Line illustration showing a black application window on a blue gradient background overlaid with a large exclamation point alert icon and three bugs.

WordPress Vulnerability Report � April 16, 2025

In this report, 374 vulnerabilities have been publicly disclosed. Security patches for 90 of these plugins and themes are available now, so run those updates as soon as possible. If you’re a Solid Security Pro user, the version management tool may have already warned you and updated these plugins, depending on your settings.

Additionally, there are 284 plugin and theme vulnerabilities, and no patch has been available yet. If you’re a Solid Security Pro user, those vulnerabilities are already protected by the Solid Security firewall. Virtual patches from Patchstack will be applied when a vulnerability is considered high or medium risk. If no patch is forthcoming from the vendor or the vulnerable software has been marked “closed” and dropped from the official WordPress repositories, you should deactivate it soon and look for alternative solutions.

WordPress Core

WordPress 6.8 “Cecil” is here! Launched April 15, 2025, it honors jazz legend Cecil Taylor, whose pioneering piano fused chaos and harmony. Explore its bold features with the same experimental spirit.

Plus, WordCamp Europe 2025 lands in Basel, Switzerland, June 5-7! Connect with WordPress enthusiasts, developers, and pros for three days of learning, networking, and collaboration with the global community.

WordPress Plugins � 87 Patched / 272 Unpatched

Ally � Web Accessibility & Usability

Plugin Slug:
pojo-accessibility

Installations
200,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

WP Table Builder � WordPress Table Plugin

Plugin Slug:
wp-table-builder

Installations
60,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

MapGeo � Interactive Geo Maps

Plugin Slug:
interactive-geo-maps

Installations
30,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

PowerPress Podcasting plugin by Blubrry

Plugin Slug:
powerpress

Installations
30,000+

Vulnerability:
Server Side Request Forgery (SSRF)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Asgaros Forum

Plugin Slug:
asgaros-forum

Installations
10,000+

Vulnerability:
Bypass Vulnerability

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Flo Forms � Easy Drag & Drop Form Builder

Plugin Slug:
flo-forms

Installations
10,000+

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Ray Enterprise Translation

Plugin Slug:
lingotek-translation

Installations
10,000+

Vulnerability:
Local File Inclusion

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Motors � Car Dealership & Classified Listings Plugin

Plugin Slug:
motors-car-dealership-classified-listings

Installations
10,000+

Vulnerability:
Local File Inclusion

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Arconix FAQ

Plugin Slug:
arconix-faq

Installations
8,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Ultimate Bootstrap Elements for Elementor

Plugin Slug:
ultimate-bootstrap-elements-for-elementor

Installations
7,000+

Vulnerability:
Local File Inclusion

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

EventON � Events Calendar

Plugin Slug:
eventon-lite

Installations
6,000+

Vulnerability:
Local File Inclusion

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Cool Flipbox � Shortcode & Gutenberg Block

Plugin Slug:
flip-boxes

Installations
6,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Specia Companion

Plugin Slug:
specia-companion

Installations
6,000+

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Survey Maker

Plugin Slug:
survey-maker

Installations
6,000+

Vulnerability:
Bypass Vulnerability

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

License For Envato

Plugin Slug:
license-envato

Installations
5,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Widgetize Pages Light

Plugin Slug:
widgetize-pages-light

Installations
4,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Piotnet Forms

Plugin Slug:
piotnetforms

Installations
3,000+

Vulnerability:
Path Traversal

Patched in Version:
No Fix

Severity Score:
Low


The vulnerability has not been patched. You should deactivate the plugin.

Simple Spoiler

Plugin Slug:
simple-spoiler

Installations
3,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Wallet System for WooCommerce

Plugin Slug:
wallet-system-for-woocommerce

Installations
3,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

WooCommerce � Payphone Gateway

Plugin Slug:
wc-payphone-gateway

Installations
3,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Insert or Embed Articulate Content into WordPress

Plugin Slug:
insert-or-embed-articulate-content-into-wordpress

Installations
2,000+

Vulnerability:
Arbitrary File Upload

Patched in Version:
No Fix

Severity Score:
Critical


The vulnerability has not been patched. You should deactivate the plugin.

Solace Extra

Plugin Slug:
solace-extra

Installations
2,000+

Vulnerability:
Arbitrary File Upload

Patched in Version:
No Fix

Severity Score:
Critical


The vulnerability has not been patched. You should deactivate the plugin.

RestroPress � Online Food Ordering System

Plugin Slug:
restropress

Installations
1,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Ultimate WP Mail

Plugin Slug:
ultimate-wp-mail

Installations
1,000+

Vulnerability:
Open Redirection

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

WordPress Webinar Plugin � WebinarPress

Plugin Slug:
wp-webinarsystem

Installations
1,000+

Vulnerability:
Open Redirection

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

WP-Hijri

Plugin:

WP-Hijri

Plugin Slug:
wp-hijri

Installations
900+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Database Toolset

Plugin Slug:
database-toolset

Installations
800+

Vulnerability:
Arbitrary File Deletion

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

FraudLabs Pro for WooCommerce

Plugin Slug:
fraudlabs-pro-for-woocommerce

Installations
800+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

JS Job Manager

Plugin Slug:
js-jobs

Installations
800+

Vulnerability:
Arbitrary File Upload

Patched in Version:
No Fix

Severity Score:
Critical


The vulnerability has not been patched. You should deactivate the plugin.

JS Job Manager

Plugin Slug:
js-jobs

Installations
800+

Vulnerability:
Local File Inclusion

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Mergado Pack

Plugin Slug:
mergado-marketing-pack

Installations
800+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Nepali Date Utilities

Plugin Slug:
nepali-date-utilities

Installations
800+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Waymark

Plugin:

Waymark

Plugin Slug:
waymark

Installations
800+

Vulnerability:
Server Side Request Forgery (SSRF)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Waymark

Plugin:

Waymark

Plugin Slug:
waymark

Installations
800+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Broadstreet

Plugin Slug:
broadstreet

Installations
700+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Doppler Forms

Plugin Slug:
doppler-form

Installations
700+

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Doppler Forms

Plugin Slug:
doppler-form

Installations
700+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

MapSVG � Vector maps, Image maps, Google Maps

Plugin Slug:
mapsvg-lite-interactive-vector-maps

Installations
700+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

MapSVG � Vector maps, Image maps, Google Maps

Plugin Slug:
mapsvg-lite-interactive-vector-maps

Installations
700+

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Movylo Marketing Automation

Plugin Slug:
movylo-widget

Installations
700+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Accessibility Suite by Ability, Inc

Plugin Slug:
online-accessibility

Installations
700+

Vulnerability:
SQL Injection

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Accessibility Suite by Ability, Inc

Plugin Slug:
online-accessibility

Installations
700+

Vulnerability:
Arbitrary File Upload

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Build App Online

Plugin Slug:
build-app-online

Installations
600+

Vulnerability:
Local File Inclusion

Patched in Version:
No Fix

Severity Score:
Critical


The vulnerability has not been patched. You should deactivate the plugin.

Question Answer

Plugin Slug:
question-answer

Installations
600+

Vulnerability:
PHP Object Injection

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Question Answer

Plugin Slug:
question-answer

Installations
600+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Request Call Back

Plugin Slug:
request-call-back

Installations
600+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Canonical Attachments

Plugin Slug:
canonical-attachments

Installations
500+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Interactive US Map

Plugin Slug:
interactive-us-map

Installations
500+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Job Board Manager

Plugin Slug:
job-board-manager

Installations
500+

Vulnerability:
PHP Object Injection

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Review Stream

Plugin Slug:
review-stream

Installations
500+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

RS Elements Elementor Addon

Plugin Slug:
rselements-lite

Installations
500+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

User Registration Using Contact Form 7

Plugin Slug:
user-registration-using-contact-form-7

Installations
500+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Wishlist

Plugin:

Wishlist

Plugin Slug:
wishlist

Installations
500+

Vulnerability:
SQL Injection

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

WP Show Stats

Plugin Slug:
wp-show-stats

Installations
500+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Anant Addons for Elementor

Plugin Slug:
anant-addons-for-elementor

Installations
400+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
Critical


The vulnerability has not been patched. You should deactivate the plugin.

Coming Soon Countdown

Plugin Slug:
coming-soon-countdown

Installations
400+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

DeBounce Email Validator

Plugin Slug:
debounce-io-email-validator

Installations
400+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Duplicate Title Checker

Plugin Slug:
duplicate-title-checker

Installations
400+

Vulnerability:
SQL Injection

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Epeken All Kurir Plugin for Woocommerce Full Version

Plugin Slug:
epeken-all-kurir

Installations
400+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Projectopia � WordPress Project Management

Plugin Slug:
projectopia-core

Installations
400+

Vulnerability:
Privilege Escalation

Patched in Version:
No Fix

Severity Score:
Critical


The vulnerability has not been patched. You should deactivate the plugin.

SERPed.net

Plugin Slug:
serped-net

Installations
400+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

WP AutoKeyword

Plugin Slug:
wp-autokeyword

Installations
400+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

WPSmartContracts

Plugin Slug:
wp-smart-contracts

Installations
400+

Vulnerability:
SQL Injection

Patched in Version:
No Fix

Severity Score:
Critical


The vulnerability has not been patched. You should deactivate the plugin.

WP w3all phpBB

Plugin Slug:
wp-w3all-phpbb-integration

Installations
400+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Custom Posts Order

Plugin Slug:
custom-posts-order

Installations
300+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Czater.pl � live chat i telefon

Plugin Slug:
czater

Installations
300+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Lock Your Updates Plugins/Themes Manager

Plugin Slug:
lock-your-updates

Installations
300+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

TableOn � WordPress Posts Table Filterable�

Plugin Slug:
posts-table-filterable

Installations
300+

Vulnerability:
PHP Object Injection

Patched in Version:
No Fix

Severity Score:
Critical


The vulnerability has not been patched. You should deactivate the plugin.

Print Science Designer

Plugin Slug:
print-science-designer

Installations
300+

Vulnerability:
Arbitrary File Download

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Silvasoft boekhouden

Plugin Slug:
silvasoft-boekhouden

Installations
300+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Task Scheduler

Plugin Slug:
task-scheduler

Installations
300+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

WP Abstracts

Plugin Slug:
wp-abstracts-manuscripts-manager

Installations
300+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

ABA PayWay Payment Gateway for WooCommerce

Plugin Slug:
aba-payway-woocommerce-payment-gateway

Installations
200+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Connector to CiviCRM with CiviMcRestFace

Plugin Slug:
connector-civicrm-mcrestface

Installations
200+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Foliopress WYSIWYG

Plugin Slug:
foliopress-wysiwyg

Installations
200+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Multiple Location Google Map

Plugin Slug:
multiple-location-google-map

Installations
200+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Nimbata Call Tracking

Plugin Slug:
nimbata-call-tracking

Installations
200+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Oxygen MyData for WooCommerce

Plugin Slug:
oxygen-mydata

Installations
200+

Vulnerability:
Arbitrary File Deletion

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Total processing card payments for WooCommerce

Plugin Slug:
totalprocessing-card-payments

Installations
200+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Tournamatch

Plugin Slug:
tournamatch

Installations
200+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

User Session Synchronizer

Plugin Slug:
user-session-synchronizer

Installations
200+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Product Excel Import Export & Bulk Edit for WooCommerce

Plugin Slug:
webd-woocommerce-product-excel-importer-bulk-edit

Installations
200+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

WooCommerce Sales MIS Report

Plugin Slug:
woocommerce-mis-report

Installations
200+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Workbox Video from Vimeo & Youtube Plugin

Plugin Slug:
workbox-video-from-vimeo-youtube-plugin

Installations
200+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Chat2

Plugin:

Chat2

Plugin Slug:
chat2

Installations
100+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

ChillPay WooCommerce

Plugin Slug:
chillpay-payment-gateway

Installations
100+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Clinked Client Portal

Plugin Slug:
clinked-client-portal

Installations
100+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Codescar Radio Widget

Plugin Slug:
codescar-radio-widget

Installations
100+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

WordPress Events Calendar Plugin � connectDaily

Plugin Slug:
connect-daily-web-calendar

Installations
100+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Course Booking System

Plugin Slug:
course-booking-system

Installations
100+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Credova Financial

Plugin Slug:
credova-financial

Installations
100+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

EmpikPlace for Woocommerce

Plugin Slug:
empik-for-woocommerce

Installations
100+

Vulnerability:
PHP Object Injection

Patched in Version:
No Fix

Severity Score:
Critical


The vulnerability has not been patched. You should deactivate the plugin.

Error Log Viewer By WP Guru

Plugin Slug:
error-log-viewer-wp

Installations
100+

Vulnerability:
SQL Injection

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

FAT Cooming Soon

Plugin Slug:
fat-coming-soon

Installations
100+

Vulnerability:
Local File Inclusion

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Flexi � Guest Submit

Plugin Slug:
flexi

Installations
100+

Vulnerability:
Local File Inclusion

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.
Plugin Slug:
gb-gallery-slideshow

Installations
100+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

iCal Feeds

Plugin Slug:
ical-feeds

Installations
100+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

KeyCAPTCHA � Social WordPress CAPTCHA

Plugin Slug:
keycaptcha

Installations
100+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Listings for Buildium

Plugin Slug:
listings-for-buildium

Installations
100+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Local Magic

Plugin Slug:
local-magic

Installations
100+

Vulnerability:
SQL Injection

Patched in Version:
No Fix

Severity Score:
Critical


The vulnerability has not been patched. You should deactivate the plugin.

Popping Content Light

Plugin Slug:
popping-content-light

Installations
100+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

QR Master

Plugin Slug:
qr-master

Installations
100+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

RentSyst � CRM solution for fleet management

Plugin Slug:
rentsyst

Installations
100+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Sync Posts

Plugin Slug:
sync-posts

Installations
100+

Vulnerability:
Arbitrary File Upload

Patched in Version:
No Fix

Severity Score:
Critical


The vulnerability has not been patched. You should deactivate the plugin.

UXsniff AI-powered Heatmaps and Session Recordings

Plugin Slug:
ux-sniff

Installations
100+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Web2application Convert your website to android and IOS apps with push notifications , web push , free ajax products search for woocommerce and many more advanced features

Plugin Slug:
web2application

Installations
100+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.
Plugin Slug:
woocommerce-products-without-featured-images

Installations
100+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.
Plugin Slug:
wp-featured-screenshot

Installations
100+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

WP Map Route Planner

Plugin Slug:
wp-map-route-planner

Installations
100+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

WP Online Users Stats

Plugin Slug:
wp-online-users-stats

Installations
100+

Vulnerability:
SQL Injection

Patched in Version:
No Fix

Severity Score:
Critical


The vulnerability has not been patched. You should deactivate the plugin.

WP Remote Thumbnail

Plugin Slug:
wp-remote-thumbnail

Installations
100+

Vulnerability:
Arbitrary File Upload

Patched in Version:
No Fix

Severity Score:
Critical


The vulnerability has not been patched. You should deactivate the plugin.

WPshop 2 � E-Commerce

Plugin Slug:
wpshop

Installations
100+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
Critical


The vulnerability has not been patched. You should deactivate the plugin.

PlainInventory � Inventory Management Plugin

Plugin Slug:
z-inventory-manager

Installations
100+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

5sterrenspecialist

Plugin Slug:
5-sterrenspecialist

Installations
90+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Add Product Frontend for WooCommerce

Plugin Slug:
add-product-frontend-for-woocommerce

Installations
90+

Vulnerability:
Arbitrary Content Deletion

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Easy Post Duplicator

Plugin Slug:
easy-post-duplicator

Installations
90+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Easy Post Duplicator

Plugin Slug:
easy-post-duplicator

Installations
90+

Vulnerability:
SQL Injection

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Neon Product Designer

Plugin Slug:
neon-product-designer-for-woocommerce

Installations
90+

Vulnerability:
SQL Injection

Patched in Version:
No Fix

Severity Score:
Critical


The vulnerability has not been patched. You should deactivate the plugin.

Restrict User Registration

Plugin Slug:
restrict-user-registration

Installations
90+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Verowa Connect

Plugin Slug:
verowa-connect

Installations
90+

Vulnerability:
SQL Injection

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

WP Easy Poll

Plugin Slug:
wp-easy-poll-afo

Installations
90+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Flags Widget

Plugin Slug:
flags-widget

Installations
80+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Review Stars Count For WooCommerce

Plugin Slug:
review-stars-count-for-woocommerce

Installations
80+

Vulnerability:
SQL Injection

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Spark GF Failed Submissions

Plugin Slug:
spark-gf-failed-submissions

Installations
80+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.
Plugin Slug:
tp-gallery-slider

Installations
80+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

WP-Planification � WP-Planning

Plugin Slug:
wp-planification

Installations
80+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Custom Smilies

Plugin Slug:
custom-smilies

Installations
70+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Nino Social Connect

Plugin Slug:
nino-social-connect

Installations
70+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Windows Live Writer

Plugin Slug:
windows-live-writer

Installations
70+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

WP-Easy Menu

Plugin Slug:
wp-easy-menu

Installations
70+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

All push notification for WP

Plugin Slug:
all-push-notification

Installations
60+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

All push notification for WP

Plugin Slug:
all-push-notification

Installations
60+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Automatic Ban IP

Plugin Slug:
automatic-ban-ip

Installations
60+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

WP_DEBUG Toggle

Plugin Slug:
enable-wp-debug-toggle

Installations
60+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

HTML5 Video Player with Playlist

Plugin Slug:
html5-video-player-with-playlist

Installations
60+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

ePaper Lister for Yumpu

Plugin Slug:
magazine-lister-for-yumpu

Installations
60+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Processing Projects

Plugin Slug:
processing-projects

Installations
60+

Vulnerability:
Arbitrary File Upload

Patched in Version:
No Fix

Severity Score:
Critical


The vulnerability has not been patched. You should deactivate the plugin.

Terminal Africa

Plugin Slug:
terminal-africa

Installations
60+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

WooCommerce TBC Credit Card Payment Gateway (Free)

Plugin Slug:
woo-tbc-payment-gateway

Installations
60+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

WP SexyLightBox

Plugin Slug:
wp-sexylightbox

Installations
60+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

WP Calais Auto Tagger

Plugin Slug:
calais-auto-tagger

Installations
50+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.
Plugin Slug:
link-shield

Installations
50+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

ShopApper: Mobile App for WooCommerce

Plugin Slug:
mobile-app-for-woocommerce

Installations
50+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Mobile Blocks

Plugin Slug:
mobile-pages

Installations
50+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Shop Products Filter

Plugin Slug:
trusty-woo-products-filter

Installations
50+

Vulnerability:
Local File Inclusion

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

WooCommerce Pickupp

Plugin Slug:
wc-pickupp

Installations
50+

Vulnerability:
Local File Inclusion

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

WooCommerce Loyal Customers

Plugin Slug:
woocommerce-loyal-customer

Installations
50+

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

SEO, Nutrition and Print for Recipes by Edamam

Plugin Slug:
seo-nutrition-and-print-for-recipes-by-edamam

Installations
40+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Simple Post Meta Manager

Plugin Slug:
simple-post-meta-manager

Installations
40+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

WP Social Stream Designer

Plugin Slug:
social-stream-design

Installations
40+

Vulnerability:
SQL Injection

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

iONE360 configurator

Plugin Slug:
ione360-configurator

Installations
30+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

MultiMailer

Plugin Slug:
scand-multi-mailer

Installations
30+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

MultiMailer

Plugin Slug:
scand-multi-mailer

Installations
30+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

AT Internet SmartTag

Plugin Slug:
at-internet

Installations
10+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Event Espresso � Custom Email Template Shortcode

Plugin Slug:
email-shortcode

Installations
10+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Make Email Customizer for WooCommerce

Plugin Slug:
make-email-customizer-for-woocommerce

Installations
10+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Nearby Locations

Plugin Slug:
nearby-locations

Installations
10+

Vulnerability:
SQL Injection

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.
Plugin Slug:
related-videos-for-jw-player

Installations
10+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Revamp CRM for WooCommerce

Plugin Slug:
revampcrm-woocommerce

Installations
10+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

WP Inquiries

Plugin Slug:
wp-inquiries

Installations
10+

Vulnerability:
SQL Injection

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

ZooEffect

Plugin:

ZooEffect

Plugin Slug:
1-jquery-photo-gallery-slideshow-flash

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

AAWP Obfuscator

Plugin:

AAWP Obfuscator

Plugin Slug:
aawp-obfuscator

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Accredible Certificates & Open Badges

Plugin:

Accredible Certificates & Open Badges

Plugin Slug:
accredible-certificates

Vulnerability:
SQL Injection

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.
Plugin:

Advanced Custom Fields: Link Picker Field

Plugin Slug:
acf-link-picker-field

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Activity Reactions For Buddypress

Plugin:

Activity Reactions For Buddypress

Plugin Slug:
activity-reactions-for-buddypress

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Admin Menu Post List

Plugin:

Admin Menu Post List

Plugin Slug:
admin-menu-post-list

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Advance WP Query Search Filter

Plugin:

Advance WP Query Search Filter

Plugin Slug:
advance-wp-query-search-filter

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Advanced Advertising System

Plugin:

Advanced Advertising System

Plugin Slug:
advanced-advertising-system

Vulnerability:
Open Redirection

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Advanced Tag Lists

Plugin:

Advanced Tag Lists

Plugin Slug:
advanced-tag-list

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

AF Tell a Friend

Plugin:

AF Tell a Friend

Plugin Slug:
af-tell-a-friend

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.
Plugin:

AnyTrack Affiliate Link Manager

Plugin Slug:
anytrack-affiliate-link-manager

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Aria Font

Plugin:

Aria Font

Plugin Slug:
aria-font

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

azurecurve Shortcodes in Comments

Plugin:

azurecurve Shortcodes in Comments

Plugin Slug:
azurecurve-shortcodes-in-comments

Vulnerability:
Content Injection

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

BP Social Connect

Plugin:

BP Social Connect

Plugin Slug:
bp-social-connect

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Brizy Pro

Plugin:

Brizy Pro

Plugin Slug:
brizy-pro

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Brizy Pro

Plugin:

Brizy Pro

Plugin Slug:
brizy-pro

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Buddypress Humanity

Plugin:

Buddypress Humanity

Plugin Slug:
buddypress-humanity

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
Critical


The vulnerability has not been patched. You should deactivate the plugin.

C9 Blocks

Plugin:

C9 Blocks

Plugin Slug:
c9-blocks

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Cart66 Cloud

Plugin:

Cart66 Cloud

Plugin Slug:
cart66-cloud

Vulnerability:
Sensitive Data Exposure

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Cart66 Cloud

Plugin:

Cart66 Cloud

Plugin Slug:
cart66-cloud

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

CG Scroll To Top

Plugin:

CG Scroll To Top

Plugin Slug:
cg-scroll-to-top

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Checkout Mestres WP

Plugin:

Checkout Mestres WP

Plugin Slug:
checkout-mestres-wp

Vulnerability:
Privilege Escalation

Patched in Version:
No Fix

Severity Score:
Critical


The vulnerability has not been patched. You should deactivate the plugin.

Comment Validation Reloaded

Plugin:

Comment Validation Reloaded

Plugin Slug:
comment-validation-reloaded

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Customize Login Page

Plugin:

Customize Login Page

Plugin Slug:
customize-login-page

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Developer Toolbar

Plugin:

Developer Toolbar

Plugin Slug:
developer-toolbar

Vulnerability:
Sensitive Data Exposure

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

ZoomSounds

Plugin:

ZoomSounds

Plugin Slug:
dzs-zoomsounds

Vulnerability:
Arbitrary File Download

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Easy Custom CSS

Plugin:

Easy Custom CSS

Plugin Slug:
easy-custom-css

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Embedder

Plugin:

Embedder

Plugin Slug:
embedder

Vulnerability:
Privilege Escalation

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Essential Breadcrumbs

Plugin:

Essential Breadcrumbs

Plugin Slug:
essential-breadcrumbs

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

FireDrum Email Marketing

Plugin:

FireDrum Email Marketing

Plugin Slug:
firedrum-email-marketing

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Sandwich Adsense

Plugin:

Sandwich Adsense

Plugin Slug:
firsth3tagadsense

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

FrescoChat Live Chat

Plugin:

FrescoChat Live Chat

Plugin Slug:
flexytalk-widget

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

FS Poster

Plugin:

FS Poster

Plugin Slug:
fs-poster

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.
Plugin:

Global Gallery

Plugin Slug:
global-gallery

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Hamburger Icon Menu Lite

Plugin:

Hamburger Icon Menu Lite

Plugin Slug:
hamburger-icon-menu-lite

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Insert HTML Here

Plugin:

Insert HTML Here

Plugin Slug:
insert-html-here

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Language Field

Plugin:

Language Field

Plugin Slug:
language-field

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Linet ERP-Woocommerce Integration

Plugin:

Linet ERP-Woocommerce Integration

Plugin Slug:
linet-erp-woocommerce-integration

Vulnerability:
Arbitrary File Deletion

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Melhor Envio

Plugin:

Melhor Envio

Plugin Slug:
melhor-envio-cotacao

Vulnerability:
Sensitive Data Exposure

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

MMX – Make Me Christmas

Plugin:

MMX – Make Me Christmas

Plugin Slug:
mmx-make-me-christmas

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Mobile Smart

Plugin:

Mobile Smart

Plugin Slug:
mobile-smart

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

More Mime Type Filters

Plugin:

More Mime Type Filters

Plugin Slug:
more-mime-type-filters

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

My auctions allegro

Plugin:

My auctions allegro

Plugin Slug:
my-auctions-allegro-free-edition

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

NewsBoard Post and RSS Scroller

Plugin:

NewsBoard Post and RSS Scroller

Plugin Slug:
newsboard

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Oppso Unit Converter

Plugin:

Oppso Unit Converter

Plugin Slug:
oppso-unit-converter

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

ORDER POST

Plugin:

ORDER POST

Plugin Slug:
order-post

Vulnerability:
Content Injection

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Payment Forms for Paystack

Plugin:

Payment Forms for Paystack

Plugin Slug:
payment-forms-for-paystack

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Rankology SEO – On-site SEO

Plugin:

Rankology SEO – On-site SEO

Plugin Slug:
rankology-seo-all-in-one-seo-analytics

Vulnerability:
Privilege Escalation

Patched in Version:
No Fix

Severity Score:
Critical


The vulnerability has not been patched. You should deactivate the plugin.

reCAPTCHA Jetpack

Plugin:

reCAPTCHA Jetpack

Plugin Slug:
recaptcha-jetpack

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Rich Table of Contents

Plugin:

Rich Table of Contents

Plugin Slug:
rich-table-of-content

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Scheduled

Plugin:

Scheduled

Plugin Slug:
scheduled

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Script Compressor

Plugin:

Script Compressor

Plugin Slug:
script-compressor

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Seo Meta Tags

Plugin:

Seo Meta Tags

Plugin Slug:
seo-meta-tags

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Simple WP Events

Plugin:

Simple WP Events

Plugin Slug:
simple-wp-events

Vulnerability:
Sensitive Data Exposure

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Simple WP Events

Plugin:

Simple WP Events

Plugin Slug:
simple-wp-events

Vulnerability:
Arbitrary File Deletion

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Coming Soon, Maintenance Mode

Plugin:

Coming Soon, Maintenance Mode

Plugin Slug:
site-mode

Vulnerability:
Local File Inclusion

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Site Notify

Plugin:

Site Notify

Plugin Slug:
site-notify

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Site Table of Contents

Plugin:

Site Table of Contents

Plugin Slug:
site-table-of-contents

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.
Plugin:

Smart Product Gallery Slider

Plugin Slug:
smart-product-gallery-slider

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Social Bookmarking RELOADED

Plugin:

Social Bookmarking RELOADED

Plugin Slug:
social-bookmarking-reloaded

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Social Crowd

Plugin:

Social Crowd

Plugin Slug:
social-crowd

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Spoiler Block

Plugin:

Spoiler Block

Plugin Slug:
spoiler-block

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Stop Registration Spam

Plugin:

Stop Registration Spam

Plugin Slug:
stop-registration-spam

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Testimonial Slider And Showcase Pro

Plugin:

Testimonial Slider And Showcase Pro

Plugin Slug:
testimonial-slider-showcase-pro

Vulnerability:
Local File Inclusion

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Testimonial Slider And Showcase Pro

Plugin:

Testimonial Slider And Showcase Pro

Plugin Slug:
testimonial-slider-showcase-pro

Vulnerability:
Local File Inclusion

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

The World

Plugin:

The World

Plugin Slug:
the-world

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

TuriTop Booking System

Plugin:

TuriTop Booking System

Plugin Slug:
turitop-booking-system

Vulnerability:
PHP Object Injection

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Twispay Credit Card Payments

Plugin:

Twispay Credit Card Payments

Plugin Slug:
twispay

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Ultra Demo Importer

Plugin:

Ultra Demo Importer

Plugin Slug:
ut-demo-importer

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
Critical


The vulnerability has not been patched. You should deactivate the plugin.

Vice Versa

Plugin:

Vice Versa

Plugin Slug:
vice-versa

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Vite Coupon

Plugin:

Vite Coupon

Plugin Slug:
vite-coupon

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
Critical


The vulnerability has not been patched. You should deactivate the plugin.

VKontakte Cross-Post

Plugin:

VKontakte Cross-Post

Plugin Slug:
vkontakte-cross-post

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Wetterwarner

Plugin:

Wetterwarner

Plugin Slug:
wetterwarner

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Woo Product Feed For Marketing Channels

Plugin:

Woo Product Feed For Marketing Channels

Plugin Slug:
woocommerce-to-google-merchant-center

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

WP Editor.md – The Perfect WordPress Markdown Editor

Plugin:

WP Editor.md – The Perfect WordPress Markdown Editor

Plugin Slug:
wp-editormd

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

WP Food ordering and Restaurant Menu

Plugin:

WP Food ordering and Restaurant Menu

Plugin Slug:
wp-food

Vulnerability:
Local File Inclusion

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

WP-GeSHi-Highlight

Plugin:

WP-GeSHi-Highlight

Plugin Slug:
wp-geshi-highlight

Vulnerability:
Denial of Service Attack

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

WP Hide Categories

Plugin:

WP Hide Categories

Plugin Slug:
wp-hide-categories

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

WP Performance Pack

Plugin:

WP Performance Pack

Plugin Slug:
wp-performance-pack

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

wp secure

Plugin:

wp secure

Plugin Slug:
wp-secure-by-sitesecuritymonitorcom

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

WP User Profiles

Plugin:

WP User Profiles

Plugin Slug:
wp-users-profiles

Vulnerability:
Privilege Escalation

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

WPSolr

Plugin:

WPSolr

Plugin Slug:
wpsolr-free

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

WS Audio Player

Plugin:

WS Audio Player

Plugin Slug:
ws-audio-player

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

YouTube Embed

Plugin:

YouTube Embed

Plugin Slug:
youtube-embed

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Royal Elementor Addons and Templates

Plugin Slug:
royal-elementor-addons

Installations
500,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.7.1013

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.7.1013.

Royal Elementor Addons and Templates

Plugin Slug:
royal-elementor-addons

Installations
500,000+

Vulnerability:
Server Side Request Forgery (SSRF)

Patched in Version:
1.7.1007

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.7.1007.

WooCommerce Multilingual & Multicurrency with WPML

Plugin Slug:
woocommerce-multilingual

Installations
100,000+

Vulnerability:
Broken Access Control

Patched in Version:
5.3.9

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 5.3.9.

Age Gate

Plugin:

Age Gate

Plugin Slug:
age-gate

Installations
40,000+

Vulnerability:
Broken Access Control

Patched in Version:
3.6.0

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 3.6.0.
Plugin Slug:
testimonial-free

Installations
40,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
3.1.7

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 3.1.7.

WPFront User Role Editor

Plugin Slug:
wpfront-user-role-editor

Installations
40,000+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
4.2.2

Severity Score:
High


The vulnerability has been patched, so you should update to version 4.2.2.

Cost Calculator Builder

Plugin Slug:
cost-calculator-builder

Installations
30,000+

Vulnerability:
SQL Injection

Patched in Version:
3.2.68

Severity Score:
High


The vulnerability has been patched, so you should update to version 3.2.68.

PowerPress Podcasting plugin by Blubrry

Plugin Slug:
powerpress

Installations
30,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
11.9.18

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 11.9.18.

PowerPress Podcasting plugin by Blubrry

Plugin Slug:
powerpress

Installations
30,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
11.12.16

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 11.12.16.

Uncanny Toolkit for LearnDash

Plugin Slug:
uncanny-learndash-toolkit

Installations
30,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
3.7.0.2

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 3.7.0.2.

InstaWP Connect � 1-click WP Staging & Migration

Plugin Slug:
instawp-connect

Installations
20,000+

Vulnerability:
Local File Inclusion

Patched in Version:
0.1.0.86

Severity Score:
Critical


The vulnerability has been patched, so you should update to version 0.1.0.86.

WordPress Mega Menu � QuadMenu

Plugin Slug:
quadmenu

Installations
20,000+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
3.2.1

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 3.2.1.

Motors � Car Dealership & Classified Listings Plugin

Plugin Slug:
motors-car-dealership-classified-listings

Installations
10,000+

Vulnerability:
Broken Access Control

Patched in Version:
1.4.67

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.4.67.

Motors � Car Dealership & Classified Listings Plugin

Plugin Slug:
motors-car-dealership-classified-listings

Installations
10,000+

Vulnerability:
Broken Access Control

Patched in Version:
1.4.65

Severity Score:
High


The vulnerability has been patched, so you should update to version 1.4.65.

Motors � Car Dealership & Classified Listings Plugin

Plugin Slug:
motors-car-dealership-classified-listings

Installations
10,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.4.64

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.4.64.

License Manager for WooCommerce

Plugin Slug:
license-manager-for-woocommerce

Installations
7,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
3.0.10

Severity Score:
High


The vulnerability has been patched, so you should update to version 3.0.10.

Raptive Ads

Plugin Slug:
adthrive-ads

Installations
5,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
3.7.4

Severity Score:
High


The vulnerability has been patched, so you should update to version 3.7.4.

WooCommerce Sync for QuickBooks Online � by MyWorks

Plugin Slug:
myworks-woo-sync-for-quickbooks-online

Installations
5,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.9.2

Severity Score:
High


The vulnerability has been patched, so you should update to version 2.9.2.
Plugin Slug:
awesome-logo-carousel-block

Installations
4,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.1.7

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.1.7.

SMTP for Amazon SES � YaySMTP

Plugin Slug:
smtp-amazon-ses

Installations
3,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.9

Severity Score:
High


The vulnerability has been patched, so you should update to version 1.9.

SKT Blocks � Gutenberg based Page Builder

Plugin Slug:
skt-blocks

Installations
2,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.0

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.0.

SKT Blocks � Gutenberg based Page Builder

Plugin Slug:
skt-blocks

Installations
2,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.9

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.9.

SKT Skill Bar

Plugin Slug:
skt-skill-bar

Installations
2,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.4

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.4.

DSGVO Youtube

Plugin Slug:
dsgvo-youtube

Installations
1,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.5.2

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.5.2.
Plugin Slug:
inpost-gallery

Installations
1,000+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
2.1.4.4

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.1.4.4.

Nav Menu Manager

Plugin Slug:
noakes-menu-manager

Installations
1,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
3.2.6

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 3.2.6.

WP Delete User Accounts

Plugin Slug:
wp-delete-user-accounts

Installations
1,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.2.4

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.2.4.

Zephyr Project Manager

Plugin Slug:
zephyr-project-manager

Installations
1,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
3.3.102

Severity Score:
High


The vulnerability has been patched, so you should update to version 3.3.102.

3DPrint Lite

Plugin Slug:
3dprint-lite

Installations
800+

Vulnerability:
SQL Injection

Patched in Version:
2.1.3.7

Severity Score:
High


The vulnerability has been patched, so you should update to version 2.1.3.7.

Nepali Date Converter

Plugin Slug:
nepali-date-converter

Installations
800+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
3.0.0

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 3.0.0.

OTP-less one tap Sign in

Plugin Slug:
otpless

Installations
700+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.0.59

Severity Score:
High


The vulnerability has been patched, so you should update to version 2.0.59.

WPC Admin Columns

Plugin Slug:
wpc-admin-columns

Installations
700+

Vulnerability:
Privilege Escalation

Patched in Version:
2.1.1

Severity Score:
High


The vulnerability has been patched, so you should update to version 2.1.1.

Additional Custom Product Tabs for WooCommerce

Plugin Slug:
product-tabs-for-woocommerce

Installations
600+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.7.1

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.7.1.

Deliver via Shipos for WooCommerce

Plugin Slug:
wc-shipos-delivery

Installations
500+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.2.0

Severity Score:
High


The vulnerability has been patched, so you should update to version 2.2.0.

Z Companion

Plugin Slug:
z-companion

Installations
500+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.1.2

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.1.2.

Administrator Z

Plugin Slug:
administrator-z

Installations
400+

Vulnerability:
Privilege Escalation

Patched in Version:
2025.03.27

Severity Score:
High


The vulnerability has been patched, so you should update to version 2025.03.27.

Team Circle Image Slider With Lightbox

Plugin Slug:
circle-image-slider-with-lightbox

Installations
400+

Vulnerability:
SQL Injection

Patched in Version:
1.0.5

Severity Score:
High


The vulnerability has been patched, so you should update to version 1.0.5.

CardGate Payments for WooCommerce

Plugin Slug:
cardgate

Installations
300+

Vulnerability:
SQL Injection

Patched in Version:
3.2.2

Severity Score:
High


The vulnerability has been patched, so you should update to version 3.2.2.

Crowdfunding for WooCommerce

Plugin Slug:
crowdfunding-for-woocommerce

Installations
300+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
3.1.13

Severity Score:
High


The vulnerability has been patched, so you should update to version 3.1.13.

Sell access, Automate, and add Engaging Exclusive Discord Access: Introducing the MemberPress Discord Addon � Elevate Your Community!

Plugin Slug:
expresstechsoftwares-memberpress-discord-add-on

Installations
300+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.1.2

Severity Score:
High


The vulnerability has been patched, so you should update to version 1.1.2.

IP2Location World Clock

Plugin Slug:
ip2location-world-clock

Installations
300+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
1.1.10

Severity Score:
High


The vulnerability has been patched, so you should update to version 1.1.10.

MSRP (RRP) Pricing for WooCommerce

Plugin Slug:
msrp-for-woocommerce

Installations
300+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.0.0

Severity Score:
High


The vulnerability has been patched, so you should update to version 2.0.0.

TableOn � WordPress Posts Table Filterable�

Plugin Slug:
posts-table-filterable

Installations
300+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.0.4

Severity Score:
High


The vulnerability has been patched, so you should update to version 1.0.4.

Click & Pledge Connect Plugin

Plugin Slug:
click-pledge-connect

Installations
200+

Vulnerability:
SQL Injection

Patched in Version:
2.24120000-WP6.7.1

Severity Score:
High


The vulnerability has been patched, so you should update to version 2.24120000-WP6.7.1.

Total processing card payments for WooCommerce

Plugin Slug:
totalprocessing-card-payments

Installations
200+

Vulnerability:
Arbitrary File Download

Patched in Version:
7.1.6

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 7.1.6.

GreenPay(tm) by Green.Money

Plugin Slug:
green-money-payment-gateway

Installations
100+

Vulnerability:
Sensitive Data Exposure

Patched in Version:
3.0.10

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 3.0.10.

IndieBlocks

Plugin Slug:
indieblocks

Installations
100+

Vulnerability:
Server Side Request Forgery (SSRF)

Patched in Version:
0.13.2

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 0.13.2.
Plugin Slug:
internal-link-finder

Installations
100+

Vulnerability:
Settings Change

Patched in Version:
5.1.3

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 5.1.3.

Email Notifications for Updates

Plugin Slug:
wp-update-mail-notification

Installations
100+

Vulnerability:
Privilege Escalation

Patched in Version:
1.2.0

Severity Score:
High


The vulnerability has been patched, so you should update to version 1.2.0.

Verowa Connect

Plugin Slug:
verowa-connect

Installations
90+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
3.0.5

Severity Score:
High


The vulnerability has been patched, so you should update to version 3.0.5.

Material Dashboard

Plugin Slug:
material-dashboard

Installations
80+

Vulnerability:
Privilege Escalation

Patched in Version:
1.4.7

Severity Score:
Critical


The vulnerability has been patched, so you should update to version 1.4.7.

Material Dashboard

Plugin Slug:
material-dashboard

Installations
80+

Vulnerability:
Local File Inclusion

Patched in Version:
1.4.6

Severity Score:
High


The vulnerability has been patched, so you should update to version 1.4.6.

Shipping by Weight for WooCommerce

Plugin Slug:
dn-shipping-by-weight

Installations
50+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.2.1

Severity Score:
High


The vulnerability has been patched, so you should update to version 1.2.1.

Accept SagePay Payments Using Contact Form 7

Plugin Slug:
accept-sagepay-payments-using-contact-form-7

Installations
10+

Vulnerability:
Sensitive Data Exposure

Patched in Version:
2.1

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.1.

ALD Login Page

Plugin Slug:
ald-login-page

Installations
10+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
1.3

Severity Score:
High


The vulnerability has been patched, so you should update to version 1.3.

coreActivity: Activity Logging for WordPress

Plugin Slug:
coreactivity

Installations
10+

Vulnerability:
SQL Injection

Patched in Version:
2.7.1

Severity Score:
High


The vulnerability has been patched, so you should update to version 2.7.1.

JetBlog

Plugin:

JetBlog

Plugin Slug:
jet-blog

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.4.3.1

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.4.3.1.

JetCompareWishlist

Plugin:

JetCompareWishlist

Plugin Slug:
jet-compare-wishlist

Vulnerability:
Local File Inclusion

Patched in Version:
1.5.10

Severity Score:
High


The vulnerability has been patched, so you should update to version 1.5.10.

JetEngine

Plugin:

JetEngine

Plugin Slug:
jet-engine

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
3.6.5

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 3.6.5.

Pagopar – WooCommerce Gateway

Plugin:

Pagopar – WooCommerce Gateway

Plugin Slug:
pagopar-woocommerce-gateway

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
2.8.0

Severity Score:
High


The vulnerability has been patched, so you should update to version 2.8.0.

WPJobBoard

Plugin:

WPJobBoard

Plugin Slug:
wpjobboard

Vulnerability:
Path Traversal

Patched in Version:
5.11.1

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 5.11.1.

WPJobBoard

Plugin:

WPJobBoard

Plugin Slug:
wpjobboard

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
5.11.1

Severity Score:
Critical


The vulnerability has been patched, so you should update to version 5.11.1.

WPJobBoard

Plugin:

WPJobBoard

Plugin Slug:
wpjobboard

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
5.11.1

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 5.11.1.

WordPress Themes � 3 Patched / 12 Unpatched

Arkhe

Theme:

Arkhe

Theme Slug:
arkhe

Downloads
91,582

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should switch themes.

Industrial Lite

Theme Slug:
industrial-lite

Downloads
100,465

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should switch themes.

SpaBiz

Theme:

SpaBiz

Theme Slug:
spabiz

Downloads
21,133

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should switch themes.

AI Hub

Theme:

AI Hub

Theme Slug:
aihub

Vulnerability:
Arbitrary File Upload

Patched in Version:
No Fix

Severity Score:
Critical


The vulnerability has not been patched. You should switch themes.

Bulk

Theme:

Bulk

Theme Slug:
bulk

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should switch themes.

Celestial Aura

Theme:

Celestial Aura

Theme Slug:
celestial-aura

Vulnerability:
Arbitrary File Upload

Patched in Version:
No Fix

Severity Score:
Critical


The vulnerability has not been patched. You should switch themes.

Customify

Theme:

Customify

Theme Slug:
customify-theme

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should switch themes.

Eximius

Theme:

Eximius

Theme Slug:
eximius

Vulnerability:
Arbitrary File Upload

Patched in Version:
No Fix

Severity Score:
Critical


The vulnerability has not been patched. You should switch themes.

Fazyvo

Theme:

Fazyvo

Theme Slug:
fazyvo

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should switch themes.

Grip

Theme:

Grip

Theme Slug:
grip

Vulnerability:
Local File Inclusion

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should switch themes.

Photography

Theme:

Photography

Theme Slug:
photography

Vulnerability:
Server Side Request Forgery (SSRF)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should switch themes.

Wireless Butler

Theme:

Wireless Butler

Theme Slug:
wireless-butler

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should switch themes.

Streamit

Theme:

Streamit

Theme Slug:
streamit

Vulnerability:
Arbitrary File Download

Patched in Version:
4.0.2

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 4.0.2.

Streamit

Theme:

Streamit

Theme Slug:
streamit

Vulnerability:
Arbitrary File Upload

Patched in Version:
4.0.2

Severity Score:
Critical


The vulnerability has been patched, so you should update to version 4.0.2.

Streamit

Theme:

Streamit

Theme Slug:
streamit

Vulnerability:
Privilege Escalation

Patched in Version:
4.0.3

Severity Score:
High


The vulnerability has been patched, so you should update to version 4.0.3.

Related articles

Wait! Get exclusive hosting insights

Subscribe to our newsletter and stay ahead of the competition with expert advice from our hosting pros.

Loading form…