WordPress Vulnerability Report � April 15, 2026

In this report, 185 vulnerabilities have been publicly disclosed. Security patches for 169 of these plugins and themes are now available. Please run these updates as soon as possible. If you’re a Solid Security Pro user, the version management tool may have already warned you and updated these plugins, depending on your settings.

Currently, 16 plugin vulnerabilities remain unpatched. If you’re a Solid Security Pro user, those vulnerabilities are already protected by the Solid Security firewall. Virtual patches from Patchstack will be applied when a vulnerability is considered high or medium risk. If no patch is forthcoming from the vendor or the vulnerable software has been marked “closed” and dropped from the official WordPress repositories, you should deactivate it soon and look for alternative solutions.

WordPress Core

WordPress 6.9.4 is available, addressing 10 security issues and a template loading bug. Immediate updates are recommended for all production sites.

WordPress 7.0 Release Candidate 2 (RC2) is now ready for testing via the Beta Tester plugin, direct download, WP-CLI, or WordPress Playground. As a pre-release version, it should only be evaluated in staging or local environments.

WordPress Plugins � 145 Patched / 16 Unpatched

AM LottiePlayer

Plugin:

AM LottiePlayer

Plugin Slug:
am-lottieplayer

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Attendance Manager

Plugin:

Attendance Manager

Plugin Slug:
attendance-manager

Vulnerability:
SQL Injection

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Columns by BestWebSoft

Plugin:

Columns by BestWebSoft

Plugin Slug:
columns-bws

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

DSGVO Google Web Fonts GDPR

Plugin:

DSGVO Google Web Fonts GDPR

Plugin Slug:
dsgvo-google-web-fonts-gdpr

Vulnerability:
Arbitrary File Upload

Patched in Version:
No Fix

Severity Score:
Critical


The vulnerability has not been patched. You should deactivate the plugin.

Gerador de Certificados � DevApps

Plugin:

Gerador de Certificados � DevApps

Plugin Slug:
gerador-de-certificados-devapps

Vulnerability:
Arbitrary File Upload

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Inquiry form to posts or pages

Plugin:

Inquiry form to posts or pages

Plugin Slug:
inquiry-form-to-posts-or-pages

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Pinterest Site Verification plugin using Meta Tag

Plugin:

Pinterest Site Verification plugin using Meta Tag

Plugin Slug:
pinterest-site-verification

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

pz-frontend-manager

Plugin:

pz-frontend-manager

Plugin Slug:
pz-frontend-manager

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Quran Translations

Plugin:

Quran Translations

Plugin Slug:
quran-translations-by-edc

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Riaxe Product Customizer

Plugin:

Riaxe Product Customizer

Plugin Slug:
riaxe-product-customizer

Vulnerability:
Sensitive Data Exposure

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Sports Club Management

Plugin:

Sports Club Management

Plugin Slug:
sports-club-management

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Wavr

Plugin:

Wavr

Plugin Slug:
wavr

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Whole Enquiry Cart for WooCommerce

Plugin:

Whole Enquiry Cart for WooCommerce

Plugin Slug:
whole-cart-enquiry

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

IDPay Payment Gateway for Woocommerce

Plugin:

IDPay Payment Gateway for Woocommerce

Plugin Slug:
woo-idpay-gateway

Vulnerability:
Sensitive Data Exposure

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

WowPress

Plugin:

WowPress

Plugin Slug:
wowpress

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

WP Blockade

Plugin:

WP Blockade

Plugin Slug:
wp-blockade

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

ManageWP Worker

Plugin Slug:
worker

Installations
1,000,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
4.9.32

Severity Score:
High


The vulnerability has been patched, so you should update to version 4.9.32.

Smart Slider 3

Plugin Slug:
smart-slider-3

Installations
800,000+

Vulnerability:
Broken Access Control

Patched in Version:
3.5.1.34

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 3.5.1.34.

BackWPup � WordPress Backup & Restore Plugin

Plugin Slug:
backwpup

Installations
500,000+

Vulnerability:
Local File Inclusion

Patched in Version:
5.6.7

Severity Score:
High


The vulnerability has been patched, so you should update to version 5.6.7.

Meta Box

Plugin:

Meta Box

Plugin Slug:
meta-box

Installations
500,000+

Vulnerability:
Arbitrary File Deletion

Patched in Version:
5.11.2

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 5.11.2.

Ocean Extra

Plugin Slug:
ocean-extra

Installations
500,000+

Vulnerability:
Broken Access Control

Patched in Version:
2.5.4

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.5.4.

YITH WooCommerce Wishlist

Plugin Slug:
yith-woocommerce-wishlist

Installations
500,000+

Vulnerability:
Insecure Direct Object References (IDOR)

Patched in Version:
4.13.0

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 4.13.0.

MW WP Form

Plugin Slug:
mw-wp-form

Installations
200,000+

Vulnerability:
Directory Traversal

Patched in Version:
5.1.2

Severity Score:
High


The vulnerability has been patched, so you should update to version 5.1.2.

Post Duplicator

Plugin Slug:
post-duplicator

Installations
200,000+

Vulnerability:
PHP Object Injection

Patched in Version:
3.0.11

Severity Score:
High


The vulnerability has been patched, so you should update to version 3.0.11.

Aruba HiSpeed Cache

Plugin Slug:
aruba-hispeed-cache

Installations
100,000+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
3.0.5

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 3.0.5.

Element Pack � Widgets, Templates & Addons for Elementor

Plugin Slug:
bdthemes-element-pack-lite

Installations
100,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
8.5.0

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 8.5.0.

Prime Slider � Addons for Elementor

Plugin Slug:
bdthemes-prime-slider-lite

Installations
100,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
4.1.11

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 4.1.11.

Beaver Builder Page Builder � Drag and Drop Website Builder

Plugin Slug:
beaver-builder-lite-version

Installations
100,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.10.1.2

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.10.1.2.

Download Manager

Plugin Slug:
download-manager

Installations
100,000+

Vulnerability:
Broken Access Control

Patched in Version:
3.3.52

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 3.3.52.

Download Manager

Plugin Slug:
download-manager

Installations
100,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
3.3.53

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 3.3.53.

MainWP Child Reports

Plugin Slug:
mainwp-child-reports

Installations
100,000+

Vulnerability:
Broken Access Control

Patched in Version:
2.3

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.3.

Tutor LMS � eLearning and online course solution

Plugin Slug:
tutor

Installations
100,000+

Vulnerability:
Insecure Direct Object References (IDOR)

Patched in Version:
3.9.8

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 3.9.8.

Tutor LMS � eLearning and online course solution

Plugin Slug:
tutor

Installations
100,000+

Vulnerability:
Broken Access Control

Patched in Version:
3.9.8

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 3.9.8.

Tutor LMS � eLearning and online course solution

Plugin Slug:
tutor

Installations
100,000+

Vulnerability:
Broken Access Control

Patched in Version:
3.9.8

Severity Score:
High


The vulnerability has been patched, so you should update to version 3.9.8.

Booking for Appointments and Events Calendar � Amelia

Plugin Slug:
ameliabooking

Installations
90,000+

Vulnerability:
Insecure Direct Object References (IDOR)

Patched in Version:
2.2

Severity Score:
High


The vulnerability has been patched, so you should update to version 2.2.

Download Monitor

Plugin Slug:
download-monitor

Installations
90,000+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
5.1.11

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 5.1.11.

Strong Testimonials

Plugin Slug:
strong-testimonials

Installations
90,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
3.2.22

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 3.2.22.

Customer Reviews for WooCommerce

Plugin Slug:
customer-reviews-woocommerce

Installations
80,000+

Vulnerability:
Broken Authentication

Patched in Version:
5.104.0

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 5.104.0.

Jupiter X Core

Plugin Slug:
jupiterx-core

Installations
80,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
4.14.2

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 4.14.2.

List category posts

Plugin Slug:
list-category-posts

Installations
80,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
0.95.0

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 0.95.0.

Advanced Contact form 7 DB

Plugin Slug:
advanced-cf7-db

Installations
70,000+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
2.1.0

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.1.0.

Advanced Contact form 7 DB

Plugin Slug:
advanced-cf7-db

Installations
70,000+

Vulnerability:
Broken Access Control

Patched in Version:
2.1.0

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.1.0.

Online Scheduling and Appointment Booking System � Bookly

Plugin Slug:
bookly-responsive-appointment-booking-tool

Installations
70,000+

Vulnerability:
Content Injection

Patched in Version:
27.1

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 27.1.

Greenshift � animation and page builder blocks

Plugin Slug:
greenshift-animation-and-page-builder-blocks

Installations
70,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
12.9.0

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 12.9.0.

Media Library Assistant

Plugin Slug:
media-library-assistant

Installations
70,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
3.35

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 3.35.

Media Library Assistant

Plugin Slug:
media-library-assistant

Installations
70,000+

Vulnerability:
SQL Injection

Patched in Version:
3.35

Severity Score:
High


The vulnerability has been patched, so you should update to version 3.35.

User Registration & Membership � Free & Paid Memberships, Subscriptions, Content Restriction, User Profile, Custom User Registration & Login Builder

Plugin Slug:
user-registration

Installations
60,000+

Vulnerability:
Open Redirection

Patched in Version:
5.1.5

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 5.1.5.

User Registration & Membership � Free & Paid Memberships, Subscriptions, Content Restriction, User Profile, Custom User Registration & Login Builder

Plugin Slug:
user-registration

Installations
60,000+

Vulnerability:
SQL Injection

Patched in Version:
5.1.3

Severity Score:
High


The vulnerability has been patched, so you should update to version 5.1.3.

Product Filter for WooCommerce by WBW

Plugin Slug:
woo-product-filter

Installations
60,000+

Vulnerability:
SQL Injection

Patched in Version:
3.1.3

Severity Score:
Critical


The vulnerability has been patched, so you should update to version 3.1.3.

Blog2Social: Social Media Auto Post & Scheduler

Plugin Slug:
blog2social

Installations
50,000+

Vulnerability:
Broken Authentication

Patched in Version:
8.8.4

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 8.8.4.
Plugin Slug:
robo-gallery

Installations
40,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
5.1.4

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 5.1.4.

LightPress Lightbox

Plugin Slug:
wp-jquery-lightbox

Installations
40,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.3.5

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.3.5.
Plugin Slug:
link-whisper

Installations
30,000+

Vulnerability:
Settings Change

Patched in Version:
0.9.1

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 0.9.1.

PowerPress Podcasting plugin by Blubrry

Plugin Slug:
powerpress

Installations
30,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
11.15.16

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 11.15.16.

Ultimate FAQ Accordion Plugin

Plugin Slug:
ultimate-faqs

Installations
30,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.4.8

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.4.8.

Visitor Traffic Real Time Statistics

Plugin Slug:
visitors-traffic-real-time-statistics

Installations
30,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
8.5

Severity Score:
High


The vulnerability has been patched, so you should update to version 8.5.
Plugin Slug:
addfunc-head-footer-code

Installations
20,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.4

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.4.

WP Visitor Statistics (Real Time Traffic)

Plugin Slug:
wp-stats-manager

Installations
20,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
8.5

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 8.5.

wpForo Forum

Plugin Slug:
wpforo

Installations
20,000+

Vulnerability:
Arbitrary File Deletion

Patched in Version:
3.0.3

Severity Score:
High


The vulnerability has been patched, so you should update to version 3.0.3.

wpForo Forum

Plugin Slug:
wpforo

Installations
20,000+

Vulnerability:
Arbitrary File Deletion

Patched in Version:
2.4.17

Severity Score:
High


The vulnerability has been patched, so you should update to version 2.4.17.

Easy Appointments

Plugin Slug:
easy-appointments

Installations
10,000+

Vulnerability:
Broken Access Control

Patched in Version:
3.12.22

Severity Score:
High


The vulnerability has been patched, so you should update to version 3.12.22.

OSM � OpenStreetMap

Plugin Slug:
osm

Installations
10,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
6.1.16

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 6.1.16.

Widgets for Social Photo Feed

Plugin Slug:
social-photo-feed-widget

Installations
10,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.8.0

Severity Score:
High


The vulnerability has been patched, so you should update to version 1.8.0.

Under Construction, Coming Soon & Maintenance Mode

Plugin Slug:
under-construction-maintenance-mode

Installations
10,000+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
2.1.2

Severity Score:
High


The vulnerability has been patched, so you should update to version 2.1.2.

Product Table and List Builder for WooCommerce Lite

Plugin Slug:
wc-product-table-lite

Installations
10,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
4.6.4

Severity Score:
High


The vulnerability has been patched, so you should update to version 4.6.4.

WP Photo Album Plus

Plugin Slug:
wp-photo-album-plus

Installations
10,000+

Vulnerability:
SQL Injection

Patched in Version:
9.1.08.002

Severity Score:
Critical


The vulnerability has been patched, so you should update to version 9.1.08.002.

YML for Yandex Market

Plugin Slug:
yml-for-yandex-market

Installations
10,000+

Vulnerability:
Remote Code Execution (RCE)

Patched in Version:
5.0.26

Severity Score:
High


The vulnerability has been patched, so you should update to version 5.0.26.

WCAPF � Ajax Product Filter for WooCommerce

Plugin Slug:
wc-ajax-product-filter

Installations
9,000+

Vulnerability:
SQL Injection

Patched in Version:
4.3.0

Severity Score:
Critical


The vulnerability has been patched, so you should update to version 4.3.0.

ActivityPub

Plugin Slug:
activitypub

Installations
6,000+

Vulnerability:
Sensitive Data Exposure

Patched in Version:
8.0.2

Severity Score:
High


The vulnerability has been patched, so you should update to version 8.0.2.

Booking Activities

Plugin Slug:
booking-activities

Installations
4,000+

Vulnerability:
Broken Access Control

Patched in Version:
1.17.0

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.17.0.

AWP Classifieds

Plugin Slug:
another-wordpress-classifieds-plugin

Installations
3,000+

Vulnerability:
Broken Access Control

Patched in Version:
4.4.5

Severity Score:
High


The vulnerability has been patched, so you should update to version 4.4.5.

SpeakOut! Email Petitions

Plugin Slug:
speakout

Installations
3,000+

Vulnerability:
SQL Injection

Patched in Version:
4.6.5.1

Severity Score:
Critical


The vulnerability has been patched, so you should update to version 4.6.5.1.

WP Directory Kit

Plugin Slug:
wpdirectorykit

Installations
3,000+

Vulnerability:
SQL Injection

Patched in Version:
1.5.1

Severity Score:
Critical


The vulnerability has been patched, so you should update to version 1.5.1.

WP Directory Kit

Plugin Slug:
wpdirectorykit

Installations
3,000+

Vulnerability:
Broken Access Control

Patched in Version:
1.5.1

Severity Score:
High


The vulnerability has been patched, so you should update to version 1.5.1.

Extensions for Leaflet Map

Plugin Slug:
extensions-leaflet-map

Installations
2,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
4.15

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 4.15.

Timetics � Appointment Booking & Scheduling

Plugin Slug:
timetics

Installations
2,000+

Vulnerability:
Broken Access Control

Patched in Version:
1.0.54

Severity Score:
High


The vulnerability has been patched, so you should update to version 1.0.54.

Event Tickets Manager for WooCommerce

Plugin Slug:
event-tickets-manager-for-woocommerce

Installations
1,000+

Vulnerability:
Broken Access Control

Patched in Version:
1.5.4

Severity Score:
High


The vulnerability has been patched, so you should update to version 1.5.4.

iControlWP

Plugin Slug:
worpit-admin-dashboard-plugin

Installations
1,000+

Vulnerability:
Privilege Escalation

Patched in Version:
5.5.4

Severity Score:
Critical


The vulnerability has been patched, so you should update to version 5.5.4.

SQL Chart Builder

Plugin Slug:
sql-chart-builder

Installations
600+

Vulnerability:
SQL Injection

Patched in Version:
2.3.8

Severity Score:
Critical


The vulnerability has been patched, so you should update to version 2.3.8.

Webling

Plugin:

Webling

Plugin Slug:
webling

Installations
500+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
3.9.1

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 3.9.1.

Datalogics Ecommerce Delivery � Datalogics

Plugin Slug:
datalogics

Installations
400+

Vulnerability:
Privilege Escalation

Patched in Version:
2.6.63

Severity Score:
Critical


The vulnerability has been patched, so you should update to version 2.6.63.

Post Blocks & Tools

Plugin Slug:
bnm-blocks

Installations
300+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.3.1

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.3.1.

TableOn � WordPress Posts Table Filterable�

Plugin Slug:
posts-table-filterable

Installations
300+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.0.5

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.0.5.

WP BASE Booking of Appointments, Services and Events

Plugin Slug:
wp-base-booking-of-appointments-services-and-events

Installations
200+

Vulnerability:
Privilege Escalation

Patched in Version:
6.0.0

Severity Score:
High


The vulnerability has been patched, so you should update to version 6.0.0.

Text to Speech � TTSWP

Plugin Slug:
text-to-speech-tts

Installations
100+

Vulnerability:
Bypass Vulnerability

Patched in Version:
1.9.9

Severity Score:
High


The vulnerability has been patched, so you should update to version 1.9.9.

LTL Freight Quotes � Worldwide Express Edition

Plugin Slug:
ltl-freight-quotes-worldwide-express-edition

Installations
90+

Vulnerability:
Broken Access Control

Patched in Version:
5.2.2

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 5.2.2.

Ziggeo

Plugin:

Ziggeo

Plugin Slug:
ziggeo

Installations
80+

Vulnerability:
Broken Access Control

Patched in Version:
3.1.2

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 3.1.2.

BuddyPress Groupblog

Plugin Slug:
bp-groupblog

Installations
50+

Vulnerability:
Privilege Escalation

Patched in Version:
1.9.4

Severity Score:
High


The vulnerability has been patched, so you should update to version 1.9.4.

Advanced Members for ACF

Plugin Slug:
advanced-members

Installations
30+

Vulnerability:
Arbitrary File Deletion

Patched in Version:
1.2.6

Severity Score:
High


The vulnerability has been patched, so you should update to version 1.2.6.

PrivateContent Free

Plugin Slug:
privatecontent-free

Installations
20+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.3.0

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.3.0.

ProSolution WP Client

Plugin Slug:
prosolution-wp-client

Installations
20+

Vulnerability:
Arbitrary File Upload

Patched in Version:
2.0.0

Severity Score:
Critical


The vulnerability has been patched, so you should update to version 2.0.0.

Experto Dashboard for WooCommerce

Plugin Slug:
experto-custom-dashboard

Installations
10+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.0.5

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.0.5.

Investi

Plugin:

Investi

Plugin Slug:
investi

Installations
10+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.0.27

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.0.27.

LTL Freight Quotes � R+L Carriers Edition

Plugin Slug:
ltl-freight-quotes-rl-edition

Installations
10+

Vulnerability:
Broken Access Control

Patched in Version:
3.3.14

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 3.3.14.

Magic Conversation For Gravity Forms

Plugin Slug:
magic-conversation-for-gravity-forms

Installations
10+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
3.0.98

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 3.0.98.

Surbma | Booking.com Shortcode

Plugin Slug:
surbma-bookingcom-shortcode

Installations
10+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.1.1

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.1.1.

WholeSale Products Dynamic Pricing Management WooCommerce

Plugin Slug:
wholesale-products-dynamic-pricing-management-woocommerce

Installations
10+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.3.0

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.3.0.

WPAMS

Plugin:

WPAMS

Plugin Slug:
apartment-management

Vulnerability:
Arbitrary Content Deletion

Patched in Version:
49.5.3

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 49.5.3.

Blocksy Companion Pro

Plugin:

Blocksy Companion Pro

Plugin Slug:
blocksy-companion-pro

Vulnerability:
SQL Injection

Patched in Version:
2.1.29

Severity Score:
Critical


The vulnerability has been patched, so you should update to version 2.1.29.

Bricksforge

Plugin:

Bricksforge

Plugin Slug:
bricksforge

Vulnerability:
Sensitive Data Exposure

Patched in Version:
3.1.8.5

Severity Score:
High


The vulnerability has been patched, so you should update to version 3.1.8.5.

Gravity Forms

Plugin:

Gravity Forms

Plugin Slug:
gravityforms

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.9.31

Severity Score:
High


The vulnerability has been patched, so you should update to version 2.9.31.

Gravity Forms

Plugin:

Gravity Forms

Plugin Slug:
gravityforms

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.9.31

Severity Score:
High


The vulnerability has been patched, so you should update to version 2.9.31.

Gravity SMTP

Plugin:

Gravity SMTP

Plugin Slug:
gravitysmtp

Vulnerability:
Broken Access Control

Patched in Version:
2.1.5

Severity Score:
High


The vulnerability has been patched, so you should update to version 2.1.5.

Integrio Core

Plugin:

Integrio Core

Plugin Slug:
integrio-core

Vulnerability:
Local File Inclusion

Patched in Version:
1.2.8

Severity Score:
High


The vulnerability has been patched, so you should update to version 1.2.8.

Listeo Core

Plugin:

Listeo Core

Plugin Slug:
listeo-core

Vulnerability:
Arbitrary File Upload

Patched in Version:
2.0.28

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.0.28.

Mikado Core

Plugin:

Mikado Core

Plugin Slug:
mikado-core

Vulnerability:
Local File Inclusion

Patched in Version:
1.7.2

Severity Score:
High


The vulnerability has been patched, so you should update to version 1.7.2.

Smart Slider 3 PRO

Plugin:

Smart Slider 3 PRO

Plugin Slug:
nextend-smart-slider3-pro

Vulnerability:
Backdoor

Patched in Version:
3.5.1.36

Severity Score:
Critical


The vulnerability has been patched, so you should update to version 3.5.1.36.

Ninja Forms File Uploads Extension

Plugin:

Ninja Forms File Uploads Extension

Plugin Slug:
ninja-forms-uploads

Vulnerability:
Arbitrary File Upload

Patched in Version:
3.3.27

Severity Score:
Critical


The vulnerability has been patched, so you should update to version 3.3.27.

pdfl.io

Plugin:

pdfl.io

Plugin Slug:
pdfl-io

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.0.6

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.0.6.

Perfmatters

Plugin:

Perfmatters

Plugin Slug:
perfmatters

Vulnerability:
Directory Traversal

Patched in Version:
2.6.0

Severity Score:
High


The vulnerability has been patched, so you should update to version 2.6.0.

Quick Playground

Plugin Slug:
quick-playground

Vulnerability:
Arbitrary File Upload

Patched in Version:
1.3.2

Severity Score:
Critical


The vulnerability has been patched, so you should update to version 1.3.2.

Softlab Core

Plugin:

Softlab Core

Plugin Slug:
softlab-core

Vulnerability:
Local File Inclusion

Patched in Version:
1.2.11

Severity Score:
High


The vulnerability has been patched, so you should update to version 1.2.11.

Solene Core

Plugin:

Solene Core

Plugin Slug:
solene-core

Vulnerability:
Local File Inclusion

Patched in Version:
2.3.4

Severity Score:
High


The vulnerability has been patched, so you should update to version 2.3.4.

Thegov Core

Plugin:

Thegov Core

Plugin Slug:
thegov-core

Vulnerability:
Local File Inclusion

Patched in Version:
2.0.23

Severity Score:
High


The vulnerability has been patched, so you should update to version 2.0.23.

Users manager � PN

Plugin Slug:
userspn

Vulnerability:
Privilege Escalation

Patched in Version:
1.1.20

Severity Score:
Critical


The vulnerability has been patched, so you should update to version 1.1.20.

MultiLoca

Plugin:

MultiLoca

Plugin Slug:
woocommerce-multi-locations-inventory-management

Vulnerability:
Privilege Escalation

Patched in Version:
4.2.16

Severity Score:
High


The vulnerability has been patched, so you should update to version 4.2.16.

WordPress Themes � 24 Patched / 0 Unpatched

Alloggio – Hotel Booking

Theme:

Alloggio – Hotel Booking

Theme Slug:
alloggio

Vulnerability:
PHP Object Injection

Patched in Version:
2.1.3

Severity Score:
High


The vulnerability has been patched, so you should update to version 2.1.3.

Aperitif

Theme:

Aperitif

Theme Slug:
aperitif

Vulnerability:
PHP Object Injection

Patched in Version:
1.6.1

Severity Score:
High


The vulnerability has been patched, so you should update to version 1.6.1.

Aperitif

Theme:

Aperitif

Theme Slug:
aperitif

Vulnerability:
Local File Inclusion

Patched in Version:
1.6

Severity Score:
High


The vulnerability has been patched, so you should update to version 1.6.

Askka

Theme:

Askka

Theme Slug:
askka

Vulnerability:
PHP Object Injection

Patched in Version:
1.4

Severity Score:
High


The vulnerability has been patched, so you should update to version 1.4.

Blueprint

Theme:

Blueprint

Theme Slug:
blueprint

Vulnerability:
Local File Inclusion

Patched in Version:
1.1.5

Severity Score:
High


The vulnerability has been patched, so you should update to version 1.1.5.

Fidalgo

Theme:

Fidalgo

Theme Slug:
fidalgo

Vulnerability:
PHP Object Injection

Patched in Version:
1.3

Severity Score:
High


The vulnerability has been patched, so you should update to version 1.3.

Getaway

Theme:

Getaway

Theme Slug:
getaway

Vulnerability:
Local File Inclusion

Patched in Version:
1.8

Severity Score:
High


The vulnerability has been patched, so you should update to version 1.8.

Hiroshi

Theme:

Hiroshi

Theme Slug:
hiroshi

Vulnerability:
PHP Object Injection

Patched in Version:
1.6

Severity Score:
High


The vulnerability has been patched, so you should update to version 1.6.

Konsept

Theme:

Konsept

Theme Slug:
konsept

Vulnerability:
PHP Object Injection

Patched in Version:
2.0

Severity Score:
High


The vulnerability has been patched, so you should update to version 2.0.

Malm�

Theme:

Malm�

Theme Slug:
malmo

Vulnerability:
Local File Inclusion

Patched in Version:
2.3

Severity Score:
High


The vulnerability has been patched, so you should update to version 2.3.

Micdrop

Theme:

Micdrop

Theme Slug:
micdrop

Vulnerability:
PHP Object Injection

Patched in Version:
1.4

Severity Score:
High


The vulnerability has been patched, so you should update to version 1.4.

Mildhill

Theme:

Mildhill

Theme Slug:
mildhill

Vulnerability:
PHP Object Injection

Patched in Version:
1.6

Severity Score:
High


The vulnerability has been patched, so you should update to version 1.6.

Mr. SEO

Theme:

Mr. SEO

Theme Slug:
mrseo

Vulnerability:
Local File Inclusion

Patched in Version:
2.1

Severity Score:
High


The vulnerability has been patched, so you should update to version 2.1.

NeoBeat

Theme:

NeoBeat

Theme Slug:
neobeat

Vulnerability:
PHP Object Injection

Patched in Version:
1.8

Severity Score:
High


The vulnerability has been patched, so you should update to version 1.8.

Playroom

Theme:

Playroom

Theme Slug:
playroom

Vulnerability:
PHP Object Injection

Patched in Version:
1.5

Severity Score:
High


The vulnerability has been patched, so you should update to version 1.5.

Sant�

Theme:

Sant�

Theme Slug:
sante

Vulnerability:
PHP Object Injection

Patched in Version:
1.6

Severity Score:
High


The vulnerability has been patched, so you should update to version 1.6.

SingleMalt

Theme:

SingleMalt

Theme Slug:
singlemalt

Vulnerability:
PHP Object Injection

Patched in Version:
1.6

Severity Score:
High


The vulnerability has been patched, so you should update to version 1.6.

Solene

Theme:

Solene

Theme Slug:
solene

Vulnerability:
Local File Inclusion

Patched in Version:
3.4.1

Severity Score:
High


The vulnerability has been patched, so you should update to version 3.4.1.

T�bel

Theme:

T�bel

Theme Slug:
tobel

Vulnerability:
PHP Object Injection

Patched in Version:
1.9

Severity Score:
High


The vulnerability has been patched, so you should update to version 1.9.

Uppercase

Theme:

Uppercase

Theme Slug:
uppercase

Vulnerability:
Local File Inclusion

Patched in Version:
1.2.2

Severity Score:
High


The vulnerability has been patched, so you should update to version 1.2.2.

Valiance

Theme:

Valiance

Theme Slug:
valiance

Vulnerability:
PHP Object Injection

Patched in Version:
1.3

Severity Score:
High


The vulnerability has been patched, so you should update to version 1.3.

WaveRide

Theme:

WaveRide

Theme Slug:
waveride

Vulnerability:
Local File Inclusion

Patched in Version:
1.5

Severity Score:
High


The vulnerability has been patched, so you should update to version 1.5.

Hitek

Theme:

Hitek

Theme Slug:
xts-hitek

Vulnerability:
Local File Inclusion

Patched in Version:
1.8.3

Severity Score:
High


The vulnerability has been patched, so you should update to version 1.8.3.

Zermatt

Theme:

Zermatt

Theme Slug:
zermatt

Vulnerability:
PHP Object Injection

Patched in Version:
1.7

Severity Score:
High


The vulnerability has been patched, so you should update to version 1.7.

Related articles

Wait! Get exclusive hosting insights

Subscribe to our newsletter and stay ahead of the competition with expert advice from our hosting pros.

Loading form…