Line illustration showing a black application window on a dark orange to black gradient background overlaid with a large exclamation point alert icon and three bugs.

WordPress Vulnerability Report � May 14, 2025

In this report, 234 vulnerabilities have been publicly disclosed. Security patches for 142 of these plugins and themes are available now, so run those updates as soon as possible. If you’re a Solid Security Pro user, the version management tool may have already warned you and updated these plugins, depending on your settings.

Additionally, there are 92 plugin and theme vulnerabilities, and no patch has been available yet. If you’re a Solid Security Pro user, those vulnerabilities are already protected by the Solid Security firewall. Virtual patches from Patchstack will be applied when a vulnerability is considered high or medium risk. If no patch is forthcoming from the vendor or the vulnerable software has been marked “closed” and dropped from the official WordPress repositories, you should deactivate it soon and look for alternative solutions.

WordPress Core

WordPress 6.8.1 has been released! This maintenance release includes fixes for 15 bugs throughout Core and the Block Editor, addressing issues affecting multiple areas of WordPress, including the block editor, multisite, and REST API. For a full list, refer to the release candidate announcement.

Plus, WordCamp Europe 2025 lands in Basel, Switzerland, June 5-7! Connect with WordPress enthusiasts, developers, and pros for three days of learning, networking, and collaboration with the global community.

WordPress Plugins � 138 Patched / 92 Unpatched

Plugin Slug:
intelly-related-posts

Installations
100,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

List category posts

Plugin Slug:
list-category-posts

Installations
90,000+

Vulnerability:
Local File Inclusion

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

WP Maintenance

Plugin Slug:
wp-maintenance

Installations
50,000+

Vulnerability:
PHP Object Injection

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

WordPress Infinite Scroll � Ajax Load More

Plugin Slug:
ajax-load-more

Installations
40,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

User Login History

Plugin Slug:
user-login-history

Installations
10,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Easy PayPal & Stripe Buy Now Button

Plugin Slug:
wp-ecommerce-paypal

Installations
10,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Spiraclethemes Site Library

Plugin Slug:
spiraclethemes-site-library

Installations
2,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

WPBakery Visual Composer WHMCS Elements

Plugin Slug:
void-visual-whmcs-element

Installations
2,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

aBlocks � WordPress Gutenberg Blocks

Plugin Slug:
ablocks

Installations
1,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Web Accessibility with Max Access

Plugin Slug:
accessibility-toolbar

Installations
1,000+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Amazon Product in a Post Plugin

Plugin Slug:
amazon-product-in-a-post-plugin

Installations
1,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Awin � Advertiser Tracking for WooCommerce

Plugin Slug:
awin-advertiser-tracking

Installations
1,000+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

belingoGeo

Plugin Slug:
belingogeo

Installations
1,000+

Vulnerability:
Arbitrary File Download

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

BMI Adult & Kid Calculator

Plugin Slug:
bmi-adultkid-calculator

Installations
1,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

CBX Map for Google Map & OpenStreetMap

Plugin Slug:
cbxgooglemap

Installations
1,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

ContentStudio

Plugin Slug:
contentstudio

Installations
1,000+

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Contribuinte Checkout

Plugin Slug:
contribuinte-checkout

Installations
1,000+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

DoFollow Case by Case

Plugin Slug:
dofollow-case-by-case

Installations
1,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

DoFollow Case by Case

Plugin Slug:
dofollow-case-by-case

Installations
1,000+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Ebook Store

Plugin Slug:
ebook-store

Installations
1,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Email Notification on Login

Plugin Slug:
email-notification-on-login

Installations
1,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

????? ?? ???? � ???? ?? ????

Plugin Slug:
pgall-for-woocommerce

Installations
1,000+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Sidebar Manager Light

Plugin Slug:
sidebar-manager-light

Installations
1,000+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Smaily for WP

Plugin Slug:
smaily-for-wp

Installations
1,000+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Woobox

Plugin:

Woobox

Plugin Slug:
woobox

Installations
1,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Woobox

Plugin:

Woobox

Plugin Slug:
woobox

Installations
1,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

WordPress CRM Plugin � WP-CRM System

Plugin Slug:
wp-crm-system

Installations
1,000+

Vulnerability:
PHP Object Injection

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

WordPress Webinar Plugin � WebinarPress

Plugin Slug:
wp-webinarsystem

Installations
1,000+

Vulnerability:
Server Side Request Forgery (SSRF)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

WPSpeed

Plugin:

WPSpeed

Plugin Slug:
wpspeed

Installations
1,000+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

xili-tidy-tags

Plugin Slug:
xili-tidy-tags

Installations
1,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.
Plugin Slug:
bulk-featured-image

Installations
900+

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Really Simple Under Construction Page

Plugin Slug:
really-simple-under-construction

Installations
700+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

WP jQuery DataTable

Plugin Slug:
wp-jquery-datatable

Installations
700+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Beacon Lead Magnets and Lead Capture

Plugin Slug:
beacon-by

Installations
600+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Submission DOM tracking for Contact Form 7

Plugin Slug:
cf7-submission-dom-tracking

Installations
600+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Color Your Bar

Plugin Slug:
color-your-bar

Installations
600+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

CookieCode

Plugin Slug:
cookiecode

Installations
600+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

EasyMe Connect

Plugin Slug:
easyme-connect

Installations
600+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

N360 | Splash Screen

Plugin Slug:
n360-splash-screen

Installations
600+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Show All Comments

Plugin Slug:
show-all-comments-in-one-page

Installations
600+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

WP Discord Invite

Plugin Slug:
wp-discord-invite

Installations
600+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

WP Pipes

Plugin:

WP Pipes

Plugin Slug:
wp-pipes

Installations
600+

Vulnerability:
Server Side Request Forgery (SSRF)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

DELUCKS SEO

Plugin Slug:
delucks-seo

Installations
500+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Lead Form Data Collection to CRM

Plugin Slug:
wp-leads-builder-any-crm

Installations
500+

Vulnerability:
Privilege Escalation

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

ELEX WordPress HelpDesk & Customer Ticketing System

Plugin Slug:
elex-helpdesk-customer-support-ticket-system

Installations
400+

Vulnerability:
Arbitrary File Upload

Patched in Version:
No Fix

Severity Score:
Critical


The vulnerability has not been patched. You should deactivate the plugin.

FunnelCockpit

Plugin Slug:
funnelcockpit

Installations
400+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Ajar in5 Embed

Plugin Slug:
ajar-productions-in5-embed

Installations
300+

Vulnerability:
Arbitrary File Upload

Patched in Version:
No Fix

Severity Score:
Critical


The vulnerability has not been patched. You should deactivate the plugin.

Pays � WooCommerce Payment Gateway

Plugin Slug:
axima-payment-gateway

Installations
300+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Integrations of Zoho CRM with Elementor form

Plugin Slug:
integrations-of-zoho-crm-with-elementor-form

Installations
300+

Vulnerability:
Open Redirection

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Calculate Prices based on Distance For WooCommerce

Plugin Slug:
calculate-prices-based-on-distance-for-woocommerce

Installations
100+

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Credova Financial

Plugin Slug:
credova-financial

Installations
100+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Soccer Live Scores

Plugin Slug:
soccer-live-scores

Installations
100+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

PSW Front-end Login & Registration

Plugin Slug:
psw-login-and-registration

Installations
90+

Vulnerability:
Broken Authentication

Patched in Version:
No Fix

Severity Score:
Critical


The vulnerability has not been patched. You should deactivate the plugin.

WP Podcasts Manager

Plugin Slug:
wp-podcasts-manager

Installations
80+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Supertext Translation and Proofreading

Plugin Slug:
polylang-supertext

Installations
60+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

StoreKeeper for WooCommerce

Plugin Slug:
storekeeper-for-woocommerce

Installations
50+

Vulnerability:
Arbitrary File Upload

Patched in Version:
No Fix

Severity Score:
Critical


The vulnerability has not been patched. You should deactivate the plugin.

CarDealerPress

Plugin Slug:
cardealerpress

Installations
40+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

ELEX Product Feed for WooCommerce

Plugin Slug:
elex-product-feed

Installations
30+

Vulnerability:
SQL Injection

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

BNS Twitter Follow Button

Plugin Slug:
bns-twitter-follow-button

Installations
10+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

1 Click WordPress Migration

Plugin:

1 Click WordPress Migration

Plugin Slug:
1-click-migration

Vulnerability:
Arbitrary File Upload

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

AHAthat

Plugin:

AHAthat

Plugin Slug:
ahathat

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.
Plugin:

Awesome Gallery

Plugin Slug:
awesome-gallery

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

External image replace

Plugin:

External image replace

Plugin Slug:
external-image-replace

Vulnerability:
Arbitrary File Upload

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Frontend Login and Registration Blocks

Plugin:

Frontend Login and Registration Blocks

Plugin Slug:
frontend-login-and-registration-blocks

Vulnerability:
Privilege Escalation

Patched in Version:
No Fix

Severity Score:
Critical


The vulnerability has not been patched. You should deactivate the plugin.

LayoutBoxx

Plugin:

LayoutBoxx

Plugin Slug:
layoutboxx

Vulnerability:
Content Injection

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

LessButtons Social Sharing and Statistics

Plugin:

LessButtons Social Sharing and Statistics

Plugin Slug:
lessbuttons

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Multiple Post Type Order

Plugin:

Multiple Post Type Order

Plugin Slug:
multiple-post-type-order

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

PeproDev Ultimate Profile Solutions

Plugin:

PeproDev Ultimate Profile Solutions

Plugin Slug:
peprodev-ups

Vulnerability:
Broken Authentication

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

PeproDev Ultimate Profile Solutions

Plugin:

PeproDev Ultimate Profile Solutions

Plugin Slug:
peprodev-ups

Vulnerability:
Broken Authentication

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

PeproDev Ultimate Profile Solutions

Plugin:

PeproDev Ultimate Profile Solutions

Plugin Slug:
peprodev-ups

Vulnerability:
Privilege Escalation

Patched in Version:
No Fix

Severity Score:
Critical


The vulnerability has not been patched. You should deactivate the plugin.

QS Dark Mode

Plugin:

QS Dark Mode

Plugin Slug:
qs-dark-mode

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Reales WP STPT

Plugin:

Reales WP STPT

Plugin Slug:
short-tax-post

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Reales WP STPT

Plugin:

Reales WP STPT

Plugin Slug:
short-tax-post

Vulnerability:
Privilege Escalation

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

WP SmartPay

Plugin:

WP SmartPay

Plugin Slug:
smartpay

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Woocommerce Multiple Addresses

Plugin:

Woocommerce Multiple Addresses

Plugin Slug:
woocommerce-multiple-addresses

Vulnerability:
Privilege Escalation

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

WordPress Review Plugin

Plugin:

WordPress Review Plugin

Plugin Slug:
wp-review

Vulnerability:
Local File Inclusion

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

WP shop

Plugin:

WP shop

Plugin Slug:
wpshop

Vulnerability:
Privilege Escalation

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

WP shop

Plugin:

WP shop

Plugin Slug:
wpshop

Vulnerability:
Insecure Direct Object References (IDOR)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Xavin’s List Subpages

Plugin:

Xavin’s List Subpages

Plugin Slug:
xavins-list-subpages

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

LiteSpeed Cache

Plugin Slug:
litespeed-cache

Installations
7,000,000+

Vulnerability:
Server Side Request Forgery (SSRF)

Patched in Version:
7.1

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 7.1.

Royal Elementor Addons and Templates

Plugin Slug:
royal-elementor-addons

Installations
600,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.7.1018

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.7.1018.

Jeg Elementor Kit

Plugin Slug:
jeg-elementor-kit

Installations
300,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.6.13

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.6.13.

Newsletter � Send awesome emails from WordPress

Plugin Slug:
newsletter

Installations
300,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
8.7.1

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 8.7.1.

Firelight Lightbox

Plugin Slug:
easy-fancybox

Installations
200,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.3.15

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.3.15.

Popup and Slider Builder by Depicter � Add Email collecting Popup, Popup Modal, Coupon Popup, Image Slider, Carousel Slider, Post Slider Carousel

Plugin Slug:
depicter

Installations
100,000+

Vulnerability:
SQL Injection

Patched in Version:
3.6.2

Severity Score:
Critical


The vulnerability has been patched, so you should update to version 3.6.2.

Login Lockdown & Protection

Plugin Slug:
login-lockdown

Installations
100,000+

Vulnerability:
Broken Access Control

Patched in Version:
2.12

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.12.
Plugin Slug:
relevanssi

Installations
100,000+

Vulnerability:
SQL Injection

Patched in Version:
4.24.5

Severity Score:
High


The vulnerability has been patched, so you should update to version 4.24.5.
Plugin Slug:
relevanssi

Installations
100,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
4.24.4

Severity Score:
High


The vulnerability has been patched, so you should update to version 4.24.4.

Download Monitor

Plugin Slug:
download-monitor

Installations
90,000+

Vulnerability:
Local File Inclusion

Patched in Version:
5.0.23

Severity Score:
High


The vulnerability has been patched, so you should update to version 5.0.23.

Jupiter X Core

Plugin Slug:
jupiterx-core

Installations
90,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
4.8.12

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 4.8.12.
Plugin Slug:
contextual-related-posts

Installations
70,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
4.0.3

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 4.0.3.

Bold Page Builder

Plugin Slug:
bold-page-builder

Installations
50,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
5.3.1

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 5.3.1.

Bold Page Builder

Plugin Slug:
bold-page-builder

Installations
50,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
5.3.3

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 5.3.3.

Ultimate Blocks � WordPress Blocks Plugin

Plugin Slug:
ultimate-blocks

Installations
50,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
3.3.0

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 3.3.0.

Ditty � Responsive News Tickers, Sliders, and Lists

Plugin Slug:
ditty-news-ticker

Installations
40,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
3.1.52

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 3.1.52.
Plugin Slug:
robo-gallery

Installations
40,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
5.0.3

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 5.0.3.

LightPress Lightbox

Plugin Slug:
wp-jquery-lightbox

Installations
40,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.3.4

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.3.4.

Envo Extra

Plugin Slug:
envo-extra

Installations
30,000+

Vulnerability:
Broken Access Control

Patched in Version:
1.9.10

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.9.10.

WP SEO Structured Data Schema

Plugin Slug:
wp-seo-structured-data-schema

Installations
30,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.8.0

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.8.0.
Plugin Slug:
beaf-before-and-after-gallery

Installations
20,000+

Vulnerability:
Arbitrary File Upload

Patched in Version:
4.6.11

Severity Score:
Critical


The vulnerability has been patched, so you should update to version 4.6.11.

Accept Donations with PayPal & Stripe

Plugin Slug:
easy-paypal-donation

Installations
20,000+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
1.5

Severity Score:
High


The vulnerability has been patched, so you should update to version 1.5.

Meks Flexible Shortcodes

Plugin Slug:
meks-flexible-shortcodes

Installations
20,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.3.7

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.3.7.

PW WooCommerce Bulk Edit

Plugin Slug:
pw-bulk-edit

Installations
20,000+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
2.135

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.135.
Plugin Slug:
top-10

Installations
20,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
4.1.1

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 4.1.1.

BlockSpare: Gutenberg Blocks & Patterns for Blogs, Magazines, Business Sites � Post Grids, Sliders, Carousels, Counters, Page Builder & Starter Site Imports, No Coding Needed

Plugin Slug:
blockspare

Installations
10,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
3.2.10

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 3.2.10.

AI Power: Complete AI Pack

Plugin Slug:
gpt3-ai-content-generator

Installations
10,000+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
1.9.15

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.9.15.

Graphina � Elementor Charts and Graphs

Plugin Slug:
graphina-elementor-charts-and-graphs

Installations
10,000+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
3.0.5

Severity Score:
High


The vulnerability has been patched, so you should update to version 3.0.5.

Graphina � Elementor Charts and Graphs

Plugin Slug:
graphina-elementor-charts-and-graphs

Installations
10,000+

Vulnerability:
Broken Access Control

Patched in Version:
3.0.5

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 3.0.5.
Plugin Slug:
meow-gallery

Installations
10,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
5.2.8

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 5.2.8.

NEX-Forms � Ultimate Forms Plugin for WordPress

Plugin Slug:
nex-forms-express-wp-form-builder

Installations
10,000+

Vulnerability:
Arbitrary Code Execution

Patched in Version:
8.9.2

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 8.9.2.

NEX-Forms � Ultimate Forms Plugin for WordPress

Plugin Slug:
nex-forms-express-wp-form-builder

Installations
10,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
8.9.2

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 8.9.2.

Countdown Timer � Widget Countdown

Plugin Slug:
widget-countdown

Installations
10,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.7.5

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.7.5.

Contact Form 7 � PayPal & Stripe Add-on

Plugin Slug:
contact-form-7-paypal-add-on

Installations
9,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.4.1

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.4.1.

Cozy Blocks � Page Builder for Gutenberg & Site Editor with Post Blocks, WooCommerce Blocks, Magazine Blocks & WordPress Gutenberg Blocks

Plugin Slug:
cozy-addons

Installations
9,000+

Vulnerability:
Broken Access Control

Patched in Version:
2.1.23

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.1.23.

WP Compress � Instant Performance & Speed Optimization

Plugin Slug:
wp-compress-image-optimizer

Installations
9,000+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
6.30.31

Severity Score:
High


The vulnerability has been patched, so you should update to version 6.30.31.

WP Hotel Booking

Plugin Slug:
wp-hotel-booking

Installations
8,000+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
2.2.0

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.2.0.

Dynamic Pricing With Discount Rules for WooCommerce

Plugin Slug:
aco-woo-dynamic-pricing

Installations
7,000+

Vulnerability:
SQL Injection

Patched in Version:
4.5.9

Severity Score:
High


The vulnerability has been patched, so you should update to version 4.5.9.

ProfileGrid � User Profiles, Groups and Communities

Plugin Slug:
profilegrid-user-profiles-groups-and-communities

Installations
7,000+

Vulnerability:
SQL Injection

Patched in Version:
5.9.5.1

Severity Score:
High


The vulnerability has been patched, so you should update to version 5.9.5.1.

Simple File List

Plugin Slug:
simple-file-list

Installations
7,000+

Vulnerability:
Settings Change

Patched in Version:
6.1.14

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 6.1.14.

TrackShip for WooCommerce

Plugin Slug:
trackship-for-woocommerce

Installations
7,000+

Vulnerability:
SQL Injection

Patched in Version:
1.9.2

Severity Score:
High


The vulnerability has been patched, so you should update to version 1.9.2.

Drag and Drop Multiple File Upload for WooCommerce

Plugin Slug:
drag-and-drop-multiple-file-upload-for-woocommerce

Installations
6,000+

Vulnerability:
Arbitrary File Upload

Patched in Version:
1.1.7

Severity Score:
Critical


The vulnerability has been patched, so you should update to version 1.1.7.

EventON � Events Calendar

Plugin Slug:
eventon-lite

Installations
6,000+

Vulnerability:
Local File Inclusion

Patched in Version:
2.4.2

Severity Score:
High


The vulnerability has been patched, so you should update to version 2.4.2.

Hotel Booking

Plugin Slug:
nd-booking

Installations
5,000+

Vulnerability:
Local File Inclusion

Patched in Version:
3.7

Severity Score:
High


The vulnerability has been patched, so you should update to version 3.7.

Simple Blog Stats

Plugin Slug:
simple-blog-stats

Installations
5,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
20250423

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 20250423.

SMS Alert Order Notifications � WooCommerce

Plugin Slug:
sms-alert

Installations
5,000+

Vulnerability:
Privilege Escalation

Patched in Version:
3.8.2

Severity Score:
High


The vulnerability has been patched, so you should update to version 3.8.2.

SMS Alert Order Notifications � WooCommerce

Plugin Slug:
sms-alert

Installations
5,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
3.8.2

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 3.8.2.

SMS Alert Order Notifications � WooCommerce

Plugin Slug:
sms-alert

Installations
5,000+

Vulnerability:
SQL Injection

Patched in Version:
3.8.2

Severity Score:
Critical


The vulnerability has been patched, so you should update to version 3.8.2.

WPAdverts � Classifieds Plugin

Plugin Slug:
wpadverts

Installations
5,000+

Vulnerability:
Local File Inclusion

Patched in Version:
2.2.3

Severity Score:
High


The vulnerability has been patched, so you should update to version 2.2.3.

Ovation Elements

Plugin Slug:
ovation-elements

Installations
4,000+

Vulnerability:
Broken Access Control

Patched in Version:
1.1.3

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.1.3.

Hash Form � Drag & Drop Form Builder

Plugin Slug:
hash-form

Installations
3,000+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
1.2.9

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.2.9.

Mollie Forms

Plugin Slug:
mollie-forms

Installations
3,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.7.13

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.7.13.

Newsletters

Plugin Slug:
newsletters-lite

Installations
3,000+

Vulnerability:
SQL Injection

Patched in Version:
4.9.9.9

Severity Score:
High


The vulnerability has been patched, so you should update to version 4.9.9.9.

Solace Extra

Plugin Slug:
solace-extra

Installations
3,000+

Vulnerability:
Server Side Request Forgery (SSRF)

Patched in Version:
1.3.2

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.3.2.

Challan � PDF Invoice & Packing Slip for WooCommerce

Plugin Slug:
webappick-pdf-invoice-for-woocommerce

Installations
3,000+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
3.7.59

Severity Score:
High


The vulnerability has been patched, so you should update to version 3.7.59.

Display Eventbrite Events

Plugin Slug:
widget-for-eventbrite-api

Installations
3,000+

Vulnerability:
Local File Inclusion

Patched in Version:
6.3

Severity Score:
High


The vulnerability has been patched, so you should update to version 6.3.

Beds24 Online Booking

Plugin Slug:
beds24-online-booking

Installations
2,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.0.30

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.0.30.

CoinPayments.net Payment Gateway for WooCommerce

Plugin Slug:
coinpayments-payment-gateway-for-woocommerce

Installations
2,000+

Vulnerability:
PHP Object Injection

Patched in Version:
1.0.18

Severity Score:
Critical


The vulnerability has been patched, so you should update to version 1.0.18.

SendPulse Email Marketing Newsletter

Plugin Slug:
sendpulse-email-marketing-newsletter

Installations
2,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.1.7

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.1.7.

SKT Skill Bar

Plugin Slug:
skt-skill-bar

Installations
2,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.5

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.5.

CC BMI Calculator

Plugin Slug:
cc-bmi-calculator

Installations
1,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.1.1

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.1.1.
Plugin Slug:
contest-gallery

Installations
1,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
26.0.7

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 26.0.7.

Easy PayPal Events & Tickets

Plugin Slug:
easy-paypal-events-tickets

Installations
1,000+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
1.3

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.3.

Logo Showcase

Plugin Slug:
logo-showcase

Installations
1,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
3.0.5

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 3.0.5.

Music Player for WooCommerce

Plugin Slug:
music-player-for-woocommerce

Installations
1,000+

Vulnerability:
Broken Access Control

Patched in Version:
1.6.0

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.6.0.

Progress Bar

Plugin Slug:
progress-bar

Installations
1,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.2.4

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.2.4.

Ultimate WP Mail

Plugin Slug:
ultimate-wp-mail

Installations
1,000+

Vulnerability:
SQL Injection

Patched in Version:
1.3.5

Severity Score:
High


The vulnerability has been patched, so you should update to version 1.3.5.

Ultimate WP Mail

Plugin Slug:
ultimate-wp-mail

Installations
1,000+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
1.3.5

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.3.5.

FundEngine � Donation and Crowdfunding Platform

Plugin Slug:
wp-fundraising-donation

Installations
1,000+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
1.7.4

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.7.4.

XT Event Widget for Social Events

Plugin Slug:
xt-facebook-events

Installations
1,000+

Vulnerability:
Local File Inclusion

Patched in Version:
1.1.8

Severity Score:
High


The vulnerability has been patched, so you should update to version 1.1.8.

Display Remote Posts Block

Plugin Slug:
display-remote-posts-block

Installations
800+

Vulnerability:
Server Side Request Forgery (SSRF)

Patched in Version:
1.1.1

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.1.1.

AWEOS WP Lock

Plugin Slug:
aweos-wp-lock

Installations
700+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.4.9

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.4.9.

Frontend Dashboard

Plugin Slug:
frontend-dashboard

Installations
700+

Vulnerability:
Privilege Escalation

Patched in Version:
2.2.8

Severity Score:
High


The vulnerability has been patched, so you should update to version 2.2.8.

Frontend Dashboard

Plugin Slug:
frontend-dashboard

Installations
700+

Vulnerability:
Privilege Escalation

Patched in Version:
2.2.7

Severity Score:
Critical


The vulnerability has been patched, so you should update to version 2.2.7.

Quran multilanguage Text & Audio

Plugin Slug:
quran-text-multilanguage

Installations
700+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.3.24

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.3.24.

Seznam Webmaster

Plugin Slug:
seznam-webmaster

Installations
700+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
1.4.8

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.4.8.

WP DPE-GES

Plugin Slug:
wp-dpe-ges

Installations
700+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.7

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.7.

Custom Checkout Fields for WooCommerce

Plugin Slug:
custom-checkout-fields-for-woocommerce

Installations
600+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.9.0

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.9.0.

Cool Author Box � For Widget and Post Content

Plugin Slug:
hm-cool-author-box-widget

Installations
600+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
3.0.1

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 3.0.1.

Listamester

Plugin Slug:
listamester

Installations
600+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
2.3.7

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.3.7.

Easy Replace Image

Plugin Slug:
easy-replace-image

Installations
500+

Vulnerability:
Server Side Request Forgery (SSRF)

Patched in Version:
3.5.1

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 3.5.1.
Plugin Slug:
ngg-smart-image-search

Installations
500+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
3.4.1

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 3.4.1.

Product Time Countdown for WooCommerce

Plugin Slug:
product-countdown-for-woocommerce

Installations
500+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.6.3

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.6.3.

TrueBooker � Appointment Booking and Scheduler Plugin.

Plugin Slug:
truebooker-appointment-booking

Installations
500+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
1.0.8

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.0.8.

Simple calendar for Elementor

Plugin Slug:
simple-calendar-for-elementor

Installations
400+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
1.6.6

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.6.6.

WZ Followed Posts � Display what visitors are reading

Plugin Slug:
where-did-they-go-from-here

Installations
400+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
3.1.1

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 3.1.1.

WP Gravity Forms Dynamics CRM

Plugin Slug:
gf-dynamics-crm

Installations
300+

Vulnerability:
Open Redirection

Patched in Version:
1.1.5

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.1.5.

Subaccounts for WooCommerce

Plugin Slug:
subaccounts-for-woocommerce

Installations
300+

Vulnerability:
Broken Authentication

Patched in Version:
1.6.7

Severity Score:
High


The vulnerability has been patched, so you should update to version 1.6.7.
Plugin Slug:
activity-link-preview-for-buddypress

Installations
200+

Vulnerability:
Server Side Request Forgery (SSRF)

Patched in Version:
1.6.0

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.6.0.

B2i Investor Tools

Plugin Slug:
b2i-investor-tools

Installations
200+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.0.8

Severity Score:
High


The vulnerability has been patched, so you should update to version 1.0.8.

Cart tracking for WooCommerce

Plugin Slug:
cart-tracking-for-woocommerce

Installations
200+

Vulnerability:
SQL Injection

Patched in Version:
1.0.18

Severity Score:
High


The vulnerability has been patched, so you should update to version 1.0.18.

EUCookieLaw

Plugin Slug:
eucookielaw

Installations
200+

Vulnerability:
Arbitrary File Download

Patched in Version:
2.7.3

Severity Score:
High


The vulnerability has been patched, so you should update to version 2.7.3.

WP Gravity Forms Zendesk

Plugin Slug:
gf-zendesk

Installations
200+

Vulnerability:
Open Redirection

Patched in Version:
1.1.3

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.1.3.

LocateAndFilter

Plugin Slug:
locateandfilter

Installations
200+

Vulnerability:
Broken Access Control

Patched in Version:
1.6.17

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.6.17.

Product Quantity Dropdown For Woocommerce

Plugin Slug:
product-quantity-dropdown-for-woocommerce

Installations
200+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
1.3

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.3.
Plugin Slug:
spostarbust

Installations
200+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
1.2.04.25

Severity Score:
High


The vulnerability has been patched, so you should update to version 1.2.04.25.

Integration for WooCommerce and Salesforce

Plugin Slug:
woo-salesforce-plugin-crm-perks

Installations
200+

Vulnerability:
Open Redirection

Patched in Version:
1.7.6

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.7.6.

Cision Block

Plugin Slug:
cision-block

Installations
100+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
4.4.0

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 4.4.0.

Wiki Embed

Plugin Slug:
wiki-embed

Installations
100+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
1.4.7

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.4.7.

GS Variation Swatches for WooCommerce

Plugin Slug:
gs-woo-variation-swatches

Installations
50+

Vulnerability:
Broken Access Control

Patched in Version:
3.0.5

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 3.0.5.

WPBookit

Plugin:

WPBookit

Plugin Slug:
wpbookit

Installations
50+

Vulnerability:
Privilege Escalation

Patched in Version:
1.0.3

Severity Score:
Critical


The vulnerability has been patched, so you should update to version 1.0.3.

BuddyPress Platform Pro

Plugin:

BuddyPress Platform Pro

Plugin Slug:
buddyboss-platform-pro

Vulnerability:
Broken Authentication

Patched in Version:
2.7.10

Severity Score:
Critical


The vulnerability has been patched, so you should update to version 2.7.10.

Cost Calculator for Elementor

Plugin:

Cost Calculator for Elementor

Plugin Slug:
cost-calculator-for-elementor

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.3.4

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.3.4.

Envolve Plugin

Plugin:

Envolve Plugin

Plugin Slug:
envolve-plugin

Vulnerability:
Arbitrary File Upload

Patched in Version:
1.1.0

Severity Score:
Critical


The vulnerability has been patched, so you should update to version 1.1.0.

Envolve Plugin

Plugin:

Envolve Plugin

Plugin Slug:
envolve-plugin

Vulnerability:
Broken Access Control

Patched in Version:
1.1.0

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.1.0.

IMITHEMES Listing

Plugin:

IMITHEMES Listing

Plugin Slug:
imithemes-listing

Vulnerability:
Privilege Escalation

Patched in Version:
3.4

Severity Score:
Critical


The vulnerability has been patched, so you should update to version 3.4.

Opal Woo Custom Product Variation

Plugin:

Opal Woo Custom Product Variation

Plugin Slug:
opal-woo-custom-product-variation

Vulnerability:
Arbitrary File Deletion

Patched in Version:
1.2.1

Severity Score:
High


The vulnerability has been patched, so you should update to version 1.2.1.

PGS Core

Plugin:

PGS Core

Plugin Slug:
pgs-core

Vulnerability:
PHP Object Injection

Patched in Version:
5.9.0

Severity Score:
Critical


The vulnerability has been patched, so you should update to version 5.9.0.

PGS Core

Plugin:

PGS Core

Plugin Slug:
pgs-core

Vulnerability:
SQL Injection

Patched in Version:
5.9.0

Severity Score:
Critical


The vulnerability has been patched, so you should update to version 5.9.0.

PGS Core

Plugin:

PGS Core

Plugin Slug:
pgs-core

Vulnerability:
Broken Access Control

Patched in Version:
5.9.0

Severity Score:
High


The vulnerability has been patched, so you should update to version 5.9.0.

Relevanssi Premium

Plugin:

Relevanssi Premium

Plugin Slug:
relevanssi-premium

Vulnerability:
SQL Injection

Patched in Version:
2.27.5

Severity Score:
High


The vulnerability has been patched, so you should update to version 2.27.5.

WordPress Themes � 4 Patched / 0 Unpatched

Blocksy

Theme:

Blocksy

Theme Slug:
blocksy

Downloads
4,484,472

Vulnerability:
Broken Access Control

Patched in Version:
2.0.98

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.0.98.

TheGem

Theme:

TheGem

Theme Slug:
thegem

Vulnerability:
Broken Access Control

Patched in Version:
5.10.3.1

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 5.10.3.1.

TheGem

Theme:

TheGem

Theme Slug:
thegem

Vulnerability:
Arbitrary File Upload

Patched in Version:
5.10.3.1

Severity Score:
High


The vulnerability has been patched, so you should update to version 5.10.3.1.

Wolmart

Theme:

Wolmart

Theme Slug:
wolmart

Vulnerability:
Content Injection

Patched in Version:
1.8.12

Severity Score:
High


The vulnerability has been patched, so you should update to version 1.8.12.

Related articles

Wait! Get exclusive hosting insights

Subscribe to our newsletter and stay ahead of the competition with expert advice from our hosting pros.

Loading form…