Line illustration showing a black application window on a dark black to purple gradient background overlaid with a large exclamation point alert icon and three bugs.

WordPress Vulnerability Report � December 10, 2025

In this report, 170 vulnerabilities have been publicly disclosed. Security patches for 79 of these plugins and themes are now available. Please run these updates as soon as possible. If you’re a Solid Security Pro user, the version management tool may have already warned you and updated these plugins, depending on your settings.

Currently, 91 plugin and theme vulnerabilities remain unpatched. If you’re a Solid Security Pro user, those vulnerabilities are already protected by the Solid Security firewall. Virtual patches from Patchstack will be applied when a vulnerability is considered high or medium risk. If no patch is forthcoming from the vendor or the vulnerable software has been marked “closed” and dropped from the official WordPress repositories, you should deactivate it soon and look for alternative solutions.

WordPress Core

WordPress 6.9 “Gene” was released on December 2, 2025. This release brings major upgrades to how teams collaborate and create. The new Notes feature adds block-level commenting for posts and pages, streamlining editorial reviews, while an expanded Command Palette helps power users navigate and operate across the dashboard even faster. The introduction of the Abilities API delivers a standardized, machine-readable permissions system that lays the groundwork for next-generation AI-powered and automated workflows. WordPress 6.9 also includes notable performance improvements for faster page loads, several new practical blocks, and more visual drag-and-drop tools to help creators build richer, more dynamic content.

Following a major release, you should not update live sites without first taking backups and testing the update in a non-production environment.

WordPress Plugins � 77 Patched / 91 Unpatched

Happy Addons for Elementor

Plugin Slug:
happy-elementor-addons

Installations
400,000+

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Yandex.Metrica

Plugin Slug:
wp-yandex-metrika

Installations
60,000+

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

WP Ultimate Review

Plugin Slug:
wp-ultimate-review

Installations
50,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Custom Field Template

Plugin Slug:
custom-field-template

Installations
30,000+

Vulnerability:
Sensitive Data Exposure

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Xpro Addons � 140+ Widgets for Elementor

Plugin Slug:
xpro-elementor-addons

Installations
30,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Page View Count

Plugin Slug:
page-views-count

Installations
20,000+

Vulnerability:
Settings Change

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Make Section & Column Clickable For Elementor

Plugin Slug:
make-section-column-clickable-elementor

Installations
10,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Order Delivery Date for WooCommerce

Plugin Slug:
order-delivery-date-for-woocommerce

Installations
10,000+

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Xagio SEO � AI Powered SEO

Plugin Slug:
xagio-seo

Installations
10,000+

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Paysera Payment Gateway for WooCommerce

Plugin Slug:
woo-payment-gateway-paysera

Installations
8,000+

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Arconix Shortcodes

Plugin Slug:
arconix-shortcodes

Installations
4,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Custom Layouts � Post + Product grids made easy

Plugin Slug:
custom-layouts

Installations
4,000+

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

MultiParcels Shipping For WooCommerce

Plugin Slug:
multiparcels-shipping-for-woocommerce

Installations
4,000+

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Shopping Cart & eCommerce Store

Plugin Slug:
wp-easycart

Installations
4,000+

Vulnerability:
Sensitive Data Exposure

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Ergonet Cache

Plugin Slug:
ergonet-varnish-cache

Installations
2,000+

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Eupago Gateway For Woocommerce

Plugin Slug:
eupago-gateway-for-woocommerce

Installations
2,000+

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Social Photo Fetcher

Plugin Slug:
facebook-photo-fetcher

Installations
2,000+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Gravitec.net � Web Push Notifications

Plugin Slug:
gravitec-net-web-push-notifications

Installations
2,000+

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Just TinyMCE Custom Styles

Plugin Slug:
just-tinymce-styles

Installations
2,000+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Media Library Downloader

Plugin Slug:
media-library-downloader

Installations
2,000+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Post Cloner

Plugin Slug:
post-cloner

Installations
2,000+

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

WP Flashy Marketing Automation

Plugin Slug:
wp-flashy-marketing-automation

Installations
2,000+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Custom Sidebars by ProteusThemes

Plugin Slug:
custom-sidebars-by-proteusthemes

Installations
1,000+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Formstack Online Forms

Plugin Slug:
formstack

Installations
1,000+

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Image Cleanup

Plugin Slug:
image-cleanup

Installations
1,000+

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Image Cleanup

Plugin Slug:
image-cleanup

Installations
1,000+

Vulnerability:
Sensitive Data Exposure

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

SMTP Mail

Plugin Slug:
smtp-mail

Installations
1,000+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

User Spam Remover

Plugin Slug:
user-spam-remover

Installations
1,000+

Vulnerability:
Sensitive Data Exposure

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

WP-CRM System � Manage Clients and Projects

Plugin Slug:
wp-crm-system

Installations
1,000+

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Generic Elements

Plugin Slug:
generic-elements-for-elementor

Installations
600+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

g-FFL Cockpit

Plugin Slug:
g-ffl-cockpit

Installations
400+

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Search, Filters & Merchandising for WooCommerce

Plugin Slug:
instantsearch-for-woocommerce

Installations
200+

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Actionwear products sync

Plugin Slug:
actionwear-products-sync

Installations
60+

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Flex QR Code Generator

Plugin Slug:
flex-qr-code-generator

Installations
50+

Vulnerability:
Arbitrary File Upload

Patched in Version:
No Fix

Severity Score:
Critical


The vulnerability has not been patched. You should deactivate the plugin.

Hype

Plugin:

Hype

Plugin Slug:
pico

Installations
50+

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Application Passwords

Plugin:

Application Passwords

Plugin Slug:
application-passwords

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.
Plugin:

ARK Related Posts

Plugin Slug:
ark-relatedpost

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.
Plugin:

Broken Link Manager

Plugin Slug:
broken-link-manager

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Canadian Nutrition Facts Label

Plugin:

Canadian Nutrition Facts Label

Plugin Slug:
canadian-nutrition-facts-label

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Clikstats

Plugin:

Clikstats

Plugin Slug:
clikstats

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

CryptX

Plugin:

CryptX

Plugin Slug:
cryptx

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

CSS3 Buttons

Plugin:

CSS3 Buttons

Plugin Slug:
css3-buttons

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

CSV Sumotto

Plugin:

CSV Sumotto

Plugin Slug:
csv-sumotto

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Cute News Ticker

Plugin:

Cute News Ticker

Plugin Slug:
cute-news-ticker

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

DB Access

Plugin:

DB Access

Plugin Slug:
db-access

Vulnerability:
SQL Injection

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.
Plugin:

dream gallery

Plugin Slug:
dream-gallery

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Extra Post Images

Plugin:

Extra Post Images

Plugin Slug:
extra-post-images

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

FitVids for WordPress

Plugin:

FitVids for WordPress

Plugin Slug:
fitvids-for-wordpress

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Helloprint

Plugin:

Helloprint

Plugin Slug:
helloprint

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Jabbernotification

Plugin:

Jabbernotification

Plugin Slug:
jabberbenachrichtigung

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

List Attachments Shortcode

Plugin:

List Attachments Shortcode

Plugin Slug:
list-attachments-shortcode

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Listar � Directory Listing & Classifieds

Plugin:

Listar � Directory Listing & Classifieds

Plugin Slug:
listar-directory-listing

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Listar � Directory Listing & Classifieds

Plugin:

Listar � Directory Listing & Classifieds

Plugin Slug:
listar-directory-listing

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Live CSS Preview

Plugin:

Live CSS Preview

Plugin Slug:
live-css-preview

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

myLCO

Plugin:

myLCO

Plugin Slug:
mylco

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Nouri.sh Newsletter

Plugin:

Nouri.sh Newsletter

Plugin Slug:
newsletters-from-rss-to-email-newsletters-using-nourish

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Payaza

Plugin:

Payaza

Plugin Slug:
payaza

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Post Grid and Gutenberg Blocks

Plugin:

Post Grid and Gutenberg Blocks

Plugin Slug:
post-grid

Vulnerability:
Insecure Direct Object References (IDOR)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

PostGallery

Plugin:

PostGallery

Plugin Slug:
postgallery

Vulnerability:
Arbitrary File Upload

Patched in Version:
No Fix

Severity Score:
Critical


The vulnerability has not been patched. You should deactivate the plugin.

Projectopia

Plugin:

Projectopia

Plugin Slug:
projectopia-core

Vulnerability:
Insecure Direct Object References (IDOR)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Projectopia

Plugin:

Projectopia

Plugin Slug:
projectopia-core

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

RevInsite

Plugin:

RevInsite

Plugin Slug:
revinsite

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.
Plugin:

Social Feed Gallery Portfolio

Plugin Slug:
social-feed-gallery-portfolio

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

WordPress eCommerce Plugin � Studiocart

Plugin:

WordPress eCommerce Plugin � Studiocart

Plugin Slug:
studiocart

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Thai Lottery Widget

Plugin:

Thai Lottery Widget

Plugin Slug:
thai-lottery-widget

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Time Sheets

Plugin:

Time Sheets

Plugin Slug:
time-sheets

Vulnerability:
Server Side Request Forgery (SSRF)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Time Sheets

Plugin:

Time Sheets

Plugin Slug:
time-sheets

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

TR Timthumb

Plugin:

TR Timthumb

Plugin Slug:
tr-timthumb

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Trail Manager

Plugin:

Trail Manager

Plugin Slug:
trail-manager

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Twitscription

Plugin:

Twitscription

Plugin Slug:
twitscription

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Ultra Skype Button

Plugin:

Ultra Skype Button

Plugin Slug:
ultra-skype-button

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

User Generator and Importer

Plugin:

User Generator and Importer

Plugin Slug:
user-importer-and-generator

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

User Verification

Plugin:

User Verification

Plugin Slug:
user-verification

Vulnerability:
Privilege Escalation

Patched in Version:
No Fix

Severity Score:
Critical


The vulnerability has not been patched. You should deactivate the plugin.

Voidek Employee Portal

Plugin:

Voidek Employee Portal

Plugin Slug:
voidek-employee-portal

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

WebP Express

Plugin:

WebP Express

Plugin Slug:
webp-express

Vulnerability:
Sensitive Data Exposure

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Weekly Planner

Plugin:

Weekly Planner

Plugin Slug:
weekly-planner

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Live Sales Notification for Woocommerce – Woomotiv

Plugin:

Live Sales Notification for Woocommerce – Woomotiv

Plugin Slug:
woomotiv

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

WP Landing Page

Plugin:

WP Landing Page

Plugin Slug:
wp-landing-page

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

WP-SOS-Donate

Plugin:

WP-SOS-Donate

Plugin Slug:
wp-sos-donate

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Yet Another WebClap for WordPress

Plugin:

Yet Another WebClap for WordPress

Plugin Slug:
yet-another-webclap-for-wordpress

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Custom Post Type UI

Plugin Slug:
custom-post-type-ui

Installations
1,000,000+

Vulnerability:
Broken Access Control

Patched in Version:
1.18.1

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.18.1.

Autoptimize

Plugin Slug:
autoptimize

Installations
900,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
3.1.14

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 3.1.14.

Widgets for Google Reviews

Plugin Slug:
wp-reviews-plugin-for-google

Installations
800,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
13.2.5

Severity Score:
High


The vulnerability has been patched, so you should update to version 13.2.5.

PDF Invoices & Packing Slips for WooCommerce

Plugin Slug:
woocommerce-pdf-invoices-packing-slips

Installations
300,000+

Vulnerability:
Broken Access Control

Patched in Version:
5.0.0

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 5.0.0.

Advanced Custom Fields: Extended

Plugin Slug:
acf-extended

Installations
100,000+

Vulnerability:
Remote Code Execution (RCE)

Patched in Version:
0.9.2

Severity Score:
Critical


The vulnerability has been patched, so you should update to version 0.9.2.

Backup Migration

Plugin Slug:
backup-backup

Installations
100,000+

Vulnerability:
Broken Access Control

Patched in Version:
2.0.0

Severity Score:
High


The vulnerability has been patched, so you should update to version 2.0.0.

Kadence WooCommerce Email Designer

Plugin Slug:
kadence-woocommerce-email-designer

Installations
100,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.5.18

Severity Score:
High


The vulnerability has been patched, so you should update to version 1.5.18.
Plugin Slug:
modula-best-grid-gallery

Installations
100,000+

Vulnerability:
Arbitrary File Upload

Patched in Version:
2.13.3

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.13.3.
Plugin Slug:
modula-best-grid-gallery

Installations
100,000+

Vulnerability:
Arbitrary File Deletion

Patched in Version:
2.13.3

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.13.3.

Rich Shortcodes for Google Reviews

Plugin Slug:
widget-google-reviews

Installations
100,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
6.8.1

Severity Score:
High


The vulnerability has been patched, so you should update to version 6.8.1.

HUSKY � Products Filter Professional for WooCommerce

Plugin Slug:
woocommerce-products-filter

Installations
100,000+

Vulnerability:
Insecure Direct Object References (IDOR)

Patched in Version:
1.3.7.3

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.3.7.3.

Wp Social Login and Register Social Counter

Plugin Slug:
wp-social

Installations
60,000+

Vulnerability:
Broken Access Control

Patched in Version:
3.1.4

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 3.1.4.

FunnelKit � Funnel Builder for WooCommerce Checkout

Plugin Slug:
funnel-builder

Installations
40,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
3.13.1.3

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 3.13.1.3.

Cost Calculator Builder

Plugin Slug:
cost-calculator-builder

Installations
30,000+

Vulnerability:
Arbitrary File Deletion

Patched in Version:
3.6.4

Severity Score:
High


The vulnerability has been patched, so you should update to version 3.6.4.

Envo Extra

Plugin Slug:
envo-extra

Installations
30,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.9.12

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.9.12.

Timetable and Event Schedule by MotoPress

Plugin Slug:
mp-timetable

Installations
30,000+

Vulnerability:
Insecure Direct Object References (IDOR)

Patched in Version:
2.4.16

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.4.16.
Plugin Slug:
all-in-one-video-gallery

Installations
20,000+

Vulnerability:
Arbitrary File Upload

Patched in Version:
4.6.4

Severity Score:
Critical


The vulnerability has been patched, so you should update to version 4.6.4.

Quiz Maker

Plugin Slug:
quiz-maker

Installations
20,000+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
6.7.0.83

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 6.7.0.83.

Frontend Admin by DynamiApps

Plugin Slug:
acf-frontend-form-element

Installations
10,000+

Vulnerability:
Privilege Escalation

Patched in Version:
3.28.21

Severity Score:
Critical


The vulnerability has been patched, so you should update to version 3.28.21.

Nexter Extension � Site Enhancements Toolkit

Plugin Slug:
nexter-extension

Installations
10,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
4.4.2

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 4.4.2.

Export All Posts, Products, Orders, Refunds & Users

Plugin Slug:
wp-ultimate-exporter

Installations
10,000+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
2.20

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.20.

GSheetConnector For WPForms

Plugin Slug:
gsheetconnector-wpforms

Installations
8,000+

Vulnerability:
Broken Access Control

Patched in Version:
4.0.1

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 4.0.1.

Event Booking Manager for WooCommerce

Plugin Slug:
mage-eventpress

Installations
8,000+

Vulnerability:
Broken Access Control

Patched in Version:
5.0.5

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 5.0.5.

WPKoi Templates for Elementor

Plugin Slug:
wpkoi-templates-for-elementor

Installations
5,000+

Vulnerability:
Broken Access Control

Patched in Version:
3.4.5

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 3.4.5.

Chartify � WordPress Chart Plugin

Plugin Slug:
chart-builder

Installations
4,000+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
3.6.4

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 3.6.4.

SMS Alert Order Notifications � WooCommerce

Plugin Slug:
sms-alert

Installations
4,000+

Vulnerability:
Broken Access Control

Patched in Version:
3.8.9

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 3.8.9.

VikRentCar Car Rental Management System

Plugin Slug:
vikrentcar

Installations
4,000+

Vulnerability:
SQL Injection

Patched in Version:
1.4.5

Severity Score:
High


The vulnerability has been patched, so you should update to version 1.4.5.

Salon Booking System � Free Version

Plugin Slug:
salon-booking-system

Installations
3,000+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
10.30.4

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 10.30.4.

WP Directory Kit

Plugin Slug:
wpdirectorykit

Installations
3,000+

Vulnerability:
Broken Authentication

Patched in Version:
1.4.5

Severity Score:
Critical


The vulnerability has been patched, so you should update to version 1.4.5.

WP Directory Kit

Plugin Slug:
wpdirectorykit

Installations
3,000+

Vulnerability:
SQL Injection

Patched in Version:
1.4.7

Severity Score:
High


The vulnerability has been patched, so you should update to version 1.4.7.

Advanced FAQ Manager

Plugin Slug:
advanced-faq-manager

Installations
2,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.5.3

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.5.3.

Auto Alt Text

Plugin Slug:
auto-alt-text

Installations
2,000+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
2.5.3

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.5.3.

CSSIgniter Shortcodes

Plugin Slug:
cssigniter-shortcodes

Installations
2,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.4.2

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.4.2.
Plugin Slug:
gallery-photo-gallery

Installations
2,000+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
6.4.9

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 6.4.9.

PDF Thumbnail Generator

Plugin Slug:
pdf-thumbnail-generator

Installations
2,000+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
1.5

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.5.

Portfolio and Projects

Plugin Slug:
portfolio-and-projects

Installations
2,000+

Vulnerability:
Sensitive Data Exposure

Patched in Version:
1.5.6

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.5.6.

Tableberg � Simple Gutenberg Table Block

Plugin Slug:
tableberg

Installations
2,000+

Vulnerability:
Broken Access Control

Patched in Version:
0.6.10

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 0.6.10.

Email Marketing Plugin � WP Email Capture

Plugin Slug:
wp-email-capture

Installations
2,000+

Vulnerability:
Broken Access Control

Patched in Version:
3.12.5

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 3.12.5.

Constant Contact + WooCommerce

Plugin Slug:
constant-contact-woocommerce

Installations
1,000+

Vulnerability:
Broken Access Control

Patched in Version:
2.4.2

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.4.2.

MxChat � AI Chatbot for WordPress

Plugin Slug:
mxchat-basic

Installations
900+

Vulnerability:
Sensitive Data Exposure

Patched in Version:
2.5.6

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.5.6.

My Tickets � Accessible Event Ticketing

Plugin Slug:
my-tickets

Installations
700+

Vulnerability:
Broken Access Control

Patched in Version:
2.1.1

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.1.1.

My auctions allegro

Plugin Slug:
my-auctions-allegro-free-edition

Installations
600+

Vulnerability:
Local File Inclusion

Patched in Version:
3.6.33

Severity Score:
High


The vulnerability has been patched, so you should update to version 3.6.33.

My auctions allegro

Plugin Slug:
my-auctions-allegro-free-edition

Installations
600+

Vulnerability:
SQL Injection

Patched in Version:
3.6.33

Severity Score:
Critical


The vulnerability has been patched, so you should update to version 3.6.33.

ELEX WordPress HelpDesk & Customer Ticketing System

Plugin Slug:
elex-helpdesk-customer-support-ticket-system

Installations
300+

Vulnerability:
Privilege Escalation

Patched in Version:
3.3.3

Severity Score:
High


The vulnerability has been patched, so you should update to version 3.3.3.

TAX SERVICE Electronic HDM

Plugin Slug:
virtual-hdm-for-taxservice-am

Installations
10+

Vulnerability:
SQL Injection

Patched in Version:
1.2.1

Severity Score:
Critical


The vulnerability has been patched, so you should update to version 1.2.1.

DesignThemes LMS

Plugin:

DesignThemes LMS

Plugin Slug:
designthemes-lms

Vulnerability:
Privilege Escalation

Patched in Version:
1.0.5

Severity Score:
Critical


The vulnerability has been patched, so you should update to version 1.0.5.

FindAll Listing

Plugin:

FindAll Listing

Plugin Slug:
findall-listing

Vulnerability:
Privilege Escalation

Patched in Version:
1.1

Severity Score:
Critical


The vulnerability has been patched, so you should update to version 1.1.
Plugin:

JNews Gallery

Plugin Slug:
jnews-gallery

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
12.0.1

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 12.0.1.

JNews Paywall

Plugin:

JNews Paywall

Plugin Slug:
jnews-paywall

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
12.0.1

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 12.0.1.

StreamTube Core

Plugin:

StreamTube Core

Plugin Slug:
streamtube-core

Vulnerability:
Broken Authentication

Patched in Version:
4.79

Severity Score:
Critical


The vulnerability has been patched, so you should update to version 4.79.

Upload.am � File Hosting & VPN

Plugin Slug:
upload-am-file-hosting-vpn

Vulnerability:
Sensitive Data Exposure

Patched in Version:
1.0.1

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.0.1.

WordPress Themes � 2 Patched / 0 Unpatched

AdForest

Theme:

AdForest

Theme Slug:
adforest

Vulnerability:
Broken Access Control

Patched in Version:
6.0.12

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 6.0.12.

Rehub

Theme:

Rehub

Theme Slug:
rehub-theme

Vulnerability:
Sensitive Data Exposure

Patched in Version:
19.9.9.2

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 19.9.9.2.

Related articles

Wait! Get exclusive hosting insights

Subscribe to our newsletter and stay ahead of the competition with expert advice from our hosting pros.

Loading form…