Line illustration showing a black application window on a dark black to purple gradient background overlaid with a large exclamation point alert icon and three bugs.

WordPress Vulnerability Report � June 25, 2025

In this report, 177 vulnerabilities have been publicly disclosed. Security patches for 59 of these plugins and themes are available now, so run those updates as soon as possible. If you’re a Solid Security Pro user, the version management tool may have already warned you and updated these plugins, depending on your settings.

Additionally, there are 118 plugin and theme vulnerabilities, and no patch has been available yet. If you’re a Solid Security Pro user, those vulnerabilities are already protected by the Solid Security firewall. Virtual patches from Patchstack will be applied when a vulnerability is considered high or medium risk. If no patch is forthcoming from the vendor or the vulnerable software has been marked “closed” and dropped from the official WordPress repositories, you should deactivate it soon and look for alternative solutions.

WordPress Core

WordPress 6.8.1 was released on April 30, 2025. This maintenance release includes fixes for 15 bugs throughout Core and the Block Editor, addressing issues affecting multiple areas of WordPress, including the block editor, multisite, and REST API. For a full list, refer to the release candidate announcement.

WordPress Plugins � 56 Patched / 105 Unpatched

Zapier for WordPress

Plugin Slug:
zapier

Installations
50,000+

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Auto Upload Images

Plugin Slug:
auto-upload-images

Installations
30,000+

Vulnerability:
Server Side Request Forgery (SSRF)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

PowerPress Podcasting plugin by Blubrry

Plugin Slug:
powerpress

Installations
30,000+

Vulnerability:
Server Side Request Forgery (SSRF)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

WP Visitor Statistics (Real Time Traffic)

Plugin Slug:
wp-stats-manager

Installations
30,000+

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

WP Customer Area

Plugin Slug:
customer-area

Installations
10,000+

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Job Postings

Plugin Slug:
job-postings

Installations
10,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

User Roles and Capabilities

Plugin Slug:
user-roles-and-capabilities

Installations
10,000+

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

WP User Profile Avatar

Plugin Slug:
wp-user-profile-avatar

Installations
10,000+

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.
Plugin Slug:
cookie-script-com

Installations
9,000+

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Download Attachments

Plugin Slug:
download-attachments

Installations
9,000+

Vulnerability:
Insecure Direct Object References (IDOR)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Automatically Hierarchic Categories in Menu

Plugin Slug:
automatically-hierarchic-categories-in-menu

Installations
3,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

ContentStudio

Plugin Slug:
contentstudio

Installations
1,000+

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

WP Inventory Manager

Plugin Slug:
wp-inventory-manager

Installations
1,000+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

WPThumb

Plugin:

WPThumb

Plugin Slug:
wp-thumb

Installations
1,000+

Vulnerability:
Server Side Request Forgery (SSRF)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Football Pool

Plugin Slug:
football-pool

Installations
900+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

ATP Call Now

Plugin Slug:
atp-call-now

Installations
800+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Better Random Redirect

Plugin Slug:
better-random-redirect

Installations
800+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

CodePen Embed Block

Plugin Slug:
codepen-embed-block

Installations
800+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

RDFa Breadcrumb

Plugin Slug:
rdfa-breadcrumb

Installations
800+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.
Plugin Slug:
simple-sticky-footer

Installations
800+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Tealium

Plugin:

Tealium

Plugin Slug:
tealium

Installations
800+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

WP Social AutoConnect

Plugin Slug:
wp-fb-autoconnect

Installations
800+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Polls CP

Plugin:

Polls CP

Plugin Slug:
cp-polls

Installations
700+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Code Engine

Plugin Slug:
code-engine

Installations
600+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

FormLift for Infusionsoft Web Forms

Plugin Slug:
formlift

Installations
600+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Trusty Whistleblowing Solution

Plugin Slug:
trusty-whistleblowing-solution

Installations
600+

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Gutenberg Blocks � ACF Blocks Suite

Plugin Slug:
acf-blocks

Installations
500+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Anant Addons for Elementor

Plugin Slug:
anant-addons-for-elementor

Installations
500+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Hand Talk

Plugin Slug:
handtalk

Installations
500+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.
Plugin Slug:
pdpa-consent

Installations
500+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

WP Register Profile With Shortcode

Plugin Slug:
wp-register-profile-with-shortcode

Installations
500+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

WP Voting Contest Lite

Plugin Slug:
wp-voting-contest

Installations
500+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Contact Form 7 AWeber Extension

Plugin Slug:
integrate-contact-form-7-and-aweber

Installations
400+

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

IP Based Login

Plugin Slug:
ip-based-login

Installations
400+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Buying Buddy IDX CRM � Real Estate MLS Plugin

Plugin Slug:
buying-buddy-idx-crm

Installations
300+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

TM Replace Howdy

Plugin Slug:
tm-replace-howdy

Installations
300+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

WooCommerce Fortnox Integration

Plugin Slug:
woocommerce-fortnox-integration

Installations
300+

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

WP Roadmap � Product Feedback Board

Plugin Slug:
wp-roadmap

Installations
300+

Vulnerability:
SQL Injection

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Abandoned Contact Form 7

Plugin Slug:
abandoned-contact-form-7

Installations
200+

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Lewe ChordPress � ChordPro Text Formatter

Plugin Slug:
chordpress

Installations
200+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

CSV Importer Improved

Plugin Slug:
csv-importer-improved

Installations
200+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

eDS Responsive Menu

Plugin Slug:
eds-responsive-menu

Installations
200+

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.
Plugin Slug:
esselinknu-settings

Installations
200+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Fyrebox Quizzes

Plugin Slug:
fyrebox-shortcode

Installations
200+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Knowledge Base � Knowledge Base Maker

Plugin Slug:
knowledge-base-maker

Installations
200+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Creative Contact Form

Plugin Slug:
sexy-contact-form

Installations
200+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

WP-DownloadCounter

Plugin Slug:
wp-downloadcounter

Installations
200+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Mailing Group Listserv

Plugin Slug:
wp-mailing-group

Installations
200+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Bluff Post

Plugin Slug:
bluff-post

Installations
100+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Import YouTube videos as WP Posts

Plugin Slug:
import-youtube-videos-as-wp-post

Installations
100+

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Inventory Presser � Car Dealer Listings

Plugin Slug:
inventory-presser

Installations
100+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

National Weather Service Alerts

Plugin Slug:
national-weather-service-alerts

Installations
100+

Vulnerability:
Local File Inclusion

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Logo Manager For Samandehi

Plugin Slug:
samandehi-logo-manager

Installations
100+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Scroll UP

Plugin Slug:
scroll-to-up

Installations
100+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

TinyNav

Plugin:

TinyNav

Plugin Slug:
tinynav

Installations
100+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Video List Manager

Plugin Slug:
video-list-manager

Installations
100+

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Video List Manager

Plugin Slug:
video-list-manager

Installations
100+

Vulnerability:
SQL Injection

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Change Cart button Colors WooCommerce

Plugin Slug:
wc-style

Installations
100+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

WP User Stylesheet Switcher

Plugin Slug:
wp-user-stylesheet-switcher

Installations
100+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

xili-dictionary

Plugin Slug:
xili-dictionary

Installations
100+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Zara 4 Image Compression

Plugin Slug:
zara-4

Installations
100+

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Infility Global

Plugin Slug:
infility-global

Installations
90+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

MDJM Event Management

Plugin Slug:
mobile-dj-manager

Installations
90+

Vulnerability:
Privilege Escalation

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Photo Express for Google

Plugin Slug:
photo-express-for-google

Installations
80+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

XML Travel Portal Widget

Plugin Slug:
oganro-reservation-widget

Installations
70+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

SpecFit-Virtual Try On Woocommerce

Plugin Slug:
try-on-for-woocommerce

Installations
60+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

DirectIQ Email Marketing

Plugin Slug:
directiq-wp

Installations
40+

Vulnerability:
SQL Injection

Patched in Version:
No Fix

Severity Score:
Critical


The vulnerability has not been patched. You should deactivate the plugin.

Live Sports Streamthunder

Plugin Slug:
live-sports-streamthunder

Installations
40+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Oganro Travel Portal Search Widget for HotelBeds APITUDE API

Plugin Slug:
oganro-travel-portal-search-widget-for-hotelbeds-apitude-api

Installations
10+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

PixelBeds Channel Manager and Hotel Booking Engine

Plugin Slug:
pixelbeds-channel-manager-booking-engine

Installations
10+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Backwp

Plugin:

Backwp

Plugin Slug:
backwp

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Bulk YouTube Post Creator

Plugin:

Bulk YouTube Post Creator

Plugin Slug:
bulk-youtube-post-creator

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.
Plugin:

ClipLink

Plugin Slug:
cliplink

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

CSV Me

Plugin:

CSV Me

Plugin Slug:
csv-me

Vulnerability:
Arbitrary File Upload

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Evangelische Termine

Plugin:

Evangelische Termine

Plugin Slug:
evangtermine

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

FastBook

Plugin:

FastBook

Plugin Slug:
fastbook-responsive-appointment-booking-and-scheduling-system

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Flexo Counter

Plugin:

Flexo Counter

Plugin Slug:
flexo-countdown

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Image Shadow

Plugin:

Image Shadow

Plugin Slug:
image-shadow

Vulnerability:
Arbitrary File Deletion

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

BRW

Plugin:

BRW

Plugin Slug:
ova-brw

Vulnerability:
Local File Inclusion

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Pixabay Images

Plugin:

Pixabay Images

Plugin Slug:
pixabay-images

Vulnerability:
Arbitrary File Upload

Patched in Version:
No Fix

Severity Score:
Critical


The vulnerability has not been patched. You should deactivate the plugin.
Plugin:

Simple Link Directory

Plugin Slug:
qc-simple-link-directory

Vulnerability:
SQL Injection

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

School Management

Plugin:

School Management

Plugin Slug:
school-management

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Smart Notification

Plugin:

Smart Notification

Plugin Slug:
smio-push-notification

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Virtual Moderator

Plugin:

Virtual Moderator

Plugin Slug:
virtual-moderator

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Woocommerce Line Notify

Plugin:

Woocommerce Line Notify

Plugin Slug:
woo-line-notify

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

JobSearch

Plugin:

JobSearch

Plugin Slug:
wp-jobsearch

Vulnerability:
Insecure Direct Object References (IDOR)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

WP Optimize By xTraffic

Plugin:

WP Optimize By xTraffic

Plugin Slug:
wp-optimize-by-xtraffic

Vulnerability:
PHP Object Injection

Patched in Version:
No Fix

Severity Score:
Critical


The vulnerability has not been patched. You should deactivate the plugin.

WP-Recall

Plugin:

WP-Recall

Plugin Slug:
wp-recall

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

WPCRM – CRM for Contact form CF7 & WooCommerce

Plugin:

WPCRM – CRM for Contact form CF7 & WooCommerce

Plugin Slug:
wpcrm

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Recipes manager � WPH

Plugin Slug:
wph-recipes-manager

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

WPKit For Elementor

Plugin:

WPKit For Elementor

Plugin Slug:
wpkit-elementor

Vulnerability:
Privilege Escalation

Patched in Version:
No Fix

Severity Score:
Critical


The vulnerability has not been patched. You should deactivate the plugin.

ElementsKit Elementor Addons and Templates

Plugin Slug:
elementskit-lite

Installations
1,000,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
3.5.3

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 3.5.3.

Click to Chat � HoliThemes

Plugin Slug:
click-to-chat-for-whatsapp

Installations
600,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
4.23

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 4.23.

YITH WooCommerce Wishlist

Plugin Slug:
yith-woocommerce-wishlist

Installations
600,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
4.6.0

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 4.6.0.

Breeze � WordPress Cache Plugin

Plugin Slug:
breeze

Installations
400,000+

Vulnerability:
Broken Access Control

Patched in Version:
2.2.14

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.2.14.

Firelight Lightbox

Plugin Slug:
easy-fancybox

Installations
200,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.3.17

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.3.17.

Ivory Search � WordPress Search Plugin

Plugin Slug:
add-search-to-menu

Installations
100,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
5.5.10

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 5.5.10.

AI Engine

Plugin Slug:
ai-engine

Installations
100,000+

Vulnerability:
Broken Access Control

Patched in Version:
2.8.4

Severity Score:
High


The vulnerability has been patched, so you should update to version 2.8.4.

Download Manager

Plugin Slug:
download-manager

Installations
100,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
3.3.19

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 3.3.19.

File Manager Pro � Filester

Plugin Slug:
filester

Installations
100,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.8.9

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.8.9.

HUSKY � Products Filter Professional for WooCommerce

Plugin Slug:
woocommerce-products-filter

Installations
100,000+

Vulnerability:
Local File Inclusion

Patched in Version:
1.3.7.1

Severity Score:
High


The vulnerability has been patched, so you should update to version 1.3.7.1.

Master Slider � Responsive Touch Slider

Plugin Slug:
master-slider

Installations
70,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
3.10.9

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 3.10.9.

Drag and Drop Multiple File Upload for Contact Form 7

Plugin Slug:
drag-and-drop-multiple-file-upload-contact-form-7

Installations
60,000+

Vulnerability:
Arbitrary File Upload

Patched in Version:
1.3.9.0

Severity Score:
High


The vulnerability has been patched, so you should update to version 1.3.9.0.

Ultra Addons for Contact Form 7

Plugin Slug:
ultimate-addons-for-contact-form-7

Installations
60,000+

Vulnerability:
Arbitrary File Upload

Patched in Version:
3.5.13

Severity Score:
High


The vulnerability has been patched, so you should update to version 3.5.13.

WP-Members Membership Plugin

Plugin Slug:
wp-members

Installations
60,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
3.5.4.1

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 3.5.4.1.

Blog2Social: Social Media Auto Post & Scheduler

Plugin Slug:
blog2social

Installations
50,000+

Vulnerability:
SQL Injection

Patched in Version:
8.4.5

Severity Score:
High


The vulnerability has been patched, so you should update to version 8.4.5.

WordPress Infinite Scroll � Ajax Load More

Plugin Slug:
ajax-load-more

Installations
40,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
7.4.1

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 7.4.1.

tarteaucitron.io

Plugin Slug:
tarteaucitronjs

Installations
10,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.9.5

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.9.5.

eCommerce Product Catalog Plugin for WordPress

Plugin Slug:
ecommerce-product-catalog

Installations
9,000+

Vulnerability:
PHP Object Injection

Patched in Version:
3.4.4

Severity Score:
High


The vulnerability has been patched, so you should update to version 3.4.4.

Poll, Survey & Quiz Maker Plugin by Opinion Stage

Plugin Slug:
social-polls-by-opinionstage

Installations
8,000+

Vulnerability:
Broken Access Control

Patched in Version:
19.10.0

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 19.10.0.

WP Dummy Content Generator

Plugin Slug:
wp-dummy-content-generator

Installations
8,000+

Vulnerability:
Arbitrary Content Deletion

Patched in Version:
4.0.0

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 4.0.0.

ProfileGrid � User Profiles, Groups and Communities

Plugin Slug:
profilegrid-user-profiles-groups-and-communities

Installations
7,000+

Vulnerability:
Full Path Disclosure (FPD)

Patched in Version:
<= 5.9.5.3

Severity Score:
Medium


The vulnerability has been patched, so you should update to version <= 5.9.5.3.

Wise Chat

Plugin Slug:
wise-chat

Installations
7,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
3.3.5

Severity Score:
High


The vulnerability has been patched, so you should update to version 3.3.5.

Modern Footnotes

Plugin Slug:
modern-footnotes

Installations
6,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.4.20

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.4.20.

Sitekit

Plugin:

Sitekit

Plugin Slug:
sitekit

Installations
2,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.0

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.0.

YITH PayPal Express Checkout for WooCommerce

Plugin Slug:
yith-paypal-express-checkout-for-woocommerce

Installations
2,000+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
1.49.1

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.49.1.

Off-Canvas Sidebars & Menus (Slidebars)

Plugin Slug:
off-canvas-sidebars

Installations
1,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
0.5.8.5

Severity Score:
High


The vulnerability has been patched, so you should update to version 0.5.8.5.
Plugin Slug:
related-products-manager-woocommerce

Installations
1,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.6.3

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.6.3.

WPComplete

Plugin Slug:
wpcomplete

Installations
1,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.9.5.1

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.9.5.1.

Conference Scheduler

Plugin Slug:
conference-scheduler

Installations
300+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.5.2

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.5.2.

Euro FxRef Currency Converter

Plugin Slug:
euro-fxref-currency-converter

Installations
200+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.0.3

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.0.3.
Plugin Slug:
simple-logo-carousel

Installations
100+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.9.4

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.9.4.

StreamWeasels Kick Integration

Plugin Slug:
streamweasels-kick-integration

Installations
100+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.1.4

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.1.4.

Target Video Easy Publish

Plugin Slug:
brid-video-easy-publish

Installations
70+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
3.8.6

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 3.8.6.

ANON::form embedded secure form

Plugin Slug:
anonform-embedded-secure-form

Installations
10+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.8

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.8.

Aiomatic

Plugin:

Aiomatic

Plugin Slug:
aiomatic-automatic-ai-content-writer

Vulnerability:
Arbitrary File Upload

Patched in Version:
2.5.1

Severity Score:
High


The vulnerability has been patched, so you should update to version 2.5.1.

Drag and Drop Multiple File Upload (Pro) – WooCommerce

Plugin:

Drag and Drop Multiple File Upload (Pro) – WooCommerce

Plugin Slug:
drag-and-drop-file-upload-wc-pro

Vulnerability:
Arbitrary File Upload

Patched in Version:
5.0.7

Severity Score:
Critical


The vulnerability has been patched, so you should update to version 5.0.7.

Elementor Pro

Plugin:

Elementor Pro

Plugin Slug:
elementor-pro

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
3.29.1

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 3.29.1.

WPBakery Page Builder

Plugin:

WPBakery Page Builder

Plugin Slug:
js_composer

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
8.5

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 8.5.

Echo RSS Feed Post Generator Plugin for WordPress

Plugin:

Echo RSS Feed Post Generator Plugin for WordPress

Plugin Slug:
rss-feed-post-generator-echo

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
5.4.9

Severity Score:
High


The vulnerability has been patched, so you should update to version 5.4.9.

Rankie

Plugin:

Rankie

Plugin Slug:
valvepress-rankie

Vulnerability:
SQL Injection

Patched in Version:
1.8.2

Severity Score:
High


The vulnerability has been patched, so you should update to version 1.8.2.

WordPress Themes � 3 Patched / 13 Unpatched

Fitness Park

Theme Slug:
fitness-park

Downloads
20,395

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should switch themes.

Hello FSE Blog

Theme Slug:
hello-fse-blog

Downloads
11,256

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should switch themes.

Spark Multipurpose

Theme Slug:
spark-multipurpose

Downloads
5,635

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should switch themes.

Zita

Theme:

Zita

Theme Slug:
zita

Downloads
405,453

Vulnerability:
Local File Inclusion

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should switch themes.

Zenny

Theme:

Zenny

Theme Slug:
bw-zenny

Vulnerability:
Local File Inclusion

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should switch themes.

HYDRO

Theme:

HYDRO

Theme Slug:
hydro

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should switch themes.

LMS

Theme:

LMS

Theme Slug:
lms

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should switch themes.

MagOne

Theme:

MagOne

Theme Slug:
magone

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should switch themes.

MBStore – Digital WooCommerce WordPress Theme

Theme:

MBStore – Digital WooCommerce WordPress Theme

Theme Slug:
mbstore

Vulnerability:
Local File Inclusion

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should switch themes.

Nuss

Theme:

Nuss

Theme Slug:
nuss

Vulnerability:
PHP Object Injection

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should switch themes.

Sala

Theme:

Sala

Theme Slug:
sala

Vulnerability:
PHP Object Injection

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should switch themes.

Seven Stars

Theme:

Seven Stars

Theme Slug:
sevenstars

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should switch themes.

Sofass

Theme:

Sofass

Theme Slug:
sofass

Vulnerability:
Local File Inclusion

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should switch themes.

OceanWP

Theme:

OceanWP

Theme Slug:
oceanwp

Downloads
8,544,159

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
4.1.0

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 4.1.0.

Amely

Theme:

Amely

Theme Slug:
amely

Vulnerability:
SQL Injection

Patched in Version:
3.2.0

Severity Score:
Critical


The vulnerability has been patched, so you should update to version 3.2.0.

Puca

Theme:

Puca

Theme Slug:
puca

Vulnerability:
Local File Inclusion

Patched in Version:
2.6.34

Severity Score:
High


The vulnerability has been patched, so you should update to version 2.6.34.

Related articles

Wait! Get exclusive hosting insights

Subscribe to our newsletter and stay ahead of the competition with expert advice from our hosting pros.

Loading form…