Line illustration showing a black application window on a dark purple gradient background overlaid with a large exclamation point alert icon and three bugs.

WordPress Vulnerability Report � February 5, 2025

In this report, 345 vulnerabilities have been publicly disclosed. Security patches for 148 of these plugins and themes are available now, so run those updates as soon as possible. If you’re a Solid Security Pro user, the version management tool may have already warned you and updated these plugins, depending on your settings.

Additionally, there are 197 plugin and theme vulnerabilities with no patch available yet. If you’re a Solid Security Pro user, those vulnerabilities are already protected by the Solid Security firewall. Virtual patches from Patchstack will be applied when a vulnerability is considered high or medium risk. If no patch is forthcoming from the vendor or the vulnerable software has been marked “closed” and dropped from the official WordPress repositories, you should deactivate it soon and look for alternative solutions.

WordPress Core

WordPress 6.7.1 is available! This minor release features 16 bug fixes throughout Core and the Block Editor.

WordPress Plugins � 146 Patched / 195 Unpatched

Shortcodes and extra features for Phlox theme

Plugin Slug:
auxin-elements

Installations
100,000+

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Meta Tag Manager

Plugin Slug:
meta-tag-manager

Installations
90,000+

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Dynamic Conditions

Plugin Slug:
dynamicconditions

Installations
60,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Hide Shipping Method For WooCommerce

Plugin Slug:
hide-shipping-method-for-woocommerce

Installations
10,000+

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Payment Forms for Paystack

Plugin Slug:
payment-forms-for-paystack

Installations
3,000+

Vulnerability:
SQL Injection

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Eventer

Plugin:

Eventer

Plugin Slug:
eventer

Installations
2,000+

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Eventer

Plugin:

Eventer

Plugin Slug:
eventer

Installations
2,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Eventer

Plugin:

Eventer

Plugin Slug:
eventer

Installations
2,000+

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Blog, Posts and Category Filter for Elementor

Plugin Slug:
blog-posts-and-category-for-elementor

Installations
1,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Nirweb support

Plugin Slug:
nirweb-support

Installations
1,000+

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Scroll Styler

Plugin Slug:
scroll-styler

Installations
1,000+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Broadstreet

Plugin Slug:
broadstreet

Installations
700+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Job Board Manager

Plugin Slug:
job-board-manager

Installations
500+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Paytm Payment Donation

Plugin Slug:
paytm-donation

Installations
400+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Designer � Elementor Addons

Plugin Slug:
designer

Installations
100+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.
Plugin Slug:
internal-link-builder

Installations
100+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Music Press Pro

Plugin Slug:
music-press-pro

Installations
100+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Image Rotator

Plugin Slug:
appten-image-rotator

Installations
90+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

All push notification for WP

Plugin Slug:
all-push-notification

Installations
70+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Linear

Plugin:

Linear

Plugin Slug:
linear

Installations
60+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.
Plugin Slug:
cwd-stealth-links

Installations
50+

Vulnerability:
SQL Injection

Patched in Version:
No Fix

Severity Score:
Critical


The vulnerability has not been patched. You should deactivate the plugin.

Print PDF Generator and Publisher

Plugin Slug:
nopeamedia

Installations
50+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Appointment Buddy Widget By Accrete

Plugin Slug:
appointment-buddy-online-appointment-booking-by-accrete

Installations
20+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

ABC Notation

Plugin:

ABC Notation

Plugin Slug:
abc-notation

Vulnerability:
Arbitrary File Download

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Altra Side Menu

Plugin:

Altra Side Menu

Plugin Slug:
altra-side-menu

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Altra Side Menu

Plugin:

Altra Side Menu

Plugin Slug:
altra-side-menu

Vulnerability:
SQL Injection

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

AnimateGL – Advanced Animation Plugin for WordPress

Plugin:

AnimateGL – Advanced Animation Plugin for WordPress

Plugin Slug:
animategl

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Ask Me Anything (Anonymously)

Plugin:

Ask Me Anything (Anonymously)

Plugin Slug:
ask-me-anything-anonymously

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Auto SEO

Plugin:

Auto SEO

Plugin Slug:
auto-seo

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

BookPress � For Book Authors

Plugin:

BookPress � For Book Authors

Plugin Slug:
book-press

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

BookPress � For Book Authors

Plugin:

BookPress � For Book Authors

Plugin Slug:
book-press

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Breaking News Ticker

Plugin:

Breaking News Ticker

Plugin Slug:
breaking-news-ticker

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

brodos.net Onlineshop Plugin

Plugin:

brodos.net Onlineshop Plugin

Plugin Slug:
brodos-net-onlineshop

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Bulk Me Now!

Plugin:

Bulk Me Now!

Plugin Slug:
bulk-me-now

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Bulk Me Now!

Plugin:

Bulk Me Now!

Plugin Slug:
bulk-me-now

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Bulk Me Now!

Plugin:

Bulk Me Now!

Plugin Slug:
bulk-me-now

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

CanvasFlow

Plugin:

CanvasFlow

Plugin Slug:
canvasflow

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Child Themes Helper

Plugin:

Child Themes Helper

Plugin Slug:
child-themes-helper

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Competition Form

Plugin:

Competition Form

Plugin Slug:
competition-form

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Connections

Plugin:

Connections

Plugin Slug:
connections1

Vulnerability:
Arbitrary File Deletion

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Custom Comment Notifications

Plugin:

Custom Comment Notifications

Plugin Slug:
custom-comment-notifications

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

A5 Custom Login Page

Plugin:

A5 Custom Login Page

Plugin Slug:
custom-login-page

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.
Plugin:

Custom Links On Admin Dashboard Toolbar

Plugin Slug:
customize-wpadmin

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Delete Comments By Status

Plugin:

Delete Comments By Status

Plugin Slug:
delete-comments-by-status

Vulnerability:
Local File Inclusion

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Dental Optimizer Patient Generator App

Plugin:

Dental Optimizer Patient Generator App

Plugin Slug:
dental-optimizer-patient-generator-app

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Dyn Business Panel

Plugin:

Dyn Business Panel

Plugin Slug:
dyn-business-panel

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Dyn Business Panel

Plugin:

Dyn Business Panel

Plugin Slug:
dyn-business-panel

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Easy Chart Builder for WordPress

Plugin:

Easy Chart Builder for WordPress

Plugin Slug:
easy-chart-builder

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.
Plugin:

Easy Related Posts

Plugin Slug:
easy-related-posts

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Easy WP Tiles

Plugin:

Easy WP Tiles

Plugin Slug:
easy-wp-tiles

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

ECPay Ecommerce for WooCommerce

Plugin:

ECPay Ecommerce for WooCommerce

Plugin Slug:
ecpay-ecommerce-for-woocommerce

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

ECT Home Page Products

Plugin:

ECT Home Page Products

Plugin Slug:
ect-homepage-products

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Embed RSS

Plugin:

Embed RSS

Plugin Slug:
embed-rss

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Embed Swagger UI

Plugin:

Embed Swagger UI

Plugin Slug:
embed-swagger-ui

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Etsy Importer

Plugin:

Etsy Importer

Plugin Slug:
etsy-importer

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

External Video For Everybody

Plugin:

External Video For Everybody

Plugin Slug:
external-video-for-everybody

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Facilita Form Tracker

Plugin:

Facilita Form Tracker

Plugin Slug:
facilita-form-tracker

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Fami Sales Popup

Plugin:

Fami Sales Popup

Plugin Slug:
fami-sales-popup

Vulnerability:
Local File Inclusion

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Fantastic Elasticsearch

Plugin:

Fantastic Elasticsearch

Plugin Slug:
fantastic-elasticsearch

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Fare Calculator

Plugin:

Fare Calculator

Plugin Slug:
fare-calculator

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Status Updater

Plugin:

Status Updater

Plugin Slug:
fb-status-updater

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

FlashCounter

Plugin:

FlashCounter

Plugin Slug:
flashcounter

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Post Title (TypeWriter)

Plugin:

Post Title (TypeWriter)

Plugin Slug:
flashnews-typewriter-pearlbells

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
Critical


The vulnerability has not been patched. You should deactivate the plugin.
Plugin:

FlexIDX Home Search

Plugin Slug:
flexidx-home-search

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Forge � Front-End Page Builder

Plugin:

Forge � Front-End Page Builder

Plugin Slug:
forge

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Frictionless

Plugin:

Frictionless

Plugin Slug:
frictionless

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Full Circle

Plugin:

Full Circle

Plugin Slug:
full-circle

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Fyrebox Quizzes

Plugin:

Fyrebox Quizzes

Plugin Slug:
fyrebox-shortcode

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

GlobalQuran

Plugin:

GlobalQuran

Plugin Slug:
globalquran

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

URL-Preview-Box

Plugin:

URL-Preview-Box

Plugin Slug:
good-url-preview-box

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Google Earth Embed

Plugin:

Google Earth Embed

Plugin Slug:
google-earth-tours

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

WordPress Google Map Professional

Plugin:

WordPress Google Map Professional

Plugin Slug:
google-map-professional

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Graceful Email Obfuscation

Plugin:

Graceful Email Obfuscation

Plugin Slug:
graceful-email-obfuscation

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

HTML5 chat

Plugin:

HTML5 chat

Plugin Slug:
html5-chat

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Plugin A/B Image Optimizer

Plugin:

Plugin A/B Image Optimizer

Plugin Slug:
images-optimizer

Vulnerability:
Arbitrary File Download

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.
Plugin:

Implied Cookie Consent

Plugin Slug:
implied-cookie-consent

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Indeed API

Plugin:

Indeed API

Plugin Slug:
indeed-api

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Infusionsoft Analytics

Plugin:

Infusionsoft Analytics

Plugin Slug:
infusionsoft-web-tracker

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

InLocation

Plugin:

InLocation

Plugin Slug:
inlocation

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Issuu Panel

Plugin:

Issuu Panel

Plugin Slug:
issuu-panel

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

WP Vehicle Manager

Plugin:

WP Vehicle Manager

Plugin Slug:
js-vehicle-manager

Vulnerability:
Local File Inclusion

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Event Kikfyre

Plugin:

Event Kikfyre

Plugin Slug:
kikfyre-events-calendar-tickets

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.
Plugin:

Kona Gallery Block

Plugin Slug:
kona-instagram-feed-for-gutenberg

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Contact Form and Calls To Action by vcita

Plugin:

Contact Form and Calls To Action by vcita

Plugin Slug:
lead-capturing-call-to-actions-by-vcita

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Like dislike plus counter

Plugin:

Like dislike plus counter

Plugin Slug:
like-dislike-plus-counter

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Link to URL / Post

Plugin:

Link to URL / Post

Plugin Slug:
link-to-url-post

Vulnerability:
SQL Injection

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.
Plugin:

Links in Captions

Plugin Slug:
links-in-captions

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Live2DWebCanvas

Plugin:

Live2DWebCanvas

Plugin Slug:
live-2d

Vulnerability:
Arbitrary File Deletion

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Login-box

Plugin:

Login-box

Plugin Slug:
login-box

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

MagicForm

Plugin:

MagicForm

Plugin Slug:
magicform

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.
Plugin:

Masy Gallery

Plugin Slug:
masy-gallery

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Munk Sites

Plugin:

Munk Sites

Plugin Slug:
munk-sites

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
Critical


The vulnerability has not been patched. You should deactivate the plugin.

Music Sheet Viewer

Plugin:

Music Sheet Viewer

Plugin Slug:
music-sheet-viewer

Vulnerability:
Arbitrary File Download

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Music Sheet Viewer

Plugin:

Music Sheet Viewer

Plugin Slug:
music-sheet-viewer

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.
Plugin:

NextGen Cooliris Gallery

Plugin Slug:
nextgen-cooliris-gallery

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Ni Sales Commission For WooCommerce

Plugin:

Ni Sales Commission For WooCommerce

Plugin Slug:
ni-woo-sales-commission

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

NOTICE BOARD BY TOWKIR

Plugin:

NOTICE BOARD BY TOWKIR

Plugin Slug:
notice-board-by-towkir

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

WordPress SEO Friendly Accordion FAQ

Plugin:

WordPress SEO Friendly Accordion FAQ

Plugin Slug:
notice-faq

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

OneStore Sites

Plugin:

OneStore Sites

Plugin Slug:
onestore-sites

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
Critical


The vulnerability has not been patched. You should deactivate the plugin.

On Page SEO + Whatsapp Chat Button

Plugin:

On Page SEO + Whatsapp Chat Button

Plugin Slug:
ops-robots-txt

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Optimate Ads

Plugin:

Optimate Ads

Plugin Slug:
optimate-ads

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.
Plugin:

Link Fixer

Plugin Slug:
permalink-finder

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Policy Genius

Plugin:

Policy Genius

Plugin Slug:
policy-genius

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Pop Up

Plugin:

Pop Up

Plugin Slug:
popup-seo-optimized

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Post Carousel Slider

Plugin:

Post Carousel Slider

Plugin Slug:
post-carousel-slider

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Power Ups for Elementor

Plugin:

Power Ups for Elementor

Plugin Slug:
power-ups-for-elementor

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Quote Comments

Plugin:

Quote Comments

Plugin Slug:
quote-comments

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.
Plugin:

Read More Copy Link

Plugin Slug:
read-more-copy-link

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Responsive iframe

Plugin:

Responsive iframe

Plugin Slug:
responsive-iframe

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

ReverbNation Widgets

Plugin:

ReverbNation Widgets

Plugin Slug:
reverbnation-widgets

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Royal Core

Plugin:

Royal Core

Plugin Slug:
royal-core

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

RSS in Page

Plugin:

RSS in Page

Plugin Slug:
rss-in-page

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Safe Ai Malware Protection for WP

Plugin:

Safe Ai Malware Protection for WP

Plugin Slug:
safe-ai-malware-protection-for-wp

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Social Share Buttons for WordPress

Plugin:

Social Share Buttons for WordPress

Plugin Slug:
share-buttons

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Social Share Buttons for WordPress

Plugin:

Social Share Buttons for WordPress

Plugin Slug:
share-buttons

Vulnerability:
Path Traversal

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Show notice or message on admin area

Plugin:

Show notice or message on admin area

Plugin Slug:
show-notice-or-message-on-admin-area

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Simple Auto Tag

Plugin:

Simple Auto Tag

Plugin Slug:
simple-auto-tag

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Simple Select All Text Box

Plugin:

Simple Select All Text Box

Plugin Slug:
simple-select-all-text-box

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Simple User Profile

Plugin:

Simple User Profile

Plugin Slug:
simple-user-profile

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Single-user-chat

Plugin:

Single-user-chat

Plugin Slug:
single-user-chat

Vulnerability:
Settings Change

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Slide Banners

Plugin:

Slide Banners

Plugin Slug:
slide-banners

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

SlideDeck 1 Lite Content Slider

Plugin:

SlideDeck 1 Lite Content Slider

Plugin Slug:
slidedeck-lite-for-wordpress

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Smart Countdown FX

Plugin:

Smart Countdown FX

Plugin Slug:
smart-countdown-fx

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Smart DoFollow

Plugin:

Smart DoFollow

Plugin Slug:
smart-dofollow

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.
Plugin:

Social Links

Plugin Slug:
social-links

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.
Plugin:

Social Links

Plugin Slug:
social-links

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Songkick Concerts and Festivals

Plugin:

Songkick Concerts and Festivals

Plugin Slug:
songkick-concerts-and-festivals

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Sports Rankings and Lists

Plugin:

Sports Rankings and Lists

Plugin Slug:
sports-rankings-lists

Vulnerability:
Arbitrary File Download

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

StageShow

Plugin:

StageShow

Plugin Slug:
stageshow

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Starter Templates by FancyWP

Plugin:

Starter Templates by FancyWP

Plugin Slug:
starter-templates

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
Critical


The vulnerability has not been patched. You should deactivate the plugin.

Starter Templates by FancyWP

Plugin:

Starter Templates by FancyWP

Plugin Slug:
starter-templates

Vulnerability:
Server Side Request Forgery (SSRF)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Stockdio Historical Chart

Plugin:

Stockdio Historical Chart

Plugin Slug:
stockdio-historical-chart

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Style Tweaker

Plugin:

Style Tweaker

Plugin Slug:
style-tweaker

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

System Dashboard

Plugin:

System Dashboard

Plugin Slug:
system-dashboard

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Tabulate

Plugin:

Tabulate

Plugin Slug:
tabulate

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Theasys

Plugin:

Theasys

Plugin Slug:
theasys

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Theme Options Z

Plugin:

Theme Options Z

Plugin Slug:
theme-options-z

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Traveler Code

Plugin:

Traveler Code

Plugin Slug:
traveler-code

Vulnerability:
SQL Injection

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Traveler Code

Plugin:

Traveler Code

Plugin Slug:
traveler-code

Vulnerability:
SQL Injection

Patched in Version:
No Fix

Severity Score:
Critical


The vulnerability has not been patched. You should deactivate the plugin.

Traveler Layout Essential For Elementor

Plugin:

Traveler Layout Essential For Elementor

Plugin Slug:
traveler-layout-essential-for-elementor

Vulnerability:
Server Side Request Forgery (SSRF)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Typer Core

Plugin:

Typer Core

Plugin Slug:
typer-core

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

uListing

Plugin:

uListing

Plugin Slug:
ulisting

Vulnerability:
SQL Injection

Patched in Version:
No Fix

Severity Score:
Critical


The vulnerability has not been patched. You should deactivate the plugin.

uListing

Plugin:

uListing

Plugin Slug:
ulisting

Vulnerability:
SQL Injection

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

User Messages

Plugin:

User Messages

Plugin Slug:
user-messages

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

User Role

Plugin:

User Role

Plugin Slug:
user-roles

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Media Manager for UserPro

Plugin:

Media Manager for UserPro

Plugin Slug:
userpro-mediamanager

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Media Manager for UserPro

Plugin:

Media Manager for UserPro

Plugin Slug:
userpro-mediamanager

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
Critical


The vulnerability has not been patched. You should deactivate the plugin.

Vignette Ads

Plugin:

Vignette Ads

Plugin Slug:
vignete-ads

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

VR-Frases

Plugin:

VR-Frases

Plugin Slug:
vr-frases

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

VR-Frases

Plugin:

VR-Frases

Plugin Slug:
vr-frases

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

VR-Frases

Plugin:

VR-Frases

Plugin Slug:
vr-frases

Vulnerability:
SQL Injection

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

WE � Testimonial Slider

Plugin:

WE � Testimonial Slider

Plugin Slug:
we-testimonial-slider

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

WizShop

Plugin:

WizShop

Plugin Slug:
wizshop

Vulnerability:
Local File Inclusion

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Wonder FontAwesome

Plugin:

Wonder FontAwesome

Plugin Slug:
wonder-fontawesome

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Woocommerce osCommerce Sync

Plugin:

Woocommerce osCommerce Sync

Plugin Slug:
woo-oscommerce-sync

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

WordPress Signature

Plugin:

WordPress Signature

Plugin Slug:
wordpress-signature

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

WP Admin Custom Page

Plugin:

WP Admin Custom Page

Plugin Slug:
wp-admin-custom-page

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

WP Contact Form7 Email Spam Blocker

Plugin:

WP Contact Form7 Email Spam Blocker

Plugin Slug:
wp-contact-form7-email-spam-blocker

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

WP Custom Post RSS Feed

Plugin:

WP Custom Post RSS Feed

Plugin Slug:
wp-custom-post-rss-feed

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

WP Dispensary

Plugin:

WP Dispensary

Plugin Slug:
wp-dispensary

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

WP Email Newsletter

Plugin:

WP Email Newsletter

Plugin Slug:
wp-email-newsletter

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

WP Finance

Plugin:

WP Finance

Plugin Slug:
wp-finance

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

WP Finance

Plugin:

WP Finance

Plugin Slug:
wp-finance

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

WP Find Your Nearest

Plugin:

WP Find Your Nearest

Plugin Slug:
wp-find-your-nearest

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

WP Frontend Submit

Plugin:

WP Frontend Submit

Plugin Slug:
wp-frontend-submit

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

WP Image Uploader

Plugin:

WP Image Uploader

Plugin Slug:
wp-post-447765 wp-image-uploader

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

WP Image Uploader

Plugin:

WP Image Uploader

Plugin Slug:
wp-post-447765 wp-image-uploader

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

WP Image Uploader

Plugin:

WP Image Uploader

Plugin Slug:
wp-post-447765 wp-image-uploader

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

WP Keyword Monitor

Plugin:

WP Keyword Monitor

Plugin Slug:
wp-keyword-monitor

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

WP MediaTagger

Plugin:

WP MediaTagger

Plugin Slug:
wp-mediatagger

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

WP MediaTagger

Plugin:

WP MediaTagger

Plugin Slug:
wp-mediatagger

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

WP SimpleWeather

Plugin:

WP SimpleWeather

Plugin Slug:
wp-simpleweather

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

WP Social Stream

Plugin:

WP Social Stream

Plugin Slug:
wp-social-stream

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

WP Spell Check

Plugin:

WP Spell Check

Plugin Slug:
wp-spell-check

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

WordPress Survey & Poll

Plugin:

WordPress Survey & Poll

Plugin Slug:
wp-survey-and-poll

Vulnerability:
SQL Injection

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

WP Triggers Lite

Plugin:

WP Triggers Lite

Plugin Slug:
wp-triggers-lite

Vulnerability:
SQL Injection

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

WP Triggers Lite

Plugin:

WP Triggers Lite

Plugin Slug:
wp-triggers-lite

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

WP doodlez

Plugin:

WP doodlez

Plugin Slug:
wpdoodlez

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Top Bar � PopUps � by WPOptin

Plugin:

Top Bar � PopUps � by WPOptin

Plugin Slug:
wpoptin

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

WPRadio

Plugin:

WPRadio

Plugin Slug:
wpradio

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Zalomen�

Plugin:

Zalomen�

Plugin Slug:
zalomeni

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

ZMSEO

Plugin:

ZMSEO

Plugin Slug:
zmseo

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

zStore Manager Basic

Plugin:

zStore Manager Basic

Plugin Slug:
zstore-manager-basic

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Orbit Fox by ThemeIsle

Plugin Slug:
themeisle-companion

Installations
200,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.10.45

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.10.45.

Tracking Code Manager

Plugin Slug:
tracking-code-manager

Installations
100,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.4.0

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.4.0.

Import any XML, CSV or Excel File to WordPress

Plugin Slug:
wp-all-import

Installations
100,000+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
3.8.0

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 3.8.0.

Import any XML, CSV or Excel File to WordPress

Plugin Slug:
wp-all-import

Installations
100,000+

Vulnerability:
PHP Object Injection

Patched in Version:
3.8.0

Severity Score:
High


The vulnerability has been patched, so you should update to version 3.8.0.

Event Tickets and Registration

Plugin Slug:
event-tickets

Installations
90,000+

Vulnerability:
Insecure Direct Object References (IDOR)

Patched in Version:
5.18.1.1

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 5.18.1.1.

HT Mega � Absolute Addons For Elementor

Plugin Slug:
ht-mega-for-elementor

Installations
90,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.7.7

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.7.7.

Jupiter X Core

Plugin Slug:
jupiterx-core

Installations
90,000+

Vulnerability:
Local File Inclusion

Patched in Version:
4.8.8

Severity Score:
High


The vulnerability has been patched, so you should update to version 4.8.8.

Jupiter X Core

Plugin Slug:
jupiterx-core

Installations
90,000+

Vulnerability:
Arbitrary File Download

Patched in Version:
4.8.8

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 4.8.8.

LearnPress � WordPress LMS Plugin

Plugin Slug:
learnpress

Installations
90,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
4.2.7.5.1

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 4.2.7.5.1.

Import and export users and customers

Plugin Slug:
import-users-from-csv-with-meta

Installations
80,000+

Vulnerability:
Sensitive Data Exposure

Patched in Version:
1.27.13

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.27.13.

Ninja Tables � Easy Data Table Builder

Plugin Slug:
ninja-tables

Installations
80,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
5.0.17

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 5.0.17.

Drag and Drop Multiple File Upload for Contact Form 7

Plugin Slug:
drag-and-drop-multiple-file-upload-contact-form-7

Installations
60,000+

Vulnerability:
Arbitrary File Deletion

Patched in Version:
1.3.8.6

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.3.8.6.

Divi Torque Lite

Plugin Slug:
addons-for-divi

Installations
50,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
4.1.1

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 4.1.1.

Better Find and Replace

Plugin Slug:
real-time-auto-find-and-replace

Installations
50,000+

Vulnerability:
Privilege Escalation

Patched in Version:
1.6.8

Severity Score:
High


The vulnerability has been patched, so you should update to version 1.6.8.

CF7 Google Sheets Connector

Plugin Slug:
cf7-google-sheets-connector

Installations
40,000+

Vulnerability:
Broken Access Control

Patched in Version:
5.0.18

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 5.0.18.

NotificationX � FOMO, Live Sales Notification, WooCommerce Sales Popup, GDPR, Social Proof, Announcement Banner & Floating Notification Bar

Plugin Slug:
notificationx

Installations
40,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
3.0.0

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 3.0.0.

Gwolle Guestbook

Plugin Slug:
gwolle-gb

Installations
30,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
4.7.2

Severity Score:
High


The vulnerability has been patched, so you should update to version 4.7.2.

Stratum � Elementor Widgets

Plugin Slug:
stratum

Installations
30,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.5.0

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.5.0.
Plugin Slug:
wow-carousel-for-divi-lite

Installations
30,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.1.0

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.1.0.

DSGVO All in one for WP

Plugin Slug:
dsgvo-all-in-one-for-wp

Installations
20,000+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
4.7

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 4.7.

WP Customer Area

Plugin Slug:
customer-area

Installations
10,000+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
8.2.5

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 8.2.5.

Membership Plugin � Restrict Content

Plugin Slug:
restrict-content

Installations
10,000+

Vulnerability:
Sensitive Data Exposure

Patched in Version:
3.2.14

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 3.2.14.

WooCommerce Product Table Lite

Plugin Slug:
wc-product-table-lite

Installations
10,000+

Vulnerability:
Remote Code Execution (RCE)

Patched in Version:
3.9.5

Severity Score:
High


The vulnerability has been patched, so you should update to version 3.9.5.

VikBooking Hotel Booking Engine & PMS

Plugin Slug:
vikbooking

Installations
8,000+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
1.7.3

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.7.3.

VikBooking Hotel Booking Engine & PMS

Plugin Slug:
vikbooking

Installations
8,000+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
1.7.3

Severity Score:
High


The vulnerability has been patched, so you should update to version 1.7.3.

JS Help Desk � The Ultimate Help Desk & Support Plugin

Plugin Slug:
js-support-ticket

Installations
6,000+

Vulnerability:
Insecure Direct Object References (IDOR)

Patched in Version:
2.8.9

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.8.9.

Survey Maker

Plugin Slug:
survey-maker

Installations
6,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
5.1.3.6

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 5.1.3.6.

Survey Maker

Plugin Slug:
survey-maker

Installations
6,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
5.1.3.4

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 5.1.3.4.

B Slider- Gutenberg Slider Block for WP

Plugin Slug:
b-slider

Installations
5,000+

Vulnerability:
Broken Access Control

Patched in Version:
1.1.24

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.1.24.

Product Blocks for WooCommerce

Plugin Slug:
product-blocks-for-woocommerce

Installations
5,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.0

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.0.

Custom Product Tabs Lite for WooCommerce

Plugin Slug:
woocommerce-custom-product-tabs-lite

Installations
5,000+

Vulnerability:
PHP Object Injection

Patched in Version:
1.9.1

Severity Score:
High


The vulnerability has been patched, so you should update to version 1.9.1.

All Bootstrap Blocks

Plugin Slug:
all-bootstrap-blocks

Installations
4,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.3.27

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.3.27.
Plugin Slug:
custom-related-posts

Installations
4,000+

Vulnerability:
Broken Access Control

Patched in Version:
1.7.4

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.7.4.

Custom Login Page Styler � Limit Login Attempts � Restrict Content With Login � Redirect After Login � Change Login URL � Sign in , Sign out

Plugin Slug:
login-page-styler

Installations
4,000+

Vulnerability:
Broken Access Control

Patched in Version:
7.1.2

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 7.1.2.

Responsive Blocks � WordPress Gutenberg Blocks

Plugin Slug:
responsive-block-editor-addons

Installations
4,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.0.0

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.0.0.

Responsive Blocks � WordPress Gutenberg Blocks

Plugin Slug:
responsive-block-editor-addons

Installations
4,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.0.0

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.0.0.

aThemes Addons for Elementor

Plugin Slug:
athemes-addons-for-elementor-lite

Installations
3,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.0.9

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.0.9.

aThemes Addons for Elementor

Plugin Slug:
athemes-addons-for-elementor-lite

Installations
3,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.0.13

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.0.13.

Automatically Hierarchic Categories in Menu

Plugin Slug:
automatically-hierarchic-categories-in-menu

Installations
3,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.0.8

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.0.8.

Multiple Page Generator Plugin � MPG

Plugin Slug:
multiple-pages-generator-by-porthas

Installations
3,000+

Vulnerability:
Server Side Request Forgery (SSRF)

Patched in Version:
4.0.6

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 4.0.6.

Eventer

Plugin:

Eventer

Plugin Slug:
eventer

Installations
2,000+

Vulnerability:
SQL Injection

Patched in Version:
3.9.9

Severity Score:
Critical


The vulnerability has been patched, so you should update to version 3.9.9.

Medical Addon for Elementor

Plugin Slug:
medical-addon-for-elementor

Installations
2,000+

Vulnerability:
Insecure Direct Object References (IDOR)

Patched in Version:
1.6.3

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.6.3.

Order Export for WooCommerce

Plugin Slug:
order-export-and-more-for-woocommerce

Installations
2,000+

Vulnerability:
Sensitive Data Exposure

Patched in Version:
3.25

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 3.25.

Plethora Plugins Tabs + Accordions

Plugin Slug:
plethora-tabs-accordions

Installations
2,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.2

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.2.

SendPulse Email Marketing Newsletter

Plugin Slug:
sendpulse-email-marketing-newsletter

Installations
2,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.1.6

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.1.6.

Ai Image Alt Text Generator for WP

Plugin Slug:
ai-image-alt-text-generator-for-wp

Installations
1,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.0.7

Severity Score:
High


The vulnerability has been patched, so you should update to version 1.0.7.

WordPress Contact Forms by Cimatti

Plugin Slug:
contact-forms

Installations
1,000+

Vulnerability:
Broken Access Control

Patched in Version:
1.9.5

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.9.5.

CP Contact Form with PayPal

Plugin Slug:
cp-contact-form-with-paypal

Installations
1,000+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
1.3.53

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.3.53.

Flexmls� IDX Plugin

Plugin Slug:
flexmls-idx

Installations
1,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
3.14.27

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 3.14.27.

GoHero Store Customizer for WooCommerce

Plugin Slug:
personalize-woocommerce-cart-page

Installations
1,000+

Vulnerability:
Broken Access Control

Patched in Version:
4.0

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 4.0.

RapidLoad � Optimize Web Vitals Automatically

Plugin Slug:
unusedcss

Installations
1,000+

Vulnerability:
Broken Access Control

Patched in Version:
2.4.5

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.4.5.

W2S � Migrate WooCommerce to Shopify

Plugin Slug:
w2s-migrate-woo-to-shopify

Installations
1,000+

Vulnerability:
Broken Access Control

Patched in Version:
1.3.0

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.3.0.

iControlWP

Plugin Slug:
worpit-admin-dashboard-plugin

Installations
1,000+

Vulnerability:
PHP Object Injection

Patched in Version:
4.5.0

Severity Score:
Critical


The vulnerability has been patched, so you should update to version 4.5.0.

AI Infographic Maker

Plugin Slug:
infographic-and-list-builder-ilist

Installations
900+

Vulnerability:
Remote Code Execution (RCE)

Patched in Version:
5.0.0

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 5.0.0.

Include Mastodon Feed

Plugin Slug:
include-mastodon-feed

Installations
800+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.9.10

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.9.10.

WP Sessions Time Monitoring Full Automatic

Plugin Slug:
activitytime

Installations
600+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.1.2

Severity Score:
High


The vulnerability has been patched, so you should update to version 1.1.2.

Product Table For WooCommerce

Plugin Slug:
product-table-for-woocommerce

Installations
600+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.2.4

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.2.4.

Simple:Press Forum

Plugin Slug:
simplepress

Installations
500+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
6.10.12

Severity Score:
High


The vulnerability has been patched, so you should update to version 6.10.12.

WP DataTable

Plugin Slug:
wp-datatable

Installations
500+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
0.2.7

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 0.2.7.

ELEX WordPress HelpDesk & Customer Ticketing System

Plugin Slug:
elex-helpdesk-customer-support-ticket-system

Installations
400+

Vulnerability:
Broken Access Control

Patched in Version:
3.2.7

Severity Score:
High


The vulnerability has been patched, so you should update to version 3.2.7.

Hesabfa Accounting

Plugin Slug:
hesabfa-accounting

Installations
400+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.1.3

Severity Score:
High


The vulnerability has been patched, so you should update to version 2.1.3.

SeatReg

Plugin:

SeatReg

Plugin Slug:
seatreg

Installations
400+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.56.1

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.56.1.

Site Search 360

Plugin Slug:
site-search-360

Installations
400+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.1.7

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.1.7.

Uix Shortcodes

Plugin Slug:
uix-shortcodes

Installations
400+

Vulnerability:
Broken Access Control

Patched in Version:
2.0.4

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.0.4.

Disable Elementor Editor Translation

Plugin Slug:
disable-elementor-editor-translation

Installations
300+

Vulnerability:
Broken Access Control

Patched in Version:
1.0.3

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.0.3.

OPSI Israel Domestic Shipments

Plugin Slug:
woo-ups-pickup

Installations
300+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.6.6

Severity Score:
High


The vulnerability has been patched, so you should update to version 2.6.6.

Alex Reservations: Smart Restaurant Booking

Plugin Slug:
alex-reservations

Installations
200+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.0.6

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.0.6.

Listings for Appfolio

Plugin Slug:
listings-for-appfolio

Installations
200+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
1.2.1

Severity Score:
High


The vulnerability has been patched, so you should update to version 1.2.1.

Tags to Keywords

Plugin Slug:
tags-to-meta-keywords

Installations
200+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
1.0.2

Severity Score:
High


The vulnerability has been patched, so you should update to version 1.0.2.

WP BASE Booking of Appointments, Services and Events

Plugin Slug:
wp-base-booking-of-appointments-services-and-events

Installations
200+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
5.1.0

Severity Score:
High


The vulnerability has been patched, so you should update to version 5.1.0.

Target Video Easy Publish

Plugin Slug:
brid-video-easy-publish

Installations
100+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
3.8.4

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 3.8.4.

Target Video Easy Publish

Plugin Slug:
brid-video-easy-publish

Installations
100+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
3.8.4

Severity Score:
High


The vulnerability has been patched, so you should update to version 3.8.4.

Clinked Client Portal

Plugin Slug:
clinked-client-portal

Installations
100+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.10

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.10.

DigiTimber cPanel Integration

Plugin Slug:
digitimber-cpanel-integration

Installations
100+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
1.4.8

Severity Score:
High


The vulnerability has been patched, so you should update to version 1.4.8.
Plugin Slug:
gallery-for-ultimate-member

Installations
100+

Vulnerability:
Server Side Request Forgery (SSRF)

Patched in Version:
1.1.3

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.1.3.

Media Downloader

Plugin Slug:
media-downloader

Installations
100+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
0.4.7.6

Severity Score:
High


The vulnerability has been patched, so you should update to version 0.4.7.6.

Morkva UA Shipping

Plugin Slug:
morkva-ua-shipping

Installations
100+

Vulnerability:
Local File Inclusion

Patched in Version:
1.0.20

Severity Score:
High


The vulnerability has been patched, so you should update to version 1.0.20.

Content Cloner

Plugin Slug:
super-seo-content-cloner

Installations
100+

Vulnerability:
Broken Access Control

Patched in Version:
1.0.2

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.0.2.

Unlimited Page Sidebars

Plugin Slug:
unlimited-page-sidebars

Installations
100+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
0.2.7

Severity Score:
High


The vulnerability has been patched, so you should update to version 0.2.7.

WP Post List Table

Plugin Slug:
wp-post-list-table

Installations
100+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.0.4

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.0.4.

Table Editor

Plugin Slug:
wp-table-editor

Installations
100+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.6.0

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.6.0.

Dynamic URL SEO

Plugin Slug:
dynamic-url-seo

Installations
80+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.2

Severity Score:
High


The vulnerability has been patched, so you should update to version 1.2.

Dynamic URL SEO

Plugin Slug:
dynamic-url-seo

Installations
80+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
1.2

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.2.

EthereumICO

Plugin Slug:
ethereumico

Installations
80+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.4.7

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.4.7.

MailUp Auto Subscription

Plugin Slug:
mailup-auto-subscribtion

Installations
80+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.2.0

Severity Score:
High


The vulnerability has been patched, so you should update to version 1.2.0.

WPBookit

Plugin:

WPBookit

Plugin Slug:
wpbookit

Installations
80+

Vulnerability:
Arbitrary File Upload

Patched in Version:
1.6.10

Severity Score:
Critical


The vulnerability has been patched, so you should update to version 1.6.10.

Infility Global

Plugin Slug:
infility-global

Installations
70+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.9.9

Severity Score:
High


The vulnerability has been patched, so you should update to version 2.9.9.

Philantro � Donations and Donor Management

Plugin Slug:
philantro

Installations
70+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
5.4

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 5.4.

Bilingual Linker

Plugin Slug:
bilingual-linker

Installations
60+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.4.1

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.4.1.

Ticketmeo � Sell Tickets � Event Ticketing

Plugin Slug:
ploxel

Installations
60+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.4.0

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.4.0.

ShopSite

Plugin:

ShopSite

Plugin Slug:
shopsite-plugin

Installations
60+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.5.11

Severity Score:
High


The vulnerability has been patched, so you should update to version 1.5.11.

eHive Objects Image Grid

Plugin Slug:
ehive-objects-image-grid

Installations
50+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.4.2

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.4.2.

Awesome Event Booking

Plugin Slug:
awesome-event-booking

Installations
40+

Vulnerability:
Broken Access Control

Patched in Version:
2.7.5

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.7.5.

Awesome Event Booking

Plugin Slug:
awesome-event-booking

Installations
40+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
2.8.0

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.8.0.

Boom Fest

Plugin Slug:
boom-fest

Installations
40+

Vulnerability:
Broken Access Control

Patched in Version:
2.2.2

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.2.2.

Admin and Site Enhancements (ASE) Pro

Plugin:

Admin and Site Enhancements (ASE) Pro

Plugin Slug:
admin-site-enhancements-pro

Vulnerability:
Privilege Escalation

Patched in Version:
7.6.3

Severity Score:
High


The vulnerability has been patched, so you should update to version 7.6.3.

BoomBox Theme Extensions

Plugin:

BoomBox Theme Extensions

Plugin Slug:
boombox-theme-extensions

Vulnerability:
Local File Inclusion

Patched in Version:
1.8.1

Severity Score:
High


The vulnerability has been patched, so you should update to version 1.8.1.

Elementor Pro

Plugin:

Elementor Pro

Plugin Slug:
elementor-pro

Vulnerability:
Sensitive Data Exposure

Patched in Version:
3.25.11

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 3.25.11.

ElementsKit Pro

Plugin:

ElementsKit Pro

Plugin Slug:
elementskit

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
3.7.9

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 3.7.9.

Goodlayers Core

Plugin:

Goodlayers Core

Plugin Slug:
goodlayers-core

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.1.3

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.1.3.

Oshine Modules

Plugin:

Oshine Modules

Plugin Slug:
oshine-modules

Vulnerability:
Server Side Request Forgery (SSRF)

Patched in Version:
3.3.8

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 3.3.8.

Tourmaster

Plugin:

Tourmaster

Plugin Slug:
tourmaster

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
5.3.5

Severity Score:
High


The vulnerability has been patched, so you should update to version 5.3.5.

ThemeREX Addons

Plugin:

ThemeREX Addons

Plugin Slug:
trx_addons

Vulnerability:
Arbitrary File Upload

Patched in Version:
2.34.0

Severity Score:
Critical


The vulnerability has been patched, so you should update to version 2.34.0.

ThemeREX Addons

Plugin:

ThemeREX Addons

Plugin Slug:
trx_addons

Vulnerability:
Local File Inclusion

Patched in Version:
2.34.0

Severity Score:
High


The vulnerability has been patched, so you should update to version 2.34.0.

WooCommerce Customers Manager

Plugin:

WooCommerce Customers Manager

Plugin Slug:
woocommerce-customers-manager

Vulnerability:
Broken Access Control

Patched in Version:
31.4

Severity Score:
High


The vulnerability has been patched, so you should update to version 31.4.

MultiLoca – WooCommerce Multi Locations Inventory Management

Plugin:

MultiLoca – WooCommerce Multi Locations Inventory Management

Plugin Slug:
woocommerce-multi-locations-inventory-management

Vulnerability:
SQL Injection

Patched in Version:
4.1.12

Severity Score:
High


The vulnerability has been patched, so you should update to version 4.1.12.

WooCommerce Support Ticket System

Plugin:

WooCommerce Support Ticket System

Plugin Slug:
woocommerce-support-ticket-system

Vulnerability:
Broken Access Control

Patched in Version:
17.9

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 17.9.

WP ALL Export Pro

Plugin:

WP ALL Export Pro

Plugin Slug:
wp-all-export-pro

Vulnerability:
Remote Code Execution (RCE)

Patched in Version:
1.9.2

Severity Score:
Critical


The vulnerability has been patched, so you should update to version 1.9.2.

WP ALL Export Pro

Plugin:

WP ALL Export Pro

Plugin Slug:
wp-all-export-pro

Vulnerability:
Remote Code Execution (RCE)

Patched in Version:
1.9.2

Severity Score:
Critical


The vulnerability has been patched, so you should update to version 1.9.2.

WP All Import Pro

Plugin:

WP All Import Pro

Plugin Slug:
wp-all-import-pro

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
4.9.8

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 4.9.8.

WP All Import Pro

Plugin:

WP All Import Pro

Plugin Slug:
wp-all-import-pro

Vulnerability:
PHP Object Injection

Patched in Version:
4.9.8

Severity Score:
High


The vulnerability has been patched, so you should update to version 4.9.8.

WPJobBoard

Plugin:

WPJobBoard

Plugin Slug:
wpjobboard

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
5.11.1

Severity Score:
High


The vulnerability has been patched, so you should update to version 5.11.1.

WordPress Themes � 2 Patched / 2 Unpatched

OnePress

Theme Slug:
onepress

Downloads
2,352,920

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should switch themes.

Storely

Theme:

Storely

Theme Slug:
storely

Downloads
470,680

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should switch themes.

SocialV

Theme:

SocialV

Theme Slug:
socialv

Vulnerability:
Broken Access Control

Patched in Version:
2.0.16

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.0.16.

Zox News

Theme:

Zox News

Theme Slug:
zox-news

Vulnerability:
Broken Access Control

Patched in Version:
3.17.0

Severity Score:
High


The vulnerability has been patched, so you should update to version 3.17.0.

Related articles

Wait! Get exclusive hosting insights

Subscribe to our newsletter and stay ahead of the competition with expert advice from our hosting pros.

Loading form…