Line illustration showing a black application window on a dark red gradient background overlaid with a large exclamation point alert icon and three bugs.

WordPress Vulnerability Report � February 18, 2026

In this report, 190 vulnerabilities have been publicly disclosed. Security patches for 96 of these plugins and themes are now available. Please run these updates as soon as possible. If you’re a Solid Security Pro user, the version management tool may have already warned you and updated these plugins, depending on your settings.

Currently, 94 plugin and theme vulnerabilities remain unpatched. If you’re a Solid Security Pro user, those vulnerabilities are already protected by the Solid Security firewall. Virtual patches from Patchstack will be applied when a vulnerability is considered high or medium risk. If no patch is forthcoming from the vendor or the vulnerable software has been marked “closed” and dropped from the official WordPress repositories, you should deactivate it soon and look for alternative solutions.

WordPress Core

WordPress 6.9.1 was released on February 3, 2026, as a short-cycle maintenance update, addressing 49 bugs across WordPress Core and the Block Editor, including fixes affecting the editor, mail functionality, and classic themes. Sites with automatic background updates may already be updated. We recommend reviewing the details and updating as part of your regular maintenance cycle.

The next major WordPress release, version 7.0, is scheduled for April 9, 2026, during WordCamp Asia.

WordPress Plugins � 83 Patched / 75 Unpatched

Persian WooCommerce SMS

Plugin Slug:
persian-woocommerce-sms

Installations
50,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.
Plugin Slug:
link-whisper

Installations
30,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

WP FullCalendar

Plugin Slug:
wp-fullcalendar

Installations
9,000+

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Chatbot for WordPress by Collect.chat ??

Plugin Slug:
collectchat

Installations
7,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.
Plugin Slug:
new-image-gallery

Installations
4,000+

Vulnerability:
PHP Object Injection

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Cliengo � Chatbot

Plugin Slug:
cliengo

Installations
2,000+

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Responsive Slideshow

Plugin Slug:
slider-responsive-slideshow

Installations
2,000+

Vulnerability:
PHP Object Injection

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

OpenPix for WooCommerce

Plugin Slug:
openpix-for-woocommerce

Installations
700+

Vulnerability:
Settings Change

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

iMoney

Plugin:

iMoney

Plugin Slug:
imoney

Installations
100+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Magic Login Mail or QR Code

Plugin Slug:
magic-login-mail

Installations
100+

Vulnerability:
Privilege Escalation

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

RVCFDI para Woocommerce

Plugin Slug:
rvcfdi-para-woocommerce

Installations
100+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Visitor Maps Extended Referer Field

Plugin Slug:
visitor-maps-extended-referer-field

Installations
100+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Simple Retail Menus

Plugin Slug:
simple-retail-menus

Installations
90+

Vulnerability:
Local File Inclusion

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

WPshop 2 � E-Commerce

Plugin Slug:
wpshop

Installations
70+

Vulnerability:
Local File Inclusion

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

OpenPOS Lite � Point of Sale for WooCommerce

Plugin Slug:
wpos-lite-version

Installations
40+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Microtango

Plugin Slug:
microtango

Installations
30+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Press3D

Plugin:

Press3D

Plugin Slug:
press3d

Installations
10+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Allow HTML in Category Descriptions

Plugin:

Allow HTML in Category Descriptions

Plugin Slug:
allow-html-in-category-descriptions

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

AMP Enhancer – Compatibility Layer for Official AMP Plugin

Plugin:

AMP Enhancer – Compatibility Layer for Official AMP Plugin

Plugin Slug:
amp-enhancer

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Best-wp-google-map

Plugin:

Best-wp-google-map

Plugin Slug:
best-wp-google-map

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

BlueSnap Payment Gateway for WooCommerce

Plugin:

BlueSnap Payment Gateway for WooCommerce

Plugin Slug:
bluesnap-payment-gateway-for-woocommerce

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Bookr

Plugin:

Bookr

Plugin Slug:
bookr

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Bravis Addons

Plugin:

Bravis Addons

Plugin Slug:
bravis-addons

Vulnerability:
Arbitrary File Upload

Patched in Version:
No Fix

Severity Score:
Critical


The vulnerability has not been patched. You should deactivate the plugin.

CallbackKiller service widget

Plugin:

CallbackKiller service widget

Plugin Slug:
callbackkiller-service-widget

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Category Image

Plugin:

Category Image

Plugin Slug:
category-image

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Citations tools

Plugin:

Citations tools

Plugin Slug:
citations-tools

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Cnvrse

Plugin:

Cnvrse

Plugin Slug:
cnvrse

Vulnerability:
Insecure Direct Object References (IDOR)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Easy Voice Mail

Plugin:

Easy Voice Mail

Plugin Slug:
easy-voice-mail

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

IDE Micro code-editor

Plugin:

IDE Micro code-editor

Plugin Slug:
flask-micro

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Flexi Product Slider and Grid for WooCommerce

Plugin:

Flexi Product Slider and Grid for WooCommerce

Plugin Slug:
flexi-product-slider-grid

Vulnerability:
Local File Inclusion

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

HTML Shortcodes

Plugin:

HTML Shortcodes

Plugin Slug:
html-shortcodes

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Invoct � PDF Invoices & Billing for WooCommerce

Plugin Slug:
kirilkirkov-pdf-invoice-manager

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.
Plugin:

Link Hopper

Plugin Slug:
link-hopper

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

BuddyHolis ListSearch

Plugin:

BuddyHolis ListSearch

Plugin Slug:
listsearch

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

MDirector Newsletter

Plugin:

MDirector Newsletter

Plugin Slug:
mdirector-newsletter

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

midi-Synth

Plugin:

midi-Synth

Plugin Slug:
midi-synth

Vulnerability:
Arbitrary File Upload

Patched in Version:
No Fix

Severity Score:
Critical


The vulnerability has not been patched. You should deactivate the plugin.

MMA Call Tracking

Plugin:

MMA Call Tracking

Plugin Slug:
mma-call-tracking

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

MailChimp Campaigns

Plugin:

MailChimp Campaigns

Plugin Slug:
olalaweb-mailchimp-campaign-manager

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Payment Page

Plugin:

Payment Page

Plugin Slug:
payment-page

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Percent to Infograph

Plugin:

Percent to Infograph

Plugin Slug:
percent-to-infograph

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

personal-authors-category

Plugin:

personal-authors-category

Plugin Slug:
personal-authors-category

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.
Plugin:

PhotoStack Gallery

Plugin Slug:
photostack-gallery

Vulnerability:
SQL Injection

Patched in Version:
No Fix

Severity Score:
Critical


The vulnerability has not been patched. You should deactivate the plugin.

Post Slides

Plugin:

Post Slides

Plugin Slug:
post-slides

Vulnerability:
Local File Inclusion

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Prime Listing Manager

Plugin:

Prime Listing Manager

Plugin Slug:
prime-listing-manager

Vulnerability:
Privilege Escalation

Patched in Version:
No Fix

Severity Score:
Critical


The vulnerability has not been patched. You should deactivate the plugin.

QuestionPro Surveys

Plugin:

QuestionPro Surveys

Plugin Slug:
questionpro-surveys

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Ravelry Designs Widget

Plugin:

Ravelry Designs Widget

Plugin Slug:
ravelry-designs-widget

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Scheduler Widget

Plugin:

Scheduler Widget

Plugin Slug:
scheduler-widget

Vulnerability:
Insecure Direct Object References (IDOR)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

SEATT: Simple Event Attendance

Plugin:

SEATT: Simple Event Attendance

Plugin Slug:
simple-event-attendance

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Simple Plyr

Plugin:

Simple Plyr

Plugin Slug:
simple-plyr

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Simple Wp colorfull Accordion

Plugin:

Simple Wp colorfull Accordion

Plugin Slug:
simple-wp-colorfull-accordion

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Slideshow Wp

Plugin:

Slideshow Wp

Plugin Slug:
slideshow-wp

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Smart Forms

Plugin:

Smart Forms

Plugin Slug:
smart-forms

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Sphere Manager

Plugin:

Sphere Manager

Plugin Slug:
sphere-manager

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Sudoku Shortcode

Plugin:

Sudoku Shortcode

Plugin Slug:
sudoku-shortcode

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Themesflat Elementor

Plugin:

Themesflat Elementor

Plugin Slug:
themesflat-elementor

Vulnerability:
PHP Object Injection

Patched in Version:
No Fix

Severity Score:
Critical


The vulnerability has not been patched. You should deactivate the plugin.

Timeline Event History

Plugin:

Timeline Event History

Plugin Slug:
timeline-event-history

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Twitter posts to Blog

Plugin:

Twitter posts to Blog

Plugin Slug:
twitter-posts-to-blog

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

ZoomifyWP Free

Plugin:

ZoomifyWP Free

Plugin Slug:
tz-zoomifywp-free

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

UpMenu

Plugin:

UpMenu

Plugin Slug:
upmenu

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

User Language Switch

Plugin:

User Language Switch

Plugin Slug:
user-language-switch

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

User Language Switch

Plugin:

User Language Switch

Plugin Slug:
user-language-switch

Vulnerability:
Server Side Request Forgery (SSRF)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Videospirecore Theme

Plugin:

Videospirecore Theme

Plugin Slug:
videospirecore

Vulnerability:
Privilege Escalation

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

WaMate Confirm

Plugin:

WaMate Confirm

Plugin Slug:
wamate-confirm

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

WDES Responsive Popup

Plugin:

WDES Responsive Popup

Plugin Slug:
wdes-responsive-popup

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

WooCommerce Bulk Product Editor

Plugin:

WooCommerce Bulk Product Editor

Plugin Slug:
woocommerce-quick-product-editor

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

WP eCommerce

Plugin:

WP eCommerce

Plugin Slug:
wp-e-commerce

Vulnerability:
PHP Object Injection

Patched in Version:
No Fix

Severity Score:
Critical


The vulnerability has not been patched. You should deactivate the plugin.

WP Quick Contact Us

Plugin:

WP Quick Contact Us

Plugin Slug:
wp-quick-contact-us

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

WP Server Log Viewer

Plugin:

WP Server Log Viewer

Plugin Slug:
wp-server-log-viewer

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Upload Files Anywhere

Plugin:

Upload Files Anywhere

Plugin Slug:
wp-upload-files-anywhere

Vulnerability:
Arbitrary File Download

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Upload Files Anywhere

Plugin:

Upload Files Anywhere

Plugin Slug:
wp-upload-files-anywhere

Vulnerability:
Arbitrary File Deletion

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

WPlyr Media Block

Plugin:

WPlyr Media Block

Plugin Slug:
wplyr-media-block

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Yoast Duplicate Post

Plugin Slug:
duplicate-post

Installations
4,000,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
3.2.4

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 3.2.4.

Migration, Backup, Staging � WPvivid Backup & Migration

Plugin Slug:
wpvivid-backuprestore

Installations
900,000+

Vulnerability:
Arbitrary File Upload

Patched in Version:
0.9.124

Severity Score:
Critical


The vulnerability has been patched, so you should update to version 0.9.124.

Kadence Blocks � Page Builder Toolkit for Gutenberg Editor

Plugin Slug:
kadence-blocks

Installations
600,000+

Vulnerability:
Broken Access Control

Patched in Version:
3.6.0

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 3.6.0.

Backup Migration

Plugin Slug:
backup-backup

Installations
100,000+

Vulnerability:
Remote Code Execution (RCE)

Patched in Version:
1.4.0

Severity Score:
High


The vulnerability has been patched, so you should update to version 1.4.0.

Beaver Builder Page Builder � Drag and Drop Website Builder

Plugin Slug:
beaver-builder-lite-version

Installations
100,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.10.0.6

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.10.0.6.
Plugin Slug:
foogallery

Installations
100,000+

Vulnerability:
Broken Access Control

Patched in Version:
3.1.10

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 3.1.10.
Plugin Slug:
modula-best-grid-gallery

Installations
100,000+

Vulnerability:
Broken Access Control

Patched in Version:
2.13.7

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.13.7.

Mollie Payments for WooCommerce

Plugin Slug:
mollie-payments-for-woocommerce

Installations
100,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
8.1.2

Severity Score:
High


The vulnerability has been patched, so you should update to version 8.1.2.

Customer Reviews for WooCommerce

Plugin Slug:
customer-reviews-woocommerce

Installations
80,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
5.98.0

Severity Score:
High


The vulnerability has been patched, so you should update to version 5.98.0.

SlimStat Analytics

Plugin Slug:
wp-slimstat

Installations
80,000+

Vulnerability:
SQL Injection

Patched in Version:
5.3.2

Severity Score:
High


The vulnerability has been patched, so you should update to version 5.3.2.

Auto Featured Image (Auto Post Thumbnail)

Plugin Slug:
auto-post-thumbnail

Installations
50,000+

Vulnerability:
Server Side Request Forgery (SSRF)

Patched in Version:
4.2.0

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 4.2.0.

WP-Members Membership Plugin

Plugin Slug:
wp-members

Installations
50,000+

Vulnerability:
Broken Access Control

Patched in Version:
3.4.9

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 3.4.9.

Calculated Fields Form

Plugin Slug:
calculated-fields-form

Installations
40,000+

Vulnerability:
Broken Access Control

Patched in Version:
5.4.4.2

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 5.4.4.2.

WP Last Modified Info

Plugin Slug:
wp-last-modified-info

Installations
30,000+

Vulnerability:
Insecure Direct Object References (IDOR)

Patched in Version:
1.9.6

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.9.6.

Custom Block Builder � Lazy Blocks

Plugin Slug:
lazy-blocks

Installations
20,000+

Vulnerability:
Remote Code Execution (RCE)

Patched in Version:
4.2.1

Severity Score:
High


The vulnerability has been patched, so you should update to version 4.2.1.

New User Approve

Plugin Slug:
new-user-approve

Installations
20,000+

Vulnerability:
Broken Access Control

Patched in Version:
3.2.1

Severity Score:
High


The vulnerability has been patched, so you should update to version 3.2.1.

Secure Copy Content Protection and Content Locking

Plugin Slug:
secure-copy-content-protection

Installations
20,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
4.9.9

Severity Score:
High


The vulnerability has been patched, so you should update to version 4.9.9.

The Events Calendar Shortcode & Block

Plugin Slug:
the-events-calendar-shortcode

Installations
20,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
3.1.3

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 3.1.3.

WCFM Marketplace � Multivendor Marketplace for WooCommerce

Plugin Slug:
wc-multivendor-marketplace

Installations
20,000+

Vulnerability:
Insecure Direct Object References (IDOR)

Patched in Version:
3.7.1

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 3.7.1.

wpForo Forum

Plugin Slug:
wpforo

Installations
20,000+

Vulnerability:
PHP Object Injection

Patched in Version:
2.4.14

Severity Score:
High


The vulnerability has been patched, so you should update to version 2.4.14.

Passster � Password Protect Pages and Content

Plugin Slug:
content-protector

Installations
10,000+

Vulnerability:
Broken Access Control

Patched in Version:
4.2.26

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 4.2.26.

Media Library Folders

Plugin Slug:
media-library-plus

Installations
10,000+

Vulnerability:
Arbitrary Content Deletion

Patched in Version:
8.3.7

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 8.3.7.

Open User Map

Plugin Slug:
open-user-map

Installations
10,000+

Vulnerability:
Arbitrary File Download

Patched in Version:
1.4.17

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.4.17.

NEX-Forms � Ultimate Forms Plugin for WordPress

Plugin Slug:
nex-forms-express-wp-form-builder

Installations
8,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
9.1.8

Severity Score:
High


The vulnerability has been patched, so you should update to version 9.1.8.

EventPrime � Events Calendar, Bookings and Tickets

Plugin Slug:
eventprime-event-calendar-management

Installations
7,000+

Vulnerability:
Broken Access Control

Patched in Version:
4.2.8.5

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 4.2.8.5.

Download Manager Addons for Elementor

Plugin Slug:
wpdm-elementor

Installations
7,000+

Vulnerability:
SQL Injection

Patched in Version:
2.0.0

Severity Score:
Critical


The vulnerability has been patched, so you should update to version 2.0.0.

YayCurrency � WooCommerce Multi-Currency Switcher

Plugin Slug:
yaycurrency

Installations
7,000+

Vulnerability:
Arbitrary Content Deletion

Patched in Version:
3.3.1

Severity Score:
High


The vulnerability has been patched, so you should update to version 3.3.1.

Simple File List

Plugin Slug:
simple-file-list

Installations
5,000+

Vulnerability:
Arbitrary File Download

Patched in Version:
6.1.16

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 6.1.16.

Name Directory

Plugin Slug:
name-directory

Installations
3,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.32.1

Severity Score:
High


The vulnerability has been patched, so you should update to version 1.32.1.

Paytium: Mollie payment forms & donations

Plugin Slug:
paytium

Installations
3,000+

Vulnerability:
Broken Access Control

Patched in Version:
4.4

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 4.4.

Paytium: Mollie payment forms & donations

Plugin Slug:
paytium

Installations
3,000+

Vulnerability:
Broken Access Control

Patched in Version:
4.4

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 4.4.

Paytium: Mollie payment forms & donations

Plugin Slug:
paytium

Installations
3,000+

Vulnerability:
Broken Access Control

Patched in Version:
4.4

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 4.4.

Paytium: Mollie payment forms & donations

Plugin Slug:
paytium

Installations
3,000+

Vulnerability:
Broken Access Control

Patched in Version:
4.4

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 4.4.

Paytium: Mollie payment forms & donations

Plugin Slug:
paytium

Installations
3,000+

Vulnerability:
Broken Access Control

Patched in Version:
4.4

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 4.4.

Paytium: Mollie payment forms & donations

Plugin Slug:
paytium

Installations
3,000+

Vulnerability:
Broken Access Control

Patched in Version:
4.4

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 4.4.

Accordion and Accordion Slider

Plugin Slug:
accordion-and-accordion-slider

Installations
2,000+

Vulnerability:
Broken Access Control

Patched in Version:
1.4.6

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.4.6.

Modal Popup Box: A Flexible Pop Up Box Builder

Plugin Slug:
modal-popup-box

Installations
2,000+

Vulnerability:
PHP Object Injection

Patched in Version:
1.6.2

Severity Score:
High


The vulnerability has been patched, so you should update to version 1.6.2.

PDF for WPForms + Drag and Drop Template Builder

Plugin Slug:
pdf-for-wpforms

Installations
1,000+

Vulnerability:
Broken Access Control

Patched in Version:
6.3.1

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 6.3.1.

Lucky Wheel Giveaway

Plugin Slug:
wp-lucky-wheel

Installations
600+

Vulnerability:
Remote Code Execution (RCE)

Patched in Version:
1.0.23

Severity Score:
Critical


The vulnerability has been patched, so you should update to version 1.0.23.

Primer MyData for Woocommerce

Plugin Slug:
primer-mydata

Installations
100+

Vulnerability:
Path Traversal

Patched in Version:
4.2.9

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 4.2.9.

Activity Log for WordPress

Plugin Slug:
winterlock

Installations
70+

Vulnerability:
Broken Access Control

Patched in Version:
1.2.9

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.2.9.

Orbisius Random Name Generator

Plugin Slug:
orbisius-random-name-generator

Installations
50+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.0.3

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.0.3.

Tune Library

Plugin Slug:
tune-library

Installations
20+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.6.4

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.6.4.

BFG Tools � Extension Zipper

Plugin Slug:
bfg-tools-extension-zipper

Vulnerability:
Path Traversal

Patched in Version:
1.0.8

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.0.8.

Fluent Forms Pro Add On Pack

Plugin:

Fluent Forms Pro Add On Pack

Plugin Slug:
fluentformpro

Vulnerability:
Server Side Request Forgery (SSRF)

Patched in Version:
6.1.13

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 6.1.13.

JetEngine

Plugin:

JetEngine

Plugin Slug:
jet-engine

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
3.8.1

Severity Score:
High


The vulnerability has been patched, so you should update to version 3.8.1.

Miraculous Elementor

Plugin:

Miraculous Elementor

Plugin Slug:
miraculous-el

Vulnerability:
Broken Authentication

Patched in Version:
2.0.8

Severity Score:
High


The vulnerability has been patched, so you should update to version 2.0.8.

StickEasy Protected Contact Form

Plugin Slug:
stickeasy-protected-contact-form

Vulnerability:
Sensitive Data Exposure

Patched in Version:
1.0.2

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.0.2.

Truelysell Core

Plugin:

Truelysell Core

Plugin Slug:
truelysell-core

Vulnerability:
Privilege Escalation

Patched in Version:
1.8.8

Severity Score:
Critical


The vulnerability has been patched, so you should update to version 1.8.8.

Uni CPO (Premium)

Plugin:

Uni CPO (Premium)

Plugin Slug:
uni-woo-custom-product-options-premium

Vulnerability:
Broken Access Control

Patched in Version:
4.9.61

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 4.9.61.

Whizz Plugins

Plugin:

Whizz Plugins

Plugin Slug:
whizz-plugins

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.0.0

Severity Score:
High


The vulnerability has been patched, so you should update to version 2.0.0.

WooCommerce Coming Soon Product with Countdown

Plugin:

WooCommerce Coming Soon Product with Countdown

Plugin Slug:
woo-coming-soon-product

Vulnerability:
Local File Inclusion

Patched in Version:
5.1

Severity Score:
High


The vulnerability has been patched, so you should update to version 5.1.

User Extra Fields

Plugin:

User Extra Fields

Plugin Slug:
wp-user-extra-fields

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
16.9

Severity Score:
High


The vulnerability has been patched, so you should update to version 16.9.

WordPress Themes � 13 Patched / 19 Unpatched

Diamond

Theme:

Diamond

Theme Slug:
diamond

Downloads
37,609

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should switch themes.

WordPress Dating Theme

Theme:

WordPress Dating Theme

Theme Slug:
DA10

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should switch themes.

Belletrist

Theme:

Belletrist

Theme Slug:
belletrist

Vulnerability:
Local File Inclusion

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should switch themes.

Cartify – WooCommerce Gutenberg WordPress Theme

Theme:

Cartify – WooCommerce Gutenberg WordPress Theme

Theme Slug:
cartify

Vulnerability:
Arbitrary Content Deletion

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should switch themes.

Cobble

Theme:

Cobble

Theme Slug:
cobble

Vulnerability:
Local File Inclusion

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should switch themes.

Extreme Store

Theme:

Extreme Store

Theme Slug:
extremestore

Vulnerability:
PHP Object Injection

Patched in Version:
No Fix

Severity Score:
Critical


The vulnerability has not been patched. You should switch themes.

Exzo

Theme:

Exzo

Theme Slug:
exzo

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should switch themes.

FiveStar

Theme:

FiveStar

Theme Slug:
fivestar

Vulnerability:
Local File Inclusion

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should switch themes.

FreightCo

Theme:

FreightCo

Theme Slug:
freightco

Vulnerability:
Local File Inclusion

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should switch themes.

Gable

Theme:

Gable

Theme Slug:
gable

Vulnerability:
Local File Inclusion

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should switch themes.

HealthFirst

Theme:

HealthFirst

Theme Slug:
healthfirst

Vulnerability:
Local File Inclusion

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should switch themes.

Lorem Ipsum | Books & Media Store

Theme:

Lorem Ipsum | Books & Media Store

Theme Slug:
lorem-ipsum-books-media-store

Vulnerability:
PHP Object Injection

Patched in Version:
No Fix

Severity Score:
Critical


The vulnerability has not been patched. You should switch themes.

PJ | Life & Business Coaching

Theme:

PJ | Life & Business Coaching

Theme Slug:
pj

Vulnerability:
Local File Inclusion

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should switch themes.

Plank

Theme:

Plank

Theme Slug:
plank

Vulnerability:
Local File Inclusion

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should switch themes.

R&F

Theme:

R&F

Theme Slug:
rf

Vulnerability:
Local File Inclusion

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should switch themes.

Splendour

Theme:

Splendour

Theme Slug:
splendour

Vulnerability:
Local File Inclusion

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should switch themes.

Struktur

Theme:

Struktur

Theme Slug:
struktur

Vulnerability:
Local File Inclusion

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should switch themes.

Tint

Theme:

Tint

Theme Slug:
tint

Vulnerability:
Local File Inclusion

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should switch themes.

Yokoo

Theme:

Yokoo

Theme Slug:
yokoo

Vulnerability:
Local File Inclusion

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should switch themes.

AdForest

Theme:

AdForest

Theme Slug:
adforest

Vulnerability:
Broken Authentication

Patched in Version:
6.0.13

Severity Score:
Critical


The vulnerability has been patched, so you should update to version 6.0.13.

Diza

Theme:

Diza

Theme Slug:
diza

Vulnerability:
Local File Inclusion

Patched in Version:
1.3.16

Severity Score:
High


The vulnerability has been patched, so you should update to version 1.3.16.

Fana

Theme:

Fana

Theme Slug:
fana

Vulnerability:
Local File Inclusion

Patched in Version:
1.1.36

Severity Score:
High


The vulnerability has been patched, so you should update to version 1.1.36.

Ippsum

Theme:

Ippsum

Theme Slug:
ippsum

Vulnerability:
PHP Object Injection

Patched in Version:
1.2.1

Severity Score:
Critical


The vulnerability has been patched, so you should update to version 1.2.1.

Nestin

Theme:

Nestin

Theme Slug:
nestin

Vulnerability:
PHP Object Injection

Patched in Version:
1.2.6

Severity Score:
Critical


The vulnerability has been patched, so you should update to version 1.2.6.

Nika

Theme:

Nika

Theme Slug:
nika

Vulnerability:
Local File Inclusion

Patched in Version:
1.2.15

Severity Score:
High


The vulnerability has been patched, so you should update to version 1.2.15.

CitiLights

Theme:

CitiLights

Theme Slug:
noo-citilights

Vulnerability:
Broken Access Control

Patched in Version:
3.7.2

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 3.7.2.

PatioTime

Theme:

PatioTime

Theme Slug:
patiotime

Vulnerability:
PHP Object Injection

Patched in Version:
2.1

Severity Score:
Critical


The vulnerability has been patched, so you should update to version 2.1.

PatioTime

Theme:

PatioTime

Theme Slug:
patiotime

Vulnerability:
Local File Inclusion

Patched in Version:
2.1

Severity Score:
High


The vulnerability has been patched, so you should update to version 2.1.

Prestige

Theme:

Prestige

Theme Slug:
prestige

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.4.1

Severity Score:
High


The vulnerability has been patched, so you should update to version 1.4.1.

Prestige

Theme:

Prestige

Theme Slug:
prestige

Vulnerability:
PHP Object Injection

Patched in Version:
1.4.1

Severity Score:
Critical


The vulnerability has been patched, so you should update to version 1.4.1.

Travelicious

Theme:

Travelicious

Theme Slug:
travelicious

Vulnerability:
PHP Object Injection

Patched in Version:
1.6.7

Severity Score:
Critical


The vulnerability has been patched, so you should update to version 1.6.7.

Zota

Theme:

Zota

Theme Slug:
zota

Vulnerability:
Local File Inclusion

Patched in Version:
1.3.15

Severity Score:
High


The vulnerability has been patched, so you should update to version 1.3.15.

Related articles

Wait! Get exclusive hosting insights

Subscribe to our newsletter and stay ahead of the competition with expert advice from our hosting pros.

Loading form…