Line illustration showing a black application window on a purple gradient background overlaid with a large exclamation point alert icon and three bugs.

WordPress Vulnerability Report � December 25, 2024

In this report, 212 vulnerabilities have been publicly disclosed. Security patches for 139 of these plugins and themes are available now, so run those updates as soon as possible. If you’re a Solid Security Pro user, the version management tool may have already warned you and updated these plugins, depending on your settings.

Additionally, there are 73 plugin and theme vulnerabilities with no patch available yet. If you’re a Solid Security Pro user, those vulnerabilities are already protected by the Solid Security firewall. Virtual patches from Patchstack will be applied when a vulnerability is considered high or medium risk. If no patch is forthcoming from the vendor or the vulnerable software has been marked “closed” and dropped from the official WordPress repositories, you should deactivate it soon and look for alternative solutions.

WordPress Core

WordPress 6.7.1 is available! This minor release features 16 bug fixes throughout Core and the Block Editor.

WordPress Plugins � 134 Patched / 69 Unpatched

Custom Product tabs for WooCommerce

Plugin Slug:
wb-custom-product-tabs-for-woocommerce

Installations
2,000+

Vulnerability:
PHP Object Injection

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

WP Menu Image

Plugin Slug:
wp-menu-image

Installations
2,000+

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Page and Post Restriction

Plugin Slug:
page-and-post-restriction

Installations
1,000+

Vulnerability:
Sensitive Data Exposure

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

One Click Upsell Funnel for WooCommerce � Funnel Builder for WordPress, Create WooCommerce Upsell, Post-Purchase Upsell & Cross Sell Offers that Boost Sales & Increase Profits with Sales Funnel Builder

Plugin Slug:
woo-one-click-upsell-funnel

Installations
600+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Outdooractive Embed

Plugin Slug:
outdooractive-embed

Installations
400+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Slope Widgets

Plugin Slug:
slope-widgets

Installations
400+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Coupon Plugin

Plugin Slug:
coupon-lite

Installations
300+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

NACC WordPress Plugin

Plugin Slug:
nacc-wordpress-plugin

Installations
100+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Partners

Plugin:

Partners

Plugin Slug:
partners

Installations
100+

Vulnerability:
PHP Object Injection

Patched in Version:
No Fix

Severity Score:
Critical


The vulnerability has not been patched. You should deactivate the plugin.

??????? ??????? ??????? ???? ????

Plugin Slug:
isee-products-extractor

Installations
60+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

VRPConnector

Plugin Slug:
vrpconnector

Installations
60+

Vulnerability:
PHP Object Injection

Patched in Version:
No Fix

Severity Score:
Critical


The vulnerability has not been patched. You should deactivate the plugin.

WP Nice Loader

Plugin Slug:
wp-nice-loader

Installations
60+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

SSL Wireless SMS Notification

Plugin Slug:
ssl-wireless-sms-notification

Installations
50+

Vulnerability:
Privilege Escalation

Patched in Version:
No Fix

Severity Score:
Critical


The vulnerability has not been patched. You should deactivate the plugin.

10CentMail

Plugin:

10CentMail

Plugin Slug:
10centmail-subscription-management-and-analytics

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

AdWork Media EZ Content Locker

Plugin:

AdWork Media EZ Content Locker

Plugin Slug:
adwork-media-ez-content-locker

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Animated Counters

Plugin:

Animated Counters

Plugin Slug:
animated-counters

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

BU Section Editing

Plugin:

BU Section Editing

Plugin Slug:
bu-section-editing

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Category Post Shortcode

Plugin:

Category Post Shortcode

Plugin Slug:
category-post-shortcode

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Category Post Slider

Plugin:

Category Post Slider

Plugin Slug:
category-post-slider

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Custom Dashboard Widget

Plugin:

Custom Dashboard Widget

Plugin Slug:
create-custom-dashboard-widget

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Easy Language Switcher

Plugin:

Easy Language Switcher

Plugin Slug:
easy-language-switcher

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

EditionGuard for WooCommerce � eBook Sales with DRM

Plugin:

EditionGuard for WooCommerce � eBook Sales with DRM

Plugin Slug:
editionguard-for-woocommerce-ebook-sales-with-drm

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Embed Twine

Plugin:

Embed Twine

Plugin Slug:
embed-twine

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

FAQs

Plugin:

FAQs

Plugin Slug:
faqs

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Financial Calculator

Plugin:

Financial Calculator

Plugin Slug:
finance-calculator-with-application-form

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Full Screen Menu for Elementor

Plugin:

Full Screen Menu for Elementor

Plugin Slug:
full-screen-menu-for-elementor

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

gap-hub-user-role

Plugin:

gap-hub-user-role

Plugin Slug:
gap-hub-user-role

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

GTPayment Donations

Plugin:

GTPayment Donations

Plugin Slug:
gtpayment-donation

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

G Web Pro Store Locator

Plugin:

G Web Pro Store Locator

Plugin Slug:
gwebpro-store-locator

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Image Mapper

Plugin:

Image Mapper

Plugin Slug:
image-mapper

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Inline Footnotes

Plugin:

Inline Footnotes

Plugin Slug:
inline-footnotes

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Kintpv Wooconnect

Plugin:

Kintpv Wooconnect

Plugin Slug:
kintpv-connect

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

LaTeX2HTML

Plugin:

LaTeX2HTML

Plugin Slug:
latex2html

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Leads CRM

Plugin:

Leads CRM

Plugin Slug:
leads-crm

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Lemonade Social Networks Autoposter Pinterest

Plugin:

Lemonade Social Networks Autoposter Pinterest

Plugin Slug:
lemonade-sna-pinterest-edition

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Maintenance & Coming Soon Redirect Animation

Plugin:

Maintenance & Coming Soon Redirect Animation

Plugin Slug:
maintenance-coming-soon-redirect-animation

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Multi-column Tag Map

Plugin:

Multi-column Tag Map

Plugin Slug:
multi-column-tag-map

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

AI Magic

Plugin:

AI Magic

Plugin Slug:
newsletter-page-redirects

Vulnerability:
Privilege Escalation

Patched in Version:
No Fix

Severity Score:
Critical


The vulnerability has not been patched. You should deactivate the plugin.

odPhotogallery

Plugin:

odPhotogallery

Plugin Slug:
od-photogallery-plugin

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Particle Background

Plugin:

Particle Background

Plugin Slug:
particle-background

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Pingmeter Uptime Monitoring

Plugin:

Pingmeter Uptime Monitoring

Plugin Slug:
pingmeter-uptime-monitoring

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.
Plugin:

Portfolio � Filterable Masonry Portfolio Gallery for Professionals

Plugin Slug:
portfolio-pro

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Preloader by WordPress Monsters

Plugin:

Preloader by WordPress Monsters

Plugin Slug:
preloader-sws

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Reactflow Visitor Recording and Heatmaps

Plugin:

Reactflow Visitor Recording and Heatmaps

Plugin Slug:
reactflow-session-replay-heatmap

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

real.Kit

Plugin:

real.Kit

Plugin Slug:
real-kit

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Saoshyant Element

Plugin:

Saoshyant Element

Plugin Slug:
saoshyant-element

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

SendSMS

Plugin:

SendSMS

Plugin Slug:
sendsms

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Services updates for customers

Plugin:

Services updates for customers

Plugin Slug:
service-updates-for-customers

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Simple Dashboard

Plugin:

Simple Dashboard

Plugin Slug:
simple-dashboard

Vulnerability:
Privilege Escalation

Patched in Version:
No Fix

Severity Score:
Critical


The vulnerability has not been patched. You should deactivate the plugin.

Simple Proxy

Plugin:

Simple Proxy

Plugin Slug:
simple-proxy

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Sinking Dropdowns

Plugin:

Sinking Dropdowns

Plugin Slug:
sinking-dropdowns

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Smart Shopify Product

Plugin:

Smart Shopify Product

Plugin Slug:
smart-shopify-product

Vulnerability:
Arbitrary Content Deletion

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Spoki � Chat Buttons and WooCommerce Notifications

Plugin:

Spoki � Chat Buttons and WooCommerce Notifications

Plugin Slug:
spoki

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Spotlightr

Plugin:

Spotlightr

Plugin Slug:
spotlightr

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

SvegliaT Buttons

Plugin:

SvegliaT Buttons

Plugin Slug:
svegliat-buttons

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Tidy Up

Plugin:

Tidy Up

Plugin Slug:
tidy-up

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

TPG Get Posts

Plugin:

TPG Get Posts

Plugin Slug:
tpg-get-posts

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Upload Scanner

Plugin:

Upload Scanner

Plugin Slug:
upload-scanner

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

User Referral

Plugin:

User Referral

Plugin Slug:
user-referral-free

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Userpro

Plugin:

Userpro

Plugin Slug:
userpro

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Userpro

Plugin:

Userpro

Plugin Slug:
userpro

Vulnerability:
Local File Inclusion

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Userpro

Plugin:

Userpro

Plugin Slug:
userpro

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Userpro

Plugin:

Userpro

Plugin Slug:
userpro

Vulnerability:
SQL Injection

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Wayne Audio Player

Plugin:

Wayne Audio Player

Plugin Slug:
wayne-audio-player

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

WP eCommerce Quickpay

Plugin:

WP eCommerce Quickpay

Plugin Slug:
wp-ecommerce-quickpay

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

WP SHAPES

Plugin:

WP SHAPES

Plugin Slug:
wp-shapes

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Tithe.ly Giving Button

Plugin:

Tithe.ly Giving Button

Plugin Slug:
wp-tithely

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Wtyczka SeoPilot dla WP

Plugin:

Wtyczka SeoPilot dla WP

Plugin Slug:
wtyczka-seopilot-dla-wp

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

LiteSpeed Cache

Plugin Slug:
litespeed-cache

Installations
6,000,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
6.5.3

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 6.5.3.
Plugin Slug:
essential-addons-for-elementor-lite

Installations
2,000,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
6.0.8

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 6.0.8.

Premium Addons for Elementor

Plugin Slug:
premium-addons-for-elementor

Installations
700,000+

Vulnerability:
Broken Access Control

Patched in Version:
4.10.57

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 4.10.57.

The Events Calendar

Plugin Slug:
the-events-calendar

Installations
700,000+

Vulnerability:
Broken Access Control

Patched in Version:
6.8.2.1

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 6.8.2.1.

User Role Editor

Plugin Slug:
user-role-editor

Installations
700,000+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
4.64.4

Severity Score:
Critical


The vulnerability has been patched, so you should update to version 4.64.4.

Royal Elementor Addons and Templates

Plugin Slug:
royal-elementor-addons

Installations
500,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.7.1002

Severity Score:
High


The vulnerability has been patched, so you should update to version 1.7.1002.

Royal Elementor Addons and Templates

Plugin Slug:
royal-elementor-addons

Installations
500,000+

Vulnerability:
Broken Access Control

Patched in Version:
1.7.1002

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.7.1002.

Royal Elementor Addons and Templates

Plugin Slug:
royal-elementor-addons

Installations
500,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.7.1

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.7.1.

AMP for WP � Accelerated Mobile Pages

Plugin Slug:
accelerated-mobile-pages

Installations
100,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.1.2

Severity Score:
High


The vulnerability has been patched, so you should update to version 1.1.2.

Advanced Google reCAPTCHA

Plugin Slug:
advanced-google-recaptcha

Installations
100,000+

Vulnerability:
Other Vulnerability Type

Patched in Version:
1.26

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.26.

Contact Form 7 � Dynamic Text Extension

Plugin Slug:
contact-form-7-dynamic-text-extension

Installations
100,000+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
5.0.2

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 5.0.2.

Download Manager

Plugin Slug:
download-manager

Installations
100,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
3.3.03

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 3.3.03.

Download Manager

Plugin Slug:
download-manager

Installations
100,000+

Vulnerability:
Broken Access Control

Patched in Version:
3.3.04

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 3.3.04.

Download Manager

Plugin Slug:
download-manager

Installations
100,000+

Vulnerability:
Arbitrary Code Execution

Patched in Version:
3.3.04

Severity Score:
High


The vulnerability has been patched, so you should update to version 3.3.04.

Download Manager

Plugin Slug:
download-manager

Installations
100,000+

Vulnerability:
Broken Access Control

Patched in Version:
3.3.04

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 3.3.04.

Tracking Code Manager

Plugin Slug:
tracking-code-manager

Installations
100,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.4.0

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.4.0.

kk Star Ratings � Rate Post & Collect User Feedbacks

Plugin Slug:
kk-star-ratings

Installations
90,000+

Vulnerability:
Arbitrary Code Execution

Patched in Version:
5.4.10.1

Severity Score:
High


The vulnerability has been patched, so you should update to version 5.4.10.1.

WordPress Button Plugin MaxButtons

Plugin Slug:
maxbuttons

Installations
90,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
9.8.1

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 9.8.1.

File Manager Pro � Filester

Plugin Slug:
filester

Installations
80,000+

Vulnerability:
Broken Access Control

Patched in Version:
1.8.7

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.8.7.

Calculated Fields Form

Plugin Slug:
calculated-fields-form

Installations
50,000+

Vulnerability:
Denial of Service Attack

Patched in Version:
5.2.64

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 5.2.64.

Seraphinite Accelerator

Plugin Slug:
seraphinite-accelerator

Installations
40,000+

Vulnerability:
Sensitive Data Exposure

Patched in Version:
2.22.16

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.22.16.

Cost Calculator Builder

Plugin Slug:
cost-calculator-builder

Installations
30,000+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
3.2.43

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 3.2.43.

PPWP � Password Protect Pages

Plugin Slug:
password-protect-page

Installations
30,000+

Vulnerability:
Sensitive Data Exposure

Patched in Version:
1.9.6

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.9.6.

Print Invoice & Delivery Notes for WooCommerce

Plugin Slug:
woocommerce-delivery-notes

Installations
30,000+

Vulnerability:
Broken Access Control

Patched in Version:
5.4.1

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 5.4.1.

Serious Slider

Plugin Slug:
cryout-serious-slider

Installations
20,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.2.7

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.2.7.

Embed PDF Viewer

Plugin Slug:
embed-pdf-viewer

Installations
20,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.4.0

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.4.0.

HTML Forms � Simple WordPress Forms Plugin

Plugin Slug:
html-forms

Installations
10,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.4.2

Severity Score:
High


The vulnerability has been patched, so you should update to version 1.4.2.

WordPress Simple Shopping Cart

Plugin Slug:
wordpress-simple-paypal-shopping-cart

Installations
10,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
5.0.8

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 5.0.8.

Frontend Admin by DynamiApps

Plugin Slug:
acf-frontend-form-element

Installations
9,000+

Vulnerability:
SQL Injection

Patched in Version:
3.25.2

Severity Score:
Critical


The vulnerability has been patched, so you should update to version 3.25.2.

eCommerce Product Catalog Plugin for WordPress

Plugin Slug:
ecommerce-product-catalog

Installations
9,000+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
3.3.44

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 3.3.44.

Affiliate Program Suite � SliceWP Affiliates

Plugin Slug:
slicewp

Installations
9,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.1.24

Severity Score:
High


The vulnerability has been patched, so you should update to version 1.1.24.

WP Datepicker

Plugin Slug:
wp-datepicker

Installations
9,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.1.5

Severity Score:
High


The vulnerability has been patched, so you should update to version 2.1.5.

Events Addon for Elementor

Plugin Slug:
events-addon-for-elementor

Installations
8,000+

Vulnerability:
Broken Access Control

Patched in Version:
2.2.4

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.2.4.

PowerPack Lite for Beaver Builder

Plugin Slug:
powerpack-addon-for-beaver-builder

Installations
8,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.3.1

Severity Score:
High


The vulnerability has been patched, so you should update to version 1.3.1.

Themify Builder

Plugin Slug:
themify-builder

Installations
6,000+

Vulnerability:
Local File Inclusion

Patched in Version:
7.6.5

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 7.6.5.

Animation Addons for Elementor

Plugin Slug:
animation-addons-for-elementor

Installations
5,000+

Vulnerability:
Sensitive Data Exposure

Patched in Version:
1.1.7

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.1.7.

Collapsing Categories

Plugin Slug:
collapsing-categories

Installations
5,000+

Vulnerability:
SQL Injection

Patched in Version:
3.0.9

Severity Score:
Critical


The vulnerability has been patched, so you should update to version 3.0.9.

Simple Page Access Restriction

Plugin Slug:
simple-page-access-restriction

Installations
5,000+

Vulnerability:
Sensitive Data Exposure

Patched in Version:
1.0.30

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.0.30.

Booking calendar, Appointment Booking System

Plugin Slug:
booking-calendar

Installations
4,000+

Vulnerability:
SQL Injection

Patched in Version:
3.2.20

Severity Score:
High


The vulnerability has been patched, so you should update to version 3.2.20.
Plugin Slug:
broken-link-finder

Installations
4,000+

Vulnerability:
Server Side Request Forgery (SSRF)

Patched in Version:
2.5.1

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.5.1.

ElementsReady Addons for Elementor

Plugin Slug:
element-ready-lite

Installations
4,000+

Vulnerability:
Sensitive Data Exposure

Patched in Version:
6.4.9

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 6.4.9.

EventPrime � Events Calendar, Bookings and Tickets

Plugin Slug:
eventprime-event-calendar-management

Installations
4,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
4.0.6.0

Severity Score:
High


The vulnerability has been patched, so you should update to version 4.0.6.0.

Responsive Blocks � WordPress Gutenberg Blocks

Plugin Slug:
responsive-block-editor-addons

Installations
4,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.9.8

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.9.8.

Wishlist for WooCommerce: Multi Wishlists Per Customer

Plugin Slug:
wish-list-for-woocommerce

Installations
3,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
3.1.3

Severity Score:
High


The vulnerability has been patched, so you should update to version 3.1.3.

WP-Appbox

Plugin Slug:
wp-appbox

Installations
3,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
4.5.4

Severity Score:
High


The vulnerability has been patched, so you should update to version 4.5.4.

WC Price History for Omnibus

Plugin Slug:
wc-price-history

Installations
2,000+

Vulnerability:
Broken Access Control

Patched in Version:
2.1.4

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.1.4.

ELEX WooCommerce Dynamic Pricing and Discounts

Plugin Slug:
elex-woocommerce-dynamic-pricing-and-discounts

Installations
1,000+

Vulnerability:
Broken Access Control

Patched in Version:
2.1.8

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.1.8.

Memberful � Membership Plugin

Plugin Slug:
memberful-wp

Installations
1,000+

Vulnerability:
Sensitive Data Exposure

Patched in Version:
1.74.0

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.74.0.

SearchIQ � The Search Solution

Plugin Slug:
searchiq

Installations
1,000+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
4.7

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 4.7.

WP Docs

Plugin:

WP Docs

Plugin Slug:
wp-docs

Installations
1,000+

Vulnerability:
SQL Injection

Patched in Version:
2.2.1

Severity Score:
High


The vulnerability has been patched, so you should update to version 2.2.1.

TicketSource Ticket Shop

Plugin Slug:
ticketsource-events

Installations
800+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
3.1.0

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 3.1.0.

Loan Comparison

Plugin Slug:
loan-comparison

Installations
500+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.0.1

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.0.1.

WooCommerce Additional Fees On Checkout (Free)

Plugin Slug:
woo-additional-fees-on-checkout-wordpress

Installations
500+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.4.8

Severity Score:
High


The vulnerability has been patched, so you should update to version 1.4.8.

CRM WordPress Plugin � RepairBuddy

Plugin Slug:
computer-repair-shop

Installations
400+

Vulnerability:
Privilege Escalation

Patched in Version:
3.8120

Severity Score:
High


The vulnerability has been patched, so you should update to version 3.8120.

CRM WordPress Plugin � RepairBuddy

Plugin Slug:
computer-repair-shop

Installations
400+

Vulnerability:
Broken Access Control

Patched in Version:
3.8122

Severity Score:
High


The vulnerability has been patched, so you should update to version 3.8122.

MagicPost � WordPress??????????

Plugin Slug:
magicpost

Installations
400+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.2.2

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.2.2.

Member Directory and Contact Form

Plugin Slug:
pta-member-directory

Installations
400+

Vulnerability:
Broken Access Control

Patched in Version:
1.8.0

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.8.0.

WP on AWS

Plugin Slug:
wp-migrate-2-aws

Installations
400+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
5.2.2

Severity Score:
High


The vulnerability has been patched, so you should update to version 5.2.2.

PCRecruiter Extensions

Plugin Slug:
pcrecruiter-extensions

Installations
300+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.4.23

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.4.23.

Peter�s Custom Anti-Spam

Plugin Slug:
peters-custom-anti-spam-image

Installations
300+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
3.2.4

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 3.2.4.

Stop Registration Spam

Plugin Slug:
stop-registration-spam

Installations
300+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
1.24

Severity Score:
High


The vulnerability has been patched, so you should update to version 1.24.

WP BASE Booking of Appointments, Services and Events

Plugin Slug:
wp-base-booking-of-appointments-services-and-events

Installations
300+

Vulnerability:
Broken Access Control

Patched in Version:
5.0.0

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 5.0.0.

WP BASE Booking of Appointments, Services and Events

Plugin Slug:
wp-base-booking-of-appointments-services-and-events

Installations
300+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
4.9.2

Severity Score:
High


The vulnerability has been patched, so you should update to version 4.9.2.

WPC Shop as a Customer for WooCommerce

Plugin Slug:
wpc-shop-as-customer

Installations
300+

Vulnerability:
Broken Access Control

Patched in Version:
1.2.9

Severity Score:
High


The vulnerability has been patched, so you should update to version 1.2.9.

Dynamic Product Category Grid, Slider for WooCommerce

Plugin Slug:
dynamic-product-categories-design

Installations
200+

Vulnerability:
Local File Inclusion

Patched in Version:
1.1.4

Severity Score:
High


The vulnerability has been patched, so you should update to version 1.1.4.

Export Customers Data

Plugin Slug:
export-customers-data

Installations
200+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.2.4

Severity Score:
High


The vulnerability has been patched, so you should update to version 1.2.4.

NinjaTeam Chat for Telegram

Plugin Slug:
ninjateam-telegram

Installations
200+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.1

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.1.

Feedify � Web Push Notifications

Plugin Slug:
push-notification-by-feedify

Installations
200+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.4.3

Severity Score:
High


The vulnerability has been patched, so you should update to version 2.4.3.

ShMapper by Teplitsa

Plugin Slug:
shmapper-by-teplitsa

Installations
200+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.5.0

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.5.0.

Accept Authorize.NET Payments Using Contact Form 7

Plugin Slug:
accept-authorize-net-payments-using-contact-form-7

Installations
100+

Vulnerability:
Sensitive Data Exposure

Patched in Version:
2.3

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.3.

Agency Toolkit

Plugin Slug:
agency-toolkit

Installations
100+

Vulnerability:
Privilege Escalation

Patched in Version:
1.0.24

Severity Score:
Critical


The vulnerability has been patched, so you should update to version 1.0.24.

Bitcoin Lightning Publisher for WordPress

Plugin Slug:
bitcoin-lightning-publisher

Installations
100+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.4.2

Severity Score:
High


The vulnerability has been patched, so you should update to version 1.4.2.

Gulri Slider

Plugin Slug:
gulri-slider

Installations
100+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
3.5.9

Severity Score:
High


The vulnerability has been patched, so you should update to version 3.5.9.

Video Share VOD � Turnkey Video Site Builder Script

Plugin Slug:
video-share-vod

Installations
100+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.6.31

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.6.31.

Contests by Rewards Fuel

Plugin Slug:
contests-from-rewards-fuel

Installations
90+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.0.66

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.0.66.

Easy Waveform Player

Plugin Slug:
easy-waveform-player

Installations
90+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.2.1

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.2.1.

FV Descriptions

Plugin Slug:
fv-descriptions

Installations
80+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.5

Severity Score:
High


The vulnerability has been patched, so you should update to version 1.5.

ScanCircle

Plugin Slug:
scancircle

Installations
80+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.9.3

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.9.3.

Optio Dentistry

Plugin Slug:
optio-dentistry

Installations
70+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.2

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.2.

Philantro � Donations and Donor Management

Plugin Slug:
philantro

Installations
70+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
5.3

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 5.3.

SMS for WooCommerce

Plugin Slug:
wc-sms

Installations
70+

Vulnerability:
Broken Access Control

Patched in Version:
2.8.1.1

Severity Score:
High


The vulnerability has been patched, so you should update to version 2.8.1.1.

Taeggie Feed

Plugin Slug:
taeggie-feed

Installations
60+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
0.1.10

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 0.1.10.

Ledenbeheer

Plugin Slug:
ledenbeheer-external-connection

Installations
20+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.1.1

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.1.1.

CodeBard Help Desk

Plugin Slug:
codebard-help-desk

Installations
10+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
1.1.2

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.1.2.

WPMozo Addons Lite for Elementor

Plugin Slug:
wpmozo-addons-lite-for-elementor

Installations
10+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.3.0

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.3.0.

Advanced Floating Content

Plugin:

Advanced Floating Content

Plugin Slug:
advanced-floating-content

Vulnerability:
SQL Injection

Patched in Version:
3.8.3

Severity Score:
High


The vulnerability has been patched, so you should update to version 3.8.3.

Biagiotti Membership

Plugin:

Biagiotti Membership

Plugin Slug:
biagiotti-membership

Vulnerability:
Privilege Escalation

Patched in Version:
1.1

Severity Score:
Critical


The vulnerability has been patched, so you should update to version 1.1.

WP SuperBackup

Plugin:

WP SuperBackup

Plugin Slug:
indeed-wp-superbackup

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.4

Severity Score:
High


The vulnerability has been patched, so you should update to version 2.4.

WP SuperBackup

Plugin:

WP SuperBackup

Plugin Slug:
indeed-wp-superbackup

Vulnerability:
Broken Access Control

Patched in Version:
2.4

Severity Score:
High


The vulnerability has been patched, so you should update to version 2.4.

WP SuperBackup

Plugin:

WP SuperBackup

Plugin Slug:
indeed-wp-superbackup

Vulnerability:
Arbitrary File Upload

Patched in Version:
2.4

Severity Score:
Critical


The vulnerability has been patched, so you should update to version 2.4.

WP SuperBackup

Plugin:

WP SuperBackup

Plugin Slug:
indeed-wp-superbackup

Vulnerability:
PHP Object Injection

Patched in Version:
2.4

Severity Score:
High


The vulnerability has been patched, so you should update to version 2.4.

WP SuperBackup

Plugin:

WP SuperBackup

Plugin Slug:
indeed-wp-superbackup

Vulnerability:
Arbitrary File Download

Patched in Version:
2.4

Severity Score:
High


The vulnerability has been patched, so you should update to version 2.4.

Seraphinite Accelerator (Full, premium)

Plugin:

Seraphinite Accelerator (Full, premium)

Plugin Slug:
seraphinite-accelerator-ext

Vulnerability:
Sensitive Data Exposure

Patched in Version:
2.22.16

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.22.16.

VibeBP

Plugin:

VibeBP

Plugin Slug:
vibebp

Vulnerability:
SQL Injection

Patched in Version:
1.9.9.5.1

Severity Score:
High


The vulnerability has been patched, so you should update to version 1.9.9.5.1.

VibeBP

Plugin:

VibeBP

Plugin Slug:
vibebp

Vulnerability:
SQL Injection

Patched in Version:
1.9.9.7.7

Severity Score:
Critical


The vulnerability has been patched, so you should update to version 1.9.9.7.7.

VibeBP

Plugin:

VibeBP

Plugin Slug:
vibebp

Vulnerability:
Privilege Escalation

Patched in Version:
1.9.9.5

Severity Score:
Critical


The vulnerability has been patched, so you should update to version 1.9.9.5.

WooCommerce PDF Vouchers

Plugin:

WooCommerce PDF Vouchers

Plugin Slug:
woocommerce-pdf-vouchers

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
4.9.9

Severity Score:
High


The vulnerability has been patched, so you should update to version 4.9.9.

WP All Import Pro

Plugin:

WP All Import Pro

Plugin Slug:
wp-all-import-pro

Vulnerability:
Server Side Request Forgery (SSRF)

Patched in Version:
4.9.4

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 4.9.4.

WPLMS

Plugin:

WPLMS

Plugin Slug:
wplms-plugin

Vulnerability:
Arbitrary File Deletion

Patched in Version:
1.9.9.5.2

Severity Score:
High


The vulnerability has been patched, so you should update to version 1.9.9.5.2.

WPLMS

Plugin:

WPLMS

Plugin Slug:
wplms-plugin

Vulnerability:
Arbitrary File Upload

Patched in Version:
1.9.9.5.2

Severity Score:
Critical


The vulnerability has been patched, so you should update to version 1.9.9.5.2.

WPLMS

Plugin:

WPLMS

Plugin Slug:
wplms-plugin

Vulnerability:
Arbitrary File Upload

Patched in Version:
1.9.9.5.2

Severity Score:
Critical


The vulnerability has been patched, so you should update to version 1.9.9.5.2.

WPLMS

Plugin:

WPLMS

Plugin Slug:
wplms-plugin

Vulnerability:
SQL Injection

Patched in Version:
1.9.9.5.3

Severity Score:
High


The vulnerability has been patched, so you should update to version 1.9.9.5.3.

WPLMS

Plugin:

WPLMS

Plugin Slug:
wplms-plugin

Vulnerability:
SQL Injection

Patched in Version:
1.9.9.5.3

Severity Score:
Critical


The vulnerability has been patched, so you should update to version 1.9.9.5.3.

WPLMS

Plugin:

WPLMS

Plugin Slug:
wplms-plugin

Vulnerability:
Arbitrary File Deletion

Patched in Version:
1.9.9.5.2

Severity Score:
High


The vulnerability has been patched, so you should update to version 1.9.9.5.2.

WPLMS

Plugin:

WPLMS

Plugin Slug:
wplms-plugin

Vulnerability:
Arbitrary File Upload

Patched in Version:
1.9.9.1

Severity Score:
Critical


The vulnerability has been patched, so you should update to version 1.9.9.1.

WPLMS

Plugin:

WPLMS

Plugin Slug:
wplms-plugin

Vulnerability:
Remote Code Execution (RCE)

Patched in Version:
1.9.9.5

Severity Score:
High


The vulnerability has been patched, so you should update to version 1.9.9.5.

WPLMS

Plugin:

WPLMS

Plugin Slug:
wplms-plugin

Vulnerability:
Privilege Escalation

Patched in Version:
1.9.9.1

Severity Score:
High


The vulnerability has been patched, so you should update to version 1.9.9.1.

WPLMS

Plugin:

WPLMS

Plugin Slug:
wplms-plugin

Vulnerability:
Arbitrary File Deletion

Patched in Version:
1.9.9.5

Severity Score:
Critical


The vulnerability has been patched, so you should update to version 1.9.9.5.

WPLMS

Plugin:

WPLMS

Plugin Slug:
wplms-plugin

Vulnerability:
Privilege Escalation

Patched in Version:
1.9.9.1

Severity Score:
Critical


The vulnerability has been patched, so you should update to version 1.9.9.1.

WPLMS

Plugin:

WPLMS

Plugin Slug:
wplms-plugin

Vulnerability:
Privilege Escalation

Patched in Version:
1.9.9.1

Severity Score:
Critical


The vulnerability has been patched, so you should update to version 1.9.9.1.

WPLMS

Plugin:

WPLMS

Plugin Slug:
wplms-plugin

Vulnerability:
Arbitrary File Upload

Patched in Version:
1.9.9.5.3

Severity Score:
Critical


The vulnerability has been patched, so you should update to version 1.9.9.5.3.

WPLMS

Plugin:

WPLMS

Plugin Slug:
wplms-plugin

Vulnerability:
Arbitrary File Upload

Patched in Version:
1.9.9.5.2

Severity Score:
Critical


The vulnerability has been patched, so you should update to version 1.9.9.5.2.

WPLMS

Plugin:

WPLMS

Plugin Slug:
wplms-plugin

Vulnerability:
SQL Injection

Patched in Version:
1.9.9.5.3

Severity Score:
High


The vulnerability has been patched, so you should update to version 1.9.9.5.3.

WordPress Themes � 5 Patched / 4 Unpatched

NewsDaily

Theme Slug:
newsdaily

Downloads
44,342

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should switch themes.

VW Automobile Lite

Theme Slug:
vw-automobile-lite

Downloads
188,505

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should switch themes.

Olivia

Theme:

Olivia

Theme Slug:
olivia

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should switch themes.

Zerif Lite

Theme:

Zerif Lite

Theme Slug:
zerif-lite

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should switch themes.

NewsMash

Theme Slug:
newsmash

Downloads
100,124

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.0.72

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.0.72.

AdForest

Theme:

AdForest

Theme Slug:
adforest

Vulnerability:
Broken Access Control

Patched in Version:
5.1.7

Severity Score:
Critical


The vulnerability has been patched, so you should update to version 5.1.7.

Kleo

Theme:

Kleo

Theme Slug:
kleo

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
5.4.4

Severity Score:
High


The vulnerability has been patched, so you should update to version 5.4.4.

Traveler

Theme:

Traveler

Theme Slug:
traveler

Vulnerability:
Broken Access Control

Patched in Version:
3.1.7

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 3.1.7.

Traveler

Theme:

Traveler

Theme Slug:
traveler

Vulnerability:
SQL Injection

Patched in Version:
3.1.7

Severity Score:
Critical


The vulnerability has been patched, so you should update to version 3.1.7.

Related articles

Wait! Get exclusive hosting insights

Subscribe to our newsletter and stay ahead of the competition with expert advice from our hosting pros.

Loading form…