WordPress Vulnerability Report � April 8, 2026

In this report, 68 vulnerabilities have been publicly disclosed. Security patches for 64 of these plugins and themes are now available. Please run these updates as soon as possible. If you’re a Solid Security Pro user, the version management tool may have already warned you and updated these plugins, depending on your settings.

Currently, 4 plugin and theme vulnerabilities remain unpatched. If you’re a Solid Security Pro user, those vulnerabilities are already protected by the Solid Security firewall. Virtual patches from Patchstack will be applied when a vulnerability is considered high or medium risk. If no patch is forthcoming from the vendor or the vulnerable software has been marked “closed” and dropped from the official WordPress repositories, you should deactivate it soon and look for alternative solutions.

WordPress Core

WordPress 6.9.4 is available, addressing 10 security issues and a template loading bug. Immediate updates are recommended for all production sites.

WordPress 7.0 Release Candidate 2 (RC2) is now ready for testing via the Beta Tester plugin, direct download, WP-CLI, or WordPress Playground. As a pre-release version, it should only be evaluated in staging or local environments.

WordPress 7.0 is scheduled for release on April 9, 2026.

WordPress Plugins � 63 Patched / 4 Unpatched

MSTW League Manager

Plugin Slug:
mstw-league-manager

Installations
100+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Auto Post Scheduler

Plugin:

Auto Post Scheduler

Plugin Slug:
auto-post-scheduler

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Performance Monitor

Plugin:

Performance Monitor

Plugin Slug:
performance-monitor

Vulnerability:
Server Side Request Forgery (SSRF)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

IDPay Payment Gateway for Woocommerce

Plugin:

IDPay Payment Gateway for Woocommerce

Plugin Slug:
woo-idpay-gateway

Vulnerability:
Sensitive Data Exposure

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.
Plugin Slug:
complianz-gdpr

Installations
1,000,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
7.4.5

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 7.4.5.

Loco Translate

Plugin Slug:
loco-translate

Installations
1,000,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.8.3

Severity Score:
High


The vulnerability has been patched, so you should update to version 2.8.3.

W3 Total Cache

Plugin Slug:
w3-total-cache

Installations
900,000+

Vulnerability:
Sensitive Data Exposure

Patched in Version:
2.9.4

Severity Score:
High


The vulnerability has been patched, so you should update to version 2.9.4.

WooPayments: Integrated WooCommerce Payments

Plugin Slug:
woocommerce-payments

Installations
900,000+

Vulnerability:
Broken Access Control

Patched in Version:
10.6.0

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 10.6.0.

WP Shortcodes Plugin � Shortcodes Ultimate

Plugin Slug:
shortcodes-ultimate

Installations
400,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
7.4.9

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 7.4.9.

WP Shortcodes Plugin � Shortcodes Ultimate

Plugin Slug:
shortcodes-ultimate

Installations
400,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
7.4.8

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 7.4.8.

WP Shortcodes Plugin � Shortcodes Ultimate

Plugin Slug:
shortcodes-ultimate

Installations
400,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
7.5.0

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 7.5.0.

MW WP Form

Plugin Slug:
mw-wp-form

Installations
200,000+

Vulnerability:
Directory Traversal

Patched in Version:
5.1.1

Severity Score:
High


The vulnerability has been patched, so you should update to version 5.1.1.

Query Monitor

Plugin Slug:
query-monitor

Installations
200,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
3.20.4

Severity Score:
High


The vulnerability has been patched, so you should update to version 3.20.4.

Kubio AI Page Builder

Plugin Slug:
kubio

Installations
100,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.7.1

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.7.1.

Booking for Appointments and Events Calendar � Amelia

Plugin Slug:
ameliabooking

Installations
90,000+

Vulnerability:
Insecure Direct Object References (IDOR)

Patched in Version:
2.2

Severity Score:
High


The vulnerability has been patched, so you should update to version 2.2.

Download Monitor

Plugin Slug:
download-monitor

Installations
90,000+

Vulnerability:
Insecure Direct Object References (IDOR)

Patched in Version:
5.1.8

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 5.1.8.

Database for Contact Form 7, WPforms, Elementor forms

Plugin Slug:
contact-form-entries

Installations
70,000+

Vulnerability:
Broken Access Control

Patched in Version:
1.5.0

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.5.0.

Media Library Assistant

Plugin Slug:
media-library-assistant

Installations
70,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
3.35

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 3.35.

Media Library Assistant

Plugin Slug:
media-library-assistant

Installations
70,000+

Vulnerability:
SQL Injection

Patched in Version:
3.35

Severity Score:
High


The vulnerability has been patched, so you should update to version 3.35.

Conditional Menus

Plugin Slug:
conditional-menus

Installations
60,000+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
1.2.7

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.2.7.

Export All URLs

Plugin Slug:
export-all-urls

Installations
50,000+

Vulnerability:
Sensitive Data Exposure

Patched in Version:
5.1

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 5.1.

Simple Membership

Plugin Slug:
simple-membership

Installations
40,000+

Vulnerability:
Broken Access Control

Patched in Version:
4.7.2

Severity Score:
High


The vulnerability has been patched, so you should update to version 4.7.2.

Blackhole for Bad Bots

Plugin Slug:
blackhole-bad-bots

Installations
30,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
3.8.1

Severity Score:
High


The vulnerability has been patched, so you should update to version 3.8.1.

WP Lightbox 2

Plugin Slug:
wp-lightbox-2

Installations
30,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
3.0.7

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 3.0.7.

Xpro Addons � 140+ Widgets for Elementor

Plugin Slug:
xpro-elementor-addons

Installations
30,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.4.21

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.4.21.

Xpro Addons � 140+ Widgets for Elementor

Plugin Slug:
xpro-elementor-addons

Installations
30,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.4.25

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.4.25.

WCFM � Frontend Manager for WooCommerce

Plugin Slug:
wc-frontend-manager

Installations
20,000+

Vulnerability:
Insecure Direct Object References (IDOR)

Patched in Version:
6.7.26

Severity Score:
High


The vulnerability has been patched, so you should update to version 6.7.26.

Frontend Admin by DynamiApps

Plugin Slug:
acf-frontend-form-element

Installations
10,000+

Vulnerability:
PHP Object Injection

Patched in Version:
3.28.32

Severity Score:
High


The vulnerability has been patched, so you should update to version 3.28.32.

Ibtana � WordPress Website Builder

Plugin Slug:
ibtana-visual-editor

Installations
10,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.2.5.8

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.2.5.8.

Minify HTML

Plugin Slug:
minify-html-markup

Installations
10,000+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
2.1.13

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.1.13.

Simple Shopping Cart

Plugin Slug:
wordpress-simple-paypal-shopping-cart

Installations
10,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
5.2.5

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 5.2.5.

Spam Protect for Contact Form 7

Plugin Slug:
wp-contact-form-7-spam-blocker

Installations
10,000+

Vulnerability:
Remote Code Execution (RCE)

Patched in Version:
1.2.10

Severity Score:
High


The vulnerability has been patched, so you should update to version 1.2.10.

Contact Form by Supsystic

Plugin Slug:
contact-form-by-supsystic

Installations
7,000+

Vulnerability:
Remote Code Execution (RCE)

Patched in Version:
1.8.0

Severity Score:
Critical


The vulnerability has been patched, so you should update to version 1.8.0.

Webmention

Plugin Slug:
webmention

Installations
900+

Vulnerability:
Server Side Request Forgery (SSRF)

Patched in Version:
5.7.0

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 5.7.0.

Webmention

Plugin Slug:
webmention

Installations
900+

Vulnerability:
Server Side Request Forgery (SSRF)

Patched in Version:
5.7.0

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 5.7.0.

TrueBooker � Appointment Booking and Scheduler System

Plugin Slug:
truebooker-appointment-booking

Installations
600+

Vulnerability:
Sensitive Data Exposure

Patched in Version:
1.1.5

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.1.5.

Debugger & Troubleshooter

Plugin Slug:
debugger-troubleshooter

Installations
50+

Vulnerability:
Privilege Escalation

Patched in Version:
1.4.0

Severity Score:
Critical


The vulnerability has been patched, so you should update to version 1.4.0.

Bricksforge

Plugin:

Bricksforge

Plugin Slug:
bricksforge

Vulnerability:
Sensitive Data Exposure

Patched in Version:
3.1.8.5

Severity Score:
High


The vulnerability has been patched, so you should update to version 3.1.8.5.

Everest Forms Pro

Plugin:

Everest Forms Pro

Plugin Slug:
everest-forms-pro

Vulnerability:
Remote Code Execution (RCE)

Patched in Version:
1.9.13

Severity Score:
Critical


The vulnerability has been patched, so you should update to version 1.9.13.

Gravity SMTP

Plugin:

Gravity SMTP

Plugin Slug:
gravitysmtp

Vulnerability:
Sensitive Data Exposure

Patched in Version:
2.1.5

Severity Score:
High


The vulnerability has been patched, so you should update to version 2.1.5.

LeadConnector

Plugin:

LeadConnector

Plugin Slug:
leadconnector

Vulnerability:
Broken Access Control

Patched in Version:
3.0.22

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 3.0.22.

Perfmatters

Plugin:

Perfmatters

Plugin Slug:
perfmatters

Vulnerability:
Arbitrary File Deletion

Patched in Version:
2.6.0

Severity Score:
High


The vulnerability has been patched, so you should update to version 2.6.0.

ThemeREX Addons

Plugin:

ThemeREX Addons

Plugin Slug:
trx_addons

Vulnerability:
Arbitrary File Upload

Patched in Version:
2.38.5

Severity Score:
Critical


The vulnerability has been patched, so you should update to version 2.38.5.

Ultimate Addons for WPBakery Page Builder

Plugin:

Ultimate Addons for WPBakery Page Builder

Plugin Slug:
ultimate_vc_addons

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
3.21.4

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 3.21.4.

WordPress Themes � 1 Patched / 0 Unpatched

Oxygen

Theme:

Oxygen

Theme Slug:
oxygen

Downloads
403,225

Vulnerability:
Server Side Request Forgery (SSRF)

Patched in Version:
6.0.9

Severity Score:
High


The vulnerability has been patched, so you should update to version 6.0.9.

Related articles

Wait! Get exclusive hosting insights

Subscribe to our newsletter and stay ahead of the competition with expert advice from our hosting pros.

Loading form…