WordPress Vulnerability Report � April 22, 2026

In this report, 216 vulnerabilities have been publicly disclosed. Security patches for 187 of these plugins and themes are now available. Please run these updates as soon as possible. If you’re a Solid Security Pro user, the version management tool may have already warned you and updated these plugins, depending on your settings.

Currently, 29 plugin and theme vulnerabilities remain unpatched. If you’re a Solid Security Pro user, those vulnerabilities are already protected by the Solid Security firewall. Virtual patches from Patchstack will be applied when a vulnerability is considered high or medium risk. If no patch is forthcoming from the vendor or the vulnerable software has been marked “closed” and dropped from the official WordPress repositories, you should deactivate it soon and look for alternative solutions.

WordPress Core

WordPress 6.9.4 is available, addressing 10 security issues and a template loading bug. Immediate updates are recommended for all production sites.

WordPress 7.0 Release Candidate 2 (RC2) is now ready for testing via the Beta Tester plugin, direct download, WP-CLI, or WordPress Playground. As a pre-release version, it should only be evaluated in staging or local environments.

WordPress Plugins � 159 Patched / 28 Unpatched

Pz-LinkCard

Plugin Slug:
pz-linkcard

Installations
20,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

WCFM Marketplace � Multivendor Marketplace for WooCommerce

Plugin Slug:
wc-multivendor-marketplace

Installations
10,000+

Vulnerability:
SQL Injection

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Smart Online Order for Clover

Plugin Slug:
clover-online-orders

Installations
1,000+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Accept Cryptocurrencies with Plisio

Plugin Slug:
plisio-payment-gateway-for-woocommerce

Installations
1,000+

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Quick Interest Slider

Plugin Slug:
quick-interest-slider

Installations
1,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Livemesh Addons for Elementor

Plugin:

Livemesh Addons for Elementor

Plugin Slug:
addons-for-elementor

Vulnerability:
Local File Inclusion

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Livemesh Addons for Elementor

Plugin:

Livemesh Addons for Elementor

Plugin Slug:
addons-for-elementor

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Canto

Plugin:

Canto

Plugin Slug:
canto

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

CMS f�r Motorrad Werkst�tten

Plugin:

CMS f�r Motorrad Werkst�tten

Plugin Slug:
cms-fuer-motorrad-werkstaetten

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Coachific Shortcode

Plugin:

Coachific Shortcode

Plugin Slug:
coachific-shortcode

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Custom New User Notification

Plugin:

Custom New User Notification

Plugin Slug:
custom-new-user-notification

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

e-shot

Plugin:

e-shot

Plugin Slug:
e-shot-form-builder

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Inquiry form to posts or pages

Plugin:

Inquiry form to posts or pages

Plugin Slug:
inquiry-form-to-posts-or-pages

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Katalogportal-pdf-sync Widget

Plugin:

Katalogportal-pdf-sync Widget

Plugin Slug:
katalogportal-pdf-sync

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Login as User

Plugin:

Login as User

Plugin Slug:
one-click-login-as-user

Vulnerability:
Privilege Escalation

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Accessibility Suite

Plugin:

Accessibility Suite

Plugin Slug:
online-accessibility

Vulnerability:
SQL Injection

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

OPEN-BRAIN

Plugin:

OPEN-BRAIN

Plugin Slug:
open-brain

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

OPEN-BRAIN

Plugin:

OPEN-BRAIN

Plugin Slug:
open-brain

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Accessibly – WordPress Website Accessibility

Plugin:

Accessibly – WordPress Website Accessibility

Plugin Slug:
otm-accessibly

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Petje.af

Plugin:

Petje.af

Plugin Slug:
petje-af

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Riaxe Product Customizer

Plugin:

Riaxe Product Customizer

Plugin Slug:
riaxe-product-customizer

Vulnerability:
SQL Injection

Patched in Version:
No Fix

Severity Score:
Critical


The vulnerability has not been patched. You should deactivate the plugin.

Riaxe Product Customizer

Plugin:

Riaxe Product Customizer

Plugin Slug:
riaxe-product-customizer

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Riaxe Product Customizer

Plugin:

Riaxe Product Customizer

Plugin Slug:
riaxe-product-customizer

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
Critical


The vulnerability has not been patched. You should deactivate the plugin.

VI: Include Post By

Plugin:

VI: Include Post By

Plugin Slug:
vi-include-post-by

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Visa Acceptance Solutions

Plugin:

Visa Acceptance Solutions

Plugin Slug:
visa-acceptance-solutions

Vulnerability:
Privilege Escalation

Patched in Version:
No Fix

Severity Score:
Critical


The vulnerability has not been patched. You should deactivate the plugin.

WM JqMath

Plugin:

WM JqMath

Plugin Slug:
wm-jqmath

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

WP Circliful

Plugin:

WP Circliful

Plugin Slug:
wp-circliful

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Power Charts

Plugin:

Power Charts

Plugin Slug:
wpgo-power-charts-lite

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Advanced Custom Fields (ACF�)

Plugin Slug:
advanced-custom-fields

Installations
2,000,000+

Vulnerability:
Broken Access Control

Patched in Version:
6.7.1

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 6.7.1.

ManageWP Worker

Plugin Slug:
worker

Installations
1,000,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
4.9.32

Severity Score:
High


The vulnerability has been patched, so you should update to version 4.9.32.

BackWPup � WordPress Backup & Restore Plugin

Plugin Slug:
backwpup

Installations
500,000+

Vulnerability:
Local File Inclusion

Patched in Version:
5.6.7

Severity Score:
High


The vulnerability has been patched, so you should update to version 5.6.7.

Meta Box

Plugin:

Meta Box

Plugin Slug:
meta-box

Installations
500,000+

Vulnerability:
Arbitrary File Deletion

Patched in Version:
5.11.2

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 5.11.2.

WP Shortcodes Plugin � Shortcodes Ultimate

Plugin Slug:
shortcodes-ultimate

Installations
400,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
7.5.0

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 7.5.0.

Page Builder Gutenberg Blocks � CoBlocks

Plugin Slug:
coblocks

Installations
300,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
3.1.17

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 3.1.17.

Unlimited Elements For Elementor

Plugin Slug:
unlimited-elements-for-elementor

Installations
300,000+

Vulnerability:
Arbitrary File Download

Patched in Version:
2.0.7

Severity Score:
High


The vulnerability has been patched, so you should update to version 2.0.7.

PDF Invoices & Packing Slips for WooCommerce

Plugin Slug:
woocommerce-pdf-invoices-packing-slips

Installations
300,000+

Vulnerability:
PHP Object Injection

Patched in Version:
5.9.0

Severity Score:
High


The vulnerability has been patched, so you should update to version 5.9.0.

CMP � Coming Soon & Maintenance Plugin by NiteoThemes

Plugin Slug:
cmp-coming-soon-maintenance

Installations
200,000+

Vulnerability:
Arbitrary File Upload

Patched in Version:
4.1.17

Severity Score:
High


The vulnerability has been patched, so you should update to version 4.1.17.

Post Duplicator

Plugin Slug:
post-duplicator

Installations
200,000+

Vulnerability:
PHP Object Injection

Patched in Version:
3.0.11

Severity Score:
High


The vulnerability has been patched, so you should update to version 3.0.11.

JetBackup � Backup, Restore & Migrate

Plugin Slug:
backup

Installations
100,000+

Vulnerability:
Path Traversal

Patched in Version:
3.1.20.3

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 3.1.20.3.

Anti-Malware Security and Brute-Force Firewall

Plugin Slug:
gotmls

Installations
100,000+

Vulnerability:
PHP Object Injection

Patched in Version:
4.23.88

Severity Score:
High


The vulnerability has been patched, so you should update to version 4.23.88.

Kubio AI Page Builder

Plugin Slug:
kubio

Installations
100,000+

Vulnerability:
Broken Access Control

Patched in Version:
2.7.3

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.7.3.
Plugin Slug:
modula-best-grid-gallery

Installations
100,000+

Vulnerability:
PHP Object Injection

Patched in Version:
2.14.19

Severity Score:
High


The vulnerability has been patched, so you should update to version 2.14.19.

Tutor LMS � eLearning and online course solution

Plugin Slug:
tutor

Installations
100,000+

Vulnerability:
Broken Access Control

Patched in Version:
3.9.9

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 3.9.9.

Download Monitor

Plugin Slug:
download-monitor

Installations
90,000+

Vulnerability:
Arbitrary File Download

Patched in Version:
5.1.10

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 5.1.10.

Customer Reviews for WooCommerce

Plugin Slug:
customer-reviews-woocommerce

Installations
80,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
5.102.0

Severity Score:
High


The vulnerability has been patched, so you should update to version 5.102.0.

Customer Reviews for WooCommerce

Plugin Slug:
customer-reviews-woocommerce

Installations
80,000+

Vulnerability:
Broken Authentication

Patched in Version:
5.104.0

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 5.104.0.

Jupiter X Core

Plugin Slug:
jupiterx-core

Installations
80,000+

Vulnerability:
Broken Access Control

Patched in Version:
4.14.2

Severity Score:
High


The vulnerability has been patched, so you should update to version 4.14.2.

Jupiter X Core

Plugin Slug:
jupiterx-core

Installations
80,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
4.14.2

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 4.14.2.

OneSignal � Web Push Notifications

Plugin Slug:
onesignal-free-web-push-notifications

Installations
70,000+

Vulnerability:
Broken Access Control

Patched in Version:
3.8.1

Severity Score:
Low


The vulnerability has been patched, so you should update to version 3.8.1.

Germanized for WooCommerce

Plugin Slug:
woocommerce-germanized

Installations
70,000+

Vulnerability:
Content Injection

Patched in Version:
3.20.6

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 3.20.6.
Plugin Slug:
contextual-related-posts

Installations
60,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
4.2.2

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 4.2.2.

Drag and Drop Multiple File Upload for Contact Form 7

Plugin Slug:
drag-and-drop-multiple-file-upload-contact-form-7

Installations
60,000+

Vulnerability:
Arbitrary File Upload

Patched in Version:
1.3.9.7

Severity Score:
High


The vulnerability has been patched, so you should update to version 1.3.9.7.

Drag and Drop Multiple File Upload for Contact Form 7

Plugin Slug:
drag-and-drop-multiple-file-upload-contact-form-7

Installations
60,000+

Vulnerability:
Arbitrary File Download

Patched in Version:
1.3.9.7

Severity Score:
High


The vulnerability has been patched, so you should update to version 1.3.9.7.

User Registration & Membership � Free & Paid Memberships, Subscriptions, Content Restriction, User Profile, Custom User Registration & Login Builder

Plugin Slug:
user-registration

Installations
60,000+

Vulnerability:
Open Redirection

Patched in Version:
5.1.5

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 5.1.5.

Product Filter for WooCommerce by WBW

Plugin Slug:
woo-product-filter

Installations
60,000+

Vulnerability:
SQL Injection

Patched in Version:
3.1.3

Severity Score:
Critical


The vulnerability has been patched, so you should update to version 3.1.3.

Product Filter for WooCommerce by WBW

Plugin Slug:
woo-product-filter

Installations
60,000+

Vulnerability:
SQL Injection

Patched in Version:
3.1.3

Severity Score:
Critical


The vulnerability has been patched, so you should update to version 3.1.3.

Advanced Product Fields (Product Addons) for WooCommerce

Plugin Slug:
advanced-product-fields-for-woocommerce

Installations
50,000+

Vulnerability:
PHP Object Injection

Patched in Version:
1.6.20

Severity Score:
High


The vulnerability has been patched, so you should update to version 1.6.20.

Categories Images

Plugin Slug:
categories-images

Installations
50,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
3.3.2

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 3.3.2.

Better Find and Replace � AI-Powered Suggestions

Plugin Slug:
real-time-auto-find-and-replace

Installations
50,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.8.0

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.8.0.

YayMail � WooCommerce Email Customizer

Plugin Slug:
yaymail

Installations
50,000+

Vulnerability:
PHP Object Injection

Patched in Version:
4.3.4

Severity Score:
High


The vulnerability has been patched, so you should update to version 4.3.4.

Website LLMs.txt

Plugin Slug:
website-llms-txt

Installations
30,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
8.2.7

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 8.2.7.

Website LLMs.txt

Plugin Slug:
website-llms-txt

Installations
30,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
8.2.7

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 8.2.7.

WP YouTube Lyte

Plugin Slug:
wp-youtube-lyte

Installations
30,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.7.30

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.7.30.

Social Slider Feed

Plugin Slug:
instagram-slider-widget

Installations
20,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.3.3

Severity Score:
High


The vulnerability has been patched, so you should update to version 2.3.3.

Payment Gateway for Redsys & WooCommerce Lite

Plugin Slug:
woo-redsys-gateway-light

Installations
20,000+

Vulnerability:
Broken Access Control

Patched in Version:
7.0.1

Severity Score:
High


The vulnerability has been patched, so you should update to version 7.0.1.

Payment Gateway for Redsys & WooCommerce Lite

Plugin Slug:
woo-redsys-gateway-light

Installations
20,000+

Vulnerability:
Bypass Vulnerability

Patched in Version:
7.0.1

Severity Score:
High


The vulnerability has been patched, so you should update to version 7.0.1.

wpForo Forum

Plugin Slug:
wpforo

Installations
20,000+

Vulnerability:
Directory Traversal

Patched in Version:
3.0.6

Severity Score:
High


The vulnerability has been patched, so you should update to version 3.0.6.

wpForo Forum

Plugin Slug:
wpforo

Installations
20,000+

Vulnerability:
Broken Access Control

Patched in Version:
3.0.0

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 3.0.0.

wpForo Forum

Plugin Slug:
wpforo

Installations
20,000+

Vulnerability:
Arbitrary File Deletion

Patched in Version:
3.0.3

Severity Score:
High


The vulnerability has been patched, so you should update to version 3.0.3.

Content Blocks (Custom Post Widget)

Plugin Slug:
custom-post-widget

Installations
10,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
3.4.1

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 3.4.1.

WP Customer Area

Plugin Slug:
customer-area

Installations
10,000+

Vulnerability:
Arbitrary File Download

Patched in Version:
8.3.5

Severity Score:
High


The vulnerability has been patched, so you should update to version 8.3.5.

Easy Appointments

Plugin Slug:
easy-appointments

Installations
10,000+

Vulnerability:
Sensitive Data Exposure

Patched in Version:
3.12.22

Severity Score:
High


The vulnerability has been patched, so you should update to version 3.12.22.

Easy Appointments

Plugin Slug:
easy-appointments

Installations
10,000+

Vulnerability:
Broken Access Control

Patched in Version:
3.12.22

Severity Score:
High


The vulnerability has been patched, so you should update to version 3.12.22.

EMC � Easily Embed Calendly Scheduling

Plugin Slug:
embed-calendly-scheduling

Installations
10,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
4.5

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 4.5.

WP Photo Album Plus

Plugin Slug:
wp-photo-album-plus

Installations
10,000+

Vulnerability:
SQL Injection

Patched in Version:
9.1.08.002

Severity Score:
Critical


The vulnerability has been patched, so you should update to version 9.1.08.002.

YML for Yandex Market

Plugin Slug:
yml-for-yandex-market

Installations
10,000+

Vulnerability:
Remote Code Execution (RCE)

Patched in Version:
5.0.26

Severity Score:
High


The vulnerability has been patched, so you should update to version 5.0.26.

WCAPF � Ajax Product Filter for WooCommerce

Plugin Slug:
wc-ajax-product-filter

Installations
9,000+

Vulnerability:
SQL Injection

Patched in Version:
4.3.0

Severity Score:
Critical


The vulnerability has been patched, so you should update to version 4.3.0.

EventPrime � Events Calendar, Bookings and Tickets

Plugin Slug:
eventprime-event-calendar-management

Installations
7,000+

Vulnerability:
Insecure Direct Object References (IDOR)

Patched in Version:
4.3.0.1

Severity Score:
High


The vulnerability has been patched, so you should update to version 4.3.0.1.

ActivityPub

Plugin Slug:
activitypub

Installations
6,000+

Vulnerability:
Sensitive Data Exposure

Patched in Version:
8.0.2

Severity Score:
High


The vulnerability has been patched, so you should update to version 8.0.2.

Nexi XPay

Plugin Slug:
cartasi-x-pay

Installations
6,000+

Vulnerability:
Broken Access Control

Patched in Version:
8.3.2

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 8.3.2.

Booking Activities

Plugin Slug:
booking-activities

Installations
4,000+

Vulnerability:
Broken Access Control

Patched in Version:
1.17.0

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.17.0.

Notification for Telegram

Plugin Slug:
notification-for-telegram

Installations
4,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
3.5.1

Severity Score:
High


The vulnerability has been patched, so you should update to version 3.5.1.

Responsive Blocks � Page Builder for Blocks & Patterns

Plugin Slug:
responsive-block-editor-addons

Installations
4,000+

Vulnerability:
Open Redirection

Patched in Version:
2.2.1

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.2.1.

Basic Google Maps Placemarks

Plugin Slug:
basic-google-maps-placemarks

Installations
3,000+

Vulnerability:
Broken Access Control

Patched in Version:
1.10.8

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.10.8.

Events Calendar for GeoDirectory

Plugin Slug:
events-for-geodirectory

Installations
3,000+

Vulnerability:
PHP Object Injection

Patched in Version:
2.3.26

Severity Score:
High


The vulnerability has been patched, so you should update to version 2.3.26.

SpeakOut! Email Petitions

Plugin Slug:
speakout

Installations
3,000+

Vulnerability:
SQL Injection

Patched in Version:
4.6.5.1

Severity Score:
Critical


The vulnerability has been patched, so you should update to version 4.6.5.1.

WP Directory Kit

Plugin Slug:
wpdirectorykit

Installations
3,000+

Vulnerability:
SQL Injection

Patched in Version:
1.5.1

Severity Score:
Critical


The vulnerability has been patched, so you should update to version 1.5.1.

Prismatic

Plugin Slug:
prismatic

Installations
2,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
3.7.4

Severity Score:
High


The vulnerability has been patched, so you should update to version 3.7.4.

Shipment Tracker for Woocommerce

Plugin Slug:
shipment-tracker-for-woocommerce

Installations
2,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.5.3.3

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.5.3.3.

MyRewards

Plugin Slug:
woorewards

Installations
2,000+

Vulnerability:
Broken Access Control

Patched in Version:
5.7.4

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 5.7.4.

Mini Ajax Cart for WooCommerce

Plugin Slug:
mini-ajax-woo-cart

Installations
1,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.3.5

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.3.5.

WP Docs

Plugin:

WP Docs

Plugin Slug:
wp-docs

Installations
1,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.3.0

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.3.0.
Plugin Slug:
inpost-gallery

Installations
800+

Vulnerability:
SQL Injection

Patched in Version:
2.1.5

Severity Score:
Critical


The vulnerability has been patched, so you should update to version 2.1.5.

WP Sessions Time Monitoring Full Automatic

Plugin Slug:
activitytime

Installations
600+

Vulnerability:
SQL Injection

Patched in Version:
1.1.5

Severity Score:
High


The vulnerability has been patched, so you should update to version 1.1.5.

List View Google Calendar

Plugin Slug:
list-view-google-calendar

Installations
500+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
7.4.4

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 7.4.4.

Webling

Plugin:

Webling

Plugin Slug:
webling

Installations
500+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
3.9.1

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 3.9.1.

Flipbox Addon for Elementor

Plugin Slug:
ultimate-flipbox-addon-for-elementor

Installations
300+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.1.2

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.1.2.

BuddyPress Groupblog

Plugin Slug:
bp-groupblog

Installations
50+

Vulnerability:
Privilege Escalation

Patched in Version:
1.9.4

Severity Score:
High


The vulnerability has been patched, so you should update to version 1.9.4.

Ultra Addons for WPForms

Plugin Slug:
ultra-addons-for-wpforms

Installations
40+

Vulnerability:
Broken Access Control

Patched in Version:
1.0.12

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.0.12.

Hostel

Plugin:

Hostel

Plugin Slug:
hostel

Installations
30+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.1.7

Severity Score:
High


The vulnerability has been patched, so you should update to version 1.1.7.

HAPPY � Helpdesk Support Ticket System

Plugin Slug:
happy-helpdesk-support-ticket-system

Installations
10+

Vulnerability:
Broken Access Control

Patched in Version:
1.0.11

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.0.11.

Surbma | Booking.com Shortcode

Plugin Slug:
surbma-bookingcom-shortcode

Installations
10+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.1.1

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.1.1.

WholeSale Products Dynamic Pricing Management WooCommerce

Plugin Slug:
wholesale-products-dynamic-pricing-management-woocommerce

Installations
10+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.3.0

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.3.0.

Academy LMS Pro

Plugin:

Academy LMS Pro

Plugin Slug:
academy-pro

Vulnerability:
Arbitrary File Upload

Patched in Version:
3.5.2

Severity Score:
High


The vulnerability has been patched, so you should update to version 3.5.2.

Accordion and Accordion Slider

Plugin:

Accordion and Accordion Slider

Plugin Slug:
accordion-and-accordion-slider

Vulnerability:
Backdoor

Patched in Version:
1.4.6.1

Severity Score:
Critical


The vulnerability has been patched, so you should update to version 1.4.6.1.
Plugin:

Album and Image Gallery plus Lightbox

Plugin Slug:
album-and-image-gallery-plus-lightbox

Vulnerability:
Backdoor

Patched in Version:
2.1.8.1

Severity Score:
Critical


The vulnerability has been patched, so you should update to version 2.1.8.1.

Blog Designer – Post and Widget

Plugin:

Blog Designer – Post and Widget

Plugin Slug:
blog-designer-for-post-and-widget

Vulnerability:
Backdoor

Patched in Version:
2.7.7.1

Severity Score:
Critical


The vulnerability has been patched, so you should update to version 2.7.7.1.

Career Section

Plugin Slug:
career-section

Vulnerability:
Arbitrary File Deletion

Patched in Version:
1.7

Severity Score:
High


The vulnerability has been patched, so you should update to version 1.7.

Countdown Timer Ultimate

Plugin:

Countdown Timer Ultimate

Plugin Slug:
countdown-timer-ultimate

Vulnerability:
Backdoor

Patched in Version:
2.6.9.1

Severity Score:
Critical


The vulnerability has been patched, so you should update to version 2.6.9.1.

Featured Post Creative

Plugin:

Featured Post Creative

Plugin Slug:
featured-post-creative

Vulnerability:
Backdoor

Patched in Version:
1.5.7.1

Severity Score:
Critical


The vulnerability has been patched, so you should update to version 1.5.7.1.

Fusion Builder

Plugin:

Fusion Builder

Plugin Slug:
fusion-builder

Vulnerability:
Content Injection

Patched in Version:
3.15.2

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 3.15.2.

Fusion Builder

Plugin:

Fusion Builder

Plugin Slug:
fusion-builder

Vulnerability:
Sensitive Data Exposure

Patched in Version:
3.15.2

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 3.15.2.

Gravity SMTP

Plugin:

Gravity SMTP

Plugin Slug:
gravitysmtp

Vulnerability:
Broken Access Control

Patched in Version:
2.1.5

Severity Score:
High


The vulnerability has been patched, so you should update to version 2.1.5.
Plugin:

Video gallery and Player

Plugin Slug:
html5-videogallery-plus-player

Vulnerability:
Backdoor

Patched in Version:
2.8.7.1

Severity Score:
Critical


The vulnerability has been patched, so you should update to version 2.8.7.1.

JetEngine

Plugin:

JetEngine

Plugin Slug:
jet-engine

Vulnerability:
SQL Injection

Patched in Version:
3.8.6.2

Severity Score:
Critical


The vulnerability has been patched, so you should update to version 3.8.6.2.

Client Portal (Pro)

Plugin:

Client Portal (Pro)

Plugin Slug:
leco-client-portal

Vulnerability:
Arbitrary File Download

Patched in Version:
5.6.3

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 5.6.3.
Plugin:

Meta slider and carousel with lightbox

Plugin Slug:
meta-slider-and-carousel-with-lightbox

Vulnerability:
Backdoor

Patched in Version:
2.0.8.1

Severity Score:
Critical


The vulnerability has been patched, so you should update to version 2.0.8.1.

MetForm Pro

Plugin:

MetForm Pro

Plugin Slug:
metform-pro

Vulnerability:
Broken Access Control

Patched in Version:
3.9.8

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 3.9.8.

Popup Anything

Plugin:

Popup Anything

Plugin Slug:
popup-anything-on-click

Vulnerability:
Backdoor

Patched in Version:
2.9.1.1

Severity Score:
Critical


The vulnerability has been patched, so you should update to version 2.9.1.1.

Portfolio and Projects

Plugin:

Portfolio and Projects

Plugin Slug:
portfolio-and-projects

Vulnerability:
Backdoor

Patched in Version:
1.5.6.1

Severity Score:
Critical


The vulnerability has been patched, so you should update to version 1.5.6.1.

Post grid and filter ultimate

Plugin:

Post grid and filter ultimate

Plugin Slug:
post-grid-and-filter-ultimate

Vulnerability:
Backdoor

Patched in Version:
1.7.4.1

Severity Score:
Critical


The vulnerability has been patched, so you should update to version 1.7.4.1.

WP responsive FAQ with category

Plugin:

WP responsive FAQ with category

Plugin Slug:
sp-faq

Vulnerability:
Backdoor

Patched in Version:
3.9.5.1

Severity Score:
Critical


The vulnerability has been patched, so you should update to version 3.9.5.1.

WP News and Scrolling Widgets

Plugin:

WP News and Scrolling Widgets

Plugin Slug:
sp-news-and-widget

Vulnerability:
Backdoor

Patched in Version:
5.0.6.1

Severity Score:
Critical


The vulnerability has been patched, so you should update to version 5.0.6.1.

WowShipping Pro

Plugin:

WowShipping Pro

Plugin Slug:
table-rate-shipping-pro

Vulnerability:
Backdoor

Patched in Version:
1.0.8

Severity Score:
Critical


The vulnerability has been patched, so you should update to version 1.0.8.

Post Ticker Ultimate

Plugin:

Post Ticker Ultimate

Plugin Slug:
ticker-ultimate

Vulnerability:
Backdoor

Patched in Version:
1.7.6.1

Severity Score:
Critical


The vulnerability has been patched, so you should update to version 1.7.6.1.

Timeline and History slider

Plugin:

Timeline and History slider

Plugin Slug:
timeline-and-history-slider

Vulnerability:
Backdoor

Patched in Version:
2.4.5.1

Severity Score:
Critical


The vulnerability has been patched, so you should update to version 2.4.5.1.

User Registration Stripe

Plugin:

User Registration Stripe

Plugin Slug:
user-registration-stripe

Vulnerability:
Broken Access Control

Patched in Version:
1.3.15

Severity Score:
High


The vulnerability has been patched, so you should update to version 1.3.15.

Userpro

Plugin:

Userpro

Plugin Slug:
userpro

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
5.1.11

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 5.1.11.

Product Pricing Table by WooBeWoo

Plugin:

Product Pricing Table by WooBeWoo

Plugin Slug:
woo-product-pricing-tables

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.1.1

Severity Score:
High


The vulnerability has been patched, so you should update to version 1.1.1.

WooCommerce Product Filters

Plugin:

WooCommerce Product Filters

Plugin Slug:
woocommerce-product-filters

Vulnerability:
PHP Object Injection

Patched in Version:
2.0.6

Severity Score:
Critical


The vulnerability has been patched, so you should update to version 2.0.6.

WP Blog and Widget

Plugin:

WP Blog and Widget

Plugin Slug:
wp-blog-and-widgets

Vulnerability:
Backdoor

Patched in Version:
2.6.6.1

Severity Score:
Critical


The vulnerability has been patched, so you should update to version 2.6.6.1.
Plugin:

WP Featured Content and Slider

Plugin Slug:
wp-featured-content-and-slider

Vulnerability:
Backdoor

Patched in Version:
1.7.6.1

Severity Score:
Critical


The vulnerability has been patched, so you should update to version 1.7.6.1.
Plugin:

WP Logo Showcase Responsive Slider and Carousel

Plugin Slug:
wp-logo-showcase-responsive-slider-slider

Vulnerability:
Backdoor

Patched in Version:
3.8.7.1

Severity Score:
Critical


The vulnerability has been patched, so you should update to version 3.8.7.1.

WP Responsive Recent Post Slider/Carousel

Plugin:

WP Responsive Recent Post Slider/Carousel

Plugin Slug:
wp-responsive-recent-post-slider

Vulnerability:
Backdoor

Patched in Version:
3.7.1.1

Severity Score:
Critical


The vulnerability has been patched, so you should update to version 3.7.1.1.
Plugin:

WP Slick Slider and Image Carousel

Plugin Slug:
wp-slick-slider-and-image-carousel

Vulnerability:
Backdoor

Patched in Version:
3.7.8.2

Severity Score:
Critical


The vulnerability has been patched, so you should update to version 3.7.8.2.
Plugin:

Team Slider and Team Grid Showcase plus Team Carousel

Plugin Slug:
wp-team-showcase-and-slider

Vulnerability:
Backdoor

Patched in Version:
2.8.6.1

Severity Score:
Critical


The vulnerability has been patched, so you should update to version 2.8.6.1.
Plugin:

Testimonial Grid and Testimonial Slider plus Carousel with Rotator Widget

Plugin Slug:
wp-testimonial-with-widget

Vulnerability:
Backdoor

Patched in Version:
3.5.6.1

Severity Score:
Critical


The vulnerability has been patched, so you should update to version 3.5.6.1.

Trending/Popular Post Slider and Widget

Plugin:

Trending/Popular Post Slider and Widget

Plugin Slug:
wp-trending-post-slider-and-widget

Vulnerability:
Backdoor

Patched in Version:
1.8.6.1

Severity Score:
Critical


The vulnerability has been patched, so you should update to version 1.8.6.1.

Royal Elementor Addons Pro

Plugin:

Royal Elementor Addons Pro

Plugin Slug:
wpr-addons-pro

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.7.1041

Severity Score:
High


The vulnerability has been patched, so you should update to version 1.7.1041.

WordPress Themes � 28 Patched / 1 Unpatched

WebStack

Theme:

WebStack

Theme Slug:
webstack

Vulnerability:
Arbitrary File Upload

Patched in Version:
No Fix

Severity Score:
Critical


The vulnerability has not been patched. You should switch themes.

Charity Zone

Theme Slug:
charity-zone

Downloads
112,126

Vulnerability:
Arbitrary File Upload

Patched in Version:
1.1.2

Severity Score:
Critical


The vulnerability has been patched, so you should update to version 1.1.2.

Ecommerce Zone

Theme Slug:
ecommerce-zone

Downloads
89,443

Vulnerability:
Arbitrary File Upload

Patched in Version:
0.9.8

Severity Score:
Critical


The vulnerability has been patched, so you should update to version 0.9.8.

Kids Gift Shop

Theme Slug:
kids-gift-shop

Downloads
20,521

Vulnerability:
Arbitrary File Upload

Patched in Version:
0.5.5

Severity Score:
Critical


The vulnerability has been patched, so you should update to version 0.5.5.

Kids Online Store

Theme Slug:
kids-online-store

Downloads
53,065

Vulnerability:
Arbitrary File Upload

Patched in Version:
0.9.0

Severity Score:
Critical


The vulnerability has been patched, so you should update to version 0.9.0.

Restaurant Zone

Theme Slug:
restaurant-zone

Downloads
80,108

Vulnerability:
Arbitrary File Upload

Patched in Version:
0.7.9

Severity Score:
Critical


The vulnerability has been patched, so you should update to version 0.7.9.

Vantage

Theme:

Vantage

Theme Slug:
vantage

Downloads
3,232,270

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.20.33

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.20.33.

Webenvo

Theme:

Webenvo

Theme Slug:
webenvo

Downloads
10,224

Vulnerability:
Arbitrary File Upload

Patched in Version:
0.0.7

Severity Score:
Critical


The vulnerability has been patched, so you should update to version 0.0.7.

Ashtanga

Theme:

Ashtanga

Theme Slug:
ashtanga

Vulnerability:
PHP Object Injection

Patched in Version:
1.3

Severity Score:
High


The vulnerability has been patched, so you should update to version 1.3.

Atomlab

Theme:

Atomlab

Theme Slug:
atomlab

Vulnerability:
Local File Inclusion

Patched in Version:
2.4.6

Severity Score:
High


The vulnerability has been patched, so you should update to version 2.4.6.

Behold

Theme:

Behold

Theme Slug:
behold

Vulnerability:
PHP Object Injection

Patched in Version:
1.6

Severity Score:
High


The vulnerability has been patched, so you should update to version 1.6.

ChapterOne

Theme:

ChapterOne

Theme Slug:
chapterone

Vulnerability:
Local File Inclusion

Patched in Version:
1.8

Severity Score:
High


The vulnerability has been patched, so you should update to version 1.8.

Ch�teau

Theme:

Ch�teau

Theme Slug:
chateau

Vulnerability:
PHP Object Injection

Patched in Version:
1.3

Severity Score:
High


The vulnerability has been patched, so you should update to version 1.3.

EasyMeals

Theme:

EasyMeals

Theme Slug:
easymeals

Vulnerability:
PHP Object Injection

Patched in Version:
1.6

Severity Score:
High


The vulnerability has been patched, so you should update to version 1.6.

Eldon

Theme:

Eldon

Theme Slug:
eldon

Vulnerability:
PHP Object Injection

Patched in Version:
1.5

Severity Score:
High


The vulnerability has been patched, so you should update to version 1.5.

Eleganzo

Theme:

Eleganzo

Theme Slug:
eleganzo

Vulnerability:
Path Traversal

Patched in Version:
1.3

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.3.

Elementra

Theme:

Elementra

Theme Slug:
elementra

Vulnerability:
PHP Object Injection

Patched in Version:
1.1.0

Severity Score:
Critical


The vulnerability has been patched, so you should update to version 1.1.0.

Esm�e

Theme:

Esm�e

Theme Slug:
esme

Vulnerability:
PHP Object Injection

Patched in Version:
1.5

Severity Score:
High


The vulnerability has been patched, so you should update to version 1.5.

Laurits

Theme:

Laurits

Theme Slug:
laurits

Vulnerability:
PHP Object Injection

Patched in Version:
1.6

Severity Score:
High


The vulnerability has been patched, so you should update to version 1.6.

L�onie

Theme:

L�onie

Theme Slug:
lonie

Vulnerability:
PHP Object Injection

Patched in Version:
1.3

Severity Score:
High


The vulnerability has been patched, so you should update to version 1.3.

LuxeDrive

Theme:

LuxeDrive

Theme Slug:
luxedrive

Vulnerability:
PHP Object Injection

Patched in Version:
1.5

Severity Score:
High


The vulnerability has been patched, so you should update to version 1.5.

MagOne

Theme:

MagOne

Theme Slug:
magone

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
9.1

Severity Score:
High


The vulnerability has been patched, so you should update to version 9.1.

Manufaktur Solutions

Theme:

Manufaktur Solutions

Theme Slug:
manufaktursolutions

Vulnerability:
PHP Object Injection

Patched in Version:
1.2

Severity Score:
High


The vulnerability has been patched, so you should update to version 1.2.

Reina

Theme:

Reina

Theme Slug:
reina

Vulnerability:
PHP Object Injection

Patched in Version:
2.2

Severity Score:
High


The vulnerability has been patched, so you should update to version 2.2.

Roisin

Theme:

Roisin

Theme Slug:
roisin

Vulnerability:
PHP Object Injection

Patched in Version:
1.5

Severity Score:
High


The vulnerability has been patched, so you should update to version 1.5.

ShiftUp

Theme:

ShiftUp

Theme Slug:
shiftup

Vulnerability:
PHP Object Injection

Patched in Version:
1.4

Severity Score:
High


The vulnerability has been patched, so you should update to version 1.4.
Theme:

TechLink

Theme Slug:
techlink

Vulnerability:
PHP Object Injection

Patched in Version:
1.4

Severity Score:
High


The vulnerability has been patched, so you should update to version 1.4.

Valeska

Theme:

Valeska

Theme Slug:
valeska

Vulnerability:
PHP Object Injection

Patched in Version:
1.3

Severity Score:
High


The vulnerability has been patched, so you should update to version 1.3.

Zoya

Theme:

Zoya

Theme Slug:
zoya

Vulnerability:
PHP Object Injection

Patched in Version:
1.5

Severity Score:
High


The vulnerability has been patched, so you should update to version 1.5.

Related articles

Wait! Get exclusive hosting insights

Subscribe to our newsletter and stay ahead of the competition with expert advice from our hosting pros.

Loading form…