Line illustration showing a black application window on a dark orange to black gradient background overlaid with a large exclamation point alert icon and three bugs.

WordPress Vulnerability Report � July 2, 2025

In this report, 213 vulnerabilities have been publicly disclosed. Security patches for 64 of these plugins and themes are available now, so run those updates as soon as possible. If you’re a Solid Security Pro user, the version management tool may have already warned you and updated these plugins, depending on your settings.

Additionally, there are 149 plugin and theme vulnerabilities, and no patch has been available yet. If you’re a Solid Security Pro user, those vulnerabilities are already protected by the Solid Security firewall. Virtual patches from Patchstack will be applied when a vulnerability is considered high or medium risk. If no patch is forthcoming from the vendor or the vulnerable software has been marked “closed” and dropped from the official WordPress repositories, you should deactivate it soon and look for alternative solutions.

WordPress Core

WordPress 6.8.1 was released on April 30, 2025. This maintenance release includes fixes for 15 bugs throughout Core and the Block Editor, addressing issues affecting multiple areas of WordPress, including the block editor, multisite, and REST API. For a full list, refer to the release candidate announcement.

WordPress Plugins � 49 Patched / 126 Unpatched

Mollie Payments for WooCommerce

Plugin Slug:
mollie-payments-for-woocommerce

Installations
100,000+

Vulnerability:
Insecure Direct Object References (IDOR)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

WP Edit

Plugin:

WP Edit

Plugin Slug:
wp-edit

Installations
50,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.
Plugin Slug:
cyrlitera

Installations
40,000+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.
Plugin Slug:
grand-media

Installations
9,000+

Vulnerability:
Local File Inclusion

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Hover Effects � easily create any hover effect

Plugin Slug:
hover-effects

Installations
8,000+

Vulnerability:
SQL Injection

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Additional Order Filters for WooCommerce

Plugin Slug:
additional-order-filters-for-woocommerce

Installations
2,000+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Cron Logger

Plugin Slug:
cron-logger

Installations
2,000+

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Address Autocomplete via Google for Gravity Forms

Plugin Slug:
gf-google-address-autocomplete

Installations
2,000+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Hide Admin Bar From Front End

Plugin Slug:
hide-admin-bar-from-front-end

Installations
2,000+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Image Cleanup

Plugin Slug:
image-cleanup

Installations
2,000+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Import external attachments

Plugin Slug:
import-external-attachments

Installations
2,000+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Leyka

Plugin:

Leyka

Plugin Slug:
leyka

Installations
2,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

My Wp Brand � Hide menu & Hide Plugin

Plugin Slug:
my-wp-brand

Installations
2,000+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

ONet Regenerate Thumbnails

Plugin Slug:
onet-regenerate-thumbnails

Installations
2,000+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Slickstream: Engagement and Conversions

Plugin Slug:
slick-engagement

Installations
2,000+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Virusdie � One-click website security

Plugin Slug:
virusdie

Installations
2,000+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.
Plugin Slug:
wp-permalink-translator

Installations
2,000+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

WP YouTube Live

Plugin Slug:
wp-youtube-live

Installations
2,000+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Writesonic

Plugin Slug:
writesonic

Installations
2,000+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Omnipress

Plugin Slug:
omnipress

Installations
1,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

IS-theme-companion

Plugin Slug:
weblizar-companion

Installations
1,000+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Football Pool

Plugin Slug:
football-pool

Installations
900+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

PlatiOnline Payments

Plugin Slug:
plationline

Installations
800+

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Spreadconnect

Plugin Slug:
wc-spod

Installations
800+

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.
Plugin Slug:
add-replace-affiliate-links-for-amazon

Installations
700+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Thumbnail Editor

Plugin Slug:
thumbnail-editor

Installations
700+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Trusty Whistleblowing Solution

Plugin Slug:
trusty-whistleblowing-solution

Installations
600+

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

WP DataTable

Plugin Slug:
wp-datatable

Installations
600+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Dashboard Widget Sidebar

Plugin Slug:
dashboard-widget-sidebar

Installations
500+

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

iCount Payment Gateway

Plugin Slug:
icount

Installations
500+

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

EC Stars Rating

Plugin Slug:
ec-stars-rating

Installations
400+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Theme Junkie Team Content

Plugin Slug:
theme-junkie-team-content

Installations
400+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Abandoned Contact Form 7

Plugin Slug:
abandoned-contact-form-7

Installations
200+

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Accept Stripe Payments Using Contact Form 7

Plugin Slug:
accept-stripe-payments-using-contact-form-7

Installations
200+

Vulnerability:
Sensitive Data Exposure

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Aviation Weather from NOAA

Plugin Slug:
aviation-weather-from-noaa

Installations
200+

Vulnerability:
Arbitrary File Deletion

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Osom Blocks

Plugin Slug:
osomblocks

Installations
200+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Accept Authorize.NET Payments Using Contact Form 7

Plugin Slug:
accept-authorize-net-payments-using-contact-form-7

Installations
100+

Vulnerability:
Sensitive Data Exposure

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Content Manager Light

Plugin Slug:
content-manager-light

Installations
100+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

WP Forum Server

Plugin Slug:
forum-server

Installations
100+

Vulnerability:
SQL Injection

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

WP Forum Server

Plugin Slug:
forum-server

Installations
100+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

HidePost

Plugin:

HidePost

Plugin Slug:
hidepost

Installations
100+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

National Weather Service Alerts

Plugin Slug:
national-weather-service-alerts

Installations
100+

Vulnerability:
Local File Inclusion

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Navayan Subscribe

Plugin Slug:
navayan-subscribe

Installations
100+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

OnionBuzz

Plugin Slug:
onionbuzz-viral-quiz

Installations
100+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Pre-Publish Post Checklist

Plugin Slug:
pre-publish-post-checklist

Installations
100+

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Raise The Money

Plugin Slug:
raise-the-money

Installations
100+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Relocate Upload

Plugin Slug:
relocate-upload

Installations
100+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Twitch TV Embed Suite

Plugin Slug:
twitch-tv-embed-suite

Installations
100+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Video List Manager

Plugin Slug:
video-list-manager

Installations
100+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

WP DB Booster

Plugin Slug:
wp-db-booster

Installations
100+

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

WP Optimizer

Plugin Slug:
wp-optimizer

Installations
100+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
Critical


The vulnerability has not been patched. You should deactivate the plugin.

WPShapere Lite

Plugin Slug:
wpshapere-lite

Installations
100+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

xili-dictionary

Plugin Slug:
xili-dictionary

Installations
100+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Infility Global

Plugin Slug:
infility-global

Installations
90+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

MDJM Event Management

Plugin Slug:
mobile-dj-manager

Installations
90+

Vulnerability:
Privilege Escalation

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Track Everything

Plugin Slug:
track-everything

Installations
90+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Photo Express for Google

Plugin Slug:
photo-express-for-google

Installations
80+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

My Resume Builder

Plugin Slug:
my-resume-builder

Installations
70+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

DirectIQ Email Marketing

Plugin Slug:
directiq-wp

Installations
40+

Vulnerability:
SQL Injection

Patched in Version:
No Fix

Severity Score:
Critical


The vulnerability has not been patched. You should deactivate the plugin.

A/B Testing for WordPress

Plugin:

A/B Testing for WordPress

Plugin Slug:
ab-testing-for-wp

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Aioseo Multibyte Descriptions

Plugin:

Aioseo Multibyte Descriptions

Plugin Slug:
aioseo-multibyte-descriptions

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Backwp

Plugin:

Backwp

Plugin Slug:
backwp

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Beauty Contact Popup Form

Plugin:

Beauty Contact Popup Form

Plugin Slug:
beauty-contact-popup-form

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

CMS Blocks

Plugin:

CMS Blocks

Plugin Slug:
cms-blocks

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Contact Form – 7 : Hide Success Message

Plugin:

Contact Form – 7 : Hide Success Message

Plugin Slug:
contact-form-7-hide-success-message

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

CTUsers

Plugin:

CTUsers

Plugin Slug:
ctuser

Vulnerability:
Local File Inclusion

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Davenport – Versatile Blog and Magazine WordPress Theme

Plugin:

Davenport – Versatile Blog and Magazine WordPress Theme

Plugin Slug:
davenport

Vulnerability:
Local File Inclusion

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Devnex Addons For Elementor

Plugin:

Devnex Addons For Elementor

Plugin Slug:
devnex-addons-for-elementor

Vulnerability:
Local File Inclusion

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Drive Folder Embedder

Plugin:

Drive Folder Embedder

Plugin Slug:
drive-folder-embeder

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

enigma-buttons

Plugin:

enigma-buttons

Plugin Slug:
e.nigma buttons

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Evangelische Termine

Plugin:

Evangelische Termine

Plugin Slug:
evangtermine

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

File Manager Plugin For WordPress

Plugin:

File Manager Plugin For WordPress

Plugin Slug:
file-manager-plugin-for-wordpress

Vulnerability:
Arbitrary File Upload

Patched in Version:
No Fix

Severity Score:
Critical


The vulnerability has not been patched. You should deactivate the plugin.

FL3R Accessibility Suite

Plugin:

FL3R Accessibility Suite

Plugin Slug:
fl3r-accessibility-suite

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Flexo Counter

Plugin:

Flexo Counter

Plugin Slug:
flexo-countdown

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Free Downloads EDD

Plugin:

Free Downloads EDD

Plugin Slug:
free-downloads-edd

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

FW Food Menu

Plugin:

FW Food Menu

Plugin Slug:
fw-food-menu

Vulnerability:
Arbitrary File Deletion

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.
Plugin:

FW Gallery

Plugin Slug:
fw-gallery

Vulnerability:
Arbitrary File Upload

Patched in Version:
No Fix

Severity Score:
Critical


The vulnerability has not been patched. You should deactivate the plugin.
Plugin:

FW Gallery

Plugin Slug:
fw-gallery

Vulnerability:
Local File Inclusion

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Game Users Share Buttons

Plugin:

Game Users Share Buttons

Plugin Slug:
game-users-share-buttons

Vulnerability:
Arbitrary File Deletion

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

GC Social Wall

Plugin:

GC Social Wall

Plugin Slug:
gc-social-wall

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

GG Bought Together for WooCommerce

Plugin:

GG Bought Together for WooCommerce

Plugin Slug:
gg-bought-together

Vulnerability:
SQL Injection

Patched in Version:
No Fix

Severity Score:
Critical


The vulnerability has not been patched. You should deactivate the plugin.

Homerunner

Plugin:

Homerunner

Plugin Slug:
homerunner-smartcheckout

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Image Shadow

Plugin:

Image Shadow

Plugin Slug:
image-shadow

Vulnerability:
Arbitrary File Deletion

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Image Slider With Description

Plugin:

Image Slider With Description

Plugin Slug:
image-slider-with-description

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Amazon Products to WooCommerce

Plugin:

Amazon Products to WooCommerce

Plugin Slug:
import-products-to-wc

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Namasha By Mdesign

Plugin:

Namasha By Mdesign

Plugin Slug:
namasha-by-mdesign

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Opal Estate Pro

Plugin:

Opal Estate Pro

Plugin Slug:
opal-estate-pro

Vulnerability:
Privilege Escalation

Patched in Version:
No Fix

Severity Score:
Critical


The vulnerability has not been patched. You should deactivate the plugin.

Plugin Inspector

Plugin:

Plugin Inspector

Plugin Slug:
plugin-inspector

Vulnerability:
Arbitrary File Download

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Podcast Feed Player Widget and Shortcode

Plugin:

Podcast Feed Player Widget and Shortcode

Plugin Slug:
podcast-feed-player-widget

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Post Rating and Review

Plugin:

Post Rating and Review

Plugin Slug:
post-rating-and-review

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

PT Project Notebooks

Plugin:

PT Project Notebooks

Plugin Slug:
project-notebooks

Vulnerability:
Privilege Escalation

Patched in Version:
No Fix

Severity Score:
Critical


The vulnerability has not been patched. You should deactivate the plugin.
Plugin:

Simple Link Directory

Plugin Slug:
qc-simple-link-directory

Vulnerability:
SQL Injection

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Quick Favicon

Plugin:

Quick Favicon

Plugin Slug:
quick-favicon

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

re.place

Plugin:

re.place

Plugin Slug:
replace

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Responsive Food and Drink Menu

Plugin:

Responsive Food and Drink Menu

Plugin Slug:
responsive-food-and-drink-menu

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.
Plugin:

Owl carousel responsive

Plugin Slug:
responsive-owl-carousel

Vulnerability:
SQL Injection

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

RSS Digest

Plugin:

RSS Digest

Plugin Slug:
rss-digest

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

SB Breadcrumbs

Plugin:

SB Breadcrumbs

Plugin Slug:
sb-breadcrumbs

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

WP SmartPay

Plugin:

WP SmartPay

Plugin Slug:
smartpay

Vulnerability:
Broken Authentication

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Spo?eczno?ciowa 6 PL 2013

Plugin:

Spo?eczno?ciowa 6 PL 2013

Plugin Slug:
spolecznosciowa-6-pl-2013

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

The Countdown � Block Countdown Timer

Plugin:

The Countdown � Block Countdown Timer

Plugin Slug:
the-countdown

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

The Pack Elementor addons

Plugin:

The Pack Elementor addons

Plugin Slug:
the-pack-addon

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

TimeZoneCalculator

Plugin:

TimeZoneCalculator

Plugin Slug:
timezonecalculator

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Tournament Bracket Generator

Plugin:

Tournament Bracket Generator

Plugin Slug:
tournament-bracket-generator

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Rankie

Plugin:

Rankie

Plugin Slug:
valvepress-rankie

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

VG WORT METIS

Plugin:

VG WORT METIS

Plugin Slug:
vgw-metis

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

VG WORT METIS

Plugin:

VG WORT METIS

Plugin Slug:
vgw-metis

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

VR Calendar

Plugin:

VR Calendar

Plugin Slug:
vr-calendar-sync

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

web-cam

Plugin:

web-cam

Plugin Slug:
web-cam

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Email Address Security by WebEmailProtector

Plugin:

Email Address Security by WebEmailProtector

Plugin Slug:
webemailprotector

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Event RSVP and Simple Event Management Plugin

Plugin:

Event RSVP and Simple Event Management Plugin

Plugin Slug:
wp-easy-events

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.
Plugin:

WP GDPR Cookie Consent

Plugin Slug:
wp-gdpr-cookie-consen

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

JobSearch

Plugin:

JobSearch

Plugin Slug:
wp-jobsearch

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

WP Optimize By xTraffic

Plugin:

WP Optimize By xTraffic

Plugin Slug:
wp-optimize-by-xtraffic

Vulnerability:
PHP Object Injection

Patched in Version:
No Fix

Severity Score:
Critical


The vulnerability has not been patched. You should deactivate the plugin.

WP-PhotoNav

Plugin:

WP-PhotoNav

Plugin Slug:
wp-photonav

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

WP-Recall

Plugin:

WP-Recall

Plugin Slug:
wp-recall

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

WP SoundSystem

Plugin:

WP SoundSystem

Plugin Slug:
wp-soundsystem

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

WP Visual Sitemap

Plugin:

WP Visual Sitemap

Plugin Slug:
wp-visual-sitemap

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

WP Wall

Plugin:

WP Wall

Plugin Slug:
wp-wall

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

WPCRM – CRM for Contact form CF7 & WooCommerce

Plugin:

WPCRM – CRM for Contact form CF7 & WooCommerce

Plugin Slug:
wpcrm

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

WPKit For Elementor

Plugin:

WPKit For Elementor

Plugin Slug:
wpkit-elementor

Vulnerability:
Privilege Escalation

Patched in Version:
No Fix

Severity Score:
Critical


The vulnerability has not been patched. You should deactivate the plugin.

Royal Elementor Addons and Templates

Plugin Slug:
royal-elementor-addons

Installations
600,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.7.1025

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.7.1025.

SiteOrigin Widgets Bundle

Plugin Slug:
so-widgets-bundle

Installations
500,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.69.0

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.69.0.

Firelight Lightbox

Plugin Slug:
easy-fancybox

Installations
200,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.3.16

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.3.16.

Qi Addons For Elementor

Plugin Slug:
qi-addons-for-elementor

Installations
200,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.9.2

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.9.2.
Plugin Slug:
responsive-lightbox

Installations
100,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.5.2

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.5.2.

Ninja Tables � Easy Data Table Builder

Plugin Slug:
ninja-tables

Installations
80,000+

Vulnerability:
Server Side Request Forgery (SSRF)

Patched in Version:
5.0.19

Severity Score:
High


The vulnerability has been patched, so you should update to version 5.0.19.

Ultra Addons for Contact Form 7

Plugin Slug:
ultimate-addons-for-contact-form-7

Installations
60,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
3.5.22

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 3.5.22.

Ultra Addons for Contact Form 7

Plugin Slug:
ultimate-addons-for-contact-form-7

Installations
60,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
3.5.20

Severity Score:
High


The vulnerability has been patched, so you should update to version 3.5.20.

HT Slider For Elementor

Plugin Slug:
ht-slider-for-elementor

Installations
20,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.6.6

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.6.6.

Frontend Admin by DynamiApps

Plugin Slug:
acf-frontend-form-element

Installations
10,000+

Vulnerability:
Arbitrary File Download

Patched in Version:
3.28.8

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 3.28.8.

BuddyPress Docs

Plugin Slug:
buddypress-docs

Installations
8,000+

Vulnerability:
Broken Access Control

Patched in Version:
2.2.5

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.2.5.

AI ChatBot for WordPress � WPBot

Plugin Slug:
chatbot

Installations
7,000+

Vulnerability:
Broken Access Control

Patched in Version:
6.7.5

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 6.7.5.

Hotel Booking

Plugin Slug:
nd-booking

Installations
5,000+

Vulnerability:
Local File Inclusion

Patched in Version:
3.8

Severity Score:
High


The vulnerability has been patched, so you should update to version 3.8.

Post Carousel Slider for Elementor

Plugin Slug:
post-carousel-slider-for-elementor

Installations
4,000+

Vulnerability:
Broken Access Control

Patched in Version:
1.7.0

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.7.0.

Responsive Blocks � WordPress Gutenberg Blocks

Plugin Slug:
responsive-block-editor-addons

Installations
4,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.0.7

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.0.7.

HT Mega � Absolute Addons for WPBakery Page Builder

Plugin Slug:
ht-mega-for-wpbakery

Installations
1,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.0.9

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.0.9.

Off-Canvas Sidebars & Menus (Slidebars)

Plugin Slug:
off-canvas-sidebars

Installations
1,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
0.5.8.5

Severity Score:
High


The vulnerability has been patched, so you should update to version 0.5.8.5.

Popup addon for Ninja Forms

Plugin Slug:
popup-addon-for-ninja-forms

Installations
1,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
3.5

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 3.5.

WP AdCenter � Ad Manager & Adsense Ads

Plugin Slug:
wpadcenter

Installations
1,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.6.1

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.6.1.

Image Editor by Pixo

Plugin Slug:
image-editor-by-pixo

Installations
800+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.3.7

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.3.7.

Booking Calendar Contact Form

Plugin Slug:
booking-calendar-contact-form

Installations
700+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.2.59

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.2.59.

SmartAgenda � Prise de rendez-vous en ligne

Plugin Slug:
smart-agenda-prise-de-rendez-vous-en-ligne

Installations
500+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
5.0

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 5.0.

Conference Scheduler

Plugin Slug:
conference-scheduler

Installations
300+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.5.2

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.5.2.

Audio Editor & Recorder

Plugin Slug:
audio-editor-recorder

Installations
200+

Vulnerability:
Sensitive Data Exposure

Patched in Version:
2.2.4

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.2.4.

Euro FxRef Currency Converter

Plugin Slug:
euro-fxref-currency-converter

Installations
200+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.0.3

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.0.3.

SERPed.net

Plugin Slug:
serped-net

Installations
200+

Vulnerability:
Local File Inclusion

Patched in Version:
4.7

Severity Score:
High


The vulnerability has been patched, so you should update to version 4.7.

WP Masonry & Infinite Scroll

Plugin Slug:
wp-masonry-infinite-scroll

Installations
200+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.3

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.3.

isMobile() Shortcode for WordPress

Plugin Slug:
ismobile

Installations
100+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.1.2

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.1.2.

Modern Design Library

Plugin Slug:
mdl-shortcodes

Installations
60+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.1.5

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.1.5.

Simple Payment

Plugin Slug:
simple-payment

Installations
40+

Vulnerability:
Bypass Vulnerability

Patched in Version:
2.3.9

Severity Score:
Critical


The vulnerability has been patched, so you should update to version 2.3.9.

Aiomatic

Plugin:

Aiomatic

Plugin Slug:
aiomatic-automatic-ai-content-writer

Vulnerability:
Arbitrary File Upload

Patched in Version:
2.5.1

Severity Score:
High


The vulnerability has been patched, so you should update to version 2.5.1.

BeeTeam368 Extensions

Plugin:

BeeTeam368 Extensions

Plugin Slug:
beeteam368-extensions

Vulnerability:
Arbitrary File Deletion

Patched in Version:
2.3.5

Severity Score:
High


The vulnerability has been patched, so you should update to version 2.3.5.

BeeTeam368 Extensions Pro

Plugin:

BeeTeam368 Extensions Pro

Plugin Slug:
beeteam368-extensions-pro

Vulnerability:
Arbitrary File Deletion

Patched in Version:
2.3.5

Severity Score:
High


The vulnerability has been patched, so you should update to version 2.3.5.

Drag and Drop Multiple File Upload (Pro) – WooCommerce

Plugin:

Drag and Drop Multiple File Upload (Pro) – WooCommerce

Plugin Slug:
drag-and-drop-file-upload-wc-pro

Vulnerability:
Arbitrary File Upload

Patched in Version:
5.0.7

Severity Score:
Critical


The vulnerability has been patched, so you should update to version 5.0.7.

Everest Forms Pro

Plugin:

Everest Forms Pro

Plugin Slug:
everest-forms-pro

Vulnerability:
Arbitrary File Deletion

Patched in Version:
1.9.5

Severity Score:
High


The vulnerability has been patched, so you should update to version 1.9.5.

JetEngine

Plugin:

JetEngine

Plugin Slug:
jet-engine

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
3.7.1.1

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 3.7.1.1.

BRW

Plugin:

BRW

Plugin Slug:
ova-brw

Vulnerability:
Local File Inclusion

Patched in Version:
1.8.8

Severity Score:
High


The vulnerability has been patched, so you should update to version 1.8.8.

Team Showcase

Plugin:

Team Showcase

Plugin Slug:
team-showcase-cm

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
25.05.13

Severity Score:
High


The vulnerability has been patched, so you should update to version 25.05.13.

Zikzag Core

Plugin:

Zikzag Core

Plugin Slug:
zikzag-core

Vulnerability:
Local File Inclusion

Patched in Version:
1.4.6

Severity Score:
High


The vulnerability has been patched, so you should update to version 1.4.6.

WordPress Themes � 15 Patched / 23 Unpatched

Constructor

Theme Slug:
constructor

Downloads
435,600

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should switch themes.

Zita

Theme:

Zita

Theme Slug:
zita

Downloads
405,845

Vulnerability:
Local File Inclusion

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should switch themes.

PrintXtore

Theme:

PrintXtore

Theme Slug:
bw-printxtore

Vulnerability:
Local File Inclusion

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should switch themes.

Zenny

Theme:

Zenny

Theme Slug:
bw-zenny

Vulnerability:
Local File Inclusion

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should switch themes.

CityGov

Theme:

CityGov

Theme Slug:
citygov

Vulnerability:
Local File Inclusion

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should switch themes.

Domnoo

Theme:

Domnoo

Theme Slug:
domnoo

Vulnerability:
Local File Inclusion

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should switch themes.

Homey

Theme:

Homey

Theme Slug:
homey

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should switch themes.

Homey

Theme:

Homey

Theme Slug:
homey

Vulnerability:
SQL Injection

Patched in Version:
No Fix

Severity Score:
Critical


The vulnerability has not been patched. You should switch themes.

Katerio – Magazine

Theme:

Katerio – Magazine

Theme Slug:
katerio

Vulnerability:
Local File Inclusion

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should switch themes.

LMS

Theme:

LMS

Theme Slug:
lms

Vulnerability:
SQL Injection

Patched in Version:
No Fix

Severity Score:
Critical


The vulnerability has not been patched. You should switch themes.

LMS

Theme:

LMS

Theme Slug:
lms

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should switch themes.

LogisticsHub

Theme:

LogisticsHub

Theme Slug:
logistics-hub

Vulnerability:
Arbitrary File Upload

Patched in Version:
No Fix

Severity Score:
Critical


The vulnerability has not been patched. You should switch themes.

MagOne

Theme:

MagOne

Theme Slug:
magone

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should switch themes.

MBStore – Digital WooCommerce WordPress Theme

Theme:

MBStore – Digital WooCommerce WordPress Theme

Theme Slug:
mbstore

Vulnerability:
Local File Inclusion

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should switch themes.

Nuss

Theme:

Nuss

Theme Slug:
nuss

Vulnerability:
PHP Object Injection

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should switch themes.

Pressroom – News Magazine WordPress Theme

Theme:

Pressroom – News Magazine WordPress Theme

Theme Slug:
pressroom

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should switch themes.

RealtyElite

Theme:

RealtyElite

Theme Slug:
realtyelite

Vulnerability:
Local File Inclusion

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should switch themes.

Red Art

Theme:

Red Art

Theme Slug:
redart

Vulnerability:
PHP Object Injection

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should switch themes.

Sala

Theme:

Sala

Theme Slug:
sala

Vulnerability:
PHP Object Injection

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should switch themes.

Samex – Clean, Minimal Shop WooCommerce WordPress Theme

Theme:

Samex – Clean, Minimal Shop WooCommerce WordPress Theme

Theme Slug:
samex

Vulnerability:
Local File Inclusion

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should switch themes.

Seven Stars

Theme:

Seven Stars

Theme Slug:
sevenstars

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should switch themes.

SNS Vicky

Theme:

SNS Vicky

Theme Slug:
snsvicky

Vulnerability:
Local File Inclusion

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should switch themes.

Sofass

Theme:

Sofass

Theme Slug:
sofass

Vulnerability:
Local File Inclusion

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should switch themes.

Blogbyte

Theme Slug:
blogbyte

Downloads
5,082

Vulnerability:
Local File Inclusion

Patched in Version:
1.1.2

Severity Score:
High


The vulnerability has been patched, so you should update to version 1.1.2.

Blogmine

Theme Slug:
blogmine

Downloads
3,498

Vulnerability:
Local File Inclusion

Patched in Version:
1.1.8

Severity Score:
High


The vulnerability has been patched, so you should update to version 1.1.8.

Blogprise

Theme Slug:
blogprise

Downloads
5,171

Vulnerability:
Local File Inclusion

Patched in Version:
1.0.10

Severity Score:
High


The vulnerability has been patched, so you should update to version 1.0.10.

Blogty

Theme:

Blogty

Theme Slug:
blogty

Downloads
3,128

Vulnerability:
Local File Inclusion

Patched in Version:
1.0.12

Severity Score:
High


The vulnerability has been patched, so you should update to version 1.0.12.

Blogvy

Theme:

Blogvy

Theme Slug:
blogvy

Downloads
4,752

Vulnerability:
Local File Inclusion

Patched in Version:
1.0.8

Severity Score:
High


The vulnerability has been patched, so you should update to version 1.0.8.

Magty

Theme:

Magty

Theme Slug:
magty

Downloads
2,670

Vulnerability:
Local File Inclusion

Patched in Version:
1.0.7

Severity Score:
High


The vulnerability has been patched, so you should update to version 1.0.7.

Magways

Theme:

Magways

Theme Slug:
magways

Downloads
1,899

Vulnerability:
Local File Inclusion

Patched in Version:
1.2.2

Severity Score:
High


The vulnerability has been patched, so you should update to version 1.2.2.

Magze

Theme:

Magze

Theme Slug:
magze

Downloads
3,707

Vulnerability:
Local File Inclusion

Patched in Version:
1.0.10

Severity Score:
High


The vulnerability has been patched, so you should update to version 1.0.10.

Neom Blog

Theme Slug:
neom-blog

Downloads
22,211

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
0.1.0

Severity Score:
High


The vulnerability has been patched, so you should update to version 0.1.0.

Amely

Theme:

Amely

Theme Slug:
amely

Vulnerability:
SQL Injection

Patched in Version:
3.2.0

Severity Score:
Critical


The vulnerability has been patched, so you should update to version 3.2.0.

DWT – Directory & Listing

Theme:

DWT – Directory & Listing

Theme Slug:
dwt-listing

Vulnerability:
Privilege Escalation

Patched in Version:
3.3.7

Severity Score:
Critical


The vulnerability has been patched, so you should update to version 3.3.7.

Elessi

Theme:

Elessi

Theme Slug:
elessi-theme

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
6.4.1

Severity Score:
High


The vulnerability has been patched, so you should update to version 6.4.1.

Greenmart

Theme:

Greenmart

Theme Slug:
greenmart

Vulnerability:
Local File Inclusion

Patched in Version:
4.2.4

Severity Score:
High


The vulnerability has been patched, so you should update to version 4.2.4.

Litho

Theme:

Litho

Theme Slug:
litho

Vulnerability:
Arbitrary File Deletion

Patched in Version:
3.1

Severity Score:
High


The vulnerability has been patched, so you should update to version 3.1.

Puca

Theme:

Puca

Theme Slug:
puca

Vulnerability:
Local File Inclusion

Patched in Version:
2.6.34

Severity Score:
High


The vulnerability has been patched, so you should update to version 2.6.34.

Related articles

Wait! Get exclusive hosting insights

Subscribe to our newsletter and stay ahead of the competition with expert advice from our hosting pros.

Loading form…