Vulnerable plugins and themes are the #1 reason WordPress websites get hacked. The weekly WordPress Vulnerability Report powered by WPScan covers recent WordPress plugin, theme, and core vulnerabilities, and what to do if you run one of the vulnerable plugins or themes on your website.
Each vulnerability will have a severity rating of Low, Medium, High, or Critical. Responsible disclosure and reporting of vulnerabilities is an integral part of keeping the WordPress community safe. New in this report: vulnerabilities are now listed in order by the number of active installs, rather than the date of the disclosure.
Please share this post with your friends to help get the word out and make WordPress safer for everyone!
WordPress 5.9: Core Major Version Update Now Available
The latest version of WordPress core is WordPress 5.9. Be sure to update to WordPress 5.9 as soon as possible!
WordPress Plugin Vulnerabilities
In this section, the latest WordPress plugin vulnerabilities have been disclosed. Each plugin listing includes the type of vulnerability, the active installations, the version number if patched, and the severity rating.
Premium Plugin Vulnerabilities
In this section, the latest vulnerabilities for premium plugins have been disclosed. Each plugin listing includes the type of vulnerability, the active installations, the version number if patched, and the severity rating.
WordPress Plugin Vulnerabilities – No Known Fix
Good news! No plugins with no known fix were disclosed this week.
WordPress Theme Vulnerabilities
In this section, the latest WordPress theme vulnerabilities have been disclosed. Each theme listing includes the type of vulnerability, the active installations, the version number if patched, and the severity rating.
WordPress Theme Vulnerabilities – No Known Fix
This section covers vulnerabilities in themes with no known fix. Until a patch is available, deactivate and uninstall the theme.
Colorway

- Theme
- ColorWay
- Downloads
- 1,313,341
- Vulnerability
- Reflected Cross-Site Scripting via Customizer Notify
- Patched in Version
- No Fix
- Severity Score
- Medium
Wallstreet

- Theme
- Wallstreet
- Downloads
- 718,444
- Vulnerability
- Reflected Cross-Site Scripting via Customizer Notify
- Patched in Version
- No Fix
- Severity Score
- Medium
Quality

- Theme
- Quality
- Downloads
- 495,739
- Vulnerability
- Reflected Cross-Site Scripting via Customizer Notify
- Patched in Version
- No Fix
- Severity Score
- Medium
StartKit

- Theme
- StartKit
- Downloads
- 459,051
- Vulnerability
- Reflected Cross-Site Scripting via Customizer Notify
- Patched in Version
- No Fix
- Severity Score
- Medium
Busiprof

- Theme
- Busiprof
- Downloads
- 458,162
- Vulnerability
- Reflected Cross-Site Scripting via Customizer Notify
- Patched in Version
- No Fix
- Severity Score
- Medium
Rambo

- Theme
- Rambo
- Downloads
- 371,342
- Vulnerability
- Reflected Cross-Site Scripting via Customizer Notify
- Patched in Version
- No Fix
- Severity Score
- Medium
Spasalon

- Theme
- Spasalon
- Downloads
- 334,726
- Vulnerability
- Reflected Cross-Site Scripting via Customizer Notify
- Patched in Version
- No Fix
- Severity Score
- Medium
HoneyPress

- Theme
- HoneyPress
- Downloads
- 226,695
- Vulnerability
- Reflected Cross-Site Scripting via Customizer Notify
- Patched in Version
- No Fix
- Severity Score
- Medium
Fifteen

- Theme
- Fifteen
- Downloads
- 212,109
- Vulnerability
- Reflected Cross-Site Scripting via Customizer Notify
- Patched in Version
- No Fix
- Severity Score
- Medium
ElitePress

- Theme
- ElitePress
- Downloads
- 148,007
- Vulnerability
- Reflected Cross-Site Scripting via Customizer Notify
- Patched in Version
- No Fix
- Severity Score
- Medium
Envo Business

- Theme
- Envo Business
- Downloads
- 111,185
- Vulnerability
- Reflected Cross-Site Scripting via Customizer Notify
- Patched in Version
- No Fix
- Severity Score
- Medium
CloudPress

- Theme
- CloudPress
- Downloads
- 102,458
- Vulnerability
- Reflected Cross-Site Scripting via Customizer Notify
- Patched in Version
- No Fix
- Severity Score
- Medium
Shopbiz Lite

- Theme
- Shopbiz Lite
- Downloads
- 83,149
- Vulnerability
- Reflected Cross-Site Scripting via Customizer Notify
- Patched in Version
- No Fix
- Severity Score
- Medium
ConsultEra

- Theme
- ConsultEra
- Downloads
- 82,730
- Vulnerability
- Reflected Cross-Site Scripting via Customizer Notify
- Patched in Version
- No Fix
- Severity Score
- Medium
EventPress

- Theme
- EventPress
- Downloads
- 70,771
- Vulnerability
- Reflected Cross-Site Scripting via Customizer Notify
- Patched in Version
- No Fix
- Severity Score
- Medium
Blain

- Theme
- Blain
- Downloads
- 50,841
- Vulnerability
- Reflected Cross-Site Scripting via Customizer Notify
- Patched in Version
- No Fix
- Severity Score
- Medium
Robolist Lite

- Theme
- Robolist Lite
- Downloads
- 48,328
- Vulnerability
- Reflected Cross-Site Scripting via Customizer Notify
- Patched in Version
- No Fix
- Severity Score
- Medium
Short

- Theme
- Short
- Downloads
- 46,868
- Vulnerability
- Reflected Cross-Site Scripting via Customizer Notify
- Patched in Version
- No Fix
- Severity Score
- Medium
BusiCare

- Theme
- BusiCare
- Downloads
- 42,606
- Vulnerability
- Reflected Cross-Site Scripting via Customizer Notify
- Patched in Version
- No Fix
- Severity Score
- Medium
Spice Software

- Theme
- Spice Software
- Downloads
- 40,528
- Vulnerability
- Reflected Cross-Site Scripting via Customizer Notify
- Patched in Version
- No Fix
- Severity Score
- Medium
WP Real Estate

- Theme
- WP Real Estate
- Downloads
- 38,280
- Vulnerability
- Reflected Cross-Site Scripting via Customizer Notify
- Patched in Version
- No Fix
- Severity Score
- Medium
Jewelry Store

- Theme
- Jewelry Store
- Downloads
- 31,042
- Vulnerability
- Reflected Cross-Site Scripting via Customizer Notify
- Patched in Version
- No Fix
- Severity Score
- Medium
IH Business Pro

- Theme
- IH Business Pro
- Downloads
- 25,480
- Vulnerability
- Reflected Cross-Site Scripting via Customizer Notify
- Patched in Version
- No Fix
- Severity Score
- Medium
Spiko

- Theme
- Spiko
- Downloads
- 20,289
- Vulnerability
- Reflected Cross-Site Scripting via Customizer Notify
- Patched in Version
- No Fix
- Severity Score
- Medium
Mediciti LIte

- Theme
- Mediciti Lite
- Downloads
- 20,137
- Vulnerability
- XSS
- Patched in Version
- No Fix
- Severity Score
- Medium
Auto Car

- Theme
- Auto Car
- Downloads
- 10,972
- Vulnerability
- XSS
- Patched in Version
- No Fix
- Severity Score
- Medium
Hasten Lite

- Theme
- Hasten Lite
- Downloads
- 10,364
- Vulnerability
- XSS
- Patched in Version
- No Fix
- Severity Score
- Medium
lawyerpress lite

- Theme
- lawyerpress lite
- Downloads
- 9,576
- Vulnerability
- Reflected Cross-Site Scripting via Customizer Notify
- Patched in Version
- No Fix
- Severity Score
- Medium
Spawp

- Theme
- Spawp
- Downloads
- 8,864
- Vulnerability
- Reflected Cross-Site Scripting via Customizer Notify
- Patched in Version
- No Fix
- Severity Score
- Medium
Businesswp

- Theme
- Businesswp
- Downloads
- 6,371
- Vulnerability
- Reflected Cross-Site Scripting via Customizer Notify
- Patched in Version
- No Fix
- Severity Score
- Medium
NGO Charity Lite
- Theme
- NGO Charity Lite
- Vulnerability
- Reflected Cross-Site Scripting via Customizer Notify
- Patched in Version
- No Fix
- Severity Score
- Medium
AStore
- Theme
- AStore
- Vulnerability
- Reflected Cross-Site Scripting via Customizer Notify
- Patched in Version
- No Fix
- Severity Score
- Medium
Cactus
- Theme
- Cactus
- Vulnerability
- Reflected Cross-Site Scripting via Customizer Notify
- Patched in Version
- No Fix
- Severity Score
- Medium
How to Protect Your WordPress Website From Vulnerable Plugins and Themes
As you can see from this report, lots of new WordPress plugin and theme vulnerabilities are disclosed each week. We know it can be difficult to stay on top of every reported vulnerability disclosure, so the iThemes Security Pro plugin makes it easy to make sure your site isn’t running a theme, plugin, or WordPress core version with a known vulnerability.
Get iThemes Security Pro with 24/7 Website Security Monitoring
iThemes Security Pro, our WordPress security plugin, offers 50+ ways to secure and protect your website from common WordPress security vulnerabilities. With WordPress, two-factor authentication, brute force protection, strong password enforcement, and more, you can add extra layers of security to your website.


