Line illustration showing a black application window on a red gradient background overlaid with a large exclamation point alert icon and three bugs.

WordPress Vulnerability Report � April 9, 2025

In this report, 612 vulnerabilities have been publicly disclosed. Security patches for 108 of these plugins and themes are available now, so run those updates as soon as possible. If you’re a Solid Security Pro user, the version management tool may have already warned you and updated these plugins, depending on your settings.

Additionally, there are 504 plugin and theme vulnerabilities with no patch available yet. If you’re a Solid Security Pro user, those vulnerabilities are already protected by the Solid Security firewall. Virtual patches from Patchstack will be applied when a vulnerability is considered high or medium risk. If no patch is forthcoming from the vendor or the vulnerable software has been marked “closed” and dropped from the official WordPress repositories, you should deactivate it soon and look for alternative solutions.

WordPress Core

The third release candidate (�RC3�) for WordPress 6.8 is ready for download and testing. This version of the WordPress software is under development. Please do not install, run, or test this version of WordPress on production or mission-critical websites. Instead, it�s recommended that you evaluate RC3 on a test server and site.

WordPress Plugins � 103 Patched / 480 Unpatched

CMP � Coming Soon & Maintenance Plugin by NiteoThemes

Plugin Slug:
cmp-coming-soon-maintenance

Installations
200,000+

Vulnerability:
Arbitrary File Upload

Patched in Version:
No Fix

Severity Score:
Critical


The vulnerability has not been patched. You should deactivate the plugin.

Colibri Page Builder

Plugin Slug:
colibri-page-builder

Installations
100,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

ShareThis Dashboard for Google Analytics

Plugin Slug:
googleanalytics

Installations
100,000+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Brizy � Page Builder

Plugin Slug:
brizy

Installations
80,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

WP ULike � All-in-One Engagement Toolkit

Plugin Slug:
wp-ulike

Installations
80,000+

Vulnerability:
Content Spoofing

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

ActiveCampaign � Forms, Site Tracking, Live Chat

Plugin Slug:
activecampaign-subscription-forms

Installations
50,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

DethemeKit for Elementor

Plugin Slug:
dethemekit-for-elementor

Installations
40,000+

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Piotnet Addons For Elementor

Plugin Slug:
piotnet-addons-for-elementor

Installations
40,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Themesflat Addons For Elementor

Plugin Slug:
themesflat-addons-for-elementor

Installations
40,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Booster for WooCommerce

Plugin Slug:
woocommerce-jetpack

Installations
40,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Advanced WordPress Backgrounds

Plugin Slug:
advanced-backgrounds

Installations
30,000+

Vulnerability:
Content Injection

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Ecwid by Lightspeed Ecommerce Shopping Cart

Plugin Slug:
ecwid-shopping-cart

Installations
20,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Read More & Accordion

Plugin Slug:
expand-maker

Installations
20,000+

Vulnerability:
Local File Inclusion

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Easy Google Maps

Plugin Slug:
google-maps-easy

Installations
20,000+

Vulnerability:
XML External Entity (XXE)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Secure Copy Content Protection and Content Locking

Plugin Slug:
secure-copy-content-protection

Installations
20,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

140+ Widgets | Xpro Addons For Elementor � FREE

Plugin Slug:
xpro-elementor-addons

Installations
20,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Advanced Woo Labels � Product Labels for WooCommerce

Plugin Slug:
advanced-woo-labels

Installations
10,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Asgaros Forum

Plugin Slug:
asgaros-forum

Installations
10,000+

Vulnerability:
Bypass Vulnerability

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Flo Forms � Easy Drag & Drop Form Builder

Plugin Slug:
flo-forms

Installations
10,000+

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

LA-Studio Element Kit for Elementor

Plugin Slug:
lastudio-element-kit

Installations
10,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Motors � Car Dealership & Classified Listings Plugin

Plugin Slug:
motors-car-dealership-classified-listings

Installations
10,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Motors � Car Dealership & Classified Listings Plugin

Plugin Slug:
motors-car-dealership-classified-listings

Installations
10,000+

Vulnerability:
Local File Inclusion

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

OSM � OpenStreetMap

Plugin Slug:
osm

Installations
10,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

WP-LESS

Plugin:

WP-LESS

Plugin Slug:
wp-less

Installations
10,000+

Vulnerability:
Sensitive Data Exposure

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

WPCargo Track & Trace

Plugin Slug:
wpcargo

Installations
10,000+

Vulnerability:
Insecure Direct Object References (IDOR)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Xpro Theme Builder For Elementor � FREE

Plugin Slug:
xpro-theme-builder

Installations
10,000+

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

YaMaps for WordPress Plugin

Plugin Slug:
yamaps

Installations
10,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

WP Mobile Bottom Menu

Plugin Slug:
mobile-bottom-menu-for-wp

Installations
8,000+

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

IMPress for IDX Broker

Plugin Slug:
idx-broker-platinum

Installations
7,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

WordPress Header Builder Plugin � Pearl

Plugin Slug:
pearl-header-builder

Installations
7,000+

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

WordPress Header Builder Plugin � Pearl

Plugin Slug:
pearl-header-builder

Installations
7,000+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

EventON � Events Calendar

Plugin Slug:
eventon-lite

Installations
6,000+

Vulnerability:
Local File Inclusion

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Sliced Invoices � WordPress Invoice Plugin

Plugin Slug:
sliced-invoices

Installations
6,000+

Vulnerability:
Insecure Direct Object References (IDOR)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Specia Companion

Plugin Slug:
specia-companion

Installations
6,000+

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Survey Maker

Plugin Slug:
survey-maker

Installations
6,000+

Vulnerability:
Bypass Vulnerability

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.
Plugin Slug:
vk-filter-search

Installations
6,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Directorist AddonsKit for Elementor

Plugin Slug:
addonskit-for-elementor

Installations
5,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

aThemes Addons for Elementor

Plugin Slug:
athemes-addons-for-elementor-lite

Installations
5,000+

Vulnerability:
Local File Inclusion

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Fusion Page Builder

Plugin Slug:
fusion

Installations
4,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.
Plugin Slug:
hyperlink-group-block

Installations
4,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Flag Icons

Plugin Slug:
language-icons-flags-switcher

Installations
4,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Privyr CRM � Instant Lead Alerts for Contact Forms

Plugin Slug:
privy-crm-integration

Installations
4,000+

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.
Plugin Slug:
simple-icons

Installations
4,000+

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Split Test For Elementor

Plugin Slug:
split-test-for-elementor

Installations
4,000+

Vulnerability:
SQL Injection

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Split Test For Elementor

Plugin Slug:
split-test-for-elementor

Installations
4,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Widgetize Pages Light

Plugin Slug:
widgetize-pages-light

Installations
4,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Fonto � Custom Web Fonts Manager

Plugin Slug:
fonto

Installations
3,000+

Vulnerability:
Arbitrary File Download

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Libro de Reclamaciones y Quejas

Plugin Slug:
libro-de-reclamaciones-y-quejas

Installations
3,000+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

News Kit Elementor Addons

Plugin Slug:
news-kit-elementor-addons

Installations
3,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Piotnet Forms

Plugin Slug:
piotnetforms

Installations
3,000+

Vulnerability:
Path Traversal

Patched in Version:
No Fix

Severity Score:
Low


The vulnerability has not been patched. You should deactivate the plugin.

Piotnet Forms

Plugin Slug:
piotnetforms

Installations
3,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Piotnet Forms

Plugin Slug:
piotnetforms

Installations
3,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Social Share Buttons & Analytics Plugin � GetSocial.io

Plugin Slug:
wp-share-buttons-analytics-by-getsocial

Installations
3,000+

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Ai Image Alt Text Generator for WP

Plugin Slug:
ai-image-alt-text-generator-for-wp

Installations
2,000+

Vulnerability:
Sensitive Data Exposure

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Ai Image Alt Text Generator for WP

Plugin Slug:
ai-image-alt-text-generator-for-wp

Installations
2,000+

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Beam me up Scotty � Back to Top Button

Plugin Slug:
beam-me-up-scotty

Installations
2,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Beds24 Online Booking

Plugin Slug:
beds24-online-booking

Installations
2,000+

Vulnerability:
Local File Inclusion

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Bulk NoIndex & NoFollow Toolkit

Plugin Slug:
bulk-noindex-nofollow-toolkit-by-mad-fish

Installations
2,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Category Icon

Plugin Slug:
category-icon

Installations
2,000+

Vulnerability:
Arbitrary File Download

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Docxpresso

Plugin Slug:
docxpresso

Installations
2,000+

Vulnerability:
Arbitrary File Download

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.
Plugin Slug:
easy-media-gallery

Installations
2,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

ELEX WooCommerce Request a Quote

Plugin Slug:
elex-request-a-quote

Installations
2,000+

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

MX Time Zone Clocks

Plugin Slug:
mx-time-zone-clocks

Installations
2,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Safe Ai Malware Protection for WP

Plugin Slug:
safe-ai-malware-protection-for-wp

Installations
2,000+

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

SrbTransLatin � Serbian Latinisation

Plugin Slug:
srbtranslatin

Installations
2,000+

Vulnerability:
Sensitive Data Exposure

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Timeline Event History

Plugin Slug:
timeline-event-history

Installations
2,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Tockify Events Calendar

Plugin Slug:
tockify-events-calendar

Installations
2,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.
Plugin Slug:
wp-modal-popup-with-cookie-integration

Installations
2,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

WordPress Simple HTML Sitemap

Plugin Slug:
wp-simple-html-sitemap

Installations
2,000+

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

WPoperation Elementor Addons

Plugin Slug:
wpop-elementor-addons

Installations
2,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Black Widgets For Elementor

Plugin Slug:
black-widgets

Installations
1,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

BuddyPress Members Only

Plugin Slug:
buddypress-members-only

Installations
1,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Cal.com

Plugin:

Cal.com

Plugin Slug:
cal-com

Installations
1,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

CLP � Custom Login Page by NiteoThemes

Plugin Slug:
clp-custom-login-page

Installations
1,000+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Contact Form Builder by vcita

Plugin Slug:
contact-form-with-a-meeting-scheduler-by-vcita

Installations
1,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Cryptocurrency Widgets Pack

Plugin Slug:
cryptocurrency-widgets-pack

Installations
1,000+

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Astra Security Suite � Firewall & Malware Scan

Plugin Slug:
getastra

Installations
1,000+

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Gutena Kit � Gutenberg Blocks and Templates

Plugin Slug:
gutena-kit

Installations
1,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Nova Blocks by Pixelgrade

Plugin Slug:
nova-blocks

Installations
1,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

onOffice for WP-Websites

Plugin Slug:
onoffice-for-wp-websites

Installations
1,000+

Vulnerability:
SQL Injection

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

PDF Generator Addon for Elementor Page Builder

Plugin Slug:
pdf-generator-addon-for-elementor-page-builder

Installations
1,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

RestroPress � Online Food Ordering System

Plugin Slug:
restropress

Installations
1,000+

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Sequential Order Numbers for WooCommerce

Plugin Slug:
sequential-order-numbers-for-woocommerce

Installations
1,000+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Sidebar Manager Light

Plugin Slug:
sidebar-manager-light

Installations
1,000+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Simple Sticky Add To Cart For WooCommerce

Plugin Slug:
sticky-add-to-cart-woo

Installations
1,000+

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Swiss Toolkit For WP

Plugin Slug:
swiss-toolkit-for-wp

Installations
1,000+

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Swiss Toolkit For WP

Plugin Slug:
swiss-toolkit-for-wp

Installations
1,000+

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Video Playlist For YouTube

Plugin Slug:
video-playlist-for-youtube

Installations
1,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

WordPress Webinar Plugin � WebinarPress

Plugin Slug:
wp-webinarsystem

Installations
1,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

WordPress Webinar Plugin � WebinarPress

Plugin Slug:
wp-webinarsystem

Installations
1,000+

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

WP AdCenter � Ad Manager & Adsense Ads

Plugin Slug:
wpadcenter

Installations
1,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

mb.YTPlayer for background videos

Plugin Slug:
wpmbytplayer

Installations
1,000+

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Follow Us Badges

Plugin Slug:
wpsite-follow-us-badges

Installations
1,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

B Blocks � The ultimate block collection

Plugin Slug:
b-blocks

Installations
900+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

ContentBot AI Writer (ChatGPT, GPT4)

Plugin Slug:
content-bot

Installations
900+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Post Custom Templates Lite

Plugin Slug:
post-custom-templates-lite

Installations
900+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Rollbar

Plugin:

Rollbar

Plugin Slug:
rollbar

Installations
900+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.
Plugin Slug:
ultraaddons-elementor-lite

Installations
900+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

404 Image Redirection (Replace Broken Images)

Plugin Slug:
broken-images-redirection

Installations
800+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Doppler Forms

Plugin Slug:
doppler-form

Installations
800+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

JS Job Manager

Plugin Slug:
js-jobs

Installations
800+

Vulnerability:
Local File Inclusion

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

JS Job Manager

Plugin Slug:
js-jobs

Installations
800+

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

JS Job Manager

Plugin Slug:
js-jobs

Installations
800+

Vulnerability:
Insecure Direct Object References (IDOR)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Product Notices for WooCommerce

Plugin Slug:
product-notices-for-woocommerce

Installations
800+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Query Wrangler

Plugin Slug:
query-wrangler

Installations
800+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

SheetDB � get your Google Spreadsheet data

Plugin Slug:
sheetdb

Installations
800+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

TailPress � Tailwind for WordPress

Plugin Slug:
tailpress

Installations
800+

Vulnerability:
Sensitive Data Exposure

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

TuriTop Booking System

Plugin Slug:
turitop-booking-system

Installations
800+

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Widget Manager Light

Plugin Slug:
widget-manager-light

Installations
800+

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Group Chat & Video Chat by AtomChat

Plugin Slug:
atomchat

Installations
700+

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Group Chat & Video Chat by AtomChat

Plugin Slug:
atomchat

Installations
700+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Broadstreet

Plugin Slug:
broadstreet

Installations
700+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Broadstreet

Plugin Slug:
broadstreet

Installations
700+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Easy!Appointments

Plugin Slug:
easyappointments

Installations
700+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Magical Blocks � Premium Gutenberg Blocks

Plugin Slug:
magical-blocks

Installations
700+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Accessibility Suite by Ability, Inc

Plugin Slug:
online-accessibility

Installations
700+

Vulnerability:
Arbitrary File Upload

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

QR Code Tag for WC order emails, POS receipt emails, PDF invoices, PDF packing slips, Blog posts, Custom post types and Pages (from goaskle.com)

Plugin Slug:
qr-code-tag-for-wc-from-goaskle-com

Installations
700+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

SCSS WP Editor

Plugin Slug:
scss-wp-editor

Installations
700+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.
Plugin Slug:
simple-owl-carousel

Installations
700+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Slider Path for Elementor

Plugin Slug:
slider-path

Installations
700+

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

SnapWidget Social Photo Feed Widget

Plugin Slug:
snapwidget-wp-instagram-widget

Installations
700+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

StaticPress

Plugin Slug:
staticpress

Installations
700+

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

WP Plugin Info Card

Plugin Slug:
wp-plugin-info-card

Installations
700+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

SMS Abandoned Cart Recovery ? CartBoss

Plugin Slug:
cartboss

Installations
600+

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Custom Database Applications by Caspio

Plugin Slug:
custom-database-applications-by-caspio

Installations
600+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Daisycon prijsvergelijkers

Plugin Slug:
daisycon

Installations
600+

Vulnerability:
SQL Injection

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Embed Chessboard

Plugin Slug:
embed-chessboard

Installations
600+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

FPW Category Thumbnails

Plugin Slug:
fpw-category-thumbnails

Installations
600+

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Google SEO Pressor for Rich snippets

Plugin Slug:
google-seo-author-snippets

Installations
600+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Google SEO Pressor for Rich snippets

Plugin Slug:
google-seo-author-snippets

Installations
600+

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

History Log by click5

Plugin Slug:
history-log-by-click5

Installations
600+

Vulnerability:
SQL Injection

Patched in Version:
No Fix

Severity Score:
Critical


The vulnerability has not been patched. You should deactivate the plugin.

Integration of Zoho CRM and Contact Form 7

Plugin Slug:
integration-of-zoho-crm-and-contact-form-7

Installations
600+

Vulnerability:
Open Redirection

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

My auctions allegro

Plugin Slug:
my-auctions-allegro-free-edition

Installations
600+

Vulnerability:
SQL Injection

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

OwnerRez

Plugin:

OwnerRez

Plugin Slug:
ownerrez

Installations
600+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Behance Portfolio Manager

Plugin Slug:
portfolio-manager-powered-by-behance

Installations
600+

Vulnerability:
SQL Injection

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Behance Portfolio Manager

Plugin Slug:
portfolio-manager-powered-by-behance

Installations
600+

Vulnerability:
SQL Injection

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Publitio

Plugin:

Publitio

Plugin Slug:
publitio

Installations
600+

Vulnerability:
Arbitrary File Download

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Publitio

Plugin:

Publitio

Plugin Slug:
publitio

Installations
600+

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Publitio

Plugin:

Publitio

Plugin Slug:
publitio

Installations
600+

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Question Answer

Plugin Slug:
question-answer

Installations
600+

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Sheet2Site

Plugin Slug:
sheet2site

Installations
600+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Showeblogin Social Plugin

Plugin Slug:
showeblogin-facebook-page-like-box

Installations
600+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Simple Post Expiration

Plugin Slug:
simple-post-expiration

Installations
600+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

TextMe SMS

Plugin Slug:
textme-sms-integration

Installations
600+

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

UPC/EAN/GTIN Code Generator

Plugin Slug:
upc-ean-barcode-generator

Installations
600+

Vulnerability:
Settings Change

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Uptime Robot Plugin for WordPress

Plugin Slug:
uptime-robot-monitor

Installations
600+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Uptime Robot Plugin for WordPress

Plugin Slug:
uptime-robot-monitor

Installations
600+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Uptime Robot Plugin for WordPress

Plugin Slug:
uptime-robot-monitor

Installations
600+

Vulnerability:
SQL Injection

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Woocommerce Role Pricing

Plugin Slug:
woocommerce-role-pricing

Installations
600+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.
Plugin Slug:
wp-link-preview

Installations
600+

Vulnerability:
Server Side Request Forgery (SSRF)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

WP Proposals

Plugin Slug:
wp-proposals

Installations
600+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

ACME Divi Modules

Plugin Slug:
acme-divi-modules

Installations
500+

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Advanced Speed Increaser

Plugin Slug:
advanced-speed-increaser

Installations
500+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Cache control by Cacholong

Plugin Slug:
cache-control-by-cacholong

Installations
500+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Cache control by Cacholong

Plugin Slug:
cache-control-by-cacholong

Installations
500+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

CF7 Spreadsheets

Plugin Slug:
cf7-spreadsheets

Installations
500+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

CF7 Spreadsheets

Plugin Slug:
cf7-spreadsheets

Installations
500+

Vulnerability:
Settings Change

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Checklist

Plugin Slug:
checklist

Installations
500+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Official CleverReach� Plugin for WooCommerce

Plugin Slug:
cleverreach-wc

Installations
500+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Display product variations dropdown on shop page

Plugin Slug:
display-product-variations-dropdown-on-shop-page

Installations
500+

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Twice Commerce � Easy Rental Booking System

Plugin Slug:
embed-rentle

Installations
500+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Freetobook Responsive Widget

Plugin Slug:
freetobook-responsive-widget

Installations
500+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

FunnelCockpit

Plugin Slug:
funnelcockpit

Installations
500+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Job Board Manager

Plugin Slug:
job-board-manager

Installations
500+

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Leartes TRY Exchange Rates

Plugin Slug:
leartes-try-exchange-rates

Installations
500+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Social Intents � Live Chat and ChatGPT Chatbots

Plugin Slug:
live-chat-support-by-social-intents

Installations
500+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

m1.DownloadList

Plugin Slug:
m1downloadlist

Installations
500+

Vulnerability:
Sensitive Data Exposure

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Ni WooCommerce Cost Of Goods

Plugin Slug:
ni-woocommerce-cost-of-goods

Installations
500+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Ni WooCommerce Cost Of Goods

Plugin Slug:
ni-woocommerce-cost-of-goods

Installations
500+

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

RDP Wiki Embed

Plugin Slug:
rdp-wiki-embed

Installations
500+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Theme Duplicator

Plugin Slug:
theme-duplicator

Installations
500+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

VG WooCarousel

Plugin Slug:
vg-woocarousel

Installations
500+

Vulnerability:
Local File Inclusion

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Webling

Plugin:

Webling

Plugin Slug:
webling

Installations
500+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Wishlist

Plugin:

Wishlist

Plugin Slug:
wishlist

Installations
500+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

WP Clone any post type

Plugin Slug:
wp-clone-any-post-type

Installations
500+

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

WP Clone any post type

Plugin Slug:
wp-clone-any-post-type

Installations
500+

Vulnerability:
Unvalidated Redirects and Forwards

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Administrator Z

Plugin Slug:
administrator-z

Installations
400+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Administrator Z

Plugin Slug:
administrator-z

Installations
400+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Appointify

Plugin Slug:
appointify

Installations
400+

Vulnerability:
Arbitrary File Upload

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Auto scroll for reading

Plugin Slug:
auto-scroll-for-reading

Installations
400+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Breaking News WP

Plugin Slug:
breaking-news-wp

Installations
400+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Breaking News WP

Plugin Slug:
breaking-news-wp

Installations
400+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Chamber Dashboard Business Directory

Plugin Slug:
chamber-dashboard-business-directory

Installations
400+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

CRM WordPress Plugin � RepairBuddy

Plugin Slug:
computer-repair-shop

Installations
400+

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Dima Take Action

Plugin Slug:
dima-take-action

Installations
400+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Pin Generator

Plugin Slug:
pin-generator

Installations
400+

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Planyo online reservation system

Plugin Slug:
planyo-online-reservation-system

Installations
400+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

RSVPMaker

Plugin Slug:
rsvpmaker

Installations
400+

Vulnerability:
SQL Injection

Patched in Version:
No Fix

Severity Score:
Critical


The vulnerability has not been patched. You should deactivate the plugin.
Plugin Slug:
tz-plus-gallery

Installations
400+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

WP AutoKeyword

Plugin Slug:
wp-autokeyword

Installations
400+

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

WP AutoKeyword

Plugin Slug:
wp-autokeyword

Installations
400+

Vulnerability:
SQL Injection

Patched in Version:
No Fix

Severity Score:
Critical


The vulnerability has not been patched. You should deactivate the plugin.

WP w3all phpBB

Plugin Slug:
wp-w3all-phpbb-integration

Installations
400+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

BWD Elementor Addons (2500+ presets, Meet The Team, Lottie, Lord Icon, Masking, Woocommerce, Theme Builder, Products, Blogs, CV, Contact Form 7 Styler, Header, Slider, Hero Section)

Plugin Slug:
bwd-elementor-addons

Installations
300+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Contact Form vCard Generator

Plugin Slug:
contact-form-vcard-generator

Installations
300+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Labinator Content Types Duplicator

Plugin Slug:
labinator-content-types-duplicator

Installations
300+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

PhotoShelter for Photographers Blog Feed Plugin

Plugin Slug:
photoshelter-official-plugin

Installations
300+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

TableOn � WordPress Posts Table Filterable�

Plugin Slug:
posts-table-filterable

Installations
300+

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Silvasoft boekhouden

Plugin Slug:
silvasoft-boekhouden

Installations
300+

Vulnerability:
SQL Injection

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

SimplyRETS Real Estate IDX

Plugin Slug:
simply-rets

Installations
300+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Viral Loops WP Integration

Plugin Slug:
viral-loops-wp-integration

Installations
300+

Vulnerability:
Sensitive Data Exposure

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

ACF City Selector

Plugin Slug:
acf-city-selector

Installations
200+

Vulnerability:
Sensitive Data Exposure

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Auto Post After Image Upload

Plugin Slug:
auto-post-after-image-upload

Installations
200+

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Connector to CiviCRM with CiviMcRestFace

Plugin Slug:
connector-civicrm-mcrestface

Installations
200+

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.
Plugin Slug:
dn-footer-contacts

Installations
200+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Export All Post Meta

Plugin Slug:
export-all-post-meta

Installations
200+

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Fonts Manager | Custom Fonts

Plugin Slug:
fonts-manager-custom-fonts

Installations
200+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Leadfox for WordPress

Plugin Slug:
leadfox

Installations
200+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

News Element Elementor Blog Magazine

Plugin Slug:
news-element

Installations
200+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Ni WooCommerce Product Enquiry

Plugin Slug:
ni-woocommerce-product-enquiry

Installations
200+

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

PeproDev CF7 Database

Plugin Slug:
pepro-cf7-database

Installations
200+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Send E-mail

Plugin Slug:
send-e-mail

Installations
200+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Shiptimize for WooCommerce

Plugin Slug:
shiptimize-for-woocommerce

Installations
200+

Vulnerability:
Settings Change

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

SMM API

Plugin:

SMM API

Plugin Slug:
smm-api

Installations
200+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

SwiftXR (3D/AR/VR) Viewer

Plugin Slug:
swiftxr-3darvr-viewer

Installations
200+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Variable Inspector

Plugin Slug:
variable-inspector

Installations
200+

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Welcome Popup

Plugin Slug:
welcome-popup

Installations
200+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Gift Cards for WooCommerce

Plugin Slug:
woo-giftcards

Installations
200+

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

WP Copy Media URL

Plugin Slug:
wp-copy-media-url

Installations
200+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

5sterrenspecialist

Plugin Slug:
5-sterrenspecialist

Installations
100+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.
Plugin Slug:
advanced-css3-related-posts-widget

Installations
100+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Agency Toolkit

Plugin Slug:
agency-toolkit

Installations
100+

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Apimo Connector

Plugin Slug:
apimo

Installations
100+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Author Bio Shortcode

Plugin Slug:
author-bio-shortcode

Installations
100+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

CBX Poll

Plugin:

CBX Poll

Plugin Slug:
cbxpoll

Installations
100+

Vulnerability:
PHP Object Injection

Patched in Version:
No Fix

Severity Score:
Critical


The vulnerability has not been patched. You should deactivate the plugin.

Clockinator Lite

Plugin Slug:
clockify-lite

Installations
100+

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Content Manager Light

Plugin Slug:
content-manager-light

Installations
100+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

ContentMX Content Publisher

Plugin Slug:
contentmx-content-publisher

Installations
100+

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Course Booking System

Plugin Slug:
course-booking-system

Installations
100+

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Custom Content Scrollbar

Plugin Slug:
custom-content-scrollbar

Installations
100+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

DobsonDev Shortcodes

Plugin Slug:
dobsondev-shortcodes

Installations
100+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

WordPress Testimonials Slider

Plugin Slug:
elfsight-testimonials-slider

Installations
100+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

WordPress Testimonials Slider

Plugin Slug:
elfsight-testimonials-slider

Installations
100+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

WordPress Testimonials Slider

Plugin Slug:
elfsight-testimonials-slider

Installations
100+

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Footnotes for WordPress

Plugin Slug:
footnotes-for-wordpress

Installations
100+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Free Woocommerce Product Table View � Woo Table Pro

Plugin Slug:
free-product-table-for-woocommerce

Installations
100+

Vulnerability:
Arbitrary Content Deletion

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Free Woocommerce Product Table View � Woo Table Pro

Plugin Slug:
free-product-table-for-woocommerce

Installations
100+

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.
Plugin Slug:
gallery-for-ultimate-member

Installations
100+

Vulnerability:
SQL Injection

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.
Plugin Slug:
gb-gallery-slideshow

Installations
100+

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.
Plugin Slug:
gdpr-cookie-notice

Installations
100+

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

JobBoard Job listing plugin

Plugin Slug:
job-board-light

Installations
100+

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

JobBoard Job listing plugin

Plugin Slug:
job-board-light

Installations
100+

Vulnerability:
Insecure Direct Object References (IDOR)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Local Magic

Plugin Slug:
local-magic

Installations
100+

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Opal Portfolio

Plugin Slug:
opal-portfolios

Installations
100+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

OpenAI Tools for WordPress & WooCommerce

Plugin Slug:
openai-tools-for-wp-wc

Installations
100+

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Pay with Contact Form 7

Plugin Slug:
pay-with-contact-form-7

Installations
100+

Vulnerability:
SQL Injection

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Payday

Plugin:

Payday

Plugin Slug:
payday

Installations
100+

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Popping Content Light

Plugin Slug:
popping-content-light

Installations
100+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

QR Master

Plugin Slug:
qr-master

Installations
100+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Review Manager

Plugin Slug:
review-manager

Installations
100+

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.
Plugin Slug:
rio-video-gallery

Installations
100+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Ship Per Product

Plugin Slug:
ship-per-product

Installations
100+

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Simple-Audioplayer

Plugin Slug:
simple-audioplayer

Installations
100+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.
Plugin Slug:
simple-website-logo

Installations
100+

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

SP Blog Designer

Plugin Slug:
sp-blog-designer

Installations
100+

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

StaffList

Plugin Slug:
stafflist

Installations
100+

Vulnerability:
Sensitive Data Exposure

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

StaffList

Plugin Slug:
stafflist

Installations
100+

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Team Members for Elementor Page Builder

Plugin Slug:
team-members-for-elementor

Installations
100+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

The Logo Slider

Plugin Slug:
the-logo-slider

Installations
100+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Ultimate Live Cricket WordPress Lite

Plugin Slug:
ultimate-live-cricket-lite

Installations
100+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

LeadLab by wiredminds

Plugin Slug:
wiredminds-leadlab

Installations
100+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

WooTumblog

Plugin Slug:
woo-tumblog

Installations
100+

Vulnerability:
Content Injection

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

WP Video Playlist

Plugin Slug:
wp-post-459206 wp-video-playlist

Installations
100+

Vulnerability:
Settings Change

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

WP Sitemap

Plugin Slug:
wpsitemap

Installations
100+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

AB Google Map Travel (AB-MAP)

Plugin Slug:
ab-google-map-travel

Installations
90+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

WordPress Adverts Plugin � Adverts Click Tracker

Plugin Slug:
adverts-click-tracker

Installations
90+

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Clients

Plugin:

Clients

Plugin Slug:
clients

Installations
90+

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

CookieHint WP

Plugin Slug:
cookiehint-wp

Installations
90+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

CoverManager

Plugin Slug:
covermanager

Installations
90+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Minimalistic Event Manager

Plugin Slug:
minimalistic-event-manager

Installations
90+

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.
Plugin Slug:
open-ai-search-bar

Installations
90+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

WR Price List Manager For Woocommerce

Plugin Slug:
wr-price-list-for-woocommerce

Installations
90+

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Advanced Typekit

Plugin Slug:
advanced-typekit

Installations
80+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

byBrick Accordion

Plugin Slug:
bybrick-accordion

Installations
80+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Subscription Form for Feedblitz

Plugin Slug:
feedblitz-email-subscription

Installations
80+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

LeadQuizzes

Plugin Slug:
leadquizzes

Installations
80+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

SWM � Shopify to WooCommerce Migration

Plugin Slug:
migrate-shopify-to-woocommerce

Installations
80+

Vulnerability:
Settings Change

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

News, Magazine and Blog Elements

Plugin Slug:
news-magazine-and-blog-elements

Installations
80+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

OpenMenu � The official plugin for OpenMenu

Plugin Slug:
open-menu

Installations
80+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.
Plugin Slug:
related-posts-list-grid-and-slider-all-in-one

Installations
80+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Terms Before Download

Plugin Slug:
terms-before-download

Installations
80+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Ultimate Push Notifications ( Mobile / Desktop ), Receive Notification From WooCommerce, BuddyPress, WordPress Default Events & Many More

Plugin Slug:
ultimate-push-notifications

Installations
80+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Varnish WordPress

Plugin Slug:
varnish-wp

Installations
80+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

6Storage Rentals

Plugin Slug:
6storage-rentals

Installations
70+

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Append Content

Plugin Slug:
append-content

Installations
70+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Hypotext

Plugin:

Hypotext

Plugin Slug:
hypotext

Installations
70+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Marketer Addons

Plugin Slug:
marketer-addons

Installations
70+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

PostmarkApp Email Integrator

Plugin Slug:
postmarkapp-email-integrator

Installations
70+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

PostmarkApp Email Integrator

Plugin Slug:
postmarkapp-email-integrator

Installations
70+

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Radius Blocks � WordPress Gutenberg Blocks

Plugin Slug:
radius-blocks

Installations
70+

Vulnerability:
Local File Inclusion

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Rich Text Editor

Plugin Slug:
richtexteditor

Installations
70+

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Rich Text Editor

Plugin Slug:
richtexteditor

Installations
70+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Simple Contact Forms

Plugin Slug:
simple-contact-forms

Installations
70+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Actionwear products sync

Plugin Slug:
actionwear-products-sync

Installations
60+

Vulnerability:
SQL Injection

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Boo Recipes

Plugin Slug:
boo-recipes

Installations
60+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Catch Dark Mode

Plugin Slug:
catch-dark-mode

Installations
60+

Vulnerability:
Local File Inclusion

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Easy Magazine

Plugin Slug:
filtr8-magazine

Installations
60+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Infusionsoft Web Form JavaScript

Plugin Slug:
infusionsoft-web-form-javascript

Installations
60+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

pCloud Backup

Plugin Slug:
pcloud-backup

Installations
60+

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Processing Projects

Plugin Slug:
processing-projects

Installations
60+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Sprout Clients � CRM and Lead Management

Plugin Slug:
sprout-clients

Installations
60+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Turbo Addons Elementor

Plugin Slug:
turbo-addons-elementor

Installations
60+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Useinfluence

Plugin Slug:
useinfluence

Installations
60+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

WPBookit

Plugin:

WPBookit

Plugin Slug:
wpbookit

Installations
60+

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

WP Genealogy � Your Family History Website

Plugin Slug:
wpgenealogy

Installations
60+

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Bulk Fields Editor

Plugin Slug:
bulk-user-editor

Installations
50+

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Chat by Chatwee

Plugin Slug:
chatwee

Installations
50+

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Easy WP Optimizer � Optimize DB & WordPress

Plugin Slug:
easy-wp-optimizer

Installations
50+

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Lightweight and Responsive Youtube Embed

Plugin Slug:
lightweight-and-responsive-youtube-embed

Installations
50+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Lightweight and Responsive Youtube Embed

Plugin Slug:
lightweight-and-responsive-youtube-embed

Installations
50+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Shopper Approved Reviews

Plugin Slug:
shopperapproved-reviews

Installations
50+

Vulnerability:
Settings Change

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

WP Chrono

Plugin Slug:
wp-chrono

Installations
50+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

BlockWheels

Plugin Slug:
blockwheels

Installations
40+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Client Showcase

Plugin Slug:
client-showcase

Installations
40+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

DesignO

Plugin:

DesignO

Plugin Slug:
designo

Installations
40+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.
Plugin Slug:
intelly-posts-footer-manager

Installations
30+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Welcome Bar

Plugin Slug:
intelly-welcome-bar

Installations
30+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Sparkle Elementor Kit

Plugin Slug:
sparkle-elementor-kit

Installations
30+

Vulnerability:
Local File Inclusion

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Simple Fixed Notice

Plugin Slug:
dn-cookie-notice

Installations
20+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Donate Me

Plugin Slug:
donate-me

Installations
20+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Design Blocks � Gutenberg Blocks collection

Plugin Slug:
exclusive-blocks

Installations
20+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

ShipDepot for WooCommerce

Plugin Slug:
ship-depot

Installations
20+

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Smartarget Popup

Plugin Slug:
smartarget-popup

Installations
20+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Turisbook Booking System

Plugin Slug:
turisbook-booking-system

Installations
20+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Ethiopian Calendar

Plugin Slug:
ethiopian-calendar

Installations
10+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Eventbee RSVP Widget

Plugin Slug:
eventbee-rsvp-widget

Installations
10+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.
Plugin Slug:
hmh-footer-builder-for-elementor

Installations
10+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Just Post Preview Widget

Plugin Slug:
just-post-preview

Installations
10+

Vulnerability:
Local File Inclusion

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Nearby Locations

Plugin Slug:
nearby-locations

Installations
10+

Vulnerability:
SQL Injection

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Support Helpdesk Ticket System Lite

Plugin Slug:
ticket-help-desk-system-lite

Installations
10+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

WPSHARE247 Elementor Addons

Plugin Slug:
wpshare247-elementor-addons

Installations
10+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

1-Click Backup & Restore Database

Plugin:

1-Click Backup & Restore Database

Plugin Slug:
1-click-backup-restore-database-by-sunbytes

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

AAWP Obfuscator

Plugin:

AAWP Obfuscator

Plugin Slug:
aawp-obfuscator

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

ABC Notation

Plugin:

ABC Notation

Plugin Slug:
abc-notation

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Advanced Advertising System

Plugin:

Advanced Advertising System

Plugin Slug:
advanced-advertising-system

Vulnerability:
Open Redirection

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Advanced Search by My Solr Server

Plugin:

Advanced Search by My Solr Server

Plugin Slug:
advanced-search-by-my-solr-server

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

AI Content Pipelines

Plugin:

AI Content Pipelines

Plugin Slug:
ai-content-pipelines

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Apptivo Business Site CRM

Plugin:

Apptivo Business Site CRM

Plugin Slug:
apptivo-business-site

Vulnerability:
Arbitrary Content Deletion

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Arkhe Blocks

Plugin:

Arkhe Blocks

Plugin Slug:
arkhe-blocks

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Arrow Custom Feed for Twitter

Plugin:

Arrow Custom Feed for Twitter

Plugin Slug:
arrow-twitter-feed

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Awesome Logos

Plugin:

Awesome Logos

Plugin Slug:
awesome-logos

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Booking Calendar and Notification

Plugin:

Booking Calendar and Notification

Plugin Slug:
booking-calendar-and-notification

Vulnerability:
Broken Authentication

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Booking Calendar and Notification

Plugin:

Booking Calendar and Notification

Plugin Slug:
booking-calendar-and-notification

Vulnerability:
SQL Injection

Patched in Version:
No Fix

Severity Score:
Critical


The vulnerability has not been patched. You should deactivate the plugin.

BookingPress

Plugin:

BookingPress

Plugin Slug:
bookingpress-appointment-booking

Vulnerability:
SQL Injection

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Botnet Attack Blocker

Plugin:

Botnet Attack Blocker

Plugin Slug:
botnet-attack-blocker

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

CGM Event Calendar

Plugin:

CGM Event Calendar

Plugin Slug:
cgm-event-calendar

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Clearbit Reveal

Plugin:

Clearbit Reveal

Plugin Slug:
clearbit

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Delete Post Revision

Plugin:

Delete Post Revision

Plugin Slug:
delete-post-revision

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Demo Awesome

Plugin:

Demo Awesome

Plugin Slug:
demo-awesome

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

DigiWidgets Image Editor

Plugin:

DigiWidgets Image Editor

Plugin Slug:
digiwidgets-image-editor

Vulnerability:
Remote Code Execution (RCE)

Patched in Version:
No Fix

Severity Score:
Critical


The vulnerability has not been patched. You should deactivate the plugin.

Multi Days Events and Multi Events in One Day Calendar

Plugin Slug:
dragon-calendar-free-version

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

DyaPress ERP/CRM

Plugin:

DyaPress ERP/CRM

Plugin Slug:
dyapress

Vulnerability:
Local File Inclusion

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

ZoomSounds

Plugin:

ZoomSounds

Plugin Slug:
dzs-zoomsounds

Vulnerability:
Arbitrary File Download

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

ZoomSounds

Plugin:

ZoomSounds

Plugin Slug:
dzs-zoomsounds

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

ZoomSounds

Plugin:

ZoomSounds

Plugin Slug:
dzs-zoomsounds

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Easy Contact

Plugin:

Easy Contact

Plugin Slug:
easy-contact

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Easy Query � WP Query Builder

Plugin:

Easy Query � WP Query Builder

Plugin Slug:
easy-query

Vulnerability:
SQL Injection

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Ebook Downloader

Plugin:

Ebook Downloader

Plugin Slug:
ebook-downloader

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Ebook Downloader

Plugin:

Ebook Downloader

Plugin Slug:
ebook-downloader

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Emma for WordPress

Plugin:

Emma for WordPress

Plugin Slug:
emma-emarketing-plugin

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Exit Popup Free

Plugin Slug:
exit-popup-free

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Extensions for Elementor

Plugin:

Extensions for Elementor

Plugin Slug:
extensions-for-elementor

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

ez Form Calculator – WordPress plugin

Plugin:

ez Form Calculator – WordPress plugin

Plugin Slug:
ez-form-calculator-premium

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Fami WooCommerce Compare

Plugin:

Fami WooCommerce Compare

Plugin Slug:
fami-woocommerce-compare

Vulnerability:
Local File Inclusion

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Flickr Photostream

Plugin:

Flickr Photostream

Plugin Slug:
flickr-photostream

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Frizzly

Plugin:

Frizzly

Plugin Slug:
frizzly

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Front End Users

Plugin:

Front End Users

Plugin Slug:
front-end-only-users

Vulnerability:
Arbitrary File Upload

Patched in Version:
No Fix

Severity Score:
Critical


The vulnerability has not been patched. You should deactivate the plugin.

Front End Users

Plugin:

Front End Users

Plugin Slug:
front-end-only-users

Vulnerability:
SQL Injection

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

GetBookingsWP

Plugin:

GetBookingsWP

Plugin Slug:
get-bookings-wp

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Salesmate Add-On for Gravity Forms

Plugin:

Salesmate Add-On for Gravity Forms

Plugin Slug:
gf-salesmate-add-on

Vulnerability:
SQL Injection

Patched in Version:
No Fix

Severity Score:
Critical


The vulnerability has not been patched. You should deactivate the plugin.

Salesmate Add-On for Gravity Forms

Plugin:

Salesmate Add-On for Gravity Forms

Plugin Slug:
gf-salesmate-add-on

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Gift Certificate Creator

Plugin:

Gift Certificate Creator

Plugin Slug:
gift-certificate-creator

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.
Plugin:

Global Gallery

Plugin Slug:
global-gallery

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

GNUCommerce

Plugin:

GNUCommerce

Plugin Slug:
gnucommerce

Vulnerability:
PHP Object Injection

Patched in Version:
No Fix

Severity Score:
Critical


The vulnerability has not been patched. You should deactivate the plugin.

Gosign � Posts Slider Block

Plugin:

Gosign � Posts Slider Block

Plugin Slug:
gosign-posts-slider-block

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

include-file

Plugin:

include-file

Plugin Slug:
include-file

Vulnerability:
Arbitrary File Download

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Jetpack Feedback Exporter

Plugin:

Jetpack Feedback Exporter

Plugin Slug:
jetpack-feedback-exporter

Vulnerability:
Sensitive Data Exposure

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

JSON Structuring Markup

Plugin:

JSON Structuring Markup

Plugin Slug:
json-structuring-markup

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

KB Support

Plugin:

KB Support

Plugin Slug:
kb-support

Vulnerability:
Sensitive Data Exposure

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Search engine keywords highlighter

Plugin:

Search engine keywords highlighter

Plugin Slug:
keywords-highlight-tool

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Lafka Plugin

Plugin:

Lafka Plugin

Plugin Slug:
lafka-plugin

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Latest Custom Post Type Updates

Plugin:

Latest Custom Post Type Updates

Plugin Slug:
latest-custom-post-type-updates

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Lexicata

Plugin:

Lexicata

Plugin Slug:
lexicata

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Limit Max IPs Per User

Plugin:

Limit Max IPs Per User

Plugin Slug:
limit-max-ips-per-user

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

MediaView

Plugin:

MediaView

Plugin Slug:
mediaview

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Melhor Envio

Plugin:

Melhor Envio

Plugin Slug:
melhor-envio-cotacao

Vulnerability:
Sensitive Data Exposure

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

mFolio Lite

Plugin Slug:
mfolio-lite

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

MyBookProgress by Stormhill Media

Plugin:

MyBookProgress by Stormhill Media

Plugin Slug:
mybookprogress

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

MyBookProgress by Stormhill Media

Plugin:

MyBookProgress by Stormhill Media

Plugin Slug:
mybookprogress

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

NanoSupport

Plugin:

NanoSupport

Plugin Slug:
nanosupport

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

NanoSupport

Plugin:

NanoSupport

Plugin Slug:
nanosupport

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Pages Order

Plugin:

Pages Order

Plugin Slug:
pages-order

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Posten � Gutenberg Post Block

Plugin Slug:
posten-post-blocks

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Blubrry PowerPress Podcasting plugin MultiSite add-on

Plugin:

Blubrry PowerPress Podcasting plugin MultiSite add-on

Plugin Slug:
powerpress-multisite

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

RJ Quickcharts

Plugin:

RJ Quickcharts

Plugin Slug:
rj-quickcharts

Vulnerability:
SQL Injection

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Maps

Plugin:

Maps

Plugin Slug:
robo-maps

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

SEO Tools

Plugin:

SEO Tools

Plugin Slug:
seo-automatic-seo-tools

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Sequel

Plugin:

Sequel

Plugin Slug:
sequel

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Simple Map No Api

Plugin:

Simple Map No Api

Plugin Slug:
simple-map-no-api

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Simple WP Events

Plugin:

Simple WP Events

Plugin Slug:
simple-wp-events

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Simple:Press

Plugin:

Simple:Press

Plugin Slug:
simplepress

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Smart Icons For WordPress

Plugin:

Smart Icons For WordPress

Plugin Slug:
smartifw

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Social Share And Social Locker

Plugin:

Social Share And Social Locker

Plugin Slug:
social-share-and-social-locker-arsocial

Vulnerability:
SQL Injection

Patched in Version:
No Fix

Severity Score:
Critical


The vulnerability has not been patched. You should deactivate the plugin.

Social Share And Social Locker

Plugin:

Social Share And Social Locker

Plugin Slug:
social-share-and-social-locker-arsocial

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Team Builder

Plugin:

Team Builder

Plugin Slug:
team-display

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Team Rosters

Plugin:

Team Rosters

Plugin Slug:
team-rosters

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Trackserver

Plugin:

Trackserver

Plugin Slug:
trackserver

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Video Url

Plugin:

Video Url

Plugin Slug:
video-sidebar-widget

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Videos

Plugin:

Videos

Plugin Slug:
videos

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Digihood HTML Sitemap

Plugin:

Digihood HTML Sitemap

Plugin Slug:
wedesin-html-sitemap

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

WP Bookmarks

Plugin:

WP Bookmarks

Plugin Slug:
wp-bookmarks

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

WP Church Donation

Plugin:

WP Church Donation

Plugin Slug:
wp-church-donation

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

WP Crowdfunding

Plugin:

WP Crowdfunding

Plugin Slug:
wp-crowdfunding

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

WordPress Galleria

Plugin:

WordPress Galleria

Plugin Slug:
wp-galleria

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

WP_Identicon

Plugin:

WP_Identicon

Plugin Slug:
wp-identicon

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

WP Profitshare

Plugin:

WP Profitshare

Plugin Slug:
wp-profitshare

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Advanced All in One Admin Search by WP Spotlight

Plugin:

Advanced All in One Admin Search by WP Spotlight

Plugin Slug:
wp-spotlight-search

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

wp Time Machine

Plugin:

wp Time Machine

Plugin Slug:
wp-time-machine

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

WP User Profiles

Plugin:

WP User Profiles

Plugin Slug:
wp-users-profiles

Vulnerability:
Privilege Escalation

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

WP Cleaner

Plugin:

WP Cleaner

Plugin Slug:
wpcleaner

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Wptobe-signinup

Plugin:

Wptobe-signinup

Plugin Slug:
wptobe-signinup

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

XV Random Quotes

Plugin:

XV Random Quotes

Plugin Slug:
xv-random-quotes

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

XV Random Quotes

Plugin:

XV Random Quotes

Plugin Slug:
xv-random-quotes

Vulnerability:
SQL Injection

Patched in Version:
No Fix

Severity Score:
Critical


The vulnerability has not been patched. You should deactivate the plugin.

Enable Media Replace

Plugin Slug:
enable-media-replace

Installations
600,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
4.1.6

Severity Score:
High


The vulnerability has been patched, so you should update to version 4.1.6.

Unlimited Elements For Elementor

Plugin Slug:
unlimited-elements-for-elementor

Installations
300,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.5.143

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.5.143.

Lightbox & Modal Popup WordPress Plugin � FooBox

Plugin Slug:
foobox-image-lightbox

Installations
100,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.7.34

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.7.34.

LuckyWP Table of Contents

Plugin Slug:
luckywp-table-of-contents

Installations
100,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.1.11

Severity Score:
High


The vulnerability has been patched, so you should update to version 2.1.11.
Plugin Slug:
modula-best-grid-gallery

Installations
100,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.10.2

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.10.2.

Media Library Assistant

Plugin Slug:
media-library-assistant

Installations
70,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
3.25

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 3.25.

Product Filter by WBW

Plugin Slug:
woo-product-filter

Installations
60,000+

Vulnerability:
SQL Injection

Patched in Version:
2.8.0

Severity Score:
Critical


The vulnerability has been patched, so you should update to version 2.8.0.

Calculated Fields Form

Plugin Slug:
calculated-fields-form

Installations
50,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
5.2.64

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 5.2.64.

MapPress Maps for WordPress

Plugin Slug:
mappress-google-maps-for-wordpress

Installations
40,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.94.9

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.94.9.

Booster for WooCommerce

Plugin Slug:
woocommerce-jetpack

Installations
40,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
7.2.5

Severity Score:
High


The vulnerability has been patched, so you should update to version 7.2.5.

Booster for WooCommerce

Plugin Slug:
woocommerce-jetpack

Installations
40,000+

Vulnerability:
Arbitrary File Upload

Patched in Version:
7.2.5

Severity Score:
High


The vulnerability has been patched, so you should update to version 7.2.5.

WPFront User Role Editor

Plugin Slug:
wpfront-user-role-editor

Installations
40,000+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
4.2.2

Severity Score:
High


The vulnerability has been patched, so you should update to version 4.2.2.

Blog Grid & Post Grid � Blog Post Slider, Blog Post Carousel, Blog Post Ticker, Blog Post Masonry, Category Post Grid By News & Blog Designer Pack

Plugin Slug:
blog-designer-pack

Installations
30,000+

Vulnerability:
Local File Inclusion

Patched in Version:
4.0.1

Severity Score:
High


The vulnerability has been patched, so you should update to version 4.0.1.

GTM Kit � Google Tag Manager & GA4 integration

Plugin Slug:
gtm-kit

Installations
30,000+

Vulnerability:
Sensitive Data Exposure

Patched in Version:
2.4.1

Severity Score:
High


The vulnerability has been patched, so you should update to version 2.4.1.

Secure Copy Content Protection and Content Locking

Plugin Slug:
secure-copy-content-protection

Installations
20,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
4.4.5

Severity Score:
High


The vulnerability has been patched, so you should update to version 4.4.5.

Import Export Suite for CSV and XML Datafeed

Plugin Slug:
wp-ultimate-csv-importer

Installations
20,000+

Vulnerability:
Arbitrary File Upload

Patched in Version:
7.19.1

Severity Score:
High


The vulnerability has been patched, so you should update to version 7.19.1.

Import Export Suite for CSV and XML Datafeed

Plugin Slug:
wp-ultimate-csv-importer

Installations
20,000+

Vulnerability:
Arbitrary File Deletion

Patched in Version:
7.19.1

Severity Score:
High


The vulnerability has been patched, so you should update to version 7.19.1.

wpForo Forum

Plugin Slug:
wpforo

Installations
20,000+

Vulnerability:
Privilege Escalation

Patched in Version:
2.4.4

Severity Score:
High


The vulnerability has been patched, so you should update to version 2.4.4.

HTML Forms � Simple WordPress Forms Plugin

Plugin Slug:
html-forms

Installations
10,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.5.2

Severity Score:
High


The vulnerability has been patched, so you should update to version 1.5.2.
Plugin Slug:
link-library

Installations
10,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
7.8

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 7.8.

Motors � Car Dealership & Classified Listings Plugin

Plugin Slug:
motors-car-dealership-classified-listings

Installations
10,000+

Vulnerability:
Broken Access Control

Patched in Version:
1.4.67

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.4.67.

Motors � Car Dealership & Classified Listings Plugin

Plugin Slug:
motors-car-dealership-classified-listings

Installations
10,000+

Vulnerability:
Broken Access Control

Patched in Version:
1.4.65

Severity Score:
High


The vulnerability has been patched, so you should update to version 1.4.65.

Motors � Car Dealership & Classified Listings Plugin

Plugin Slug:
motors-car-dealership-classified-listings

Installations
10,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.4.64

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.4.64.

WP Date and Time Shortcode

Plugin Slug:
wp-date-and-time-shortcode

Installations
10,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.6.8

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.6.8.
Plugin Slug:
automatic-featured-images-from-videos

Installations
8,000+

Vulnerability:
Broken Access Control

Patched in Version:
1.2.5

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.2.5.

Cue by AudioTheme.com

Plugin Slug:
cue

Installations
7,000+

Vulnerability:
Broken Access Control

Patched in Version:
2.4.5

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.4.5.

Insert Headers and Footers Code � HT Script

Plugin Slug:
insert-headers-and-footers-script

Installations
7,000+

Vulnerability:
Broken Access Control

Patched in Version:
1.1.3

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.1.3.

Drag and Drop Multiple File Upload for WooCommerce

Plugin Slug:
drag-and-drop-multiple-file-upload-for-woocommerce

Installations
6,000+

Vulnerability:
Directory Traversal

Patched in Version:
1.1.5

Severity Score:
Critical


The vulnerability has been patched, so you should update to version 1.1.5.

SMS Alert Order Notifications � WooCommerce

Plugin Slug:
sms-alert

Installations
5,000+

Vulnerability:
Privilege Escalation

Patched in Version:
3.8.0

Severity Score:
Critical


The vulnerability has been patched, so you should update to version 3.8.0.

Watu Quiz

Plugin Slug:
watu

Installations
4,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
3.4.3

Severity Score:
High


The vulnerability has been patched, so you should update to version 3.4.3.

Lana Downloads Manager

Plugin Slug:
lana-downloads-manager

Installations
3,000+

Vulnerability:
Arbitrary File Download

Patched in Version:
1.10.0

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.10.0.

Beds24 Online Booking

Plugin Slug:
beds24-online-booking

Installations
2,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.0.28

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.0.28.

teachPress

Plugin Slug:
teachpress

Installations
2,000+

Vulnerability:
SQL Injection

Patched in Version:
9.0.12

Severity Score:
High


The vulnerability has been patched, so you should update to version 9.0.12.

Product Table by WBW

Plugin Slug:
woo-product-tables

Installations
2,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.1.5

Severity Score:
High


The vulnerability has been patched, so you should update to version 2.1.5.

Social proof testimonials and reviews by Repuso

Plugin Slug:
social-testimonials-and-reviews-widget

Installations
1,000+

Vulnerability:
Broken Access Control

Patched in Version:
5.22

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 5.22.

YayExtra � WooCommerce Extra Product Options

Plugin Slug:
yayextra

Installations
1,000+

Vulnerability:
Broken Access Control

Patched in Version:
1.5.3

Severity Score:
High


The vulnerability has been patched, so you should update to version 1.5.3.

3DPrint Lite

Plugin Slug:
3dprint-lite

Installations
900+

Vulnerability:
SQL Injection

Patched in Version:
2.1.3.7

Severity Score:
High


The vulnerability has been patched, so you should update to version 2.1.3.7.

Ultra Addons Lite for Elementor

Plugin Slug:
ut-elementor-addons-lite

Installations
900+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.1.9

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.1.9.

xili-language

Plugin Slug:
xili-language

Installations
900+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.21.3

Severity Score:
High


The vulnerability has been patched, so you should update to version 2.21.3.

Feedbucket � Website Feedback Tool

Plugin Slug:
feedbucket

Installations
800+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
1.0.7

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.0.7.

Maps for WP

Plugin Slug:
maps-for-wp

Installations
600+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.2.5

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.2.5.

Theater for WordPress

Plugin Slug:
theatre

Installations
600+

Vulnerability:
Broken Access Control

Patched in Version:
0.18.8

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 0.18.8.

Snow Storm

Plugin Slug:
snow-storm

Installations
500+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.4.7

Severity Score:
High


The vulnerability has been patched, so you should update to version 1.4.7.

Web Directory Free

Plugin Slug:
web-directory-free

Installations
500+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
1.7.8

Severity Score:
High


The vulnerability has been patched, so you should update to version 1.7.8.

WordPress Access Areas

Plugin Slug:
wp-access-areas

Installations
500+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.5.20

Severity Score:
High


The vulnerability has been patched, so you should update to version 1.5.20.

Post to Social Media � WordPress to Hootsuite

Plugin Slug:
wp-to-hootsuite

Installations
500+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
1.6.0

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.6.0.

Team Circle Image Slider With Lightbox

Plugin Slug:
circle-image-slider-with-lightbox

Installations
400+

Vulnerability:
SQL Injection

Patched in Version:
1.0.5

Severity Score:
High


The vulnerability has been patched, so you should update to version 1.0.5.

DeBounce Email Validator

Plugin Slug:
debounce-io-email-validator

Installations
400+

Vulnerability:
Local File Inclusion

Patched in Version:
5.71

Severity Score:
High


The vulnerability has been patched, so you should update to version 5.71.

Plugin Oficial � Getnet para WooCommerce

Plugin Slug:
wc-checkout-getnet

Installations
400+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.8.0

Severity Score:
High


The vulnerability has been patched, so you should update to version 1.8.0.

Order Splitter for WooCommerce

Plugin Slug:
woo-order-splitter

Installations
400+

Vulnerability:
SQL Injection

Patched in Version:
5.3.1

Severity Score:
High


The vulnerability has been patched, so you should update to version 5.3.1.

CardGate Payments for WooCommerce

Plugin Slug:
cardgate

Installations
300+

Vulnerability:
SQL Injection

Patched in Version:
3.2.2

Severity Score:
High


The vulnerability has been patched, so you should update to version 3.2.2.

Falling Things

Plugin Slug:
falling-things

Installations
300+

Vulnerability:
SQL Injection

Patched in Version:
1.09

Severity Score:
High


The vulnerability has been patched, so you should update to version 1.09.

Search, Filters & Merchandising for WooCommerce

Plugin Slug:
instantsearch-for-woocommerce

Installations
300+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
3.0.59

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 3.0.59.

Next-Cart Store to WooCommerce Migration

Plugin Slug:
nextcart-woocommerce-migration

Installations
200+

Vulnerability:
SQL Injection

Patched in Version:
3.9.5

Severity Score:
Critical


The vulnerability has been patched, so you should update to version 3.9.5.

Oracle Cards Lite

Plugin Slug:
oracle-cards

Installations
200+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.2.2

Severity Score:
High


The vulnerability has been patched, so you should update to version 1.2.2.

Perfect Font Awesome Integration

Plugin Slug:
perfect-font-awesome-integration

Installations
200+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.3.1

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.3.1.

Residential Address Detection

Plugin Slug:
residential-address-detection

Installations
200+

Vulnerability:
Broken Access Control

Patched in Version:
2.5.5

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.5.5.

Total processing card payments for WooCommerce

Plugin Slug:
totalprocessing-card-payments

Installations
200+

Vulnerability:
Arbitrary File Download

Patched in Version:
7.1.6

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 7.1.6.

Big Boom Directory

Plugin Slug:
big-boom-directory

Installations
100+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.5.1

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.5.1.

GreenPay(tm) by Green.Money

Plugin Slug:
green-money-payment-gateway

Installations
100+

Vulnerability:
Sensitive Data Exposure

Patched in Version:
3.0.10

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 3.0.10.
Plugin Slug:
internal-link-finder

Installations
100+

Vulnerability:
Settings Change

Patched in Version:
5.1.3

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 5.1.3.

Material Dashboard

Plugin Slug:
material-dashboard

Installations
80+

Vulnerability:
Local File Inclusion

Patched in Version:
1.4.6

Severity Score:
High


The vulnerability has been patched, so you should update to version 1.4.6.

Norse Rune Oracle Plugin

Plugin Slug:
norse-runes-oracle

Installations
70+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.4.4

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.4.4.

Small Package Quotes � Worldwide Express Edition

Plugin Slug:
small-package-quotes-wwe-edition

Installations
70+

Vulnerability:
Broken Access Control

Patched in Version:
5.2.20

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 5.2.20.

Small Package Quotes � Worldwide Express Edition

Plugin Slug:
small-package-quotes-wwe-edition

Installations
70+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
5.2.19

Severity Score:
High


The vulnerability has been patched, so you should update to version 5.2.19.

Awesome Event Booking

Plugin Slug:
awesome-event-booking

Installations
50+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.8.5

Severity Score:
High


The vulnerability has been patched, so you should update to version 2.8.5.

Accept SagePay Payments Using Contact Form 7

Plugin Slug:
accept-sagepay-payments-using-contact-form-7

Installations
10+

Vulnerability:
Sensitive Data Exposure

Patched in Version:
2.1

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.1.

coreActivity: Activity Logging for WordPress

Plugin Slug:
coreactivity

Installations
10+

Vulnerability:
SQL Injection

Patched in Version:
2.7.1

Severity Score:
High


The vulnerability has been patched, so you should update to version 2.7.1.

Bridge Core

Plugin:

Bridge Core

Plugin Slug:
bridge-core

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
3.3.1

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 3.3.1.

Contempo Real Estate Core

Plugin:

Contempo Real Estate Core

Plugin Slug:
ct-real-estate-core

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
3.6.4

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 3.6.4.

Fusion Builder

Plugin:

Fusion Builder

Plugin Slug:
fusion-builder

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
3.11.15

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 3.11.15.

tagDiv Composer

Plugin:

tagDiv Composer

Plugin Slug:
td-composer

Vulnerability:
PHP Object Injection

Patched in Version:
5.4

Severity Score:
Critical


The vulnerability has been patched, so you should update to version 5.4.

User Registration & Membership Pro

Plugin:

User Registration & Membership Pro

Plugin Slug:
user-registration-pro

Vulnerability:
Broken Authentication

Patched in Version:
5.1.3

Severity Score:
Critical


The vulnerability has been patched, so you should update to version 5.1.3.

Vehica Core

Plugin:

Vehica Core

Plugin Slug:
vehica-core

Vulnerability:
Privilege Escalation

Patched in Version:
1.0.98

Severity Score:
High


The vulnerability has been patched, so you should update to version 1.0.98.

Vitepos

Plugin:

Vitepos

Plugin Slug:
vitepos-lite

Vulnerability:
Broken Authentication

Patched in Version:
3.1.5

Severity Score:
High


The vulnerability has been patched, so you should update to version 3.1.5.

Woffice Core

Plugin:

Woffice Core

Plugin Slug:
woffice-core

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
5.4.22

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 5.4.22.

Woffice Core

Plugin:

Woffice Core

Plugin Slug:
woffice-core

Vulnerability:
Arbitrary File Upload

Patched in Version:
5.4.22

Severity Score:
Critical


The vulnerability has been patched, so you should update to version 5.4.22.

WP RealEstate

Plugin:

WP RealEstate

Plugin Slug:
wp-realestate

Vulnerability:
Privilege Escalation

Patched in Version:
1.6.27

Severity Score:
Critical


The vulnerability has been patched, so you should update to version 1.6.27.

WordPress Themes � 5 Patched / 24 Unpatched

Glossy Blog

Theme Slug:
glossy-blog

Downloads
5,059

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should switch themes.

Home Services

Theme Slug:
home-services

Downloads
19,959

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should switch themes.

Simplish

Theme Slug:
simplish

Downloads
28,664

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should switch themes.

Tain�

Theme:

Tain�

Theme Slug:
taina

Downloads
1,311

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should switch themes.

Bloggie

Theme:

Bloggie

Theme Slug:
bloggie

Vulnerability:
Arbitrary File Upload

Patched in Version:
No Fix

Severity Score:
Critical


The vulnerability has not been patched. You should switch themes.

Themify Edmin

Theme:

Themify Edmin

Theme Slug:
edmin

Vulnerability:
Arbitrary File Upload

Patched in Version:
No Fix

Severity Score:
Critical


The vulnerability has not been patched. You should switch themes.

Themify Edmin

Theme:

Themify Edmin

Theme Slug:
edmin

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should switch themes.

Themify Folo

Theme:

Themify Folo

Theme Slug:
folo

Vulnerability:
Arbitrary File Upload

Patched in Version:
No Fix

Severity Score:
Critical


The vulnerability has not been patched. You should switch themes.

Themify Folo

Theme:

Themify Folo

Theme Slug:
folo

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should switch themes.

Gravel

Theme:

Gravel

Theme Slug:
gravel

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should switch themes.

Themify Newsy

Theme:

Themify Newsy

Theme Slug:
newsy

Vulnerability:
Arbitrary File Upload

Patched in Version:
No Fix

Severity Score:
Critical


The vulnerability has not been patched. You should switch themes.

Themify Newsy

Theme:

Themify Newsy

Theme Slug:
newsy

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should switch themes.

Photobox

Theme:

Photobox

Theme Slug:
photobox

Vulnerability:
Arbitrary File Upload

Patched in Version:
No Fix

Severity Score:
Critical


The vulnerability has not been patched. You should switch themes.

Photobox

Theme:

Photobox

Theme Slug:
photobox

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should switch themes.

Rezo

Theme:

Rezo

Theme Slug:
rezo

Vulnerability:
Arbitrary File Upload

Patched in Version:
No Fix

Severity Score:
Critical


The vulnerability has not been patched. You should switch themes.

Rezo

Theme:

Rezo

Theme Slug:
rezo

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should switch themes.

Shopo

Theme:

Shopo

Theme Slug:
shopo

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should switch themes.

Themify Sidepane WordPress Theme

Theme:

Themify Sidepane WordPress Theme

Theme Slug:
sidepane

Vulnerability:
Arbitrary File Upload

Patched in Version:
No Fix

Severity Score:
Critical


The vulnerability has not been patched. You should switch themes.

Themify Sidepane WordPress Theme

Theme:

Themify Sidepane WordPress Theme

Theme Slug:
sidepane

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should switch themes.

Slide

Theme:

Slide

Theme Slug:
slide

Vulnerability:
Arbitrary File Upload

Patched in Version:
No Fix

Severity Score:
Critical


The vulnerability has not been patched. You should switch themes.

Slide

Theme:

Slide

Theme Slug:
slide

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should switch themes.

Tiger

Theme:

Tiger

Theme Slug:
tiger

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should switch themes.

Tiger

Theme:

Tiger

Theme Slug:
tiger

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should switch themes.

Wigi

Theme:

Wigi

Theme Slug:
wigi

Vulnerability:
Arbitrary File Upload

Patched in Version:
No Fix

Severity Score:
Critical


The vulnerability has not been patched. You should switch themes.

Real Estate 7

Theme:

Real Estate 7

Theme Slug:
realestate-7

Vulnerability:
Arbitrary File Upload

Patched in Version:
3.5.5

Severity Score:
High


The vulnerability has been patched, so you should update to version 3.5.5.

Streamit

Theme:

Streamit

Theme Slug:
streamit

Vulnerability:
Arbitrary File Download

Patched in Version:
4.0.2

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 4.0.2.

Streamit

Theme:

Streamit

Theme Slug:
streamit

Vulnerability:
Arbitrary File Upload

Patched in Version:
4.0.2

Severity Score:
Critical


The vulnerability has been patched, so you should update to version 4.0.2.

Streamit

Theme:

Streamit

Theme Slug:
streamit

Vulnerability:
Privilege Escalation

Patched in Version:
4.0.3

Severity Score:
High


The vulnerability has been patched, so you should update to version 4.0.3.

Woffice

Theme:

Woffice

Theme Slug:
woffice

Vulnerability:
Privilege Escalation

Patched in Version:
5.4.22

Severity Score:
Critical


The vulnerability has been patched, so you should update to version 5.4.22.

Related articles

Wait! Get exclusive hosting insights

Subscribe to our newsletter and stay ahead of the competition with expert advice from our hosting pros.

Loading form…