Line illustration showing a black application window on a blue gradient background overlaid with a large exclamation point alert icon and three bugs.

WordPress Vulnerability Report � June 11, 2025

In this report, 306 vulnerabilities have been publicly disclosed. Security patches for 134 of these plugins and themes are available now, so run those updates as soon as possible. If you’re a Solid Security Pro user, the version management tool may have already warned you and updated these plugins, depending on your settings.

Additionally, there are 172 plugin and theme vulnerabilities, and no patch has been available yet. If you’re a Solid Security Pro user, those vulnerabilities are already protected by the Solid Security firewall. Virtual patches from Patchstack will be applied when a vulnerability is considered high or medium risk. If no patch is forthcoming from the vendor or the vulnerable software has been marked “closed” and dropped from the official WordPress repositories, you should deactivate it soon and look for alternative solutions.

WordPress Core

WordPress 6.8.1 was released on April 30, 2025. This maintenance release includes fixes for 15 bugs throughout Core and the Block Editor, addressing issues affecting multiple areas of WordPress, including the block editor, multisite, and REST API. For a full list, refer to the release candidate announcement.

WordPress Plugins � 120 Patched / 151 Unpatched

Widget Logic

Plugin Slug:
widget-logic

Installations
100,000+

Vulnerability:
Remote Code Execution (RCE)

Patched in Version:
No Fix

Severity Score:
Critical


The vulnerability has not been patched. You should deactivate the plugin.

CubeWP � All-in-One Dynamic Content Framework

Plugin Slug:
cubewp-framework

Installations
5,000+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

PayU CommercePro Plugin

Plugin Slug:
payu-india

Installations
5,000+

Vulnerability:
Broken Authentication

Patched in Version:
No Fix

Severity Score:
Critical


The vulnerability has not been patched. You should deactivate the plugin.

WP Shopify

Plugin Slug:
wp-shopify

Installations
4,000+

Vulnerability:
Local File Inclusion

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Easy Mega Menu Plugin for WordPress � ThemeHunk

Plugin Slug:
themehunk-megamenu-plus

Installations
3,000+

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Widgetize Pages Light

Plugin Slug:
widgetize-pages-light

Installations
3,000+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Premium Packages � Sell Digital Products Securely

Plugin Slug:
wpdm-premium-packages

Installations
3,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Category Icon

Plugin Slug:
category-icon

Installations
2,000+

Vulnerability:
XML External Entity (XXE)

Patched in Version:
No Fix

Severity Score:
Critical


The vulnerability has not been patched. You should deactivate the plugin.

Post Grid Master � Custom Post Types, Taxonomies & Ajax Filter Everything with Infinite Scroll, Load More, Pagination & Shortcode Builder

Plugin Slug:
ajax-filter-posts

Installations
1,000+

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Booqable Rental Plugin

Plugin Slug:
booqable-rental-reservations

Installations
1,000+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Activity Plus Reloaded for BuddyPress

Plugin Slug:
bp-activity-plus-reloaded

Installations
1,000+

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

onOffice for WP-Websites

Plugin Slug:
onoffice-for-wp-websites

Installations
1,000+

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.
Plugin Slug:
simple-keyword-to-link

Installations
1,000+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

All Currencies for WooCommerce

Plugin Slug:
woocommerce-all-currencies

Installations
1,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

WP Compress for MainWP

Plugin Slug:
wp-compress-mainwp

Installations
900+

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

???????????????

Plugin Slug:
os-diagnosis-generator

Installations
800+

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Spice Blocks

Plugin Slug:
spice-blocks

Installations
800+

Vulnerability:
Arbitrary File Download

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

ACF: Yandex Maps Field

Plugin Slug:
acf-yandex-maps-field

Installations
700+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Broadly for WordPress

Plugin Slug:
broadly

Installations
700+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Bitly URL Shortener

Plugin Slug:
codehaveli-bitly-url-shortener

Installations
700+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

�?????????� ?? DaData.ru

Plugin Slug:
dadata-ru

Installations
700+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

IFrame Widget

Plugin Slug:
iframe-widget

Installations
700+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Melipayamak

Plugin Slug:
melipayamak

Installations
700+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Accessibility Suite by Ability, Inc

Plugin Slug:
online-accessibility

Installations
700+

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Pinterest Verify Meta Tag

Plugin Slug:
pinterest-verify-meta-tag

Installations
700+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Responsify WP

Plugin Slug:
responsify-wp

Installations
700+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Wordapp

Plugin:

Wordapp

Plugin Slug:
wordapp

Installations
700+

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

WordLift � AI powered SEO � Schema

Plugin Slug:
wordlift

Installations
600+

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Behance Portfolio Manager

Plugin Slug:
portfolio-manager-powered-by-behance

Installations
500+

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Wishlist

Plugin:

Wishlist

Plugin Slug:
wishlist

Installations
500+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

HR Management Lite

Plugin Slug:
hr-management-lite

Installations
400+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Multi CryptoCurrency Payments

Plugin Slug:
multi-crypto-currency-payment

Installations
400+

Vulnerability:
SQL Injection

Patched in Version:
No Fix

Severity Score:
Critical


The vulnerability has not been patched. You should deactivate the plugin.

WP AutoKeyword

Plugin Slug:
wp-autokeyword

Installations
400+

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

GPP Slideshow

Plugin Slug:
gpp-slideshow

Installations
300+

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Viral Loops WP Integration

Plugin Slug:
viral-loops-wp-integration

Installations
300+

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Viral Loops WP Integration

Plugin Slug:
viral-loops-wp-integration

Installations
300+

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Elastic Email Subscribe Form

Plugin Slug:
elastic-email-subscribe-form

Installations
200+

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Epicwin Plugin

Plugin Slug:
epicwin-subscribers

Installations
200+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Read More Login

Plugin Slug:
read-more-login

Installations
200+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Subscription Renewal Reminders for WooCommerce

Plugin Slug:
subscriptions-renewal-reminders

Installations
200+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Pay with Contact Form 7

Plugin Slug:
pay-with-contact-form-7

Installations
100+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Quick Event Calendar

Plugin Slug:
quick-event-calendar

Installations
100+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Recover abandoned cart for WooCommerce

Plugin Slug:
recover-wc-abandoned-cart

Installations
100+

Vulnerability:
SQL Injection

Patched in Version:
No Fix

Severity Score:
Critical


The vulnerability has not been patched. You should deactivate the plugin.

WP Media File Type Manager

Plugin Slug:
wp-media-file-type-manager

Installations
100+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

TicketBAI Facturas para WooCommerce

Plugin Slug:
wp-ticketbai

Installations
80+

Vulnerability:
SQL Injection

Patched in Version:
No Fix

Severity Score:
Critical


The vulnerability has not been patched. You should deactivate the plugin.

TicketBAI Facturas para WooCommerce

Plugin Slug:
wp-ticketbai

Installations
80+

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

One-Login

Plugin Slug:
one-login

Installations
70+

Vulnerability:
Privilege Escalation

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Next Event Calendar

Plugin Slug:
next-event-calendar

Installations
60+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

WP Post Corrector

Plugin Slug:
wp-post-corrector

Installations
60+

Vulnerability:
SQL Injection

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

6Storage Rentals

Plugin Slug:
6storage-rentals

Installations
50+

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Bang tinh vay

Plugin Slug:
bang-tinh-lai-suat

Installations
50+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Sola Support Tickets

Plugin Slug:
sola-support-tickets

Installations
50+

Vulnerability:
Arbitrary Content Deletion

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Interactive Regional Map of Africa

Plugin Slug:
interactive-map-of-africa

Installations
30+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

SEPA Girocode

Plugin Slug:
sepa-girocode

Installations
30+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Admin Notes

Plugin Slug:
admin-note

Installations
20+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Interactive UK Regional Map

Plugin Slug:
interactive-uk-regional-map

Installations
20+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Bacon Ipsum

Plugin Slug:
bacon-ipsum

Installations
10+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Interactive Regional Map of Florida

Plugin Slug:
interactive-map-of-florida

Installations
10+

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Team Builder

Plugin:

Team Builder

Plugin Slug:
a-team-showcase

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Abbie Expander

Plugin:

Abbie Expander

Plugin Slug:
abbie-expander

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Advanced Post List

Plugin:

Advanced Post List

Plugin Slug:
advanced-post-list

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

AI Mortgage Calculator

Plugin:

AI Mortgage Calculator

Plugin Slug:
ai-mortgage-calculator

Vulnerability:
Local File Inclusion

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

AppBanners

Plugin:

AppBanners

Plugin Slug:
appbanners

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Atelier Create CV

Plugin Slug:
atelier-create-cv

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Backwp

Plugin:

Backwp

Plugin Slug:
backwp

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

bbPress API

Plugin:

bbPress API

Plugin Slug:
bbp-api

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Bg Orthodox Calendar

Plugin:

Bg Orthodox Calendar

Plugin Slug:
bg-orthodox-calendar

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.
Plugin:

BNS Featured Category

Plugin Slug:
bns-featured-category

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

BP Profile as Homepage

Plugin:

BP Profile as Homepage

Plugin Slug:
bp-profile-as-homepage

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Bunny�s Print CSS

Plugin:

Bunny�s Print CSS

Plugin Slug:
bunnys-print-css

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

WPCHURCH

Plugin:

WPCHURCH

Plugin Slug:
church-management

Vulnerability:
SQL Injection

Patched in Version:
No Fix

Severity Score:
Critical


The vulnerability has not been patched. You should deactivate the plugin.

HyperComments

Plugin:

HyperComments

Plugin Slug:
comments-with-hypercommentscom

Vulnerability:
Privilege Escalation

Patched in Version:
No Fix

Severity Score:
Critical


The vulnerability has not been patched. You should deactivate the plugin.

Complete Google Seo Scan

Plugin:

Complete Google Seo Scan

Plugin Slug:
complete-google-seo-scan

Vulnerability:
SQL Injection

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Contact Form

Plugin:

Contact Form

Plugin Slug:
contact-form-ready

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

WordPress Ajax Load More and Infinite Scroll

Plugin:

WordPress Ajax Load More and Infinite Scroll

Plugin Slug:
cpt-ajax-load-more

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

CubePoints

Plugin:

CubePoints

Plugin Slug:
cubepoints

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Custom Bulk/Quick Edit

Plugin:

Custom Bulk/Quick Edit

Plugin Slug:
custom-bulkquick-edit

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Custom Category/Post Type Post order

Plugin:

Custom Category/Post Type Post order

Plugin Slug:
custom-post-order-category

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Developer Formatter

Plugin:

Developer Formatter

Plugin Slug:
devformatter

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Slack Notifications by dorzki

Plugin:

Slack Notifications by dorzki

Plugin Slug:
dorzki-notifications-to-slack

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

ZoomSounds

Plugin:

ZoomSounds

Plugin Slug:
dzs-zoomsounds

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Elegant Visitor Counter

Plugin:

Elegant Visitor Counter

Plugin Slug:
elegant-visitor-counter

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Universal Video Player

Plugin:

Universal Video Player

Plugin Slug:
elementor_widget_universal_video_player

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

elfsight Contact Form widget

Plugin:

elfsight Contact Form widget

Plugin Slug:
elfsight-contact-form

Vulnerability:
Sensitive Data Exposure

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Elite Video Player

Plugin:

Elite Video Player

Plugin Slug:
elite-video-player

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Foxit eSign for WordPress

Plugin:

Foxit eSign for WordPress

Plugin Slug:
esign-genie-for-wp

Vulnerability:
Other Vulnerability Type

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

ESV Bible Shortcode for WordPress

Plugin:

ESV Bible Shortcode for WordPress

Plugin Slug:
esv-bible-shortcode-for-wordpress

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

FastBook

Plugin:

FastBook

Plugin Slug:
fastbook-responsive-appointment-booking-and-scheduling-system

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

File Provider

Plugin:

File Provider

Plugin Slug:
file-provider

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

File Provider

Plugin:

File Provider

Plugin Slug:
file-provider

Vulnerability:
SQL Injection

Patched in Version:
No Fix

Severity Score:
Critical


The vulnerability has not been patched. You should deactivate the plugin.

Free WP Mail SMTP

Plugin:

Free WP Mail SMTP

Plugin Slug:
free-wp-mail-smtp

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Global Translator

Plugin:

Global Translator

Plugin Slug:
global-translator

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Global Translator

Plugin:

Global Translator

Plugin Slug:
global-translator

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Hide It

Plugin:

Hide It

Plugin Slug:
hide-it

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Hive Support

Plugin:

Hive Support

Plugin Slug:
hive-support

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Hive Support

Plugin:

Hive Support

Plugin Slug:
hive-support

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Image Hover Effects Block

Plugin:

Image Hover Effects Block

Plugin Slug:
image-hover-effects-block

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

InWave Jobs

Plugin:

InWave Jobs

Plugin Slug:
iwjob

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
Critical


The vulnerability has not been patched. You should deactivate the plugin.

KI Live Video Conferences

Plugin:

KI Live Video Conferences

Plugin Slug:
ki-live-video-conferences

Vulnerability:
Sensitive Data Exposure

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

KI Live Video Conferences

Plugin:

KI Live Video Conferences

Plugin Slug:
ki-live-video-conferences

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Konami Easter Egg

Plugin:

Konami Easter Egg

Plugin Slug:
konami-easter-egg

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Layouts for Elementor

Plugin:

Layouts for Elementor

Plugin Slug:
layouts-for-elementor

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

CLEVER

Plugin:

CLEVER

Plugin Slug:
lbg-audio11-html5-shoutcast_history

Vulnerability:
Arbitrary File Download

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Sticky Radio Player

Plugin:

Sticky Radio Player

Plugin Slug:
lbg-audio5-html5-shoutcast_sticky

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

SHOUT

Plugin:

SHOUT

Plugin Slug:
lbg-audio8-html5-radio_ads

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

WP Lead Capturing Pages

Plugin:

WP Lead Capturing Pages

Plugin Slug:
leadcapture

Vulnerability:
SQL Injection

Patched in Version:
No Fix

Severity Score:
Critical


The vulnerability has not been patched. You should deactivate the plugin.

MapSVG

Plugin:

MapSVG

Plugin Slug:
mapsvg

Vulnerability:
Privilege Escalation

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Mediabay – WordPress Media Library Folders

Plugin:

Mediabay – WordPress Media Library Folders

Plugin Slug:
mediabay

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

No Spam At All

Plugin:

No Spam At All

Plugin Slug:
no-spam-at-all

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.
Plugin:

Paged Gallery

Plugin Slug:
paged-gallery

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Payment QR WooCommerce

Plugin:

Payment QR WooCommerce

Plugin Slug:
payment-qr-woo

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Personal Favicon

Plugin:

Personal Favicon

Plugin Slug:
personal-favicon

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Post Author

Plugin:

Post Author

Plugin Slug:
post-author

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Post Custom Templates Lite

Plugin:

Post Custom Templates Lite

Plugin Slug:
post-custom-templates-lite

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Powie’s Uptime Robot

Plugin:

Powie’s Uptime Robot

Plugin Slug:
powies-uptime-robot

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Recent Posts Slider Responsive

Plugin:

Recent Posts Slider Responsive

Plugin Slug:
recent-posts-slider-responsive

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Responsive Flipbooks

Plugin:

Responsive Flipbooks

Plugin Slug:
responsive-flipbooks

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Revolution Video Player

Plugin:

Revolution Video Player

Plugin Slug:
revolution_video_player

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Runners Log

Plugin:

Runners Log

Plugin Slug:
runners-log

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Seofy Core

Plugin:

Seofy Core

Plugin Slug:
seofy-core

Vulnerability:
Local File Inclusion

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Simple Google Static Map

Plugin:

Simple Google Static Map

Plugin Slug:
simple-google-static-map

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Simple Nested Menu

Plugin Slug:
simple-nested-menu

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

SocialMark

Plugin:

SocialMark

Plugin Slug:
socialmark

Vulnerability:
Server Side Request Forgery (SSRF)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

StageShow

Plugin:

StageShow

Plugin Slug:
stageshow

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Motors – Events

Plugin:

Motors – Events

Plugin Slug:
stm-motors-events

Vulnerability:
Local File Inclusion

Patched in Version:
No Fix

Severity Score:
Critical


The vulnerability has not been patched. You should deactivate the plugin.

Stop Spammers

Plugin:

Stop Spammers

Plugin Slug:
stop-spammer-registrations-plugin

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

The Holiday Calendar

Plugin:

The Holiday Calendar

Plugin Slug:
the-holiday-calendar

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Universal Video Player

Plugin:

Universal Video Player

Plugin Slug:
universal_video_player

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Video Embeds

Plugin:

Video Embeds

Plugin Slug:
video-embeds

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Direct Checkout for WooCommerce Lite

Plugin:

Direct Checkout for WooCommerce Lite

Plugin Slug:
woo-direct-checkout-lite

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

WooCommerce Photo Reviews – Review Reminders – Review for Discounts

Plugin:

WooCommerce Photo Reviews – Review Reminders – Review for Discounts

Plugin Slug:
woocommerce-photo-reviews

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

WooCommerce Ultimate Gift Card – Create, Sell and Manage Gift Cards with Customized Email Templates

Plugin:

WooCommerce Ultimate Gift Card – Create, Sell and Manage Gift Cards with Customized Email Templates

Plugin Slug:
woocommerce-ultimate-gift-card

Vulnerability:
SQL Injection

Patched in Version:
No Fix

Severity Score:
Critical


The vulnerability has not been patched. You should deactivate the plugin.

WooBeWoo Product Filter Pro

Plugin:

WooBeWoo Product Filter Pro

Plugin Slug:
woofilter-pro

Vulnerability:
SQL Injection

Patched in Version:
No Fix

Severity Score:
Critical


The vulnerability has not been patched. You should deactivate the plugin.

Wp Easy Allopass

Plugin:

Wp Easy Allopass

Plugin Slug:
wordpress-easy-allopass

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

WP-Addpub

Plugin:

WP-Addpub

Plugin Slug:
wp-addpub

Vulnerability:
SQL Injection

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

WP Biographia

Plugin:

WP Biographia

Plugin Slug:
wp-biographia

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

WP Email Debug

Plugin:

WP Email Debug

Plugin Slug:
wp-email-debug

Vulnerability:
Privilege Escalation

Patched in Version:
No Fix

Severity Score:
Critical


The vulnerability has not been patched. You should deactivate the plugin.
Plugin:

WP Featured Content Slider

Plugin Slug:
wp-featured-content-slider

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Freemind Viewer

Plugin:

Freemind Viewer

Plugin Slug:
wp-freemind

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

WP Mail Options

Plugin:

WP Mail Options

Plugin Slug:
wp-mail-options

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

WP Online Users Stats

Plugin:

WP Online Users Stats

Plugin Slug:
wp-online-users-stats

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

WP-Recall

Plugin:

WP-Recall

Plugin Slug:
wp-recall

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

WP Security Master

Plugin Slug:
wp-security-master

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

WP Text Expander

Plugin:

WP Text Expander

Plugin Slug:
wp-text-expander

Vulnerability:
SQL Injection

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.
Plugin:

YouTube Simple Gallery

Plugin Slug:
youtube-simple-gallery

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.
Plugin Slug:
broken-link-checker

Installations
600,000+

Vulnerability:
Sensitive Data Exposure

Patched in Version:
2.4.5

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.4.5.

Ocean Extra

Plugin Slug:
ocean-extra

Installations
600,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.4.9

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.4.9.

WP Shortcodes Plugin � Shortcodes Ultimate

Plugin Slug:
shortcodes-ultimate

Installations
500,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
7.4.0

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 7.4.0.
Plugin Slug:
real-cookie-banner

Installations
100,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
5.1.6

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 5.1.6.

Social Sharing Plugin � Sassy Social Share

Plugin Slug:
sassy-social-share

Installations
100,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
3.3.76

Severity Score:
High


The vulnerability has been patched, so you should update to version 3.3.76.

Ninja Tables � Easy Data Table Builder

Plugin Slug:
ninja-tables

Installations
80,000+

Vulnerability:
PHP Object Injection

Patched in Version:
5.0.19

Severity Score:
Critical


The vulnerability has been patched, so you should update to version 5.0.19.

WP Table Builder � WordPress Table Plugin

Plugin Slug:
wp-table-builder

Installations
60,000+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
2.0.7

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.0.7.

Calculated Fields Form

Plugin Slug:
calculated-fields-form

Installations
50,000+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
5.3.59

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 5.3.59.

Greenshift � animation and page builder blocks

Plugin Slug:
greenshift-animation-and-page-builder-blocks

Installations
50,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
11.5.7

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 11.5.7.
Plugin Slug:
sina-extension-for-elementor

Installations
50,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
3.7.0

Severity Score:
High


The vulnerability has been patched, so you should update to version 3.7.0.

FancyBox for WordPress

Plugin Slug:
fancybox-for-wordpress

Installations
40,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
3.3.6

Severity Score:
High


The vulnerability has been patched, so you should update to version 3.3.6.

?????? ????? ??????? Persian WooCommerce SMS

Plugin Slug:
persian-woocommerce-sms

Installations
40,000+

Vulnerability:
SQL Injection

Patched in Version:
7.1.0

Severity Score:
High


The vulnerability has been patched, so you should update to version 7.1.0.

Simple Membership

Plugin Slug:
simple-membership

Installations
40,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
4.6.4

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 4.6.4.

RTMKit Addons for Elementor

Plugin Slug:
rometheme-for-elementor

Installations
30,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.6.1

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.6.1.

Print Invoice & Delivery Notes for WooCommerce

Plugin Slug:
woocommerce-delivery-notes

Installations
30,000+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
5.6.0

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 5.6.0.

Welcart e-Commerce

Plugin Slug:
usc-e-shop

Installations
20,000+

Vulnerability:
Arbitrary File Deletion

Patched in Version:
2.11.14

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.11.14.

Backup and Staging by WP Time Capsule

Plugin Slug:
wp-time-capsule

Installations
20,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.22.24

Severity Score:
High


The vulnerability has been patched, so you should update to version 1.22.24.

Store Locator WordPress

Plugin Slug:
agile-store-locator

Installations
10,000+

Vulnerability:
Arbitrary File Upload

Patched in Version:
1.5.3

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.5.3.

Store Locator WordPress

Plugin Slug:
agile-store-locator

Installations
10,000+

Vulnerability:
SQL Injection

Patched in Version:
1.5.2

Severity Score:
High


The vulnerability has been patched, so you should update to version 1.5.2.

Bellows Accordion Menu

Plugin Slug:
bellows-accordion-menu

Installations
10,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.4.4

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.4.4.

ShiftNav � Responsive Mobile Menu

Plugin Slug:
shiftnav-responsive-mobile-menu

Installations
10,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.8.1

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.8.1.

WP Multilang � Translation and Multilingual Plugin

Plugin Slug:
wp-multilang

Installations
10,000+

Vulnerability:
Local File Inclusion

Patched in Version:
2.4.19.1

Severity Score:
High


The vulnerability has been patched, so you should update to version 2.4.19.1.

Ultimate Gift Cards for WooCommerce

Plugin Slug:
woo-gift-cards-lite

Installations
7,000+

Vulnerability:
SQL Injection

Patched in Version:
3.1.5

Severity Score:
High


The vulnerability has been patched, so you should update to version 3.1.5.

Password Policy Manager | Password Manager

Plugin Slug:
password-policy-manager

Installations
5,000+

Vulnerability:
Broken Authentication

Patched in Version:
2.0.5

Severity Score:
High


The vulnerability has been patched, so you should update to version 2.0.5.

WP Social Widget

Plugin Slug:
wp-social-widget

Installations
5,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.3.1

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.3.1.

Min Max Step Quantity Limits Manager for WooCommerce

Plugin Slug:
product-quantity-for-woocommerce

Installations
4,000+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
5.1.1

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 5.1.1.

WordPress Comments Import & Export

Plugin Slug:
comments-import-export-woocommerce

Installations
3,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.4.4

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.4.4.

The Events Calendar Countdown Addon

Plugin Slug:
countdown-for-the-events-calendar

Installations
3,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.4.10

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.4.10.

Libro de Reclamaciones y Quejas

Plugin Slug:
libro-de-reclamaciones-y-quejas

Installations
3,000+

Vulnerability:
SQL Injection

Patched in Version:
1.0

Severity Score:
High


The vulnerability has been patched, so you should update to version 1.0.

Newsletters

Plugin Slug:
newsletters-lite

Installations
3,000+

Vulnerability:
Local File Inclusion

Patched in Version:
4.10

Severity Score:
High


The vulnerability has been patched, so you should update to version 4.10.

WP Maintenance Mode & Site Under Construction

Plugin Slug:
wp-maintenance-mode-site-under-construction

Installations
3,000+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
4.4

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 4.4.

BlockStrap Page Builder � Bootstrap Blocks

Plugin Slug:
blockstrap-page-builder-blocks

Installations
2,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
0.1.37

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 0.1.37.

oik

Plugin:

oik

Plugin Slug:
oik

Installations
2,000+

Vulnerability:
Broken Access Control

Patched in Version:
4.15.2

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 4.15.2.

Event post

Plugin Slug:
event-post

Installations
1,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
5.10.2

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 5.10.2.

WP Gravity Forms Salesforce

Plugin Slug:
gf-salesforce-crmperks

Installations
1,000+

Vulnerability:
Open Redirection

Patched in Version:
1.4.8

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.4.8.

Market Exporter

Plugin Slug:
market-exporter

Installations
1,000+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
2.0.23

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.0.23.

Membership For WooCommerce

Plugin Slug:
membership-for-woocommerce

Installations
1,000+

Vulnerability:
Broken Access Control

Patched in Version:
2.8.2

Severity Score:
High


The vulnerability has been patched, so you should update to version 2.8.2.

Newspack Newsletters

Plugin Slug:
newspack-newsletters

Installations
1,000+

Vulnerability:
Open Redirection

Patched in Version:
3.14.0

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 3.14.0.

Product Catalog Simple

Plugin Slug:
post-type-x

Installations
1,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.8.2

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.8.2.

Raychat

Plugin:

Raychat

Plugin Slug:
raychat

Installations
1,000+

Vulnerability:
Broken Access Control

Patched in Version:
2.2.0

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.2.0.

Stock Locations for WooCommerce

Plugin Slug:
stock-locations-for-woocommerce

Installations
1,000+

Vulnerability:
Broken Access Control

Patched in Version:
2.8.7

Severity Score:
High


The vulnerability has been patched, so you should update to version 2.8.7.

Vayu Blocks � Website Builder for the Block Editor

Plugin Slug:
vayu-blocks

Installations
1,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.3.2

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.3.2.

WordPress CRM Plugin � WP-CRM System

Plugin Slug:
wp-crm-system

Installations
1,000+

Vulnerability:
Broken Access Control

Patched in Version:
3.4.3

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 3.4.3.

WP Time Slots Booking Form

Plugin Slug:
wp-time-slots-booking-form

Installations
1,000+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
1.2.31

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.2.31.

WordPress Contact Forms by Cimatti

Plugin Slug:
contact-forms

Installations
900+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
1.9.9

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.9.9.

WP Gravity Forms Constant Contact Plugin

Plugin Slug:
gf-constant-contact

Installations
900+

Vulnerability:
Open Redirection

Patched in Version:
1.1.1

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.1.1.

PDF for WPForms + Drag and Drop Template Builder

Plugin Slug:
pdf-for-wpforms

Installations
900+

Vulnerability:
Broken Access Control

Patched in Version:
5.6.1

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 5.6.1.

Ultimate WP Mail

Plugin Slug:
ultimate-wp-mail

Installations
900+

Vulnerability:
Broken Authentication

Patched in Version:
1.3.6

Severity Score:
High


The vulnerability has been patched, so you should update to version 1.3.6.

FraudLabs Pro for WooCommerce

Plugin Slug:
fraudlabs-pro-for-woocommerce

Installations
800+

Vulnerability:
Broken Access Control

Patched in Version:
2.22.12

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.22.12.

Booking Ultra Pro Appointments Booking Calendar Plugin

Plugin Slug:
booking-ultra-pro

Installations
700+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.1.21

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.1.21.

Broadstreet

Plugin Slug:
broadstreet

Installations
700+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.51.8

Severity Score:
High


The vulnerability has been patched, so you should update to version 1.51.8.

Frontend Dashboard

Plugin Slug:
frontend-dashboard

Installations
700+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.2.9

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.2.9.

WP Team � WordPress Team Member Plugin

Plugin Slug:
ht-team-member

Installations
700+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.1.8

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.1.8.

POEditor

Plugin:

POEditor

Plugin Slug:
poeditor

Installations
700+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
0.9.11

Severity Score:
High


The vulnerability has been patched, so you should update to version 0.9.11.

WC MyParcel Belgium

Plugin Slug:
wc-myparcel-belgium

Installations
700+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
4.5.6

Severity Score:
High


The vulnerability has been patched, so you should update to version 4.5.6.

WP Page Loading

Plugin Slug:
wp-page-loading

Installations
700+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
1.0.7

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.0.7.

WP Plugin Info Card

Plugin Slug:
wp-plugin-info-card

Installations
700+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
5.4.0

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 5.4.0.

Search with Typesense

Plugin Slug:
search-with-typesense

Installations
600+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.0.11

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.0.11.

Verge3D Publishing and E-Commerce

Plugin Slug:
verge3d

Installations
600+

Vulnerability:
Broken Access Control

Patched in Version:
4.9.5

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 4.9.5.

404 Page by SeedProd

Plugin Slug:
404-page

Installations
500+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.0.2

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.0.2.

DocsPress � Online Documentation

Plugin Slug:
docspress

Installations
500+

Vulnerability:
Broken Access Control

Patched in Version:
2.5.3

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.5.3.

Job Board Manager

Plugin Slug:
job-board-manager

Installations
500+

Vulnerability:
Broken Access Control

Patched in Version:
2.1.61

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.1.61.

WebHotelier for WordPress

Plugin Slug:
webhotelier

Installations
500+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.10.0

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.10.0.

Audio Editor & Recorder

Plugin Slug:
audio-editor-recorder

Installations
200+

Vulnerability:
Broken Access Control

Patched in Version:
2.2.2

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.2.2.

Knowledge Base

Plugin Slug:
knowledgebase

Installations
100+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.3.1

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.3.1.

MyStyle Custom Product Designer

Plugin Slug:
mystyle-custom-product-designer

Installations
80+

Vulnerability:
SQL Injection

Patched in Version:
3.21.2

Severity Score:
Critical


The vulnerability has been patched, so you should update to version 3.21.2.

LTL Freight Quotes � Day & Ross Edition

Plugin Slug:
ltl-freight-quotes-day-ross-edition

Installations
10+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.1.11

Severity Score:
High


The vulnerability has been patched, so you should update to version 2.1.11.

Art Theme

Plugin:

Art Theme

Plugin Slug:
art-theme

Vulnerability:
Broken Access Control

Patched in Version:
3.12.3

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 3.12.3.

Civi Framework

Plugin:

Civi Framework

Plugin Slug:
civi-framework

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
2.1.6.4

Severity Score:
High


The vulnerability has been patched, so you should update to version 2.1.6.4.

Crawlomatic Multisite Scraper Post Generator

Plugin:

Crawlomatic Multisite Scraper Post Generator

Plugin Slug:
crawlomatic-multipage-scraper-post-generator

Vulnerability:
Sensitive Data Exposure

Patched in Version:
2.6.9

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.6.9.

Crawlomatic Multisite Scraper Post Generator

Plugin:

Crawlomatic Multisite Scraper Post Generator

Plugin Slug:
crawlomatic-multipage-scraper-post-generator

Vulnerability:
Broken Access Control

Patched in Version:
2.6.9

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.6.9.

LTL Freight Quotes � Daylight Edition

Plugin Slug:
ltl-freight-quotes-daylight-edition

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.2.7

Severity Score:
High


The vulnerability has been patched, so you should update to version 2.2.7.

LTL Freight Quotes � Freightview Edition

Plugin Slug:
ltl-freight-quotes-freightview-edition

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.0.12

Severity Score:
High


The vulnerability has been patched, so you should update to version 1.0.12.

Modern Events Calendar Lite

Plugin:

Modern Events Calendar Lite

Plugin Slug:
modern-events-calendar-lite

Vulnerability:
Sensitive Data Exposure

Patched in Version:
7.22

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 7.22.

Nasa Core

Plugin:

Nasa Core

Plugin Slug:
nasa-core

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
6.4.1

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 6.4.1.

BRW

Plugin:

BRW

Plugin Slug:
ova-brw

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.8.7

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.8.7.

BRW

Plugin:

BRW

Plugin Slug:
ova-brw

Vulnerability:
Local File Inclusion

Patched in Version:
1.8.7

Severity Score:
High


The vulnerability has been patched, so you should update to version 1.8.7.

NewsLetter

Plugin:

NewsLetter

Plugin Slug:
plugin-newsletter

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
8.8.5

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 8.8.5.

NewsLetter

Plugin:

NewsLetter

Plugin Slug:
plugin-newsletter

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
8.8.2

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 8.8.2.
Plugin:

Real Cookie Banner Pro

Plugin Slug:
real-cookie-banner-pro

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
5.1.6

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 5.1.6.

Team Showcase

Plugin:

Team Showcase

Plugin Slug:
team-showcase-cm

Vulnerability:
Content Injection

Patched in Version:
25.05.13

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 25.05.13.

Team Showcase

Plugin:

Team Showcase

Plugin Slug:
team-showcase-cm

Vulnerability:
Broken Access Control

Patched in Version:
25.05.13

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 25.05.13.

Testimonials Showcase

Plugin:

Testimonials Showcase

Plugin Slug:
testimonials-showcase

Vulnerability:
Broken Access Control

Patched in Version:
1.9.18

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.9.18.

Abandoned Cart Pro for WooCommerce

Plugin:

Abandoned Cart Pro for WooCommerce

Plugin Slug:
woocommerce-abandon-cart-pro

Vulnerability:
Arbitrary File Upload

Patched in Version:
9.17.0

Severity Score:
Critical


The vulnerability has been patched, so you should update to version 9.17.0.

WP User Frontend Pro

Plugin:

WP User Frontend Pro

Plugin Slug:
wp-user-frontend-pro

Vulnerability:
Arbitrary File Upload

Patched in Version:
4.1.4

Severity Score:
Critical


The vulnerability has been patched, so you should update to version 4.1.4.

WP User Frontend Pro

Plugin:

WP User Frontend Pro

Plugin Slug:
wp-user-frontend-pro

Vulnerability:
Arbitrary File Deletion

Patched in Version:
4.1.4

Severity Score:
High


The vulnerability has been patched, so you should update to version 4.1.4.

wpForo Advanced Attachments

Plugin:

wpForo Advanced Attachments

Plugin Slug:
wpforo-advanced-attachments

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
3.2.0

Severity Score:
High


The vulnerability has been patched, so you should update to version 3.2.0.

WordPress Themes � 14 Patched / 21 Unpatched

Arlo

Theme:

Arlo

Theme Slug:
arlo

Vulnerability:
Local File Inclusion

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should switch themes.

BodyCenter – Gym, Fitness WooCommerce WordPress Theme

Theme:

BodyCenter – Gym, Fitness WooCommerce WordPress Theme

Theme Slug:
bodycenter

Vulnerability:
Local File Inclusion

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should switch themes.

CraftXtore

Theme:

CraftXtore

Theme Slug:
bw-craftxtore

Vulnerability:
Local File Inclusion

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should switch themes.

Fitrush

Theme:

Fitrush

Theme Slug:
bw-fitrush

Vulnerability:
Local File Inclusion

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should switch themes.

GiftXtore

Theme:

GiftXtore

Theme Slug:
bw-giftxtore

Vulnerability:
Local File Inclusion

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should switch themes.

Petito

Theme:

Petito

Theme Slug:
bw-petito

Vulnerability:
Local File Inclusion

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should switch themes.

Car Repair Services

Theme:

Car Repair Services

Theme Slug:
car-repair-services

Vulnerability:
Server Side Request Forgery (SSRF)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should switch themes.

Themify Edmin

Theme:

Themify Edmin

Theme Slug:
edmin

Vulnerability:
PHP Object Injection

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should switch themes.

FLAP – Business WordPress Theme

Theme:

FLAP – Business WordPress Theme

Theme Slug:
flap

Vulnerability:
PHP Object Injection

Patched in Version:
No Fix

Severity Score:
Critical


The vulnerability has not been patched. You should switch themes.

FlatNews

Theme:

FlatNews

Theme Slug:
flatnews

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should switch themes.

Inset

Theme:

Inset

Theme Slug:
inset

Vulnerability:
Local File Inclusion

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should switch themes.

Krowd

Theme:

Krowd

Theme Slug:
krowd

Vulnerability:
Local File Inclusion

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should switch themes.

PIMP – Creative MultiPurpose

Theme:

PIMP – Creative MultiPurpose

Theme Slug:
pimp

Vulnerability:
Deserialization of untrusted data

Patched in Version:
No Fix

Severity Score:
Critical


The vulnerability has not been patched. You should switch themes.

PressGrid – Frontend Publish Reaction & Multimedia Theme

Theme:

PressGrid – Frontend Publish Reaction & Multimedia Theme

Theme Slug:
press-grid

Vulnerability:
Deserialization of untrusted data

Patched in Version:
No Fix

Severity Score:
Critical


The vulnerability has not been patched. You should switch themes.

Revo

Theme:

Revo

Theme Slug:
revo

Vulnerability:
Local File Inclusion

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should switch themes.

SNS Anton

Theme:

SNS Anton

Theme Slug:
snsanton

Vulnerability:
Local File Inclusion

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should switch themes.

Avaz

Theme:

Avaz

Theme Slug:
snsavaz

Vulnerability:
Local File Inclusion

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should switch themes.

Nitan

Theme:

Nitan

Theme Slug:
snsnitan

Vulnerability:
Local File Inclusion

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should switch themes.

Soho Hotel

Theme:

Soho Hotel

Theme Slug:
soho-hotel

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should switch themes.

Spare

Theme:

Spare

Theme Slug:
spare

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should switch themes.

Valen – Sport, Fashion WooCommerce WordPress Theme

Theme:

Valen – Sport, Fashion WooCommerce WordPress Theme

Theme Slug:
valen

Vulnerability:
Local File Inclusion

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should switch themes.

Courtney

Theme:

Courtney

Theme Slug:
courtney

Vulnerability:
Local File Inclusion

Patched in Version:
1.3.1

Severity Score:
High


The vulnerability has been patched, so you should update to version 1.3.1.

CozyStay

Theme:

CozyStay

Theme Slug:
cozystay

Vulnerability:
PHP Object Injection

Patched in Version:
1.7.1

Severity Score:
Critical


The vulnerability has been patched, so you should update to version 1.7.1.

GrandPrix

Theme:

GrandPrix

Theme Slug:
grandprix

Vulnerability:
Local File Inclusion

Patched in Version:
1.6.1

Severity Score:
High


The vulnerability has been patched, so you should update to version 1.6.1.

Grill and Chow

Theme:

Grill and Chow

Theme Slug:
grillandchow

Vulnerability:
Local File Inclusion

Patched in Version:
1.6.1

Severity Score:
High


The vulnerability has been patched, so you should update to version 1.6.1.

Lesya

Theme:

Lesya

Theme Slug:
lesya

Vulnerability:
Local File Inclusion

Patched in Version:
1.7.3

Severity Score:
High


The vulnerability has been patched, so you should update to version 1.7.3.

Lettery

Theme:

Lettery

Theme Slug:
lettery

Vulnerability:
Local File Inclusion

Patched in Version:
1.1.8

Severity Score:
High


The vulnerability has been patched, so you should update to version 1.1.8.

MediClinic

Theme:

MediClinic

Theme Slug:
mediclinic

Vulnerability:
Local File Inclusion

Patched in Version:
2.2

Severity Score:
High


The vulnerability has been patched, so you should update to version 2.2.

Minterio

Theme:

Minterio

Theme Slug:
minterio

Vulnerability:
Local File Inclusion

Patched in Version:
1.4.1

Severity Score:
High


The vulnerability has been patched, so you should update to version 1.4.1.

Mr. Murphy

Theme:

Mr. Murphy

Theme Slug:
mr-murphy

Vulnerability:
PHP Object Injection

Patched in Version:
1.2.12.1

Severity Score:
Critical


The vulnerability has been patched, so you should update to version 1.2.12.1.

RealHomes

Theme:

RealHomes

Theme Slug:
realhomes

Vulnerability:
Privilege Escalation

Patched in Version:
4.4.1

Severity Score:
High


The vulnerability has been patched, so you should update to version 4.4.1.

Starbelly

Theme:

Starbelly

Theme Slug:
starbelly

Vulnerability:
Local File Inclusion

Patched in Version:
1.3.7

Severity Score:
High


The vulnerability has been patched, so you should update to version 1.3.7.

Sweet Dessert

Theme:

Sweet Dessert

Theme Slug:
sweet-dessert

Vulnerability:
PHP Object Injection

Patched in Version:
1.1.13

Severity Score:
Critical


The vulnerability has been patched, so you should update to version 1.1.13.

TinySalt

Theme:

TinySalt

Theme Slug:
tinysalt

Vulnerability:
PHP Object Injection

Patched in Version:
3.10.0

Severity Score:
Critical


The vulnerability has been patched, so you should update to version 3.10.0.

TinySalt

Theme:

TinySalt

Theme Slug:
tinysalt

Vulnerability:
Local File Inclusion

Patched in Version:
3.10.0

Severity Score:
High


The vulnerability has been patched, so you should update to version 3.10.0.

Related articles

Wait! Get exclusive hosting insights

Subscribe to our newsletter and stay ahead of the competition with expert advice from our hosting pros.

Loading form…