Line illustration showing a black application window on a dark orange to black gradient background overlaid with a large exclamation point alert icon and three bugs.

WordPress Vulnerability Report � May 7, 2025

In this report, 88 vulnerabilities have been publicly disclosed. Security patches for 46 of these plugins and themes are available now, so run those updates as soon as possible. If you’re a Solid Security Pro user, the version management tool may have already warned you and updated these plugins, depending on your settings.

Additionally, there are 42 plugin and theme vulnerabilities, and no patch has been available yet. If you’re a Solid Security Pro user, those vulnerabilities are already protected by the Solid Security firewall. Virtual patches from Patchstack will be applied when a vulnerability is considered high or medium risk. If no patch is forthcoming from the vendor or the vulnerable software has been marked “closed” and dropped from the official WordPress repositories, you should deactivate it soon and look for alternative solutions.

WordPress Core

WordPress 6.8.1 has been released! This maintenance release includes fixes for 15 bugs throughout Core and the Block Editor, addressing issues affecting multiple areas of WordPress, including the block editor, multisite, and REST API. For a full list, refer to the release candidate announcement.

Plus, WordCamp Europe 2025 lands in Basel, Switzerland, June 5-7! Connect with WordPress enthusiasts, developers, and pros for three days of learning, networking, and collaboration with the global community.

WordPress Plugins � 40 Patched / 42 Unpatched

Section Widget

Plugin Slug:
section-widget

Installations
600+

Vulnerability:
Path Traversal

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Section Widget

Plugin Slug:
section-widget

Installations
600+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Crossword Compiler Puzzles

Plugin Slug:
crossword-compiler-puzzles

Installations
400+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Total processing card payments for WooCommerce

Plugin Slug:
totalprocessing-card-payments

Installations
200+

Vulnerability:
Arbitrary File Download

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Abundatrade

Plugin:

Abundatrade

Plugin Slug:
abundatrade-plugin

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Advanced Reorder Image Text Slider

Plugin:

Advanced Reorder Image Text Slider

Plugin Slug:
advanced-reorder-image-text-slider

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

AHAthat

Plugin:

AHAthat

Plugin Slug:
ahathat

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.
Plugin:

Alink Tap

Plugin Slug:
alink-tap

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Buddyboss Platform

Plugin:

Buddyboss Platform

Plugin Slug:
buddyboss-platform

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Category Widget

Plugin:

Category Widget

Plugin Slug:
category-widget

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Custom PC Builder Lite for WooCommerce

Plugin:

Custom PC Builder Lite for WooCommerce

Plugin Slug:
custom-pc-builder-lite-for-woocommerce

Vulnerability:
Settings Change

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Database Toolset

Plugin:

Database Toolset

Plugin Slug:
database-toolset

Vulnerability:
Sensitive Data Exposure

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

EC Authorize.net

Plugin:

EC Authorize.net

Plugin Slug:
ec-authorizenet

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

External image replace

Plugin:

External image replace

Plugin Slug:
external-image-replace

Vulnerability:
Arbitrary File Upload

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Flynax Bridge

Plugin:

Flynax Bridge

Plugin Slug:
flynax-bridge

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

GmapsMania

Plugin:

GmapsMania

Plugin Slug:
gmapsmania

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.
Plugin:

IGIT Related Posts With Thumb Image After Posts

Plugin Slug:
igit-related-posts-with-thumb-images-after-posts

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Job Listings

Plugin:

Job Listings

Plugin Slug:
job-listings

Vulnerability:
Privilege Escalation

Patched in Version:
No Fix

Severity Score:
Critical


The vulnerability has not been patched. You should deactivate the plugin.

KiwiChat NextClient

Plugin:

KiwiChat NextClient

Plugin Slug:
kiwichat

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

kStats Reloaded

Plugin:

kStats Reloaded

Plugin Slug:
kstats-reloaded

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

LayoutBoxx

Plugin:

LayoutBoxx

Plugin Slug:
layoutboxx

Vulnerability:
Content Injection

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Web3Press

Plugin:

Web3Press

Plugin Slug:
likecoin

Vulnerability:
Arbitrary File Download

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Custom Login and Registration

Plugin:

Custom Login and Registration

Plugin Slug:
ms-registration

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Nautic Pages

Plugin:

Nautic Pages

Plugin Slug:
nautic-pages

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

occupancyplan

Plugin:

occupancyplan

Plugin Slug:
occupancyplan

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

OTP-less one tap Sign in

Plugin:

OTP-less one tap Sign in

Plugin Slug:
otpless

Vulnerability:
Privilege Escalation

Patched in Version:
No Fix

Severity Score:
Critical


The vulnerability has not been patched. You should deactivate the plugin.

Remote Images Grabber

Plugin:

Remote Images Grabber

Plugin Slug:
remote-images-grabber

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Separator Shortcode and Widget

Plugin:

Separator Shortcode and Widget

Plugin Slug:
separator-shortcode-and-widget

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Reales WP STPT

Plugin:

Reales WP STPT

Plugin Slug:
short-tax-post

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Reales WP STPT

Plugin:

Reales WP STPT

Plugin Slug:
short-tax-post

Vulnerability:
Privilege Escalation

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Subpage List

Plugin:

Subpage List

Plugin Slug:
subpage-view

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Syndicate Out

Plugin:

Syndicate Out

Plugin Slug:
syndicate-out

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Theme Blvd Sliders

Plugin:

Theme Blvd Sliders

Plugin Slug:
theme-blvd-sliders

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Total Donations

Plugin:

Total Donations

Plugin Slug:
total-donations

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

VerticalResponse Newsletter Widget

Plugin:

VerticalResponse Newsletter Widget

Plugin Slug:
vertical-response-newsletter-widget

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Visual Builder

Plugin:

Visual Builder

Plugin Slug:
visual-builder

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Widgets as Shortcodes

Plugin:

Widgets as Shortcodes

Plugin Slug:
widgets-as-shortcodes

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Meta Keywords & Description

Plugin:

Meta Keywords & Description

Plugin Slug:
wp-meta-keywords-meta-description

Vulnerability:
Local File Inclusion

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Xavin’s Review Ratings

Plugin:

Xavin’s Review Ratings

Plugin Slug:
xavins-review-ratings

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Yame

Plugin:

Yame

Plugin Slug:
yame-linkinbio

Vulnerability:
Sensitive Data Exposure

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Newsletter � Send awesome emails from WordPress

Plugin Slug:
newsletter

Installations
300,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
8.7.1

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 8.7.1.

Admin and Site Enhancements (ASE)

Plugin Slug:
admin-site-enhancements

Installations
100,000+

Vulnerability:
Bypass Vulnerability

Patched in Version:
7.6.10

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 7.6.10.

Popup and Slider Builder by Depicter � Add Email collecting Popup, Popup Modal, Coupon Popup, Image Slider, Carousel Slider, Post Slider Carousel

Plugin Slug:
depicter

Installations
100,000+

Vulnerability:
SQL Injection

Patched in Version:
3.6.2

Severity Score:
Critical


The vulnerability has been patched, so you should update to version 3.6.2.

WP Maps � Display Google Maps Perfectly with Ease

Plugin Slug:
wp-google-map-plugin

Installations
70,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
4.7.2

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 4.7.2.

Calculated Fields Form

Plugin Slug:
calculated-fields-form

Installations
50,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
5.2.62

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 5.2.62.

Seraphinite Accelerator

Plugin Slug:
seraphinite-accelerator

Installations
50,000+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
2.27.22

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.27.22.

FULL � Cliente

Plugin Slug:
full-customer

Installations
40,000+

Vulnerability:
SQL Injection

Patched in Version:
3.1.26

Severity Score:
High


The vulnerability has been patched, so you should update to version 3.1.26.

SecuPress Free � WordPress Security

Plugin Slug:
secupress

Installations
40,000+

Vulnerability:
Broken Access Control

Patched in Version:
2.3.10

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.3.10.

Page View Count

Plugin Slug:
page-views-count

Installations
20,000+

Vulnerability:
Settings Change

Patched in Version:
2.8.5

Severity Score:
High


The vulnerability has been patched, so you should update to version 2.8.5.

WordPress Simple Shopping Cart

Plugin Slug:
wordpress-simple-paypal-shopping-cart

Installations
10,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
5.1.4

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 5.1.4.

WordPress Simple Shopping Cart

Plugin Slug:
wordpress-simple-paypal-shopping-cart

Installations
10,000+

Vulnerability:
Insecure Direct Object References (IDOR)

Patched in Version:
5.1.4

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 5.1.4.

WP-Recall � Registration, Profile, Commerce & More

Plugin Slug:
wp-recall

Installations
2,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
16.26.12

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 16.26.12.

Product Category Slider for WooCommerce

Plugin Slug:
woo-category-slider-by-pluginever

Installations
1,000+

Vulnerability:
Local File Inclusion

Patched in Version:
4.3.5

Severity Score:
High


The vulnerability has been patched, so you should update to version 4.3.5.

AM LottiePlayer

Plugin Slug:
am-lottieplayer

Installations
700+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
3.5.4

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 3.5.4.

Projectopia � WordPress Project Management

Plugin Slug:
projectopia-core

Installations
400+

Vulnerability:
Broken Access Control

Patched in Version:
5.1.17

Severity Score:
High


The vulnerability has been patched, so you should update to version 5.1.17.

BP Messages Tool

Plugin Slug:
bp-messages-tool

Installations
200+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.5

Severity Score:
High


The vulnerability has been patched, so you should update to version 2.5.

Formality

Plugin Slug:
formality

Installations
200+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.5.9

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.5.9.

Cision Block

Plugin Slug:
cision-block

Installations
100+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
4.4.0

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 4.4.0.

List Children

Plugin Slug:
list-children

Installations
100+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.2.0

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.2.0.

Taxonomy Chain Menu

Plugin Slug:
taxonomy-chain-menu

Installations
100+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.0.9

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.0.9.

Ads Pro Plugin

Plugin:

Ads Pro Plugin

Plugin Slug:
ap-plugin-scripteo

Vulnerability:
SQL Injection

Patched in Version:
4.89

Severity Score:
Critical


The vulnerability has been patched, so you should update to version 4.89.

BuddyPress Platform Pro

Plugin:

BuddyPress Platform Pro

Plugin Slug:
buddyboss-platform-pro

Vulnerability:
Broken Authentication

Patched in Version:
2.7.10

Severity Score:
Critical


The vulnerability has been patched, so you should update to version 2.7.10.

Envolve Plugin

Plugin:

Envolve Plugin

Plugin Slug:
envolve-plugin

Vulnerability:
Broken Access Control

Patched in Version:
1.1.0

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.1.0.

Gravity Forms WebHooks

Plugin:

Gravity Forms WebHooks

Plugin Slug:
gravityformswebhooks

Vulnerability:
Server Side Request Forgery (SSRF)

Patched in Version:
1.7.0

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.7.0.

Order Delivery Date for WP e-Commerce

Plugin:

Order Delivery Date for WP e-Commerce

Plugin Slug:
order-delivery-date

Vulnerability:
Privilege Escalation

Patched in Version:
12.3.1

Severity Score:
Critical


The vulnerability has been patched, so you should update to version 12.3.1.

Advance Seat Reservation Management for WooCommerce

Plugin:

Advance Seat Reservation Management for WooCommerce

Plugin Slug:
scw-seat-reservation

Vulnerability:
SQL Injection

Patched in Version:
3.4

Severity Score:
Critical


The vulnerability has been patched, so you should update to version 3.4.

Multilingual CMS

Plugin:

Multilingual CMS

Plugin Slug:
sitepress-multilingual-cms

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
4.7.4

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 4.7.4.

tagDiv Composer

Plugin:

tagDiv Composer

Plugin Slug:
td-composer

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
5.4.1

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 5.4.1.

tagDiv Opt-In Builder

Plugin:

tagDiv Opt-In Builder

Plugin Slug:
td-subscription

Vulnerability:
SQL Injection

Patched in Version:
1.7.1

Severity Score:
High


The vulnerability has been patched, so you should update to version 1.7.1.

Ultimate Auction Pro

Plugin:

Ultimate Auction Pro

Plugin Slug:
ultimate-woocommerce-auction-pro

Vulnerability:
SQL Injection

Patched in Version:
1.5.3

Severity Score:
Critical


The vulnerability has been patched, so you should update to version 1.5.3.

WordPress Themes � 6 Patched / 0 Unpatched

NewsBlogger

Theme Slug:
newsblogger

Downloads
100,624

Vulnerability:
Arbitrary File Upload

Patched in Version:
0.2.5.2

Severity Score:
High


The vulnerability has been patched, so you should update to version 0.2.5.2.

NewsBlogger

Theme Slug:
newsblogger

Downloads
100,624

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
0.2.5.5

Severity Score:
High


The vulnerability has been patched, so you should update to version 0.2.5.5.

Homey

Theme:

Homey

Theme Slug:
homey

Vulnerability:
Broken Access Control

Patched in Version:
2.4.5

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.4.5.

Homey

Theme:

Homey

Theme Slug:
homey

Vulnerability:
Insecure Direct Object References (IDOR)

Patched in Version:
2.4.5

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.4.5.

Kleo

Theme:

Kleo

Theme Slug:
kleo

Vulnerability:
Broken Access Control

Patched in Version:
5.4.4

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 5.4.4.

Motors

Theme:

Motors

Theme Slug:
motors

Vulnerability:
Content Injection

Patched in Version:
5.6.66

Severity Score:
High


The vulnerability has been patched, so you should update to version 5.6.66.

Related articles

Wait! Get exclusive hosting insights

Subscribe to our newsletter and stay ahead of the competition with expert advice from our hosting pros.

Loading form…