WordPress Vulnerability Report � February 25, 2026

In this report, 244 vulnerabilities have been publicly disclosed. Security patches for 164 of these plugins and themes are now available. Please run these updates as soon as possible. If you’re a Solid Security Pro user, the version management tool may have already warned you and updated these plugins, depending on your settings.

Currently, 80 plugin and theme vulnerabilities remain unpatched. If you’re a Solid Security Pro user, those vulnerabilities are already protected by the Solid Security firewall. Virtual patches from Patchstack will be applied when a vulnerability is considered high or medium risk. If no patch is forthcoming from the vendor or the vulnerable software has been marked “closed” and dropped from the official WordPress repositories, you should deactivate it soon and look for alternative solutions.

WordPress Core

WordPress 7.0 Beta 1 is now available for testing. As this is a pre-release version, it is intended for testing and development only and should not be installed on production or mission-critical sites. Organizations should use local or staging environments to evaluate compatibility and new features before the final rollout.

The full release of WordPress 7.0 is currently scheduled for April 9, 2026. You can find the complete release schedule and technical testing details in the official announcement.

WordPress Plugins � 156 Patched / 49 Unpatched

SiteGuard WP Plugin

Plugin Slug:
siteguard

Installations
500,000+

Vulnerability:
Bypass Vulnerability

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.
Plugin Slug:
link-whisper

Installations
30,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Frontend File Manager Plugin

Plugin Slug:
nmedia-user-file-uploader

Installations
1,000+

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Premmerce

Plugin Slug:
premmerce

Installations
500+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Prodigy Commerce

Plugin Slug:
prodigy-commerce

Installations
100+

Vulnerability:
Local File Inclusion

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

TalkJS

Plugin:

TalkJS

Plugin Slug:
talkjs

Installations
50+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Filestack

Plugin Slug:
filepicker-media-uploader

Installations
20+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Address Bar Ads

Plugin:

Address Bar Ads

Plugin Slug:
address-bar-ads

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Advance Block Extend

Plugin:

Advance Block Extend

Plugin Slug:
advance-block-extend

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Applay – Shortcodes

Plugin:

Applay – Shortcodes

Plugin Slug:
applay-shortcodes

Vulnerability:
PHP Object Injection

Patched in Version:
No Fix

Severity Score:
Critical


The vulnerability has not been patched. You should deactivate the plugin.

BlueSnap Payment Gateway for WooCommerce

Plugin:

BlueSnap Payment Gateway for WooCommerce

Plugin Slug:
bluesnap-payment-gateway-for-woocommerce

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Clasifico Listing

Plugin:

Clasifico Listing

Plugin Slug:
clasifico-listing

Vulnerability:
Privilege Escalation

Patched in Version:
No Fix

Severity Score:
Critical


The vulnerability has not been patched. You should deactivate the plugin.

Country Blocker for AdSense

Plugin Slug:
country-blocker-for-adsense

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Dealia � Request a quote

Plugin Slug:
dealia-request-a-quote

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Dealia � Request a quote

Plugin Slug:
dealia-request-a-quote

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

DesignThemes Booking Manager

Plugin:

DesignThemes Booking Manager

Plugin Slug:
designthemes-booking-manager

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

DesignThemes Directory Addon

Plugin:

DesignThemes Directory Addon

Plugin Slug:
designthemes-directory-addon

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Directory Pro

Plugin:

Directory Pro

Plugin Slug:
directory-pro

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Eagle Booking

Plugin:

Eagle Booking

Plugin Slug:
eagle-booking

Vulnerability:
SQL Injection

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Easy Author Image

Plugin:

Easy Author Image

Plugin Slug:
easy-author-image

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Geo Widget

Plugin:

Geo Widget

Plugin Slug:
geowidget

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

iXML

Plugin:

iXML

Plugin Slug:
ixml

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

MP-Ukagaka

Plugin:

MP-Ukagaka

Plugin Slug:
mp-ukagaka

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

News Element Elementor Blog Magazine

Plugin:

News Element Elementor Blog Magazine

Plugin Slug:
news-element

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Page Title, Description & Open Graph Updater

Plugin:

Page Title, Description & Open Graph Updater

Plugin Slug:
page-title-description-open-graph-updater

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

personal-authors-category

Plugin:

personal-authors-category

Plugin Slug:
personal-authors-category

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Profile Builder Pro

Plugin:

Profile Builder Pro

Plugin Slug:
profile-builder-pro

Vulnerability:
SQL Injection

Patched in Version:
No Fix

Severity Score:
Critical


The vulnerability has not been patched. You should deactivate the plugin.

Really Simple Security Pro

Plugin:

Really Simple Security Pro

Plugin Slug:
really-simple-ssl-pro

Vulnerability:
Insecure Direct Object References (IDOR)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Remove Post Type Slug

Plugin:

Remove Post Type Slug

Plugin Slug:
remove-post-type-slug

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

salavat counter

Plugin:

salavat counter

Plugin Slug:
salavat-counter

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Slider Future

Plugin:

Slider Future

Plugin Slug:
slider-future

Vulnerability:
Arbitrary File Upload

Patched in Version:
No Fix

Severity Score:
Critical


The vulnerability has not been patched. You should deactivate the plugin.

Slidorion

Plugin:

Slidorion

Plugin Slug:
slidorion

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

StyleBidet

Plugin:

StyleBidet

Plugin Slug:
stylebidet

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Subitem AL Slider

Plugin:

Subitem AL Slider

Plugin Slug:
subitem-al-slider

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Super Simple Contact Form

Plugin:

Super Simple Contact Form

Plugin Slug:
super-simple-contact-form

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Tennis Court Bookings

Plugin:

Tennis Court Bookings

Plugin Slug:
tennis-court-bookings

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Toret Manager

Plugin:

Toret Manager

Plugin Slug:
toret-manager

Vulnerability:
Settings Change

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

WeDesignTech Ultimate Booking Addon

Plugin:

WeDesignTech Ultimate Booking Addon

Plugin Slug:
wedesigntech-ultimate-booking-addon

Vulnerability:
Broken Authentication

Patched in Version:
No Fix

Severity Score:
Critical


The vulnerability has not been patched. You should deactivate the plugin.

WeDesignTech Ultimate Booking Addon

Plugin:

WeDesignTech Ultimate Booking Addon

Plugin Slug:
wedesigntech-ultimate-booking-addon

Vulnerability:
Broken Authentication

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Whatsiplus Scheduled Notification for Woocommerce

Plugin:

Whatsiplus Scheduled Notification for Woocommerce

Plugin Slug:
whatsiplus-scheduled-notification-for-woocommerce

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Woocommerce Wholesale Lead Capture

Plugin:

Woocommerce Wholesale Lead Capture

Plugin Slug:
woocommerce-wholesale-lead-capture

Vulnerability:
Privilege Escalation

Patched in Version:
No Fix

Severity Score:
Critical


The vulnerability has not been patched. You should deactivate the plugin.

Woocommerce Wholesale Lead Capture

Plugin:

Woocommerce Wholesale Lead Capture

Plugin Slug:
woocommerce-wholesale-lead-capture

Vulnerability:
Arbitrary File Upload

Patched in Version:
No Fix

Severity Score:
Critical


The vulnerability has not been patched. You should deactivate the plugin.
Plugin:

WP AUDIO GALLERY

Plugin Slug:
wp-audio-gallery

Vulnerability:
Arbitrary File Download

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Client Testimonial Slider

Plugin:

Client Testimonial Slider

Plugin Slug:
wp-client-testimonial

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

LiquidPoll

Plugin:

LiquidPoll

Plugin Slug:
wp-poll

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

xmlrpc attacks blocker

Plugin:

xmlrpc attacks blocker

Plugin Slug:
xmlrpc-attacks-blocker

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

XO Event Calendar

Plugin:

XO Event Calendar

Plugin Slug:
xo-event-calendar

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.
Plugin Slug:
complianz-gdpr

Installations
1,000,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
7.4.4

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 7.4.4.

Breadcrumb NavXT

Plugin Slug:
breadcrumb-navxt

Installations
800,000+

Vulnerability:
Broken Access Control

Patched in Version:
7.5.1

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 7.5.1.

Easy Table of Contents

Plugin Slug:
easy-table-of-contents

Installations
600,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.0.79

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.0.79.

BackWPup � WordPress Backup & Restore Plugin

Plugin Slug:
backwpup

Installations
500,000+

Vulnerability:
Broken Access Control

Patched in Version:
5.6.3

Severity Score:
High


The vulnerability has been patched, so you should update to version 5.6.3.

PixelYourSite � Your smart PIXEL (TAG) & API Manager

Plugin Slug:
pixelyoursite

Installations
500,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
11.2.0.2

Severity Score:
High


The vulnerability has been patched, so you should update to version 11.2.0.2.

PixelYourSite � Your smart PIXEL (TAG) & API Manager

Plugin Slug:
pixelyoursite

Installations
500,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
11.2.0.1

Severity Score:
High


The vulnerability has been patched, so you should update to version 11.2.0.1.

Ally � Web Accessibility & Usability

Plugin Slug:
pojo-accessibility

Installations
400,000+

Vulnerability:
Broken Access Control

Patched in Version:
4.0.3

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 4.0.3.

SiteOrigin Widgets Bundle

Plugin Slug:
so-widgets-bundle

Installations
400,000+

Vulnerability:
Content Injection

Patched in Version:
1.71.0

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.71.0.

PDF Invoices & Packing Slips for WooCommerce

Plugin Slug:
woocommerce-pdf-invoices-packing-slips

Installations
300,000+

Vulnerability:
Broken Access Control

Patched in Version:
5.7.0

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 5.7.0.

Advanced Ads ��Ad Manager & AdSense

Plugin Slug:
advanced-ads

Installations
100,000+

Vulnerability:
Broken Access Control

Patched in Version:
2.0.15

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.0.15.

Advanced Custom Fields: Font Awesome Field

Plugin Slug:
advanced-custom-fields-font-awesome

Installations
100,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
5.0.2

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 5.0.2.

Aruba HiSpeed Cache

Plugin Slug:
aruba-hispeed-cache

Installations
100,000+

Vulnerability:
Broken Access Control

Patched in Version:
3.0.3

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 3.0.3.

Aruba HiSpeed Cache

Plugin Slug:
aruba-hispeed-cache

Installations
100,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
3.0.3

Severity Score:
High


The vulnerability has been patched, so you should update to version 3.0.3.

Aruba HiSpeed Cache

Plugin Slug:
aruba-hispeed-cache

Installations
100,000+

Vulnerability:
Broken Access Control

Patched in Version:
3.0.5

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 3.0.5.

Backup Migration

Plugin Slug:
backup-backup

Installations
100,000+

Vulnerability:
Remote Code Execution (RCE)

Patched in Version:
1.4.0

Severity Score:
High


The vulnerability has been patched, so you should update to version 1.4.0.

Download Manager

Plugin Slug:
download-manager

Installations
100,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
3.3.47

Severity Score:
High


The vulnerability has been patched, so you should update to version 3.3.47.

Brevo � Email, SMS, Web Push, Chat, and more.

Plugin Slug:
mailin

Installations
100,000+

Vulnerability:
Broken Access Control

Patched in Version:
3.3.1

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 3.3.1.

VK All in One Expansion Unit

Plugin Slug:
vk-all-in-one-expansion-unit

Installations
100,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
9.112.4

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 9.112.4.

Razorpay for WooCommerce

Plugin Slug:
woo-razorpay

Installations
90,000+

Vulnerability:
Broken Access Control

Patched in Version:
4.7.9

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 4.7.9.

Checkout Field Manager (Checkout Manager) for WooCommerce

Plugin Slug:
woocommerce-checkout-manager

Installations
90,000+

Vulnerability:
Arbitrary Content Deletion

Patched in Version:
7.8.6

Severity Score:
High


The vulnerability has been patched, so you should update to version 7.8.6.

Customer Reviews for WooCommerce

Plugin Slug:
customer-reviews-woocommerce

Installations
80,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
5.98.0

Severity Score:
High


The vulnerability has been patched, so you should update to version 5.98.0.

StatCounter � Free Real Time Visitor Stats

Plugin Slug:
official-statcounter-plugin-for-wordpress

Installations
70,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.1.1

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.1.1.

Mailchimp List Subscribe Form

Plugin Slug:
mailchimp

Installations
60,000+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
2.0.1

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.0.1.

Mesmerize Companion

Plugin Slug:
mesmerize-companion

Installations
60,000+

Vulnerability:
Broken Access Control

Patched in Version:
1.6.162

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.6.162.
Plugin Slug:
navz-photo-gallery

Installations
60,000+

Vulnerability:
Broken Access Control

Patched in Version:
3.1

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 3.1.

Zarinpal Gateway

Plugin Slug:
zarinpal-woocommerce-payment-gateway

Installations
60,000+

Vulnerability:
Broken Access Control

Patched in Version:
5.0.17

Severity Score:
High


The vulnerability has been patched, so you should update to version 5.0.17.

Auto Featured Image (Auto Post Thumbnail)

Plugin Slug:
auto-post-thumbnail

Installations
50,000+

Vulnerability:
Server Side Request Forgery (SSRF)

Patched in Version:
4.2.0

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 4.2.0.

Blog2Social: Social Media Auto Post & Scheduler

Plugin Slug:
blog2social

Installations
50,000+

Vulnerability:
Broken Access Control

Patched in Version:
8.7.5

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 8.7.5.

Booking Calendar

Plugin Slug:
booking

Installations
50,000+

Vulnerability:
Insecure Direct Object References (IDOR)

Patched in Version:
10.14.15

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 10.14.15.

Printful Integration for WooCommerce

Plugin Slug:
printful-shipping-for-woocommerce

Installations
50,000+

Vulnerability:
Server Side Request Forgery (SSRF)

Patched in Version:
2.2.12

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.2.12.

Advanced AJAX Product Filters

Plugin Slug:
woocommerce-ajax-filters

Installations
50,000+

Vulnerability:
PHP Object Injection

Patched in Version:
3.1.9.7

Severity Score:
High


The vulnerability has been patched, so you should update to version 3.1.9.7.

Super Page Cache

Plugin Slug:
wp-cloudflare-page-cache

Installations
50,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
5.2.3

Severity Score:
High


The vulnerability has been patched, so you should update to version 5.2.3.

WP-Members Membership Plugin

Plugin Slug:
wp-members

Installations
50,000+

Vulnerability:
Broken Access Control

Patched in Version:
3.4.9

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 3.4.9.

YayMail � WooCommerce Email Customizer

Plugin Slug:
yaymail

Installations
50,000+

Vulnerability:
Broken Access Control

Patched in Version:
4.3.3

Severity Score:
Low


The vulnerability has been patched, so you should update to version 4.3.3.

YayMail � WooCommerce Email Customizer

Plugin Slug:
yaymail

Installations
50,000+

Vulnerability:
Broken Access Control

Patched in Version:
4.3.3

Severity Score:
Low


The vulnerability has been patched, so you should update to version 4.3.3.

YayMail � WooCommerce Email Customizer

Plugin Slug:
yaymail

Installations
50,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
4.3.3

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 4.3.3.

YayMail � WooCommerce Email Customizer

Plugin Slug:
yaymail

Installations
50,000+

Vulnerability:
Broken Access Control

Patched in Version:
4.3.3

Severity Score:
High


The vulnerability has been patched, so you should update to version 4.3.3.

Calculated Fields Form

Plugin Slug:
calculated-fields-form

Installations
40,000+

Vulnerability:
Broken Access Control

Patched in Version:
5.4.4.2

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 5.4.4.2.

Easy SVG Support

Plugin Slug:
easy-svg

Installations
40,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
4.1

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 4.1.

OneClick Chat to Order

Plugin Slug:
oneclick-whatsapp-order

Installations
40,000+

Vulnerability:
Broken Access Control

Patched in Version:
1.1.0

Severity Score:
Low


The vulnerability has been patched, so you should update to version 1.1.0.

Simple Membership

Plugin Slug:
simple-membership

Installations
40,000+

Vulnerability:
Broken Access Control

Patched in Version:
4.7.1

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 4.7.1.

Image Hotspot by DevVN

Plugin Slug:
devvn-image-hotspot

Installations
30,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.3.0

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.3.0.

SEO Plugin by Squirrly SEO

Plugin Slug:
squirrly-seo

Installations
30,000+

Vulnerability:
Broken Access Control

Patched in Version:
12.4.15

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 12.4.15.

WP 404 Auto Redirect to Similar Post

Plugin Slug:
wp-404-auto-redirect-to-similar-post

Installations
30,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.0.6

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.0.6.

Apollo13 Framework Extensions

Plugin Slug:
apollo13-framework-extensions

Installations
20,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.9.9

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.9.9.
Plugin Slug:
final-tiles-grid-gallery-lite

Installations
20,000+

Vulnerability:
Broken Access Control

Patched in Version:
3.6.11

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 3.6.11.

Kali Forms � Contact Form & Drag-and-Drop Builder

Plugin Slug:
kali-forms

Installations
20,000+

Vulnerability:
Sensitive Data Exposure

Patched in Version:
2.4.9

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.4.9.

Quiz Maker

Plugin Slug:
quiz-maker

Installations
20,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
6.7.1.8

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 6.7.1.8.

Secure Copy Content Protection and Content Locking

Plugin Slug:
secure-copy-content-protection

Installations
20,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
4.9.9

Severity Score:
High


The vulnerability has been patched, so you should update to version 4.9.9.

Video Conferencing with Zoom

Plugin Slug:
video-conferencing-with-zoom-api

Installations
20,000+

Vulnerability:
Broken Access Control

Patched in Version:
4.6.6

Severity Score:
High


The vulnerability has been patched, so you should update to version 4.6.6.

WP Customer Reviews

Plugin Slug:
wp-customer-reviews

Installations
20,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
3.7.6

Severity Score:
High


The vulnerability has been patched, so you should update to version 3.7.6.

wpForo Forum

Plugin Slug:
wpforo

Installations
20,000+

Vulnerability:
SQL Injection

Patched in Version:
2.4.15

Severity Score:
Critical


The vulnerability has been patched, so you should update to version 2.4.15.

wpForo Forum

Plugin Slug:
wpforo

Installations
20,000+

Vulnerability:
PHP Object Injection

Patched in Version:
2.4.14

Severity Score:
High


The vulnerability has been patched, so you should update to version 2.4.14.

Web Accessibility by accessiBe

Plugin Slug:
accessibe

Installations
10,000+

Vulnerability:
Sensitive Data Exposure

Patched in Version:
2.12

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.12.
Plugin Slug:
gdpr-cookie-consent

Installations
10,000+

Vulnerability:
Broken Access Control

Patched in Version:
4.1.3

Severity Score:
High


The vulnerability has been patched, so you should update to version 4.1.3.

Groups

Plugin:

Groups

Plugin Slug:
groups

Installations
10,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
3.11.0

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 3.11.0.

Open User Map

Plugin Slug:
open-user-map

Installations
10,000+

Vulnerability:
Arbitrary File Download

Patched in Version:
1.4.17

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.4.17.

Membership Plugin � Restrict Content

Plugin Slug:
restrict-content

Installations
10,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
3.2.19

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 3.2.19.

Two Factor (2FA) Authentication via Email

Plugin Slug:
two-factor-2fa-via-email

Installations
10,000+

Vulnerability:
Broken Authentication

Patched in Version:
1.9.9

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.9.9.

URL Shortify � Simple and Easy URL Shortener

Plugin Slug:
url-shortify

Installations
10,000+

Vulnerability:
Open Redirection

Patched in Version:
1.12.2

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.12.2.

URL Shortify � Simple and Easy URL Shortener

Plugin Slug:
url-shortify

Installations
10,000+

Vulnerability:
Server Side Request Forgery (SSRF)

Patched in Version:
1.12.4

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.12.4.

Product Table and List Builder for WooCommerce Lite

Plugin Slug:
wc-product-table-lite

Installations
10,000+

Vulnerability:
SQL Injection

Patched in Version:
4.6.3

Severity Score:
Critical


The vulnerability has been patched, so you should update to version 4.6.3.

WP Compress � Instant Performance & Speed Optimization

Plugin Slug:
wp-compress-image-optimizer

Installations
10,000+

Vulnerability:
Broken Access Control

Patched in Version:
6.60.29

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 6.60.29.

YaMaps for WordPress Plugin

Plugin Slug:
yamaps

Installations
10,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
0.6.41

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 0.6.41.
Plugin Slug:
album-and-image-gallery-plus-lightbox

Installations
9,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.1.8

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.1.8.

EventPrime � Events Calendar, Bookings and Tickets

Plugin Slug:
eventprime-event-calendar-management

Installations
7,000+

Vulnerability:
Broken Access Control

Patched in Version:
4.2.8.5

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 4.2.8.5.

EventPrime � Events Calendar, Bookings and Tickets

Plugin Slug:
eventprime-event-calendar-management

Installations
7,000+

Vulnerability:
Sensitive Data Exposure

Patched in Version:
4.2.8.4

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 4.2.8.4.

EventPrime � Events Calendar, Bookings and Tickets

Plugin Slug:
eventprime-event-calendar-management

Installations
7,000+

Vulnerability:
Broken Access Control

Patched in Version:
4.2.8.5

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 4.2.8.5.

Event Booking Manager for WooCommerce

Plugin Slug:
mage-eventpress

Installations
7,000+

Vulnerability:
PHP Object Injection

Patched in Version:
5.1.2

Severity Score:
Critical


The vulnerability has been patched, so you should update to version 5.1.2.

Cart All In One For WooCommerce

Plugin Slug:
woo-cart-all-in-one

Installations
6,000+

Vulnerability:
Content Injection

Patched in Version:
1.1.22

Severity Score:
High


The vulnerability has been patched, so you should update to version 1.1.22.

Popup Box � Easily Create WordPress Popups

Plugin Slug:
popup-box

Installations
5,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
3.2.13

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 3.2.13.

Import Eventbrite Events

Plugin Slug:
import-eventbrite-events

Installations
3,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.7.5

Severity Score:
High


The vulnerability has been patched, so you should update to version 1.7.5.

Paytium: Mollie payment forms & donations

Plugin Slug:
paytium

Installations
3,000+

Vulnerability:
Broken Access Control

Patched in Version:
4.4

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 4.4.

Paytium: Mollie payment forms & donations

Plugin Slug:
paytium

Installations
3,000+

Vulnerability:
Broken Access Control

Patched in Version:
4.4

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 4.4.

Paytium: Mollie payment forms & donations

Plugin Slug:
paytium

Installations
3,000+

Vulnerability:
Broken Access Control

Patched in Version:
4.4

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 4.4.

Paytium: Mollie payment forms & donations

Plugin Slug:
paytium

Installations
3,000+

Vulnerability:
Broken Access Control

Patched in Version:
4.4

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 4.4.

Paytium: Mollie payment forms & donations

Plugin Slug:
paytium

Installations
3,000+

Vulnerability:
Broken Access Control

Patched in Version:
4.4

Severity Score:
High


The vulnerability has been patched, so you should update to version 4.4.

Paytium: Mollie payment forms & donations

Plugin Slug:
paytium

Installations
3,000+

Vulnerability:
Broken Access Control

Patched in Version:
4.4

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 4.4.

Paytium: Mollie payment forms & donations

Plugin Slug:
paytium

Installations
3,000+

Vulnerability:
Broken Access Control

Patched in Version:
4.4

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 4.4.

Paytium: Mollie payment forms & donations

Plugin Slug:
paytium

Installations
3,000+

Vulnerability:
Broken Access Control

Patched in Version:
4.4

Severity Score:
High


The vulnerability has been patched, so you should update to version 4.4.

Tickera � Sell Tickets & Manage Events

Plugin Slug:
tickera-event-ticketing-system

Installations
3,000+

Vulnerability:
Broken Access Control

Patched in Version:
3.5.6.5

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 3.5.6.5.

WP-DownloadManager

Plugin Slug:
wp-downloadmanager

Installations
3,000+

Vulnerability:
Arbitrary File Deletion

Patched in Version:
1.69.1

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.69.1.

WP-DownloadManager

Plugin Slug:
wp-downloadmanager

Installations
3,000+

Vulnerability:
Arbitrary File Download

Patched in Version:
1.69.1

Severity Score:
Low


The vulnerability has been patched, so you should update to version 1.69.1.

IMGspider � ????????

Plugin Slug:
imgspider

Installations
2,000+

Vulnerability:
Arbitrary File Upload

Patched in Version:
2.3.11

Severity Score:
Critical


The vulnerability has been patched, so you should update to version 2.3.11.

Simple Ajax Chat � Add a Fast, Secure Chat Box

Plugin Slug:
simple-ajax-chat

Installations
2,000+

Vulnerability:
Sensitive Data Exposure

Patched in Version:
20260217

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 20260217.

Virusdie � One-click website security

Plugin Slug:
virusdie

Installations
2,000+

Vulnerability:
Broken Access Control

Patched in Version:
1.1.8

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.1.8.

WP-Lister Lite for eBay

Plugin Slug:
wp-lister-for-ebay

Installations
2,000+

Vulnerability:
Broken Access Control

Patched in Version:
3.8.6

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 3.8.6.

WowRevenue � Product Bundles & Bulk Discounts

Plugin Slug:
revenue

Installations
1,000+

Vulnerability:
Broken Access Control

Patched in Version:
2.1.4

Severity Score:
High


The vulnerability has been patched, so you should update to version 2.1.4.

Dam Spam

Plugin:

Dam Spam

Plugin Slug:
dam-spam

Installations
700+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
1.0.9

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.0.9.

My Tickets � Accessible Event Ticketing

Plugin Slug:
my-tickets

Installations
700+

Vulnerability:
Sensitive Data Exposure

Patched in Version:
2.1.1

Severity Score:
High


The vulnerability has been patched, so you should update to version 2.1.1.

WP Plugin Info Card

Plugin Slug:
wp-plugin-info-card

Installations
600+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
6.3.0

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 6.3.0.

Build App Online

Plugin Slug:
build-app-online

Installations
500+

Vulnerability:
Privilege Escalation

Patched in Version:
1.0.23

Severity Score:
High


The vulnerability has been patched, so you should update to version 1.0.23.

Library Management System

Plugin Slug:
library-management-system

Installations
300+

Vulnerability:
SQL Injection

Patched in Version:
3.3

Severity Score:
Critical


The vulnerability has been patched, so you should update to version 3.3.

Order Splitter for WooCommerce

Plugin Slug:
woo-order-splitter

Installations
300+

Vulnerability:
Broken Access Control

Patched in Version:
5.3.6

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 5.3.6.

Display During Conditional Shortcode

Plugin Slug:
display-during-conditional-shortcode

Installations
200+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.3

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.3.

Video Share VOD � Turnkey Video Site Builder Script

Plugin Slug:
video-share-vod

Installations
80+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.7.12

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.7.12.

Private Comment

Plugin Slug:
private-comment

Installations
60+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
0.0.5

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 0.0.5.

Frontend User Notes

Plugin Slug:
frontend-user-notes

Installations
50+

Vulnerability:
Insecure Direct Object References (IDOR)

Patched in Version:
2.1.1

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.1.1.

Activity Log for WordPress

Plugin Slug:
winterlock

Installations
50+

Vulnerability:
Broken Access Control

Patched in Version:
1.2.9

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.2.9.

Community Events

Plugin Slug:
community-events

Installations
30+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.5.8

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.5.8.

Keybase.io Verification

Plugin Slug:
wp-keybase-verification

Installations
30+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
1.4.6

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.4.6.

InteractiveCalculator for WordPress

Plugin Slug:
interactivecalculator

Installations
20+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.0.4

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.0.4.

Rent Fetch

Plugin Slug:
rentfetch

Installations
20+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
0.32.7

Severity Score:
High


The vulnerability has been patched, so you should update to version 0.32.7.

Ads Pro

Plugin:

Ads Pro

Plugin Slug:
ap-plugin-scripteo

Vulnerability:
Broken Access Control

Patched in Version:
5.1

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 5.1.

ARForms Form Builder

Plugin:

ARForms Form Builder

Plugin Slug:
arforms-form-builder

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.5.9

Severity Score:
High


The vulnerability has been patched, so you should update to version 1.5.9.

Lizza LMS Pro

Plugin:

Lizza LMS Pro

Plugin Slug:
lizza-lms-pro

Vulnerability:
Privilege Escalation

Patched in Version:
1.0.4

Severity Score:
Critical


The vulnerability has been patched, so you should update to version 1.0.4.

tagDiv Composer

Plugin:

tagDiv Composer

Plugin Slug:
td-composer

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
5.1

Severity Score:
High


The vulnerability has been patched, so you should update to version 5.1.

Truelysell Core

Plugin:

Truelysell Core

Plugin Slug:
truelysell-core

Vulnerability:
Privilege Escalation

Patched in Version:
1.8.8

Severity Score:
Critical


The vulnerability has been patched, so you should update to version 1.8.8.

Uni CPO (Premium)

Plugin:

Uni CPO (Premium)

Plugin Slug:
uni-woo-custom-product-options-premium

Vulnerability:
Broken Access Control

Patched in Version:
4.9.61

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 4.9.61.

Wolmart Core

Plugin:

Wolmart Core

Plugin Slug:
wolmart-core

Vulnerability:
SQL Injection

Patched in Version:
1.9.7

Severity Score:
Critical


The vulnerability has been patched, so you should update to version 1.9.7.

WordPress Themes � 8 Patched / 31 Unpatched

Drift

Theme:

Drift

Theme Slug:
drift

Downloads
30,869

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should switch themes.

Mega Store Woocommerce

Theme Slug:
mega-store-woocommerce

Downloads
42,273

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should switch themes.

NewsBlogger

Theme Slug:
newsblogger

Downloads
155,250

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should switch themes.

Renden

Theme:

Renden

Theme Slug:
renden

Downloads
328,852

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should switch themes.

A-Mart

Theme:

A-Mart

Theme Slug:
a-mart

Vulnerability:
Local File Inclusion

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should switch themes.

Blabber

Theme:

Blabber

Theme Slug:
blabber

Vulnerability:
Local File Inclusion

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should switch themes.

Buyent

Theme:

Buyent

Theme Slug:
buyent

Vulnerability:
Privilege Escalation

Patched in Version:
No Fix

Severity Score:
Critical


The vulnerability has not been patched. You should switch themes.

Coworking

Theme:

Coworking

Theme Slug:
coworking

Vulnerability:
Local File Inclusion

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should switch themes.

Dentario

Theme:

Dentario

Theme Slug:
dentario

Vulnerability:
PHP Object Injection

Patched in Version:
No Fix

Severity Score:
Critical


The vulnerability has not been patched. You should switch themes.

Fooddy

Theme:

Fooddy

Theme Slug:
fooddy

Vulnerability:
Local File Inclusion

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should switch themes.

Gustavo

Theme:

Gustavo

Theme Slug:
gustavo

Vulnerability:
Local File Inclusion

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should switch themes.

Impacto Patronus

Theme:

Impacto Patronus

Theme Slug:
impacto-patronus

Vulnerability:
Local File Inclusion

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should switch themes.

Ironfit

Theme:

Ironfit

Theme Slug:
ironfit

Vulnerability:
Local File Inclusion

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should switch themes.

Isida

Theme:

Isida

Theme Slug:
isida

Vulnerability:
Local File Inclusion

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should switch themes.

Jude

Theme:

Jude

Theme Slug:
jude

Vulnerability:
Local File Inclusion

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should switch themes.

Kingler

Theme:

Kingler

Theme Slug:
kingler

Vulnerability:
PHP Object Injection

Patched in Version:
No Fix

Severity Score:
Critical


The vulnerability has not been patched. You should switch themes.

Marveland

Theme:

Marveland

Theme Slug:
marveland

Vulnerability:
Local File Inclusion

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should switch themes.

Netmix

Theme:

Netmix

Theme Slug:
netmix

Vulnerability:
Local File Inclusion

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should switch themes.

Parkivia

Theme:

Parkivia

Theme Slug:
parkivia

Vulnerability:
Local File Inclusion

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should switch themes.

PawFriends – Pet Shop and Veterinary WordPress Theme

Theme:

PawFriends – Pet Shop and Veterinary WordPress Theme

Theme Slug:
pawfriends

Vulnerability:
Insecure Direct Object References (IDOR)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should switch themes.

PawFriends – Pet Shop and Veterinary WordPress Theme

Theme:

PawFriends – Pet Shop and Veterinary WordPress Theme

Theme Slug:
pawfriends

Vulnerability:
Local File Inclusion

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should switch themes.

Photolia

Theme:

Photolia

Theme Slug:
photolia

Vulnerability:
Local File Inclusion

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should switch themes.

Redy

Theme:

Redy

Theme Slug:
redy

Vulnerability:
Local File Inclusion

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should switch themes.

Rhodos

Theme:

Rhodos

Theme Slug:
rhodos

Vulnerability:
Local File Inclusion

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should switch themes.

Saveo

Theme:

Saveo

Theme Slug:
saveo

Vulnerability:
Local File Inclusion

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should switch themes.

SevenTrees

Theme:

SevenTrees

Theme Slug:
seventrees

Vulnerability:
Local File Inclusion

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should switch themes.

Soleng

Theme:

Soleng

Theme Slug:
soleng

Vulnerability:
Local File Inclusion

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should switch themes.

Tennis Club

Theme:

Tennis Club

Theme Slug:
tennis-sportclub

Vulnerability:
PHP Object Injection

Patched in Version:
No Fix

Severity Score:
Critical


The vulnerability has not been patched. You should switch themes.

UnlimHost

Theme:

UnlimHost

Theme Slug:
unlimhost

Vulnerability:
Local File Inclusion

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should switch themes.

Valenti

Theme:

Valenti

Theme Slug:
valenti

Vulnerability:
PHP Object Injection

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should switch themes.

Zio Alberto

Theme:

Zio Alberto

Theme Slug:
zioalberto

Vulnerability:
Local File Inclusion

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should switch themes.

Context Blog

Theme Slug:
context-blog

Downloads
84,231

Vulnerability:
Sensitive Data Exposure

Patched in Version:
1.2.6

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.2.6.

Shopire

Theme:

Shopire

Theme Slug:
shopire

Downloads
89,293

Vulnerability:
Broken Access Control

Patched in Version:
1.0.58

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.0.58.

Spa and Salon

Theme Slug:
spa-and-salon

Downloads
165,530

Vulnerability:
Broken Access Control

Patched in Version:
1.3.3

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.3.3.

Grand Restaurant

Theme:

Grand Restaurant

Theme Slug:
grandrestaurant

Vulnerability:
PHP Object Injection

Patched in Version:
7.0.11

Severity Score:
Critical


The vulnerability has been patched, so you should update to version 7.0.11.

Ippsum

Theme:

Ippsum

Theme Slug:
ippsum

Vulnerability:
PHP Object Injection

Patched in Version:
1.2.1

Severity Score:
Critical


The vulnerability has been patched, so you should update to version 1.2.1.

CitiLights

Theme:

CitiLights

Theme Slug:
noo-citilights

Vulnerability:
Broken Access Control

Patched in Version:
3.7.2

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 3.7.2.

Sweet Date

Theme:

Sweet Date

Theme Slug:
sweetdate

Vulnerability:
PHP Object Injection

Patched in Version:
4.0.1

Severity Score:
Critical


The vulnerability has been patched, so you should update to version 4.0.1.

Wiguard

Theme:

Wiguard

Theme Slug:
wiguard

Vulnerability:
Arbitrary File Upload

Patched in Version:
2.0.1

Severity Score:
Critical


The vulnerability has been patched, so you should update to version 2.0.1.

Related articles

Wait! Get exclusive hosting insights

Subscribe to our newsletter and stay ahead of the competition with expert advice from our hosting pros.

Loading form…