slug:
age-gate

Installations
40,000+

Vulnerability:
Local File Inclusion

Patched in Version:
3.5.4

Severity Score:
Critical


The vulnerability has been patched, so you should update to version 3.5.4.

NP Quote Request for WooCommerce

Plugin Slug:
woo-rfq-for-woocommerce

Installations
9,000+

Vulnerability:
Insecure Direct Object References (IDOR)

Patched in Version:
1.9.180

Severity Score:
High


The vulnerability has been patched, so you should update to version 1.9.180.

WP Compress � Instant Performance & Speed Optimization

Plugin Slug:
wp-compress-image-optimizer

Installations
8,000+

Vulnerability:
Server Side Request Forgery (SSRF)

Patched in Version:
6.30.16

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 6.30.16.

ProfileGrid � User Profiles, Groups and Communities

Plugin Slug:
profilegrid-user-profiles-groups-and-communities

Installations
7,000+

Vulnerability:
SQL Injection

Patched in Version:
5.9.4.8

Severity Score:
High


The vulnerability has been patched, so you should update to version 5.9.4.8.

Newsletters

Plugin Slug:
newsletters-lite

Installations
3,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
4.9.9.8

Severity Score:
High


The vulnerability has been patched, so you should update to version 4.9.9.8.

Digital License Manager

Plugin Slug:
digital-license-manager

Installations
600+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.7.4

Severity Score:
High


The vulnerability has been patched, so you should update to version 1.7.4.

Web Directory Free

Plugin Slug:
web-directory-free

Installations
500+

Vulnerability:
SQL Injection

Patched in Version:
1.7.7

Severity Score:
Critical


The vulnerability has been patched, so you should update to version 1.7.7.

Formality

Plugin Slug:
formality

Installations
200+

Vulnerability:
Local File Inclusion

Patched in Version:
1.5.8

Severity Score:
High


The vulnerability has been patched, so you should update to version 1.5.8.

DICOM Support

Plugin Slug:
dicom-support

Installations
100+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
0.10.7

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 0.10.7.

Your Simple SVG Support

Plugin Slug:
your-simple-svg-support

Installations
10+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.0.2

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.0.2.

Bitspecter Suite

Plugin Slug:
bitspecter-suite

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.1.0

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.1.0.

BoomBox Theme Extensions

Plugin:

BoomBox Theme Extensions

Plugin Slug:
boombox-theme-extensions

Vulnerability:
Privilege Escalation

Patched in Version:
1.8.1

Severity Score:
High


The vulnerability has been patched, so you should update to version 1.8.1.

Service Finder Booking

Plugin:

Service Finder Booking

Plugin Slug:
sf-booking

Vulnerability:
Privilege Escalation

Patched in Version:
5.1

Severity Score:
Critical


The vulnerability has been patched, so you should update to version 5.1.

FoodBakery

Plugin:

FoodBakery

Plugin Slug:
wp-foodbakery

Vulnerability:
Broken Access Control

Patched in Version:
4.8

Severity Score:
High


The vulnerability has been patched, so you should update to version 4.8.

WordPress Themes � 5 Patched / 9 Unpatched

AuraMart

Theme Slug:
auramart

Downloads
802

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should switch themes.

Hester

Theme:

Hester

Theme Slug:
hester

Downloads
7,268

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should switch themes.

MorningTime Lite

Theme Slug:
morningtime-lite

Downloads
40,087

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should switch themes.

StoreBiz

Theme Slug:
storebiz

Downloads
102,239

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should switch themes.

Build

Theme:

Build

Theme Slug:
build

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should switch themes.

City Store

Theme:

City Store

Theme Slug:
city-store

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should switch themes.

newseqo

Theme:

newseqo

Theme Slug:
newseqo

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should switch themes.

RainbowNews

Theme:

RainbowNews

Theme Slug:
rainbownews

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should switch themes.

Whitish Lite

Theme:

Whitish Lite

Theme Slug:
whitish-lite

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should switch themes.

Altair

Theme:

Altair

Theme Slug:
altair

Vulnerability:
Settings Change

Patched in Version:
5.2.5

Severity Score:
Critical


The vulnerability has been patched, so you should update to version 5.2.5.

CozyStay

Theme:

CozyStay

Theme Slug:
cozystay

Vulnerability:
Broken Access Control

Patched in Version:
1.7.1

Severity Score:
High


The vulnerability has been patched, so you should update to version 1.7.1.

CozyStay

Theme:

CozyStay

Theme Slug:
cozystay

Vulnerability:
PHP Object Injection

Patched in Version:
1.7.1

Severity Score:
Critical


The vulnerability has been patched, so you should update to version 1.7.1.

MinimogWP

Theme:

MinimogWP

Theme Slug:
minimog

Vulnerability:
Local File Inclusion

Patched in Version:
3.8.0

Severity Score:
Critical


The vulnerability has been patched, so you should update to version 3.8.0.

TinySalt

Theme:

TinySalt

Theme Slug:
tinysalt

Vulnerability:
PHP Object Injection

Patched in Version:
3.10.0

Severity Score:
Critical


The vulnerability has been patched, so you should update to version 3.10.0.

Related articles

Wait! Get exclusive hosting insights

Subscribe to our newsletter and stay ahead of the competition with expert advice from our hosting pros.

Loading form…