Line illustration showing a black application window on a red gradient background overlaid with a large exclamation point alert icon and three bugs.

WordPress Vulnerability Report � June 4, 2025

In this report, 97 vulnerabilities have been publicly disclosed. Security patches for 59 of these plugins and themes are available now, so run those updates as soon as possible. If you’re a Solid Security Pro user, the version management tool may have already warned you and updated these plugins, depending on your settings.

Additionally, there are 38 plugin and theme vulnerabilities, and no patch has been available yet. If you’re a Solid Security Pro user, those vulnerabilities are already protected by the Solid Security firewall. Virtual patches from Patchstack will be applied when a vulnerability is considered high or medium risk. If no patch is forthcoming from the vendor or the vulnerable software has been marked “closed” and dropped from the official WordPress repositories, you should deactivate it soon and look for alternative solutions.

WordPress Core

WordPress 6.8.1 was released on April 30, 2025. This maintenance release includes fixes for 15 bugs�throughout Core�and�the Block Editor,�addressing issues affecting multiple areas of WordPress, including the block editor, multisite, and REST API. For a full list, refer to the�release candidate announcement.

WordPress Plugins � 52 Patched / 29 Unpatched

Real Time Validation for Gravity Forms

Plugin Slug:
real-time-validation-for-gravity-forms

Installations
2,000+

Vulnerability:
Local File Inclusion

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Real Time Validation for Gravity Forms

Plugin Slug:
real-time-validation-for-gravity-forms

Installations
2,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Real Time Validation for Gravity Forms

Plugin Slug:
real-time-validation-for-gravity-forms

Installations
2,000+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

History Log by click5

Plugin Slug:
history-log-by-click5

Installations
500+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Product Subtitle for WooCommerce

Plugin Slug:
product-subtitle-for-woocommerce

Installations
400+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Infility Global

Plugin Slug:
infility-global

Installations
90+

Vulnerability:
SQL Injection

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

SUMO Affiliates Pro

Plugin:

SUMO Affiliates Pro

Plugin Slug:
affs

Vulnerability:
Arbitrary File Upload

Patched in Version:
No Fix

Severity Score:
Critical


The vulnerability has not been patched. You should deactivate the plugin.
Plugin:

Apptha Slider Gallery

Plugin Slug:
apptha-slider-gallery

Vulnerability:
Arbitrary File Download

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Blog Designer PRO for WordPress

Plugin:

Blog Designer PRO for WordPress

Plugin Slug:
blog-designer-pro

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Browse As

Plugin:

Browse As

Plugin Slug:
browse-as

Vulnerability:
Broken Authentication

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

WPCHURCH

Plugin:

WPCHURCH

Plugin Slug:
church-management

Vulnerability:
Privilege Escalation

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

CSV Mass Importer

Plugin:

CSV Mass Importer

Plugin Slug:
csv-mass-importer

Vulnerability:
Arbitrary File Upload

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Daisycon prijsvergelijkers

Plugin:

Daisycon prijsvergelijkers

Plugin Slug:
daisycon

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

FastSpring

Plugin:

FastSpring

Plugin Slug:
fastspring

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Flynax Bridge

Plugin:

Flynax Bridge

Plugin Slug:
flynax-bridge

Vulnerability:
Privilege Escalation

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Gearside Developer Dashboard

Plugin:

Gearside Developer Dashboard

Plugin Slug:
gearside-developer-dashboard

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Likes and Dislikes

Plugin:

Likes and Dislikes

Plugin Slug:
inprosysmedia-likes-dislikes-post

Vulnerability:
SQL Injection

Patched in Version:
No Fix

Severity Score:
Critical


The vulnerability has not been patched. You should deactivate the plugin.

Offsprout Page Builder

Plugin:

Offsprout Page Builder

Plugin Slug:
offsprout-page-builder

Vulnerability:
Privilege Escalation

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

QuickCab

Plugin:

QuickCab

Plugin Slug:
quickcab

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

WBW Product Table PRO

Plugin:

WBW Product Table PRO

Plugin Slug:
woo-producttables-pro

Vulnerability:
SQL Injection

Patched in Version:
No Fix

Severity Score:
Critical


The vulnerability has not been patched. You should deactivate the plugin.

Woo Slider Pro

Plugin:

Woo Slider Pro

Plugin Slug:
woo-slider-pro-drag-drop-slider-builder-for-woocommerce

Vulnerability:
Arbitrary Content Deletion

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Woo Slider Pro

Plugin:

Woo Slider Pro

Plugin Slug:
woo-slider-pro-drag-drop-slider-builder-for-woocommerce

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

WooCommerce Orders & Customers Exporter

Plugin:

WooCommerce Orders & Customers Exporter

Plugin Slug:
woocommerce-orders-customers-exporter

Vulnerability:
Sensitive Data Exposure

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

WP-GeoMeta

Plugin:

WP-GeoMeta

Plugin Slug:
wp-geometa

Vulnerability:
Privilege Escalation

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

WP Guppy

Plugin:

WP Guppy

Plugin Slug:
wp-guppy

Vulnerability:
SQL Injection

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.
Plugin Slug:
broken-link-checker

Installations
600,000+

Vulnerability:
Sensitive Data Exposure

Patched in Version:
2.4.5

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.4.5.

Ocean Extra

Plugin Slug:
ocean-extra

Installations
600,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.4.9

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.4.9.

Royal Elementor Addons and Templates

Plugin Slug:
royal-elementor-addons

Installations
600,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.7.1021

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.7.1021.
Plugin Slug:
real-cookie-banner

Installations
100,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
5.1.6

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 5.1.6.

Ninja Tables � Easy Data Table Builder

Plugin Slug:
ninja-tables

Installations
80,000+

Vulnerability:
PHP Object Injection

Patched in Version:
5.0.19

Severity Score:
Critical


The vulnerability has been patched, so you should update to version 5.0.19.

Exclusive Addons for Elementor

Plugin Slug:
exclusive-addons-for-elementor

Installations
60,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.7.9.2

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.7.9.2.

Bold Page Builder

Plugin Slug:
bold-page-builder

Installations
50,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
5.3.7

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 5.3.7.

PowerPress Podcasting plugin by Blubrry

Plugin Slug:
powerpress

Installations
30,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
11.9.18

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 11.9.18.

LA-Studio Element Kit for Elementor

Plugin Slug:
lastudio-element-kit

Installations
20,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.5.3

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.5.3.

LA-Studio Element Kit for Elementor

Plugin Slug:
lastudio-element-kit

Installations
20,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.5.3

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.5.3.

All-in-One Addons for Elementor � WidgetKit

Plugin Slug:
widgetkit-for-elementor

Installations
10,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.5.5

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.5.5.

Ultimate Gift Cards for WooCommerce

Plugin Slug:
woo-gift-cards-lite

Installations
7,000+

Vulnerability:
SQL Injection

Patched in Version:
3.1.5

Severity Score:
High


The vulnerability has been patched, so you should update to version 3.1.5.

Borderless � Elementor Addons and Templates

Plugin Slug:
borderless

Installations
6,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.7.2

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.7.2.

Simple Page Access Restriction

Plugin Slug:
simple-page-access-restriction

Installations
6,000+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
1.0.32

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.0.32.

EU/UK VAT Validation Manager for WooCommerce

Plugin Slug:
eu-vat-for-woocommerce

Installations
5,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
4.4.3

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 4.4.3.

Min Max Step Quantity Limits Manager for WooCommerce

Plugin Slug:
product-quantity-for-woocommerce

Installations
4,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
5.0.4

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 5.0.4.

WP Attachments

Plugin Slug:
wp-attachments

Installations
4,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
5.1

Severity Score:
High


The vulnerability has been patched, so you should update to version 5.1.
Plugin Slug:
wp-posts-carousel

Installations
4,000+

Vulnerability:
PHP Object Injection

Patched in Version:
1.3.13

Severity Score:
High


The vulnerability has been patched, so you should update to version 1.3.13.

WordPress Comments Import & Export

Plugin Slug:
comments-import-export-woocommerce

Installations
3,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.4.4

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.4.4.

Newsletters

Plugin Slug:
newsletters-lite

Installations
3,000+

Vulnerability:
Local File Inclusion

Patched in Version:
4.10

Severity Score:
High


The vulnerability has been patched, so you should update to version 4.10.

Volunteer Sign Up Sheets

Plugin Slug:
pta-volunteer-sign-up-sheets

Installations
2,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
5.5.5

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 5.5.5.

Quick Contact Form

Plugin Slug:
quick-contact-form

Installations
2,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
8.2.2

Severity Score:
High


The vulnerability has been patched, so you should update to version 8.2.2.

Dynamic Pricing and Discount Rules

Plugin Slug:
discount-and-dynamic-pricing

Installations
1,000+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
2.3.0

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.3.0.

The Ultimate WordPress Toolkit � WP Extended

Plugin Slug:
wpextended

Installations
1,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
3.0.16

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 3.0.16.

WordPress Contact Forms by Cimatti

Plugin Slug:
contact-forms

Installations
900+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
1.9.9

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.9.9.

Map Block Leaflet

Plugin Slug:
map-block-leaflet

Installations
700+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
3.2.2

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 3.2.2.

WP Plugin Info Card

Plugin Slug:
wp-plugin-info-card

Installations
700+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
5.4.0

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 5.4.0.

Verge3D Publishing and E-Commerce

Plugin Slug:
verge3d

Installations
600+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
4.9.4

Severity Score:
High


The vulnerability has been patched, so you should update to version 4.9.4.

Wishlist

Plugin:

Wishlist

Plugin Slug:
wishlist

Installations
500+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.0.44

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.0.44.

WP Pipes

Plugin:

WP Pipes

Plugin Slug:
wp-pipes

Installations
500+

Vulnerability:
Arbitrary File Deletion

Patched in Version:
1.4.3

Severity Score:
High


The vulnerability has been patched, so you should update to version 1.4.3.

NinjaTeam Chat for Telegram

Plugin Slug:
ninjateam-telegram

Installations
200+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.2

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.2.

Tournamatch

Plugin Slug:
tournamatch

Installations
200+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
4.6.2

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 4.6.2.

Minimal Share Buttons

Plugin Slug:
minimal-share-buttons

Installations
100+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.7.4

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.7.4.

OpenSheetMusicDisplay

Plugin Slug:
opensheetmusicdisplay

Installations
100+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.4.1

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.4.1.

Property � Real Estate Directory Listing

Plugin Slug:
property

Installations
20+

Vulnerability:
Privilege Escalation

Patched in Version:
1.0.7

Severity Score:
High


The vulnerability has been patched, so you should update to version 1.0.7.

MasterStudy LMS Pro

Plugin:

MasterStudy LMS Pro

Plugin Slug:
masterstudy-lms-learning-management-system-pro

Vulnerability:
Arbitrary File Upload

Patched in Version:
4.7.1

Severity Score:
Critical


The vulnerability has been patched, so you should update to version 4.7.1.
Plugin:

Real Cookie Banner Pro

Plugin Slug:
real-cookie-banner-pro

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
5.1.6

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 5.1.6.

wpForo Advanced Attachments

Plugin:

wpForo Advanced Attachments

Plugin Slug:
wpforo-advanced-attachments

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
3.2.0

Severity Score:
High


The vulnerability has been patched, so you should update to version 3.2.0.

WordPress Themes � 7 Patched / 9 Unpatched

Arlo

Theme:

Arlo

Theme Slug:
arlo

Vulnerability:
Local File Inclusion

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should switch themes.

FLAP – Business WordPress Theme

Theme:

FLAP – Business WordPress Theme

Theme Slug:
flap

Vulnerability:
PHP Object Injection

Patched in Version:
No Fix

Severity Score:
Critical


The vulnerability has not been patched. You should switch themes.

FlatNews

Theme:

FlatNews

Theme Slug:
flatnews

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should switch themes.

Krowd

Theme:

Krowd

Theme Slug:
krowd

Vulnerability:
Local File Inclusion

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should switch themes.

PIMP – Creative MultiPurpose

Theme:

PIMP – Creative MultiPurpose

Theme Slug:
pimp

Vulnerability:
Deserialization of untrusted data

Patched in Version:
No Fix

Severity Score:
Critical


The vulnerability has not been patched. You should switch themes.

PressGrid – Frontend Publish Reaction & Multimedia Theme

Theme:

PressGrid – Frontend Publish Reaction & Multimedia Theme

Theme Slug:
press-grid

Vulnerability:
Deserialization of untrusted data

Patched in Version:
No Fix

Severity Score:
Critical


The vulnerability has not been patched. You should switch themes.

Revo

Theme:

Revo

Theme Slug:
revo

Vulnerability:
Local File Inclusion

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should switch themes.

Soho Hotel

Theme:

Soho Hotel

Theme Slug:
soho-hotel

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should switch themes.

Spare

Theme:

Spare

Theme Slug:
spare

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should switch themes.

Courtney

Theme:

Courtney

Theme Slug:
courtney

Vulnerability:
Local File Inclusion

Patched in Version:
1.3.1

Severity Score:
High


The vulnerability has been patched, so you should update to version 1.3.1.

Lesya

Theme:

Lesya

Theme Slug:
lesya

Vulnerability:
Local File Inclusion

Patched in Version:
1.7.3

Severity Score:
High


The vulnerability has been patched, so you should update to version 1.7.3.

Lettery

Theme:

Lettery

Theme Slug:
lettery

Vulnerability:
Local File Inclusion

Patched in Version:
1.1.8

Severity Score:
High


The vulnerability has been patched, so you should update to version 1.1.8.

Minterio

Theme:

Minterio

Theme Slug:
minterio

Vulnerability:
Local File Inclusion

Patched in Version:
1.4.1

Severity Score:
High


The vulnerability has been patched, so you should update to version 1.4.1.

Mr. Murphy

Theme:

Mr. Murphy

Theme Slug:
mr-murphy

Vulnerability:
PHP Object Injection

Patched in Version:
1.2.12.1

Severity Score:
Critical


The vulnerability has been patched, so you should update to version 1.2.12.1.

Starbelly

Theme:

Starbelly

Theme Slug:
starbelly

Vulnerability:
Local File Inclusion

Patched in Version:
1.3.7

Severity Score:
High


The vulnerability has been patched, so you should update to version 1.3.7.

Sweet Dessert

Theme:

Sweet Dessert

Theme Slug:
sweet-dessert

Vulnerability:
PHP Object Injection

Patched in Version:
1.1.13

Severity Score:
Critical


The vulnerability has been patched, so you should update to version 1.1.13.

Related articles

Wait! Get exclusive hosting insights

Subscribe to our newsletter and stay ahead of the competition with expert advice from our hosting pros.

Loading form…