Line illustration showing a black application window on a red gradient background overlaid with a large exclamation point alert icon and three bugs.

WordPress Vulnerability Report � January 14, 2026

In this report, 282 vulnerabilities have been publicly disclosed. Security patches for 120 of these plugins and themes are now available. Please run these updates as soon as possible. If you’re a Solid Security Pro user, the version management tool may have already warned you and updated these plugins, depending on your settings.

Currently, 162 plugin and theme vulnerabilities remain unpatched. If you’re a Solid Security Pro user, those vulnerabilities are already protected by the Solid Security firewall. Virtual patches from Patchstack will be applied when a vulnerability is considered high or medium risk. If no patch is forthcoming from the vendor or the vulnerable software has been marked “closed” and dropped from the official WordPress repositories, you should deactivate it soon and look for alternative solutions.

WordPress Core

WordPress 6.9 “Gene” was released on December 2, 2025, adding Notes for block-level comments, an expanded Command Palette, and the new Abilities API to standardize permissions for future automation. It also includes performance improvements and new blocks and design tools to support faster, more flexible site building.

After any major release, don�t update live sites until you�ve taken backups and tested in a non-production environment.

WordPress Plugins � 106 Patched / 127 Unpatched

Cookies and Content Security Policy

Plugin Slug:
cookies-and-content-security-policy

Installations
10,000+

Vulnerability:
Sensitive Data Exposure

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Responsive Pricing Table

Plugin Slug:
dk-pricr-responsive-pricing-table

Installations
10,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Responsive Pricing Table

Plugin Slug:
dk-pricr-responsive-pricing-table

Installations
10,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Yoco Payments

Plugin Slug:
yoco-payment-gateway

Installations
10,000+

Vulnerability:
Arbitrary File Download

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Campaign Monitor for WordPress

Plugin Slug:
forms-for-campaign-monitor

Installations
3,000+

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Image Slider Slideshow

Plugin Slug:
image-slider-slideshow

Installations
3,000+

Vulnerability:
Insecure Direct Object References (IDOR)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.
Plugin Slug:
nextgen-download-gallery

Installations
3,000+

Vulnerability:
Sensitive Data Exposure

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Speed Kit

Plugin Slug:
baqend

Installations
2,000+

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

BD Courier Order Ratio Checker

Plugin Slug:
bd-courier-order-ratio-checker

Installations
2,000+

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Dashboard Welcome for Beaver Builder

Plugin Slug:
dashboard-welcome-for-beaver-builder

Installations
2,000+

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

GA4WP � Analytics Dashboard for the Website

Plugin Slug:
ga-for-wp

Installations
2,000+

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

IMGspider � ????????

Plugin Slug:
imgspider

Installations
2,000+

Vulnerability:
Server Side Request Forgery (SSRF)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

teachPress

Plugin Slug:
teachpress

Installations
2,000+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

X Addons for Elementor

Plugin Slug:
x-addons-elementor

Installations
700+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.
Plugin Slug:
regallery

Installations
400+

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

HBLPAY Payment Gateway for WooCommerce

Plugin Slug:
hblpay-payment-gateway-for-woocommerce

Installations
300+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Page Keys

Plugin Slug:
page-keys

Installations
80+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Money Space

Plugin Slug:
money-space

Installations
70+

Vulnerability:
Sensitive Data Exposure

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

FireStorm Professional Real Estate Plugin

Plugin Slug:
fs-real-estate-plugin

Installations
10+

Vulnerability:
SQL Injection

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

1180px Shortcodes

Plugin:

1180px Shortcodes

Plugin Slug:
1180px-shortcodes

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

WP Virtual Assistant

Plugin:

WP Virtual Assistant

Plugin Slug:
VirtualAssistant

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

WP Attractive Donations System – Easy Stripe & Paypal donations

Plugin:

WP Attractive Donations System – Easy Stripe & Paypal donations

Plugin Slug:
WP_AttractiveDonationsSystem

Vulnerability:
Arbitrary Content Deletion

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

AA Block country

Plugin:

AA Block country

Plugin Slug:
aa-block-country

Vulnerability:
Bypass Vulnerability

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Accordion Slider PRO

Plugin:

Accordion Slider PRO

Plugin Slug:
accordion_slider_pro

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

ACF to REST API

Plugin:

ACF to REST API

Plugin Slug:
acf-to-rest-api

Vulnerability:
Insecure Direct Object References (IDOR)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

AD Sliding FAQ

Plugin:

AD Sliding FAQ

Plugin Slug:
ad-sliding-faq

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

AH Shortcodes

Plugin:

AH Shortcodes

Plugin Slug:
ah-shortcodes

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

AS Password Field In Default Registration Form

Plugin:

AS Password Field In Default Registration Form

Plugin Slug:
as-password-field-in-default-registration-form

Vulnerability:
Privilege Escalation

Patched in Version:
No Fix

Severity Score:
Critical


The vulnerability has not been patched. You should deactivate the plugin.

Autogen Headers Menu

Plugin:

Autogen Headers Menu

Plugin Slug:
autogen-headers-menu

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Awesome Hotel Booking

Plugin Slug:
awesome-hotel-booking

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.
Plugin:

WP Page Permalink Extension

Plugin Slug:
change-wp-page-permalinks

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Contact Form vCard Generator

Plugin:

Contact Form vCard Generator

Plugin Slug:
contact-form-vcard-generator

Vulnerability:
Sensitive Data Exposure

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Contact Us Simple Form

Plugin:

Contact Us Simple Form

Plugin Slug:
contact-us-simple-form

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Cool YT Player

Plugin:

Cool YT Player

Plugin Slug:
cool-yt-player

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

CountDown With Image or Video Background

Plugin:

CountDown With Image or Video Background

Plugin Slug:
countdown-with-background

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Curved Text

Plugin:

Curved Text

Plugin Slug:
curved-text

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Debt.com Business in a Box

Plugin:

Debt.com Business in a Box

Plugin Slug:
debtcom-business-in-a-box

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.
Plugin:

DZS Video Gallery

Plugin Slug:
dzs-videogallery

Vulnerability:
SQL Injection

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Easy GitHub Gist Shortcodes

Plugin:

Easy GitHub Gist Shortcodes

Plugin Slug:
easy-github-gist-shortcodes

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

EDD Download Info

Plugin:

EDD Download Info

Plugin Slug:
edd-download-info

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Email Customizer for WooCommerce

Plugin:

Email Customizer for WooCommerce

Plugin Slug:
email-customizer-for-woocommerce

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Entry Views

Plugin:

Entry Views

Plugin Slug:
entry-views

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.
Plugin:

Famous – Responsive Image And Video Grid Gallery WordPress Plugin

Plugin Slug:
famous_grid_image_and_video_gallery

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Felan Framework

Plugin:

Felan Framework

Plugin Slug:
felan-framework

Vulnerability:
SQL Injection

Patched in Version:
No Fix

Severity Score:
Critical


The vulnerability has not been patched. You should deactivate the plugin.

Felan Framework

Plugin:

Felan Framework

Plugin Slug:
felan-framework

Vulnerability:
Broken Authentication

Patched in Version:
No Fix

Severity Score:
Critical


The vulnerability has not been patched. You should deactivate the plugin.

Flashcard

Plugin:

Flashcard

Plugin Slug:
flashcard

Vulnerability:
Arbitrary File Download

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

ShareThis Dashboard for Google Analytics

Plugin:

ShareThis Dashboard for Google Analytics

Plugin Slug:
googleanalytics

Vulnerability:
Sensitive Data Exposure

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Handmade Framework

Plugin:

Handmade Framework

Plugin Slug:
handmade-framework

Vulnerability:
Local File Inclusion

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.
Plugin:

Header and Footer Scripts

Plugin Slug:
header-and-footer-scripts

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

HelpDesk contact form

Plugin:

HelpDesk contact form

Plugin Slug:
helpdesk-contact-form

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

JNews – Frontend Submit

Plugin:

JNews – Frontend Submit

Plugin Slug:
jnews-frontend-submit

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Latest Tabs

Plugin:

Latest Tabs

Plugin Slug:
kento-latest-tabs

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Key Figures

Plugin:

Key Figures

Plugin Slug:
key-figures

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Latest Registered Users

Plugin:

Latest Registered Users

Plugin Slug:
latest-registered-users

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

HTML5 Video Player

Plugin:

HTML5 Video Player

Plugin Slug:
lbg-vp2-html5-bottom

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

HTML5 Video Player with Playlist & Multiple Skins

Plugin:

HTML5 Video Player with Playlist & Multiple Skins

Plugin Slug:
lbg-vp2-html5-rightside

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Image&Video FullScreen Background

Plugin:

Image&Video FullScreen Background

Plugin Slug:
lbg_fullscreen_fullwidth_slider

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Lesson Plan Book

Plugin:

Lesson Plan Book

Plugin Slug:
lesson-plan-book

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

ListingHub

Plugin:

ListingHub

Plugin Slug:
listinghub

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.
Plugin:

Magic Responsive Slider and Carousel WordPress

Plugin Slug:
magic_carousel

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Magic Slider

Plugin:

Magic Slider

Plugin Slug:
magic_slider

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Mamurjor Employee Info

Plugin:

Mamurjor Employee Info

Plugin Slug:
mamurjor-employee-info

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Menu Card

Plugin:

Menu Card

Plugin Slug:
menu-card

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

MG AdvancedOptions

Plugin:

MG AdvancedOptions

Plugin Slug:
mg-advancedoptions

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Moosend Landing Pages

Plugin:

Moosend Landing Pages

Plugin Slug:
moosend-landing-pages

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Mstoic Shortcodes

Plugin:

Mstoic Shortcodes

Plugin Slug:
mstoic-shortcodes

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

MTCaptcha

Plugin:

MTCaptcha

Plugin Slug:
mtcaptcha

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Multi-column Tag Map

Plugin:

Multi-column Tag Map

Plugin Slug:
multi-column-tag-map

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.
Plugin:

My Album Gallery

Plugin Slug:
my-album-gallery

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.
Plugin:

My Album Gallery

Plugin Slug:
my-album-gallery

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Nearby Now Reviews

Plugin:

Nearby Now Reviews

Plugin Slug:
nearby-now-reviews

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Newsletter Email Subscribe

Plugin:

Newsletter Email Subscribe

Plugin Slug:
newsletter-email-subscribe

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Niche Hero

Plugin:

Niche Hero

Plugin Slug:
niche-hero

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

nK Themes Helper

Plugin:

nK Themes Helper

Plugin Slug:
nk-themes-helper

Vulnerability:
Server Side Request Forgery (SSRF)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

NS Ie Compatibility Fixer

Plugin:

NS Ie Compatibility Fixer

Plugin Slug:
ns-ie-compatibility-fixer

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Optional Email

Plugin:

Optional Email

Plugin Slug:
optional-email

Vulnerability:
Privilege Escalation

Patched in Version:
No Fix

Severity Score:
Critical


The vulnerability has not been patched. You should deactivate the plugin.

PhotoFade

Plugin:

PhotoFade

Plugin Slug:
photofade

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Post Like Dislike

Plugin:

Post Like Dislike

Plugin Slug:
post-like-dislike

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

PullQuote

Plugin:

PullQuote

Plugin Slug:
pullquote

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Pure WC Variation Swatches

Plugin:

Pure WC Variation Swatches

Plugin Slug:
pure-wc-variations-swatches

Vulnerability:
Settings Change

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

QR Code Tag for WC

Plugin:

QR Code Tag for WC

Plugin Slug:
qr-code-tag-for-wc-from-goaskle-com

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Quote Comments

Plugin:

Quote Comments

Plugin Slug:
quote-comments

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Rankology SEO and Analytics Tool

Plugin:

Rankology SEO and Analytics Tool

Plugin Slug:
rankology-seo-and-analytics-tool

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
Low


The vulnerability has not been patched. You should deactivate the plugin.

Real Estate Pro

Plugin:

Real Estate Pro

Plugin Slug:
real-estate-pro

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

REHub Framework

Plugin:

REHub Framework

Plugin Slug:
rehub-framework

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Shabat Keeper

Plugin:

Shabat Keeper

Plugin Slug:
shabat-keeper

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Simcast

Plugin:

Simcast

Plugin Slug:
simcast

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Simple User Meta Editor

Plugin:

Simple User Meta Editor

Plugin Slug:
simple-user-meta-editor

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Smart App Banners

Plugin:

Smart App Banners

Plugin Slug:
smart-app-banners

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Snillrik Restaurant

Plugin:

Snillrik Restaurant

Plugin Slug:
snillrik-restaurant-menu

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Starred Review

Plugin:

Starred Review

Plugin Slug:
starred-review

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Sticky Action Buttons

Plugin:

Sticky Action Buttons

Plugin Slug:
sticky-action-buttons

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.
Plugin:

STM Gallery 1.9

Plugin Slug:
stm-gallery

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Stumble! for WordPress

Plugin:

Stumble! for WordPress

Plugin Slug:
stumble-for-wordpress

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Stylish Order Form Builder

Plugin:

Stylish Order Form Builder

Plugin Slug:
stylish-order-form-builder

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Super Interactive Maps

Plugin:

Super Interactive Maps

Plugin Slug:
super-interactive-maps

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

SVG Map Plugin

Plugin:

SVG Map Plugin

Plugin Slug:
svg-map-by-saedi

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Testimonial Master

Plugin:

Testimonial Master

Plugin Slug:
testimonial-master

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

The Tooltip

Plugin:

The Tooltip

Plugin Slug:
the-tooltip

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Top Position Google Finance

Plugin:

Top Position Google Finance

Plugin Slug:
top-position-google-finance

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

xPromoter

Plugin:

xPromoter

Plugin Slug:
top_bar_promoter

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

twinklesmtp

Plugin:

twinklesmtp

Plugin Slug:
twinklesmtp

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Unify

Plugin:

Unify

Plugin Slug:
unify

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

User Activity Log

Plugin:

User Activity Log

Plugin Slug:
user-activity-log

Vulnerability:
Settings Change

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Viitor Button Shortcodes

Plugin:

Viitor Button Shortcodes

Plugin Slug:
viitor-shortcodes

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Wish To Go

Plugin:

Wish To Go

Plugin Slug:
wish-to-go

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Premmerce WooCommerce Customers Manager

Plugin:

Premmerce WooCommerce Customers Manager

Plugin Slug:
woo-customers-manager

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Piraeus Bank WooCommerce Payment Gateway

Plugin:

Piraeus Bank WooCommerce Payment Gateway

Plugin Slug:
woo-payment-gateway-for-piraeus-bank

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

WooCommerce Orders & Customers Exporter

Plugin:

WooCommerce Orders & Customers Exporter

Plugin Slug:
woocommerce-orders-ei

Vulnerability:
SQL Injection

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Woodpecker for WordPress

Plugin:

Woodpecker for WordPress

Plugin Slug:
woodpecker

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Workreap (theme’s plugin)

Plugin:

Workreap (theme’s plugin)

Plugin Slug:
workreap

Vulnerability:
SQL Injection

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

WP Status Notifier

Plugin:

WP Status Notifier

Plugin Slug:
wp-change-status-notifier

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Client Testimonial Slider

Plugin:

Client Testimonial Slider

Plugin Slug:
wp-client-testimonial

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

WP Enable WebP

Plugin:

WP Enable WebP

Plugin Slug:
wp-enable-webp

Vulnerability:
Arbitrary File Upload

Patched in Version:
No Fix

Severity Score:
Critical


The vulnerability has not been patched. You should deactivate the plugin.

WP Js List Pages Shortcodes

Plugin:

WP Js List Pages Shortcodes

Plugin Slug:
wp-js-list-pages-shortcodes

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

WP Lead Capturing Pages

Plugin:

WP Lead Capturing Pages

Plugin Slug:
wp-lead-capture

Vulnerability:
SQL Injection

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

WP Lead Capturing Pages

Plugin:

WP Lead Capturing Pages

Plugin Slug:
wp-lead-capture

Vulnerability:
SQL Injection

Patched in Version:
No Fix

Severity Score:
Critical


The vulnerability has not been patched. You should deactivate the plugin.

WP Recipe Manager

Plugin:

WP Recipe Manager

Plugin Slug:
wp-recipe-manager

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

WP Widget Changer

Plugin:

WP Widget Changer

Plugin Slug:
wp-widget-changer

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

WP Popup Magic

Plugin:

WP Popup Magic

Plugin Slug:
wppopupmagic

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

xShare

Plugin:

xShare

Plugin Slug:
xshare

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

The Events Calendar

Plugin Slug:
the-events-calendar

Installations
700,000+

Vulnerability:
Broken Access Control

Patched in Version:
6.15.13

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 6.15.13.

Download Manager

Plugin Slug:
download-manager

Installations
100,000+

Vulnerability:
Privilege Escalation

Patched in Version:
3.3.41

Severity Score:
High


The vulnerability has been patched, so you should update to version 3.3.41.

AMP for WP � Accelerated Mobile Pages

Plugin Slug:
accelerated-mobile-pages

Installations
90,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.1.11

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.1.11.

AMP for WP � Accelerated Mobile Pages

Plugin Slug:
accelerated-mobile-pages

Installations
90,000+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
1.1.10

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.1.10.

Depicter � Popup & Slider Builder

Plugin Slug:
depicter

Installations
90,000+

Vulnerability:
Broken Access Control

Patched in Version:
4.7.0

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 4.7.0.

Depicter � Popup & Slider Builder

Plugin Slug:
depicter

Installations
90,000+

Vulnerability:
Broken Access Control

Patched in Version:
4.0.5

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 4.0.5.

Customer Reviews for WooCommerce

Plugin Slug:
customer-reviews-woocommerce

Installations
80,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
5.94.0

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 5.94.0.

Jupiter X Core

Plugin Slug:
jupiterx-core

Installations
80,000+

Vulnerability:
PHP Object Injection

Patched in Version:
4.11.0

Severity Score:
High


The vulnerability has been patched, so you should update to version 4.11.0.

LearnPress � WordPress LMS Plugin

Plugin Slug:
learnpress

Installations
80,000+

Vulnerability:
Insecure Direct Object References (IDOR)

Patched in Version:
4.3.2.2

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 4.3.2.2.

LearnPress � WordPress LMS Plugin

Plugin Slug:
learnpress

Installations
80,000+

Vulnerability:
Broken Access Control

Patched in Version:
4.3.2.1

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 4.3.2.1.

Ninja Tables � Easy Data Table Builder

Plugin Slug:
ninja-tables

Installations
80,000+

Vulnerability:
SQL Injection

Patched in Version:
5.2.5

Severity Score:
High


The vulnerability has been patched, so you should update to version 5.2.5.

WooCommerce Square

Plugin Slug:
woocommerce-square

Installations
80,000+

Vulnerability:
Insecure Direct Object References (IDOR)

Patched in Version:
5.1.2

Severity Score:
High


The vulnerability has been patched, so you should update to version 5.1.2.

SlimStat Analytics

Plugin Slug:
wp-slimstat

Installations
80,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
5.3.4

Severity Score:
High


The vulnerability has been patched, so you should update to version 5.3.4.

SlimStat Analytics

Plugin Slug:
wp-slimstat

Installations
80,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
5.3.5

Severity Score:
High


The vulnerability has been patched, so you should update to version 5.3.5.

Drag and Drop Multiple File Upload for Contact Form 7

Plugin Slug:
drag-and-drop-multiple-file-upload-contact-form-7

Installations
60,000+

Vulnerability:
Arbitrary File Upload

Patched in Version:
1.3.9.3

Severity Score:
Critical


The vulnerability has been patched, so you should update to version 1.3.9.3.

User Registration & Membership � Custom Registration Form Builder, Custom Login Form, User Profile, Content Restriction & Membership Plugin

Plugin Slug:
user-registration

Installations
60,000+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
4.4.9

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 4.4.9.

Table Field Add-on for ACF and SCF

Plugin Slug:
advanced-custom-fields-table-field

Installations
50,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.3.31

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.3.31.

Blog2Social: Social Media Auto Post & Scheduler

Plugin Slug:
blog2social

Installations
50,000+

Vulnerability:
Sensitive Data Exposure

Patched in Version:
8.7.3

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 8.7.3.

Booking Calendar

Plugin Slug:
booking

Installations
50,000+

Vulnerability:
Sensitive Data Exposure

Patched in Version:
10.14.11

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 10.14.11.

EmailKit � Email Customizer for WooCommerce & WP

Plugin Slug:
emailkit

Installations
50,000+

Vulnerability:
Arbitrary File Download

Patched in Version:
1.6.2

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.6.2.

WP-Members Membership Plugin

Plugin Slug:
wp-members

Installations
50,000+

Vulnerability:
Sensitive Data Exposure

Patched in Version:
3.5.4.5

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 3.5.4.5.

WP Table Builder � Drag & Drop Table Builder

Plugin Slug:
wp-table-builder

Installations
50,000+

Vulnerability:
Broken Access Control

Patched in Version:
2.0.20

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.0.20.

BulletProof Security

Plugin Slug:
bulletproof-security

Installations
30,000+

Vulnerability:
Sensitive Data Exposure

Patched in Version:
7.0

Severity Score:
High


The vulnerability has been patched, so you should update to version 7.0.
Plugin Slug:
link-whisper

Installations
30,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
0.8.9

Severity Score:
High


The vulnerability has been patched, so you should update to version 0.8.9.

Docket Cache � Object Cache Accelerator

Plugin Slug:
docket-cache

Installations
20,000+

Vulnerability:
Broken Access Control

Patched in Version:
24.07.05

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 24.07.05.

Quiz Maker

Plugin Slug:
quiz-maker

Installations
20,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
6.7.0.89

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 6.7.0.89.

Brevo for WooCommerce

Plugin Slug:
woocommerce-sendinblue-newsletter-subscription

Installations
20,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
4.0.50

Severity Score:
High


The vulnerability has been patched, so you should update to version 4.0.50.

Frontend Admin by DynamiApps

Plugin Slug:
acf-frontend-form-element

Installations
10,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
3.28.24

Severity Score:
High


The vulnerability has been patched, so you should update to version 3.28.24.

Frontend Admin by DynamiApps

Plugin Slug:
acf-frontend-form-element

Installations
10,000+

Vulnerability:
Broken Access Control

Patched in Version:
3.28.26

Severity Score:
Critical


The vulnerability has been patched, so you should update to version 3.28.26.

Frontend Admin by DynamiApps

Plugin Slug:
acf-frontend-form-element

Installations
10,000+

Vulnerability:
Privilege Escalation

Patched in Version:
3.28.26

Severity Score:
Critical


The vulnerability has been patched, so you should update to version 3.28.26.

AffiliateX � Amazon Affiliate Plugin

Plugin Slug:
affiliatex

Installations
10,000+

Vulnerability:
Broken Access Control

Patched in Version:
1.4.0

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.4.0.

Demo Importer Plus

Plugin Slug:
demo-importer-plus

Installations
10,000+

Vulnerability:
Broken Access Control

Patched in Version:
2.0.9

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.0.9.

Easy Media Download

Plugin Slug:
easy-media-download

Installations
10,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.1.12

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.1.12.

Form Vibes � Database Manager for Forms

Plugin Slug:
form-vibes

Installations
10,000+

Vulnerability:
SQL Injection

Patched in Version:
1.5

Severity Score:
High


The vulnerability has been patched, so you should update to version 1.5.

ShopMagic � email automation

Plugin Slug:
shopmagic-for-woocommerce

Installations
10,000+

Vulnerability:
Broken Access Control

Patched in Version:
4.7.3

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 4.7.3.

Team � Team Members Showcase Plugin

Plugin Slug:
tlp-team

Installations
10,000+

Vulnerability:
SQL Injection

Patched in Version:
5.0.11

Severity Score:
Critical


The vulnerability has been patched, so you should update to version 5.0.11.

Japanized for WooCommerce

Plugin Slug:
woocommerce-for-japan

Installations
10,000+

Vulnerability:
Broken Access Control

Patched in Version:
2.8.0

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.8.0.

WP Photo Album Plus

Plugin Slug:
wp-photo-album-plus

Installations
10,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
9.1.05.009

Severity Score:
High


The vulnerability has been patched, so you should update to version 9.1.05.009.

Xagio SEO � AI Powered SEO

Plugin Slug:
xagio-seo

Installations
10,000+

Vulnerability:
Server Side Request Forgery (SSRF)

Patched in Version:
7.1.0.31

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 7.1.0.31.

NEX-Forms � Ultimate Forms Plugin for WordPress

Plugin Slug:
nex-forms-express-wp-form-builder

Installations
8,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
9.1.8

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 9.1.8.

MediaPress

Plugin Slug:
mediapress

Installations
5,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.6.3

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.6.3.

BuddyPress Xprofile Custom Field Types

Plugin Slug:
bp-xprofile-custom-field-types

Installations
4,000+

Vulnerability:
Arbitrary File Deletion

Patched in Version:
1.3.0

Severity Score:
High


The vulnerability has been patched, so you should update to version 1.3.0.

FlexTable � Data Table Sync with Google Sheets

Plugin Slug:
sheets-to-wp-table-live-sync

Installations
4,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
3.19.2

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 3.19.2.

The Events Calendar Countdown Addon

Plugin Slug:
countdown-for-the-events-calendar

Installations
3,000+

Vulnerability:
Broken Access Control

Patched in Version:
1.4.16

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.4.16.

Bulk Page Generator � LPagery

Plugin Slug:
lpagery

Installations
3,000+

Vulnerability:
Broken Access Control

Patched in Version:
2.4.10

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.4.10.

Spiffy Calendar

Plugin Slug:
spiffy-calendar

Installations
3,000+

Vulnerability:
Broken Access Control

Patched in Version:
5.0.8

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 5.0.8.

Tickera � Sell Tickets & Manage Events

Plugin Slug:
tickera-event-ticketing-system

Installations
3,000+

Vulnerability:
Broken Access Control

Patched in Version:
3.5.6.5

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 3.5.6.5.

RSS Feed Widget

Plugin Slug:
rss-feed-widget

Installations
2,000+

Vulnerability:
Broken Access Control

Patched in Version:
3.0.3

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 3.0.3.

CBX Bookmark & Favorite

Plugin Slug:
cbxwpbookmark

Installations
1,000+

Vulnerability:
SQL Injection

Patched in Version:
2.0.5

Severity Score:
High


The vulnerability has been patched, so you should update to version 2.0.5.

Proxy & VPN Blocker

Plugin Slug:
proxy-vpn-blocker

Installations
1,000+

Vulnerability:
Broken Access Control

Patched in Version:
3.5.4

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 3.5.4.

ForumWP � Forum & Discussion Board

Plugin Slug:
forumwp

Installations
900+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.1.7

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.1.7.

IndieWeb

Plugin:

IndieWeb

Plugin Slug:
indieweb

Installations
600+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
5.0.0

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 5.0.0.

Recras

Plugin:

Recras

Plugin Slug:
recras

Installations
300+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
6.4.2

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 6.4.2.

URL Image Importer

Plugin Slug:
url-image-importer

Installations
300+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.0.8

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.0.8.

ilGhera Support System for WooCommerce

Plugin Slug:
wc-support-system

Installations
100+

Vulnerability:
Broken Access Control

Patched in Version:
1.2.7

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.2.7.
Plugin Slug:
ehive-search

Installations
50+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.5.1

Severity Score:
High


The vulnerability has been patched, so you should update to version 2.5.1.

FS Registration Password

Plugin Slug:
registration-password

Installations
40+

Vulnerability:
Privilege Escalation

Patched in Version:
2.0.1

Severity Score:
Critical


The vulnerability has been patched, so you should update to version 2.0.1.

iPaymu Payment Gateway for WooCommerce

Plugin Slug:
ipaymu-for-woocommerce

Installations
10+

Vulnerability:
Sensitive Data Exposure

Patched in Version:
2.0.3

Severity Score:
High


The vulnerability has been patched, so you should update to version 2.0.3.

Page Expire Popup/Redirection for WordPress

Plugin Slug:
page-expire-popup

Installations
10+

Vulnerability:
SQL Injection

Patched in Version:
1.1

Severity Score:
High


The vulnerability has been patched, so you should update to version 1.1.

Automotive Listings

Plugin:

Automotive Listings

Plugin Slug:
automotive

Vulnerability:
SQL Injection

Patched in Version:
18.7

Severity Score:
Critical


The vulnerability has been patched, so you should update to version 18.7.

JetEngine

Plugin:

JetEngine

Plugin Slug:
jet-engine

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
3.7.8

Severity Score:
High


The vulnerability has been patched, so you should update to version 3.7.8.

Listeo Core

Plugin:

Listeo Core

Plugin Slug:
listeo-core

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.0.19

Severity Score:
High


The vulnerability has been patched, so you should update to version 2.0.19.

TheGem Theme Elements (for WPBakery)

Plugin:

TheGem Theme Elements (for WPBakery)

Plugin Slug:
thegem-elements

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
5.11.1

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 5.11.1.

TheGem Theme Elements (for Elementor)

Plugin:

TheGem Theme Elements (for Elementor)

Plugin Slug:
thegem-elements-elementor

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
5.11.1

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 5.11.1.

TheGem Theme Elements (for Elementor)

Plugin:

TheGem Theme Elements (for Elementor)

Plugin Slug:
thegem-elements-elementor

Vulnerability:
Local File Inclusion

Patched in Version:
5.11.1

Severity Score:
High


The vulnerability has been patched, so you should update to version 5.11.1.

Woffice Core

Plugin:

Woffice Core

Plugin Slug:
woffice-core

Vulnerability:
Insecure Direct Object References (IDOR)

Patched in Version:
5.4.31

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 5.4.31.

WordPress Themes � 14 Patched / 35 Unpatched

AeroLand

Theme:

AeroLand

Theme Slug:
aeroland

Vulnerability:
Local File Inclusion

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should switch themes.

Amuli

Theme:

Amuli

Theme Slug:
amuli

Vulnerability:
Local File Inclusion

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should switch themes.

Anarkali

Theme:

Anarkali

Theme Slug:
anarkali

Vulnerability:
Local File Inclusion

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should switch themes.

Athens

Theme:

Athens

Theme Slug:
athens

Vulnerability:
Local File Inclusion

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should switch themes.

Atlas

Theme:

Atlas

Theme Slug:
atlas

Vulnerability:
Local File Inclusion

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should switch themes.

AutoParts

Theme:

AutoParts

Theme Slug:
autoparts

Vulnerability:
Local File Inclusion

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should switch themes.

Barberry

Theme:

Barberry

Theme Slug:
barberry

Vulnerability:
Local File Inclusion

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should switch themes.

Brook

Theme:

Brook

Theme Slug:
brook

Vulnerability:
Local File Inclusion

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should switch themes.

Consult Aid

Theme:

Consult Aid

Theme Slug:
consultaid

Vulnerability:
PHP Object Injection

Patched in Version:
No Fix

Severity Score:
Critical


The vulnerability has not been patched. You should switch themes.

DeepDigital

Theme:

DeepDigital

Theme Slug:
deepdigital

Vulnerability:
Content Injection

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should switch themes.

Depot

Theme:

Depot

Theme Slug:
depot

Vulnerability:
Local File Inclusion

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should switch themes.

Drone

Theme:

Drone

Theme Slug:
drone

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should switch themes.

Electron

Theme:

Electron

Theme Slug:
electron

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should switch themes.

Energia

Theme:

Energia

Theme Slug:
energia

Vulnerability:
Arbitrary File Upload

Patched in Version:
No Fix

Severity Score:
Critical


The vulnerability has not been patched. You should switch themes.

Melania

Theme:

Melania

Theme Slug:
melania

Vulnerability:
Local File Inclusion

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should switch themes.

Mella

Theme:

Mella

Theme Slug:
mella

Vulnerability:
Local File Inclusion

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should switch themes.

Mitech

Theme:

Mitech

Theme Slug:
mitech

Vulnerability:
Local File Inclusion

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should switch themes.

Myour

Theme:

Myour

Theme Slug:
myour

Vulnerability:
Local File Inclusion

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should switch themes.

Navian

Theme:

Navian

Theme Slug:
navian

Vulnerability:
Local File Inclusion

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should switch themes.

OchaHouse

Theme:

OchaHouse

Theme Slug:
ochahouse

Vulnerability:
Local File Inclusion

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should switch themes.

Oshine

Theme:

Oshine

Theme Slug:
oshin

Vulnerability:
Local File Inclusion

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should switch themes.

Promo

Theme:

Promo

Theme Slug:
promo

Vulnerability:
Local File Inclusion

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should switch themes.

Racquet

Theme:

Racquet

Theme Slug:
racquet

Vulnerability:
Local File Inclusion

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should switch themes.

Reprizo

Theme:

Reprizo

Theme Slug:
reprizo

Vulnerability:
Local File Inclusion

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should switch themes.

Right Way

Theme:

Right Way

Theme Slug:
rightway

Vulnerability:
Local File Inclusion

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should switch themes.

Rozy – Flower Shop

Theme:

Rozy – Flower Shop

Theme Slug:
rozy

Vulnerability:
Local File Inclusion

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should switch themes.

Search & Go

Theme:

Search & Go

Theme Slug:
search-and-go

Vulnerability:
Local File Inclusion

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should switch themes.

TheNa

Theme:

TheNa

Theme Slug:
thena

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should switch themes.

Moody

Theme:

Moody

Theme Slug:
tm-moody

Vulnerability:
Local File Inclusion

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should switch themes.

Typify

Theme:

Typify

Theme Slug:
typify

Vulnerability:
Local File Inclusion

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should switch themes.

VideoPro

Theme:

VideoPro

Theme Slug:
videopro

Vulnerability:
Local File Inclusion

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should switch themes.

xSmart

Theme:

xSmart

Theme Slug:
xsmart

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should switch themes.

xSmart

Theme:

xSmart

Theme Slug:
xsmart

Vulnerability:
Privilege Escalation

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should switch themes.

xSmart

Theme:

xSmart

Theme Slug:
xsmart

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should switch themes.

Zorka

Theme:

Zorka

Theme Slug:
zorka

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should switch themes.

Phlox

Theme:

Phlox

Theme Slug:
phlox

Downloads
1,711,142

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.17.11

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.17.11.

Corpkit

Theme:

Corpkit

Theme Slug:
corpkit

Vulnerability:
Local File Inclusion

Patched in Version:
2.0.1

Severity Score:
High


The vulnerability has been patched, so you should update to version 2.0.1.

Corpkit

Theme:

Corpkit

Theme Slug:
corpkit

Vulnerability:
Arbitrary File Upload

Patched in Version:
2.0.1

Severity Score:
Critical


The vulnerability has been patched, so you should update to version 2.0.1.

Curly

Theme:

Curly

Theme Slug:
curly

Vulnerability:
Local File Inclusion

Patched in Version:
3.3

Severity Score:
High


The vulnerability has been patched, so you should update to version 3.3.

Grand Restaurant

Theme:

Grand Restaurant

Theme Slug:
grandrestaurant

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
7.0.9

Severity Score:
High


The vulnerability has been patched, so you should update to version 7.0.9.

Hendon

Theme:

Hendon

Theme Slug:
hendon

Vulnerability:
Local File Inclusion

Patched in Version:
1.7

Severity Score:
High


The vulnerability has been patched, so you should update to version 1.7.

Jobify

Theme:

Jobify

Theme Slug:
jobify

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
4.3.1

Severity Score:
High


The vulnerability has been patched, so you should update to version 4.3.1.

Lobo

Theme:

Lobo

Theme Slug:
lobo

Vulnerability:
SQL Injection

Patched in Version:
2.8.6

Severity Score:
High


The vulnerability has been patched, so you should update to version 2.8.6.

Neo Ocular

Theme:

Neo Ocular

Theme Slug:
neoocular

Vulnerability:
Local File Inclusion

Patched in Version:
1.2

Severity Score:
High


The vulnerability has been patched, so you should update to version 1.2.

Optimize

Theme:

Optimize

Theme Slug:
optimizewp

Vulnerability:
Local File Inclusion

Patched in Version:
2.4

Severity Score:
High


The vulnerability has been patched, so you should update to version 2.4.

Photography

Theme:

Photography

Theme Slug:
photography

Vulnerability:
Local File Inclusion

Patched in Version:
7.7.5

Severity Score:
High


The vulnerability has been patched, so you should update to version 7.7.5.

Traveler

Theme:

Traveler

Theme Slug:
traveler

Vulnerability:
Broken Access Control

Patched in Version:
3.2.7

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 3.2.7.

Wellspring

Theme:

Wellspring

Theme Slug:
wellspring

Vulnerability:
Local File Inclusion

Patched in Version:
2.8

Severity Score:
High


The vulnerability has been patched, so you should update to version 2.8.

Woffice

Theme:

Woffice

Theme Slug:
woffice

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
5.4.31

Severity Score:
High


The vulnerability has been patched, so you should update to version 5.4.31.

Related articles

Wait! Get exclusive hosting insights

Subscribe to our newsletter and stay ahead of the competition with expert advice from our hosting pros.

Loading form…