WordPress Vulnerability Report � April 1, 2026

In this report, 225 vulnerabilities have been publicly disclosed. Security patches for 134 of these plugins and themes are now available. Please run these updates as soon as possible. If you’re a Solid Security Pro user, the version management tool may have already warned you and updated these plugins, depending on your settings.

Currently, 91 plugin and theme vulnerabilities remain unpatched. If you’re a Solid Security Pro user, those vulnerabilities are already protected by the Solid Security firewall. Virtual patches from Patchstack will be applied when a vulnerability is considered high or medium risk. If no patch is forthcoming from the vendor or the vulnerable software has been marked “closed” and dropped from the official WordPress repositories, you should deactivate it soon and look for alternative solutions.

WordPress Core

WordPress 6.9.4 is available, addressing 10 security issues and a template loading bug. Immediate updates are recommended for all production sites.

WordPress 7.0 Release Candidate 2 (RC2) is now ready for testing via the Beta Tester plugin, direct download, WP-CLI, or WordPress Playground. As a pre-release version, it should only be evaluated in staging or local environments.

WordPress 7.0 is scheduled for release on April 9, 2026.

WordPress Plugins � 113 Patched / 90 Unpatched

WPCargo Track & Trace

Plugin Slug:
wpcargo

Installations
10,000+

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.
Plugin Slug:
mimetypes-link-icons

Installations
8,000+

Vulnerability:
Server Side Request Forgery (SSRF)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Coinbase Commerce � Crypto Gateway for WooCommerce

Plugin Slug:
commerce-coinbase-for-woocommerce

Installations
1,000+

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

SurveyJS: Drag & Drop Form Builder

Plugin Slug:
surveyjs

Installations
500+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

File Uploader for WooCommerce

Plugin Slug:
file-uploader-for-woocommerce

Installations
100+

Vulnerability:
Path Traversal

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Any Post Slider

Plugin Slug:
any-post-slider

Installations
60+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

FuseDesk

Plugin:

FuseDesk

Plugin Slug:
fusedesk

Installations
60+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

WPFAQBlock� FAQ & Accordion Plugin For Gutenberg

Plugin Slug:
wpfaqblock

Installations
10+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Ad Short

Plugin:

Ad Short

Plugin Slug:
ad-short

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Add Google Social Profiles to Knowledge Graph Box

Plugin:

Add Google Social Profiles to Knowledge Graph Box

Plugin Slug:
add-google-social-profiles-to-knowledge-graph-box

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Alfie

Plugin:

Alfie

Plugin Slug:
alfie-the-productfeedtool-wp-plugin

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

App Builder

Plugin:

App Builder

Plugin Slug:
app-builder

Vulnerability:
Privilege Escalation

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Reward Video Ad for WordPress

Plugin:

Reward Video Ad for WordPress

Plugin Slug:
applixir

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Appmax

Plugin:

Appmax

Plugin Slug:
appmax

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

ARForms Form Builder

Plugin:

ARForms Form Builder

Plugin Slug:
arforms-form-builder

Vulnerability:
Content Injection

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Build App Online

Plugin:

Build App Online

Plugin Slug:
build-app-online

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Canto

Plugin:

Canto

Plugin Slug:
canto

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

CMS Commander

Plugin:

CMS Commander

Plugin Slug:
cms-commander-client

Vulnerability:
SQL Injection

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Comment Genius

Plugin:

Comment Genius

Plugin Slug:
comment-genius

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Comment SPAM Wiper

Plugin:

Comment SPAM Wiper

Plugin Slug:
comment-spam-wiper

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Company Posts for LinkedIn

Plugin:

Company Posts for LinkedIn

Plugin Slug:
company-posts-for-linkedin

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Content Syndication Toolkit

Plugin:

Content Syndication Toolkit

Plugin Slug:
content-syndication-toolkit

Vulnerability:
Server Side Request Forgery (SSRF)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

e-shot

Plugin:

e-shot

Plugin Slug:
e-shot-form-builder

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.
Plugin:

Easy Image Gallery

Plugin Slug:
easy-image-gallery

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Ecover Builder For Dummies

Plugin:

Ecover Builder For Dummies

Plugin Slug:
ecover-builder-for-dummies

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Ed’s Font Awesome

Plugin:

Ed’s Font Awesome

Plugin Slug:
eds-font-awesome

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Ed’s Social Share

Plugin:

Ed’s Social Share

Plugin Slug:
eds-social-share

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

ElementCamp

Plugin:

ElementCamp

Plugin Slug:
element-camp

Vulnerability:
SQL Injection

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Expire Users

Plugin:

Expire Users

Plugin Slug:
expire-users

Vulnerability:
Privilege Escalation

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Fonts Manager | Custom Fonts

Plugin:

Fonts Manager | Custom Fonts

Plugin Slug:
fonts-manager-custom-fonts

Vulnerability:
SQL Injection

Patched in Version:
No Fix

Severity Score:
Critical


The vulnerability has not been patched. You should deactivate the plugin.

fyyd podcast shortcodes

Plugin:

fyyd podcast shortcodes

Plugin Slug:
fyyd-podcast-shortcodes

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Go Night Pro

Plugin:

Go Night Pro

Plugin Slug:
go-night-pro

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Hr Press Lite

Plugin:

Hr Press Lite

Plugin Slug:
hr-press-lite

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Integration with Hubspot Forms

Plugin:

Integration with Hubspot Forms

Plugin Slug:
integration-with-hubspot-forms

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Invelity Product Feeds

Plugin:

Invelity Product Feeds

Plugin Slug:
invelity-products-feeds

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

itsukaita

Plugin:

itsukaita

Plugin Slug:
itsukaita

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

iVysilani Shortcode

Plugin:

iVysilani Shortcode

Plugin Slug:
ivysilani-shortcode

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Linksy Search and Replace

Plugin:

Linksy Search and Replace

Plugin Slug:
linksy-search-and-replace

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Lobot Slider Administrator

Plugin:

Lobot Slider Administrator

Plugin Slug:
lobot-slider-administrator

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

login_register

Plugin:

login_register

Plugin Slug:
login-register

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Mandatory Field

Plugin:

Mandatory Field

Plugin Slug:
mandatory-fields

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.
Plugin:

MinhNhut Link Gateway

Plugin Slug:
minhnhut-link-gateway

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Multi Functional Flexi Lightbox

Plugin:

Multi Functional Flexi Lightbox

Plugin Slug:
multi-functional-flexi-lightbox

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Multi Post Carousel by Category

Plugin:

Multi Post Carousel by Category

Plugin Slug:
multi-post-carousel

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

myLinksDump

Plugin:

myLinksDump

Plugin Slug:
mylinksdump

Vulnerability:
SQL Injection

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Neos Connector for Fakturama

Plugin:

Neos Connector for Fakturama

Plugin Slug:
neos-connector-for-fakturama

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Outgrow

Plugin:

Outgrow

Plugin Slug:
outgrow

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Paypal Shortcodes

Plugin:

Paypal Shortcodes

Plugin Slug:
paypal-shortcodes

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

PQ Addons � Creative Elementor Widgets

Plugin:

PQ Addons � Creative Elementor Widgets

Plugin Slug:
peacefulqode-elementzplus-widgets

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Performance Monitor

Plugin:

Performance Monitor

Plugin Slug:
performance-monitor

Vulnerability:
Server Side Request Forgery (SSRF)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Post Flagger

Plugin:

Post Flagger

Plugin Slug:
post-flagger

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Post Snippits

Plugin:

Post Snippits

Plugin Slug:
post-snippits

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Post Affiliate Pro

Plugin:

Post Affiliate Pro

Plugin Slug:
postaffiliatepro

Vulnerability:
Server Side Request Forgery (SSRF)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Pre* Party Resource Hints

Plugin:

Pre* Party Resource Hints

Plugin Slug:
pre-party-browser-hints

Vulnerability:
SQL Injection

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Punnel � Landing Page Builder

Plugin:

Punnel � Landing Page Builder

Plugin Slug:
punnel-landing-page-builder

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Quentn WP

Plugin:

Quentn WP

Plugin Slug:
quentn-wp

Vulnerability:
SQL Injection

Patched in Version:
No Fix

Severity Score:
Critical


The vulnerability has not been patched. You should deactivate the plugin.

Redirect countdown

Plugin:

Redirect countdown

Plugin Slug:
redirect-countdown

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

REST API TO MiniProgram

Plugin:

REST API TO MiniProgram

Plugin Slug:
rest-api-to-miniprogram

Vulnerability:
Insecure Direct Object References (IDOR)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Review Map by RevuKangaroo

Plugin:

Review Map by RevuKangaroo

Plugin Slug:
review-map-by-revukangaroo

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

rexCrawler

Plugin:

rexCrawler

Plugin Slug:
rexcrawler

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.
Plugin:

Ricerca � advanced search

Plugin Slug:
ricerca-smart-search

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Schema Shortcode

Plugin:

Schema Shortcode

Plugin Slug:
schema-shortcode

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Sheets2Table

Plugin:

Sheets2Table

Plugin Slug:
sheets2table

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Sherk Custom Post Type Displays

Plugin:

Sherk Custom Post Type Displays

Plugin Slug:
sherk-custom-post-type-displays

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Weaver Show Posts

Plugin:

Weaver Show Posts

Plugin Slug:
show-posts

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Show Posts list

Plugin:

Show Posts list

Plugin Slug:
show-posts-shortcodes

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Simple Football Scoreboard

Plugin:

Simple Football Scoreboard

Plugin Slug:
simple-football-score-board

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Smarter Analytics

Plugin:

Smarter Analytics

Plugin Slug:
smarter-analytics

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Speedup Optimization

Plugin:

Speedup Optimization

Plugin Slug:
speedup-optimization

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

SR WP Minify HTML

Plugin:

SR WP Minify HTML

Plugin Slug:
sr-wp-minify-html

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Survey

Plugin:

Survey

Plugin Slug:
survey

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Task Manager

Plugin:

Task Manager

Plugin Slug:
task-manager

Vulnerability:
Arbitrary File Download

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Task Manager

Plugin:

Task Manager

Plugin Slug:
task-manager

Vulnerability:
Content Injection

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Text Toggle

Plugin:

Text Toggle

Plugin Slug:
text-toggle

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Tour & Activity Operator Plugin for TourCMS

Plugin:

Tour & Activity Operator Plugin for TourCMS

Plugin Slug:
tour-operator-plugin

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Tutor LMS Pro

Plugin:

Tutor LMS Pro

Plugin Slug:
tutor-pro

Vulnerability:
Broken Authentication

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Twitter Feeds

Plugin:

Twitter Feeds

Plugin Slug:
twitter-feeds

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Shortcodes Blocks Creator Ultimate

Plugin:

Shortcodes Blocks Creator Ultimate

Plugin Slug:
ultimate-shortcodes-creator

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Shortcodes Blocks Creator Ultimate

Plugin:

Shortcodes Blocks Creator Ultimate

Plugin Slug:
ultimate-shortcodes-creator

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Vagaro Booking Widget

Plugin:

Vagaro Booking Widget

Plugin Slug:
vagaro-booking-widget

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Wikilookup

Plugin:

Wikilookup

Plugin Slug:
wikilookup

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

WordPress PayPal Donation

Plugin:

WordPress PayPal Donation

Plugin Slug:
wordpress-paypal-donation

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

WP Games Embed

Plugin:

WP Games Embed

Plugin Slug:
wp-games-embed

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

WP NG Weather

Plugin:

WP NG Weather

Plugin Slug:
wp-ng-weather

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

WP Posts Re-order

Plugin:

WP Posts Re-order

Plugin Slug:
wp-posts-re-order

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

WP Random Button

Plugin:

WP Random Button

Plugin Slug:
wp-random-button

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

WP-WebAuthn

Plugin:

WP-WebAuthn

Plugin Slug:
wp-webauthn

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

WPBookit Pro

Plugin:

WPBookit Pro

Plugin Slug:
wpbookit-pro

Vulnerability:
Arbitrary File Upload

Patched in Version:
No Fix

Severity Score:
Critical


The vulnerability has not been patched. You should deactivate the plugin.

WPBookit Pro

Plugin:

WPBookit Pro

Plugin Slug:
wpbookit-pro

Vulnerability:
Privilege Escalation

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Xhanch � My Advanced Settings

Plugin:

Xhanch � My Advanced Settings

Plugin Slug:
xhanch-my-advanced-settings

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.
Plugin Slug:
complianz-gdpr

Installations
1,000,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
7.4.5

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 7.4.5.

Smart Slider 3

Plugin Slug:
smart-slider-3

Installations
800,000+

Vulnerability:
Arbitrary File Download

Patched in Version:
3.5.1.34

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 3.5.1.34.

Download Monitor

Plugin Slug:
download-monitor

Installations
90,000+

Vulnerability:
Insecure Direct Object References (IDOR)

Patched in Version:
5.1.8

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 5.1.8.

JetFormBuilder � Dynamic Blocks Form Builder

Plugin Slug:
jetformbuilder

Installations
90,000+

Vulnerability:
Arbitrary File Download

Patched in Version:
3.5.6.3

Severity Score:
High


The vulnerability has been patched, so you should update to version 3.5.6.3.

JetFormBuilder � Dynamic Blocks Form Builder

Plugin Slug:
jetformbuilder

Installations
90,000+

Vulnerability:
Remote Code Execution (RCE)

Patched in Version:
3.5.6.2

Severity Score:
Critical


The vulnerability has been patched, so you should update to version 3.5.6.2.

Import and export users and customers

Plugin Slug:
import-users-from-csv-with-meta

Installations
80,000+

Vulnerability:
Privilege Escalation

Patched in Version:
2.0

Severity Score:
High


The vulnerability has been patched, so you should update to version 2.0.

Jupiter X Core

Plugin Slug:
jupiterx-core

Installations
80,000+

Vulnerability:
Broken Access Control

Patched in Version:
4.14.2

Severity Score:
High


The vulnerability has been patched, so you should update to version 4.14.2.

Conditional Menus

Plugin Slug:
conditional-menus

Installations
60,000+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
1.2.7

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.2.7.

User Registration & Membership � Free & Paid Memberships, Subscriptions, Content Restriction, User Profile, Custom User Registration & Login Builder

Plugin Slug:
user-registration

Installations
60,000+

Vulnerability:
Broken Access Control

Patched in Version:
5.1.5

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 5.1.5.

User Registration & Membership � Free & Paid Memberships, Subscriptions, Content Restriction, User Profile, Custom User Registration & Login Builder

Plugin Slug:
user-registration

Installations
60,000+

Vulnerability:
Privilege Escalation

Patched in Version:
5.1.3

Severity Score:
High


The vulnerability has been patched, so you should update to version 5.1.3.

Product Filter for WooCommerce by WBW

Plugin Slug:
woo-product-filter

Installations
60,000+

Vulnerability:
Broken Access Control

Patched in Version:
3.1.3

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 3.1.3.

Blog2Social: Social Media Auto Post & Scheduler

Plugin Slug:
blog2social

Installations
50,000+

Vulnerability:
Broken Access Control

Patched in Version:
8.8.3

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 8.8.3.

Sina Extension for Elementor

Plugin Slug:
sina-extension-for-elementor

Installations
50,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
3.7.1

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 3.7.1.

Smart Custom Fields

Plugin Slug:
smart-custom-fields

Installations
50,000+

Vulnerability:
Broken Access Control

Patched in Version:
5.0.7

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 5.0.7.
Plugin Slug:
simply-gallery-block

Installations
40,000+

Vulnerability:
Arbitrary Code Execution

Patched in Version:
3.3.2.1

Severity Score:
Critical


The vulnerability has been patched, so you should update to version 3.3.2.1.

Blackhole for Bad Bots

Plugin Slug:
blackhole-bad-bots

Installations
30,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
3.8.1

Severity Score:
High


The vulnerability has been patched, so you should update to version 3.8.1.

LeadConnector

Plugin Slug:
leadconnector

Installations
30,000+

Vulnerability:
Broken Access Control

Patched in Version:
3.0.22

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 3.0.22.

PPWP � Password Protect Pages

Plugin Slug:
password-protect-page

Installations
30,000+

Vulnerability:
Broken Access Control

Patched in Version:
1.9.16

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.9.16.

WPGraphQL

Plugin Slug:
wp-graphql

Installations
30,000+

Vulnerability:
Broken Access Control

Patched in Version:
2.10

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.10.

WP Lightbox 2

Plugin Slug:
wp-lightbox-2

Installations
30,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
3.0.7

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 3.0.7.

Ibtana � WordPress Website Builder

Plugin Slug:
ibtana-visual-editor

Installations
20,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.2.5.8

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.2.5.8.

Quads Ads Manager for Google AdSense

Plugin Slug:
quick-adsense-reloaded

Installations
20,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.0.99

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.0.99.

Frontend Admin by DynamiApps

Plugin Slug:
acf-frontend-form-element

Installations
10,000+

Vulnerability:
PHP Object Injection

Patched in Version:
3.28.32

Severity Score:
High


The vulnerability has been patched, so you should update to version 3.28.32.

Kali Forms � Contact Form & Drag-and-Drop Builder

Plugin Slug:
kali-forms

Installations
10,000+

Vulnerability:
Remote Code Execution (RCE)

Patched in Version:
2.4.10

Severity Score:
Critical


The vulnerability has been patched, so you should update to version 2.4.10.

Lead Form Builder & Contact Form

Plugin Slug:
lead-form-builder

Installations
10,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.0.2

Severity Score:
High


The vulnerability has been patched, so you should update to version 2.0.2.

WP DSGVO Tools (GDPR)

Plugin Slug:
shapepress-dsgvo

Installations
10,000+

Vulnerability:
Broken Access Control

Patched in Version:
3.1.39

Severity Score:
Critical


The vulnerability has been patched, so you should update to version 3.1.39.

Team � Team Members Showcase Plugin

Plugin Slug:
tlp-team

Installations
10,000+

Vulnerability:
Broken Access Control

Patched in Version:
5.0.12

Severity Score:
High


The vulnerability has been patched, so you should update to version 5.0.12.

WP REST Cache

Plugin Slug:
wp-rest-cache

Installations
10,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2026.1.1

Severity Score:
High


The vulnerability has been patched, so you should update to version 2026.1.1.

YML for Yandex Market

Plugin Slug:
yml-for-yandex-market

Installations
10,000+

Vulnerability:
Arbitrary File Deletion

Patched in Version:
5.3.0

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 5.3.0.

Contact Form Email

Plugin Slug:
contact-form-to-email

Installations
9,000+

Vulnerability:
Broken Access Control

Patched in Version:
1.3.64

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.3.64.

WP TripAdvisor Review Slider

Plugin Slug:
wp-tripadvisor-review-slider

Installations
8,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
14.2

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 14.2.

JS Help Desk � AI-Powered Support & Ticketing System

Plugin Slug:
js-support-ticket

Installations
7,000+

Vulnerability:
Insecure Direct Object References (IDOR)

Patched in Version:
3.0.4

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 3.0.4.

WP Review Slider

Plugin Slug:
wp-facebook-reviews

Installations
7,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
14.0

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 14.0.

PeproDev Ultimate Invoice

Plugin Slug:
pepro-ultimate-invoice

Installations
6,000+

Vulnerability:
Sensitive Data Exposure

Patched in Version:
2.2.6

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.2.6.

ProfileGrid � User Profiles, Groups and Communities

Plugin Slug:
profilegrid-user-profiles-groups-and-communities

Installations
6,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
5.9.8.2

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 5.9.8.2.

User Verification by PickPlugins

Plugin Slug:
user-verification

Installations
5,000+

Vulnerability:
Broken Authentication

Patched in Version:
2.0.46

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.0.46.

RSFirewall!

Plugin Slug:
rsfirewall

Installations
4,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.1.46

Severity Score:
High


The vulnerability has been patched, so you should update to version 1.1.46.
Plugin Slug:
wptelegram-widget

Installations
4,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.2.14

Severity Score:
High


The vulnerability has been patched, so you should update to version 2.2.14.

ElementInvader Addons for Elementor

Plugin Slug:
elementinvader-addons-for-elementor

Installations
3,000+

Vulnerability:
SQL Injection

Patched in Version:
1.4.3

Severity Score:
High


The vulnerability has been patched, so you should update to version 1.4.3.

KiviCare � Clinic & Patient Management System (EHR)

Plugin Slug:
kivicare-clinic-management-system

Installations
2,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
4.0.0

Severity Score:
High


The vulnerability has been patched, so you should update to version 4.0.0.

KiviCare � Clinic & Patient Management System (EHR)

Plugin Slug:
kivicare-clinic-management-system

Installations
2,000+

Vulnerability:
Broken Access Control

Patched in Version:
4.0.0

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 4.0.0.

Simple Download Counter

Plugin Slug:
simple-download-counter

Installations
2,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.3.1

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.3.1.

Injection Guard

Plugin Slug:
injection-guard

Installations
1,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.3.0

Severity Score:
High


The vulnerability has been patched, so you should update to version 1.3.0.

The Ultimate WordPress Toolkit � WP Extended

Plugin Slug:
wpextended

Installations
700+

Vulnerability:
Privilege Escalation

Patched in Version:
3.2.5

Severity Score:
High


The vulnerability has been patched, so you should update to version 3.2.5.

Truebooker � Appointment Booking and Scheduler System

Plugin Slug:
truebooker-appointment-booking

Installations
600+

Vulnerability:
Sensitive Data Exposure

Patched in Version:
1.1.5

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.1.5.

VikRestaurants Table Reservations and Take-Away

Plugin Slug:
vikrestaurants

Installations
600+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.5.3

Severity Score:
High


The vulnerability has been patched, so you should update to version 1.5.3.

Vertex Addons for Elementor

Plugin Slug:
addons-for-elementor-builder

Installations
400+

Vulnerability:
Broken Access Control

Patched in Version:
1.7.0

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.7.0.

FormLift for Infusionsoft Web Forms

Plugin Slug:
formlift

Installations
400+

Vulnerability:
Broken Access Control

Patched in Version:
7.5.22

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 7.5.22.

Helpdesk Support Ticket System for WooCommerce

Plugin Slug:
support-ticket-system-for-woocommerce

Installations
200+

Vulnerability:
Broken Access Control

Patched in Version:
2.1.3

Severity Score:
High


The vulnerability has been patched, so you should update to version 2.1.3.

Contact Manager

Plugin Slug:
contact-manager

Installations
100+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
9.1.1

Severity Score:
High


The vulnerability has been patched, so you should update to version 9.1.1.

DSGVO snippet for Leaflet Map and its Extensions

Plugin Slug:
dsgvo-leaflet-map

Installations
100+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
3.4

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 3.4.
Plugin Slug:
gallery-for-ultimate-member

Installations
100+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.1.2

Severity Score:
High


The vulnerability has been patched, so you should update to version 1.1.2.

Product File Upload for WooCommerce

Plugin Slug:
products-file-upload-for-woocommerce

Installations
100+

Vulnerability:
Arbitrary File Deletion

Patched in Version:
2.2.5

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.2.5.

Filestack WP Upload

Plugin Slug:
filestack-upload

Installations
60+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
3.0.0

Severity Score:
High


The vulnerability has been patched, so you should update to version 3.0.0.

Debugger & Troubleshooter

Plugin Slug:
debugger-troubleshooter

Installations
40+

Vulnerability:
Privilege Escalation

Patched in Version:
1.4.0

Severity Score:
Critical


The vulnerability has been patched, so you should update to version 1.4.0.

BWL Advanced FAQ Manager Lite

Plugin Slug:
bwl-advanced-faq-manager-lite

Installations
30+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.1.2

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.1.2.

WP Cost Estimation & Payment Forms Builder

Plugin:

WP Cost Estimation & Payment Forms Builder

Plugin Slug:
WP_Estimation_Form

Vulnerability:
Broken Access Control

Patched in Version:
10.3.0

Severity Score:
High


The vulnerability has been patched, so you should update to version 10.3.0.

Addon Jobsearch Chat

Plugin:

Addon Jobsearch Chat

Plugin Slug:
addon-jobsearch-chat

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
3.1

Severity Score:
High


The vulnerability has been patched, so you should update to version 3.1.

Addon Jobsearch Chat

Plugin:

Addon Jobsearch Chat

Plugin Slug:
addon-jobsearch-chat

Vulnerability:
SQL Injection

Patched in Version:
3.1

Severity Score:
Critical


The vulnerability has been patched, so you should update to version 3.1.

Gyan Elements

Plugin:

Gyan Elements

Plugin Slug:
gyan-elements

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.2.2

Severity Score:
High


The vulnerability has been patched, so you should update to version 2.2.2.

Ultimate Membership Pro

Plugin:

Ultimate Membership Pro

Plugin Slug:
indeed-membership-pro

Vulnerability:
Broken Authentication

Patched in Version:
13.7.1

Severity Score:
High


The vulnerability has been patched, so you should update to version 13.7.1.

JetEngine

Plugin:

JetEngine

Plugin Slug:
jet-engine

Vulnerability:
SQL Injection

Patched in Version:
3.8.6.2

Severity Score:
Critical


The vulnerability has been patched, so you should update to version 3.8.6.2.

NaturaLife Extensions

Plugin:

NaturaLife Extensions

Plugin Slug:
naturalife-extensions

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.2

Severity Score:
High


The vulnerability has been patched, so you should update to version 2.2.

NaturaLife Extensions

Plugin:

NaturaLife Extensions

Plugin Slug:
naturalife-extensions

Vulnerability:
Local File Inclusion

Patched in Version:
2.2

Severity Score:
High


The vulnerability has been patched, so you should update to version 2.2.

Salon Booking System Pro

Plugin:

Salon Booking System Pro

Plugin Slug:
salon-booking-plugin-pro

Vulnerability:
Broken Authentication

Patched in Version:
10.30.12

Severity Score:
High


The vulnerability has been patched, so you should update to version 10.30.12.

LearnDash LMS

Plugin:

LearnDash LMS

Plugin Slug:
sfwd-lms

Vulnerability:
SQL Injection

Patched in Version:
5.0.3.1

Severity Score:
High


The vulnerability has been patched, so you should update to version 5.0.3.1.

The Grid

Plugin:

The Grid

Plugin Slug:
the-grid

Vulnerability:
Broken Access Control

Patched in Version:
2.8.0

Severity Score:
High


The vulnerability has been patched, so you should update to version 2.8.0.

The Grid

Plugin:

The Grid

Plugin Slug:
the-grid

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.8.0

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.8.0.

ThemeREX Addons

Plugin:

ThemeREX Addons

Plugin Slug:
trx_addons

Vulnerability:
Arbitrary File Upload

Patched in Version:
2.38.5

Severity Score:
Critical


The vulnerability has been patched, so you should update to version 2.38.5.

Woocommerce Custom Product Addons Pro

Plugin:

Woocommerce Custom Product Addons Pro

Plugin Slug:
woo-custom-product-addons-pro

Vulnerability:
Remote Code Execution (RCE)

Patched in Version:
5.4.2

Severity Score:
Critical


The vulnerability has been patched, so you should update to version 5.4.2.

WP Configurator Pro

Plugin:

WP Configurator Pro

Plugin Slug:
wp-configurator-pro

Vulnerability:
Broken Access Control

Patched in Version:
3.8.0

Severity Score:
High


The vulnerability has been patched, so you should update to version 3.8.0.

JobSearch

Plugin:

JobSearch

Plugin Slug:
wp-jobsearch

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
3.2.2

Severity Score:
High


The vulnerability has been patched, so you should update to version 3.2.2.

WordPress Themes � 21 Patched / 1 Unpatched

Apicona

Theme:

Apicona

Theme Slug:
apicona

Vulnerability:
PHP Object Injection

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should switch themes.

Ona

Theme:

Ona

Theme Slug:
ona

Downloads
244,053

Vulnerability:
Arbitrary File Upload

Patched in Version:
1.24

Severity Score:
Critical


The vulnerability has been patched, so you should update to version 1.24.

Archicon

Theme:

Archicon

Theme Slug:
archicon

Vulnerability:
PHP Object Injection

Patched in Version:
1.7

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.7.

Borgholm

Theme:

Borgholm

Theme Slug:
borgholm-marketing-agency-theme

Vulnerability:
PHP Object Injection

Patched in Version:
1.6

Severity Score:
Critical


The vulnerability has been patched, so you should update to version 1.6.

Car Dealer

Theme:

Car Dealer

Theme Slug:
cardealer

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.6.8

Severity Score:
High


The vulnerability has been patched, so you should update to version 1.6.8.

Gaea

Theme:

Gaea

Theme Slug:
gaea

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
3.8

Severity Score:
High


The vulnerability has been patched, so you should update to version 3.8.

Goldish

Theme:

Goldish

Theme Slug:
goldish

Vulnerability:
PHP Object Injection

Patched in Version:
3.47

Severity Score:
Critical


The vulnerability has been patched, so you should update to version 3.47.

Golo

Theme:

Golo

Theme Slug:
golo

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.7.5

Severity Score:
High


The vulnerability has been patched, so you should update to version 1.7.5.

Gracey

Theme:

Gracey

Theme Slug:
gracey

Vulnerability:
PHP Object Injection

Patched in Version:
1.4

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.4.

Halstein

Theme:

Halstein

Theme Slug:
halstein

Vulnerability:
PHP Object Injection

Patched in Version:
1.8

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.8.

Kamperen

Theme:

Kamperen

Theme Slug:
kamperen

Vulnerability:
PHP Object Injection

Patched in Version:
1.3

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.3.

KIDZ

Theme:

KIDZ

Theme Slug:
kidz

Vulnerability:
PHP Object Injection

Patched in Version:
5.25

Severity Score:
Critical


The vulnerability has been patched, so you should update to version 5.25.

Boutique

Theme:

Boutique

Theme Slug:
kute-boutique

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.4.6

Severity Score:
High


The vulnerability has been patched, so you should update to version 2.4.6.

Leroux

Theme:

Leroux

Theme Slug:
leroux

Vulnerability:
PHP Object Injection

Patched in Version:
1.4

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.4.

Meloo

Theme:

Meloo

Theme Slug:
meloo

Vulnerability:
PHP Object Injection

Patched in Version:
2.8.2

Severity Score:
High


The vulnerability has been patched, so you should update to version 2.8.2.

Jobmonster

Theme:

Jobmonster

Theme Slug:
noo-jobmonster

Vulnerability:
SQL Injection

Patched in Version:
4.8.4

Severity Score:
Critical


The vulnerability has been patched, so you should update to version 4.8.4.

Ricky

Theme:

Ricky

Theme Slug:
ricky

Vulnerability:
PHP Object Injection

Patched in Version:
2.31

Severity Score:
Critical


The vulnerability has been patched, so you should update to version 2.31.

Sanzo

Theme:

Sanzo

Theme Slug:
sanzo

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.4.3

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.4.3.

St�l

Theme:

St�l

Theme Slug:
stal

Vulnerability:
PHP Object Injection

Patched in Version:
1.7

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.7.

Tasty Daily

Theme:

Tasty Daily

Theme Slug:
tastydaily

Vulnerability:
PHP Object Injection

Patched in Version:
1.27

Severity Score:
Critical


The vulnerability has been patched, so you should update to version 1.27.

Vayvo

Theme:

Vayvo

Theme Slug:
vayvo-progression

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
6.8

Severity Score:
High


The vulnerability has been patched, so you should update to version 6.8.

WoodMart

Theme:

WoodMart

Theme Slug:
woodmart

Vulnerability:
PHP Object Injection

Patched in Version:
8.3.9

Severity Score:
High


The vulnerability has been patched, so you should update to version 8.3.9.

Related articles

Wait! Get exclusive hosting insights

Subscribe to our newsletter and stay ahead of the competition with expert advice from our hosting pros.

Loading form…