Line illustration showing a black application window on a dark red gradient background overlaid with a large exclamation point alert icon and three bugs.

WordPress Vulnerability Report � January 22, 2025

In this report, 486 vulnerabilities have been publicly disclosed. Security patches for 93 of these plugins and themes are available now, so run those updates as soon as possible. If you’re a Solid Security Pro user, the version management tool may have already warned you and updated these plugins, depending on your settings.

Additionally, there are 393 plugin and theme vulnerabilities with no patch available yet. If you’re a Solid Security Pro user, those vulnerabilities are already protected by the Solid Security firewall. Virtual patches from Patchstack will be applied when a vulnerability is considered high or medium risk. If no patch is forthcoming from the vendor or the vulnerable software has been marked “closed” and dropped from the official WordPress repositories, you should deactivate it soon and look for alternative solutions.

WordPress Core

WordPress 6.7.1 is available! This minor release features 16 bug fixes throughout Core and the Block Editor.

WordPress Plugins � 90 Patched / 371 Unpatched

CoDesigner � All in One Elementor WooCommerce Builder

Plugin Slug:
woolementor

Installations
9,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Bold pagos en linea

Plugin Slug:
bold-pagos-en-linea

Installations
1,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

GSheetConnector for Forminator Forms

Plugin Slug:
gsheetconnector-forminator

Installations
700+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Post Carousel & Slider

Plugin Slug:
post-types-carousel-slider

Installations
400+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.
Plugin Slug:
woorousell

Installations
400+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

WP Headmaster

Plugin Slug:
wp-headmaster

Installations
200+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Course Booking System

Plugin Slug:
course-booking-system

Installations
100+

Vulnerability:
SQL Injection

Patched in Version:
No Fix

Severity Score:
Critical


The vulnerability has not been patched. You should deactivate the plugin.

Neon Product Designer

Plugin Slug:
neon-product-designer-for-woocommerce

Installations
100+

Vulnerability:
SQL Injection

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Partners

Plugin:

Partners

Plugin Slug:
partners

Installations
100+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Online Payments � Get Paid with PayPal, Square & Stripe

Plugin Slug:
paypal-payment-button-by-vcita

Installations
100+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

WP Order By

Plugin Slug:
wp-order-by

Installations
100+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

WR Price List Manager For Woocommerce

Plugin Slug:
wr-price-list-for-woocommerce

Installations
100+

Vulnerability:
Remote Code Execution (RCE)

Patched in Version:
No Fix

Severity Score:
Critical


The vulnerability has not been patched. You should deactivate the plugin.

Estatebud � Properties & Listings

Plugin Slug:
estatebud-properties-listings

Installations
90+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Amber

Plugin:

Amber

Plugin Slug:
amberlink

Installations
80+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Multilang Contact Form

Plugin Slug:
multilang-contact-form

Installations
80+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Responsive jQuery Slider

Plugin Slug:
responsive-jquery-slider

Installations
80+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.
Plugin Slug:
gallery-and-lightbox

Installations
70+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

User Management

Plugin Slug:
user-management

Installations
70+

Vulnerability:
Privilege Escalation

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

WP Post Corrector

Plugin Slug:
wp-post-corrector

Installations
70+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Foundation Columns

Plugin Slug:
foundation-columns

Installations
50+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Navigation Du Lapin Blanc

Plugin Slug:
navigation-du-lapin-blanc

Installations
50+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

S-DEV SEO

Plugin Slug:
s-dev-seo

Installations
50+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

SetMore Theme � Custom Post Types

Plugin Slug:
service-provider-profile-cpt

Installations
50+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Social Media Engine

Plugin Slug:
social-media-engine

Installations
50+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

WP ViewSTL

Plugin Slug:
wp-viewstl

Installations
50+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

HireHive Job Plugin

Plugin Slug:
zartis-job-plugin

Installations
50+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Ajax Contact Form

Plugin Slug:
fws-ajax-contact-form

Installations
40+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Related Post Shortcode

Plugin Slug:
related-post-shortcode

Installations
30+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

CodeBard Help Desk

Plugin Slug:
codebard-help-desk

Installations
10+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

1003 Mortgage Application

Plugin:

1003 Mortgage Application

Plugin Slug:
1003-mortgage-application

Vulnerability:
Sensitive Data Exposure

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

a Gateway for Pasargad Bank on WooCommerce

Plugin:

a Gateway for Pasargad Bank on WooCommerce

Plugin Slug:
a-gateway-for-pasargad-bank-on-woocommerce

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Ad Blocking Detector

Plugin:

Ad Blocking Detector

Plugin Slug:
ad-blocking-detector

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

add custom google tag manager

Plugin:

add custom google tag manager

Plugin Slug:
add-custom-google-tag-manager

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Add RSS

Plugin:

Add RSS

Plugin Slug:
add-rss

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Admin Cleanup

Plugin:

Admin Cleanup

Plugin Slug:
admin-cleanup

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Admin Menu Organizer

Plugin:

Admin Menu Organizer

Plugin Slug:
admin-menu-organizer

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Elementor AI Addons

Plugin:

Elementor AI Addons

Plugin Slug:
ai-addons-for-elementor

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.
Plugin:

AI Responsive Gallery Album

Plugin Slug:
ai-responsive-gallery-album

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Ajax WP Query Search Filter

Plugin:

Ajax WP Query Search Filter

Plugin Slug:
ajax-wp-query-search-filter

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

AlT Report

Plugin:

AlT Report

Plugin Slug:
alt-report

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Altima Lookbook Free for WooCommerce

Plugin:

Altima Lookbook Free for WooCommerce

Plugin Slug:
altima-lookbook-free-for-woocommerce

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

amr personalise

Plugin:

amr personalise

Plugin Slug:
amr-personalise

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Annie

Plugin:

Annie

Plugin Slug:
annie

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Annie

Plugin:

Annie

Plugin Slug:
annie

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.
Plugin:

Anonymize Links

Plugin Slug:
anonymize-links

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

AnyRoad

Plugin:

AnyRoad

Plugin Slug:
anyguide

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Apply with LinkedIn buttons

Plugin:

Apply with LinkedIn buttons

Plugin Slug:
apply-with-linkedin-buttons

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Apply with LinkedIn buttons

Plugin:

Apply with LinkedIn buttons

Plugin Slug:
apply-with-linkedin-buttons

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Auphonic Importer

Plugin:

Auphonic Importer

Plugin Slug:
auphonic-importer

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Auto FTP

Plugin:

Auto FTP

Plugin Slug:
auto-ftp

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Background animation blocks

Plugin:

Background animation blocks

Plugin Slug:
background-animation-blocks

Vulnerability:
Local File Inclusion

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Background Control

Plugin:

Background Control

Plugin Slug:
background-control

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Better Protected Pages

Plugin:

Better Protected Pages

Plugin Slug:
better-protected-pages

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Bible Embed

Plugin:

Bible Embed

Plugin Slug:
bible-embed

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Bit.ly linker

Plugin:

Bit.ly linker

Plugin Slug:
bitly-linker

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

BizLibrary

Plugin:

BizLibrary

Plugin Slug:
bizlibrary

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Blog Summary

Plugin:

Blog Summary

Plugin Slug:
blog-summary

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Blogger Image Import

Plugin:

Blogger Image Import

Plugin Slug:
blogger-image-import

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Blrt WP Embed

Plugin:

Blrt WP Embed

Plugin Slug:
blrt-wp-embed

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Blue Wrench Video Widget

Plugin:

Blue Wrench Video Widget

Plugin Slug:
blue-wrench-videos-widget

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Board Election

Plugin:

Board Election

Plugin Slug:
board-election

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Bonjour Bar

Plugin:

Bonjour Bar

Plugin Slug:
bonjour-bar

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Book a Place

Plugin:

Book a Place

Plugin Slug:
book-a-place

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Bookalet

Plugin:

Bookalet

Plugin Slug:
bookalet

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Brizy Pro

Plugin:

Brizy Pro

Plugin Slug:
brizy-pro

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Calendi

Plugin:

Calendi

Plugin Slug:
calendi

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Call me Now

Plugin:

Call me Now

Plugin Slug:
call-me-now

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Call To Action Popup

Plugin:

Call To Action Popup

Plugin Slug:
call-to-action-popup

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

CAMOO SMS

Plugin:

CAMOO SMS

Plugin Slug:
camoo-sms

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Captchelfie � Captcha by Selfie

Plugin:

Captchelfie � Captcha by Selfie

Plugin Slug:
captchelfie-captcha-by-selfie

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Car Demon

Plugin:

Car Demon

Plugin Slug:
car-demon

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Category D3 Tree

Plugin:

Category D3 Tree

Plugin Slug:
category-d3-tree

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Category Custom Fields

Plugin:

Category Custom Fields

Plugin Slug:
categorycustomfields

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

CC Circle Progress Bar

Plugin:

CC Circle Progress Bar

Plugin Slug:
cc-circle-progress-bar

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Contact Form 7 � CCAvenue Add-on

Plugin:

Contact Form 7 � CCAvenue Add-on

Plugin Slug:
cf7-cc-avenue-add-on

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Charity-thermometer

Plugin:

Charity-thermometer

Plugin Slug:
charitydonation-thermometer

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Chatter

Plugin:

Chatter

Plugin Slug:
chatter

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Chess Tempo Viewer

Plugin:

Chess Tempo Viewer

Plugin Slug:
chesstempoviewer

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

CJ Custom Content

Plugin:

CJ Custom Content

Plugin Slug:
cj-custom-content

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

CMC MIGRATE

Plugin:

CMC MIGRATE

Plugin Slug:
cmc-migrate

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

CNZZ&51LA for WordPress

Plugin:

CNZZ&51LA for WordPress

Plugin Slug:
cnzz51la-for-wordpress

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Comment-Emailer

Plugin:

Comment-Emailer

Plugin Slug:
comment-emailer

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

HyperComments

Plugin:

HyperComments

Plugin Slug:
comments-with-hypercommentscom

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Compare Ninja

Plugin:

Compare Ninja

Plugin Slug:
compare-ninja-comparison-tables

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Contact Form 7 Anti Spambot

Plugin:

Contact Form 7 Anti Spambot

Plugin Slug:
contact-form-7-anti-spambot

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Contact Form 7 Round Robin Lead Distribution

Plugin:

Contact Form 7 Round Robin Lead Distribution

Plugin Slug:
contact-form-7-round-robin-lead-distribution

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Contact Form 7 Round Robin Lead Distribution

Plugin:

Contact Form 7 Round Robin Lead Distribution

Plugin Slug:
contact-form-7-round-robin-lead-distribution

Vulnerability:
SQL Injection

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Contact Form Master � by Edmon

Plugin:

Contact Form Master � by Edmon

Plugin Slug:
contact-form-master

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Content Mirror

Plugin:

Content Mirror

Plugin Slug:
content-mirror

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Content Planner

Plugin:

Content Planner

Plugin Slug:
content-planner

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Content Security Policy Pro

Plugin:

Content Security Policy Pro

Plugin Slug:
content-security-policy-pro

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

ContentOptin Lite

Plugin:

ContentOptin Lite

Plugin Slug:
contentoptin

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.
Plugin:

Cookie Consent & Autoblock for GDPR/CCPA

Plugin Slug:
cookie-consent-autoblock

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Copy Move Posts

Plugin:

Copy Move Posts

Plugin Slug:
copy-move-posts

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.
Plugin:

Copyright Safeguard Footer Notice

Plugin Slug:
copyright-safeguard-footer-notice

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Custom CSS Addons

Plugin:

Custom CSS Addons

Plugin Slug:
css-addons

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Custom List Table Example

Plugin:

Custom List Table Example

Plugin Slug:
custom-list-table-example

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Custom Post

Plugin:

Custom Post

Plugin Slug:
custom-post-type-gui

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Custom Post Type Lockdown

Plugin:

Custom Post Type Lockdown

Plugin Slug:
custom-post-type-lockdown

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Custom Widget Classes

Plugin:

Custom Widget Classes

Plugin Slug:
custom-widget-classes

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Customizable Captcha and Contact Us

Plugin:

Customizable Captcha and Contact Us

Plugin Slug:
customizable-captcha-and-contact-us-form

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Cyber Slider

Plugin:

Cyber Slider

Plugin Slug:
cyber-new-slider

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Daily Proverb

Plugin:

Daily Proverb

Plugin Slug:
daily-proverb

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Database Sync

Plugin:

Database Sync

Plugin Slug:
database-sync

Vulnerability:
Sensitive Data Exposure

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

DD Roles

Plugin:

DD Roles

Plugin Slug:
dd-roles

Vulnerability:
Privilege Escalation

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Debt Calculator

Plugin:

Debt Calculator

Plugin Slug:
debt-calculator

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Debug Tool

Plugin:

Debug Tool

Plugin Slug:
debug-tool

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

DF Draggable

Plugin:

DF Draggable

Plugin Slug:
df-draggable

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

dForms

Plugin:

dForms

Plugin Slug:
dforms

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

WordPress Local SEO

Plugin:

WordPress Local SEO

Plugin Slug:
dh-local-seo

Vulnerability:
SQL Injection

Patched in Version:
No Fix

Severity Score:
Critical


The vulnerability has not been patched. You should deactivate the plugin.

REAL WordPress Sidebar

Plugin:

REAL WordPress Sidebar

Plugin Slug:
drag-and-drop-custom-sidebar

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

EU DSGVO Helper

Plugin:

EU DSGVO Helper

Plugin Slug:
dsgvo

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Easy Automatic Newsletter Lite

Plugin:

Easy Automatic Newsletter Lite

Plugin Slug:
easy-automatic-newsletter

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Easy Code Snippets

Plugin:

Easy Code Snippets

Plugin Slug:
easy-code-snippets

Vulnerability:
SQL Injection

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.
Plugin:

Easy EU Cookie law

Plugin Slug:
easy-eu-cookie-law

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Easy FAQs

Plugin:

Easy FAQs

Plugin Slug:
easy-faqs

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Easy Filtering

Plugin:

Easy Filtering

Plugin Slug:
easy-filtering

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Easy Portfolio

Plugin:

Easy Portfolio

Plugin Slug:
easy-portfolio

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Post-to-Post Links

Plugin:

Post-to-Post Links

Plugin Slug:
easy-post-to-post-links

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Easy Real Estate

Plugin:

Easy Real Estate

Plugin Slug:
easy-real-estate

Vulnerability:
Privilege Escalation

Patched in Version:
No Fix

Severity Score:
Critical


The vulnerability has not been patched. You should deactivate the plugin.

Easy Shortcode Buttons

Plugin:

Easy Shortcode Buttons

Plugin Slug:
easy-shortcode-buttons

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Easy Tweet Embed

Plugin:

Easy Tweet Embed

Plugin Slug:
easy-tweet-embed

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Easy Tynt

Plugin:

Easy Tynt

Plugin Slug:
easy-tynt

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

ECT Add to Cart Button

Plugin:

ECT Add to Cart Button

Plugin Slug:
ect-add-to-cart-button

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

EditionGuard for WooCommerce � eBook Sales with DRM

Plugin:

EditionGuard for WooCommerce � eBook Sales with DRM

Plugin Slug:
editionguard-for-woocommerce-ebook-sales-with-drm

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

EELV Newsletter

Plugin:

EELV Newsletter

Plugin Slug:
eelv-newsletter

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Email Capture & Lead Generation

Plugin:

Email Capture & Lead Generation

Plugin Slug:
email-capture-lead-generation

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Email on Publish

Plugin:

Email on Publish

Plugin Slug:
email-on-publish

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

EmailShroud

Plugin:

EmailShroud

Plugin Slug:
emailshroud

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

iSpring Embedder

Plugin:

iSpring Embedder

Plugin Slug:
embed-ispring

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
Critical


The vulnerability has not been patched. You should deactivate the plugin.

Enhanced YouTube Shortcode

Plugin:

Enhanced YouTube Shortcode

Plugin Slug:
enhanced-youtube-shortcode

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Error Notification

Plugin:

Error Notification

Plugin Slug:
error-notification

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Event Countdown Timer Plugin by TechMix

Plugin:

Event Countdown Timer Plugin by TechMix

Plugin Slug:
event-countdown-timer

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Event Registration Calendar By vcita

Plugin:

Event Registration Calendar By vcita

Plugin Slug:
event-registration-calendar-by-vcita

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Explara Membership

Plugin:

Explara Membership

Plugin Slug:
explara-membership

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Explore pages

Plugin:

Explore pages

Plugin Slug:
explore-pages

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Extra Options � Favicons

Plugin:

Extra Options � Favicons

Plugin Slug:
extra-options-favicons

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

EZPlayer

Plugin:

EZPlayer

Plugin Slug:
ezplayer

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Fast Tube

Plugin:

Fast Tube

Plugin Slug:
fast-tube

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

FAT Event Lite

Plugin:

FAT Event Lite

Plugin Slug:
fat-event-lite

Vulnerability:
Local File Inclusion

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

FAT Event Lite

Plugin:

FAT Event Lite

Plugin Slug:
fat-event-lite

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Feedburner Optin Form

Plugin:

Feedburner Optin Form

Plugin Slug:
feedburner-optin-form

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Find Your Reps

Plugin:

Find Your Reps

Plugin Slug:
find-your-reps

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Flexible Blogtitle

Plugin:

Flexible Blogtitle

Plugin Slug:
flexible-blogtitle

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Floatbox Plus

Plugin:

Floatbox Plus

Plugin Slug:
floatbox-plus

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Flying Twitter Birds

Plugin:

Flying Twitter Birds

Plugin Slug:
flying-twitter-birds

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

FontAwesome.io ShortCodes

Plugin:

FontAwesome.io ShortCodes

Plugin Slug:
fontawesomeio-shortcodes

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Formatted post

Plugin:

Formatted post

Plugin Slug:
formatted-post

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

FP RSS Category Excluder

Plugin:

FP RSS Category Excluder

Plugin Slug:
fp-rss-category-excluder

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

FWD Slider

Plugin:

FWD Slider

Plugin Slug:
fwd-slider

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

GDPR Personal Data Reports

Plugin:

GDPR Personal Data Reports

Plugin Slug:
gdpr-personal-data-reports

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

GDReseller

Plugin:

GDReseller

Plugin Slug:
gdreseller

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Genki Announcement

Plugin:

Genki Announcement

Plugin Slug:
genki-announcement

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Geotagged Media

Plugin:

Geotagged Media

Plugin Slug:
geotagged-media

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Multi Uploader for Gravity Forms

Plugin:

Multi Uploader for Gravity Forms

Plugin Slug:
gf-multi-uploader

Vulnerability:
Arbitrary File Upload

Patched in Version:
No Fix

Severity Score:
Critical


The vulnerability has not been patched. You should deactivate the plugin.

Giveaways and Contests by PromoSimple

Plugin:

Giveaways and Contests by PromoSimple

Plugin Slug:
giveaways-contests-by-promosimple

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Glofox Shortcodes

Plugin:

Glofox Shortcodes

Plugin Slug:
glofox-shortcodes

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

GMap Shortcode

Plugin:

GMap Shortcode

Plugin Slug:
gmap-shortcode

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

GMAPS for WPBakery Page Builder Free

Plugin:

GMAPS for WPBakery Page Builder Free

Plugin Slug:
gmaps-for-visual-composer-free

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

go Social

Plugin:

go Social

Plugin Slug:
go-social

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Goldstar

Plugin:

Goldstar

Plugin Slug:
goldstar

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.
Plugin:

Good Old Gallery

Plugin Slug:
good-old-gallery

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

WordPress Google Map Professional

Plugin:

WordPress Google Map Professional

Plugin Slug:
google-map-professional

Vulnerability:
SQL Injection

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Google Org Chart

Plugin:

Google Org Chart

Plugin Slug:
google-org-chart

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

WordPress Graphs & Charts

Plugin:

WordPress Graphs & Charts

Plugin Slug:
graph-lite

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

GravatarLocalCache

Plugin:

GravatarLocalCache

Plugin Slug:
gravatarlocalcache

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Greek Namedays Widget From Eortologio.Net

Plugin:

Greek Namedays Widget From Eortologio.Net

Plugin Slug:
greek-namedays-widget

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Group category creator

Plugin:

Group category creator

Plugin Slug:
group-category-creator

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Hack me if you can

Plugin:

Hack me if you can

Plugin Slug:
hack-me-if-you-can

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

History timeline

Plugin:

History timeline

Plugin Slug:
history-timeline

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Horizontal Line Shortcode

Plugin:

Horizontal Line Shortcode

Plugin Slug:
horizontal-line-shortcode

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Hotspots Analytics

Plugin:

Hotspots Analytics

Plugin Slug:
hotspots

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.
Plugin:

HTTP to HTTPS link changer by Eyga.net

Plugin Slug:
https-links-in-content

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.
Plugin:

Gallery: Hybrid � Advanced Visual Gallery

Plugin Slug:
hybrid-gallery

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.
Plugin:

CtyGrid Hyp3rL0cal Search

Plugin Slug:
hyp3rl0cal-city-search

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.
Plugin:

Image Gallery Box by CRUDLab

Plugin Slug:
image-gallery-box-by-crudlab

Vulnerability:
Local File Inclusion

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Image Switcher

Plugin:

Image Switcher

Plugin Slug:
image-switcher

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Image Switcher

Plugin:

Image Switcher

Plugin Slug:
image-switcher

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

imaGenius

Plugin:

imaGenius

Plugin Slug:
imagenius

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Import Users to MailChimp

Plugin:

Import Users to MailChimp

Plugin Slug:
import-users-to-mailchimp

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Improved Sale Badges � Free Version

Plugin:

Improved Sale Badges � Free Version

Plugin Slug:
improved-sale-badges-free-version

Vulnerability:
Local File Inclusion

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Incredible Font Awesome

Plugin:

Incredible Font Awesome

Plugin Slug:
incredible-font-awesome

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

InFunding

Plugin:

InFunding

Plugin Slug:
infunding

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Instant Appointment

Plugin:

Instant Appointment

Plugin Slug:
instant-appointment

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Interactive Page Hierarchy

Plugin:

Interactive Page Hierarchy

Plugin Slug:
interactive-page-hierarchy

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

JB Horizontal Scroller News Ticker

Plugin:

JB Horizontal Scroller News Ticker

Plugin Slug:
jb-horizontal-scroller-news-ticker

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Jet Skinner for BuddyPress

Plugin:

Jet Skinner for BuddyPress

Plugin Slug:
jet-skinner-for-buddypress

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Kapost

Plugin:

Kapost

Plugin Slug:
kapost-byline

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Kopa Nictitate Toolkit

Plugin:

Kopa Nictitate Toolkit

Plugin Slug:
kopa-nictitate-toolkit

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Len Slider

Plugin:

Len Slider

Plugin Slug:
len-slider

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

LH Email

Plugin:

LH Email

Plugin Slug:
lh-email

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

LH Login Page

Plugin:

LH Login Page

Plugin Slug:
lh-login-page

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Lime Developer Login

Plugin:

Lime Developer Login

Plugin Slug:
lime-developer-login

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

LocalGrid

Plugin:

LocalGrid

Plugin Slug:
localgrid

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Loginplus

Plugin:

Loginplus

Plugin Slug:
loginplus

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

LSD Google Maps Embedder

Plugin:

LSD Google Maps Embedder

Plugin Slug:
lsd-google-maps-embedder

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

MACME

Plugin:

MACME

Plugin Slug:
macme

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Magic Google Maps

Plugin:

Magic Google Maps

Plugin Slug:
magic-google-maps

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Free MailClient FMC

Plugin:

Free MailClient FMC

Plugin Slug:
mailclient

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Mapbox for WP Advanced

Plugin:

Mapbox for WP Advanced

Plugin Slug:
mapbox-for-wp-advanced

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Mark Posts

Plugin:

Mark Posts

Plugin Slug:
mark-posts

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Marmoset Viewer

Plugin:

Marmoset Viewer

Plugin Slug:
marmoset-viewer

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Marquee Style RSS News Ticker

Plugin:

Marquee Style RSS News Ticker

Plugin Slug:
marquee-style-rss-news-ticker

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Mass Custom Fields Manager

Plugin:

Mass Custom Fields Manager

Plugin Slug:
mass-custom-fields-manager

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Mass Messaging in BuddyPress

Plugin:

Mass Messaging in BuddyPress

Plugin Slug:
mass-messaging-in-buddypress

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

MD Custom content after or before of post

Plugin:

MD Custom content after or before of post

Plugin Slug:
md-custom-content

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

MDC YouTube Downloader

Plugin:

MDC YouTube Downloader

Plugin Slug:
mdc-youtube-downloader

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

MeinTurnierplan.de Widget Viewer

Plugin:

MeinTurnierplan.de Widget Viewer

Plugin Slug:
meinturnierplande-widget-viewer

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

MemeOne

Plugin:

MemeOne

Plugin Slug:
memeone

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Menus Plus+

Plugin:

Menus Plus+

Plugin Slug:
menus-plus

Vulnerability:
SQL Injection

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

MercadoLibre Integration

Plugin:

MercadoLibre Integration

Plugin Slug:
mercadolibre-integration

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

MFPlugin

Plugin:

MFPlugin

Plugin Slug:
mfplugin

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

MHR-Custom-Anti-Copy

Plugin:

MHR-Custom-Anti-Copy

Plugin Slug:
mhr-custom-anti-copy

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Mindmeister Shortcode

Plugin:

Mindmeister Shortcode

Plugin Slug:
mindmeister-shortcode

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.
Plugin:

More Link Modifier

Plugin Slug:
more-link-modifier

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

WP VTiger Synchronization

Plugin:

WP VTiger Synchronization

Plugin Slug:
msstiger

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Metaphor Widgets

Plugin:

Metaphor Widgets

Plugin Slug:
mtphr-widgets

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Muzaara Google Ads Report

Plugin:

Muzaara Google Ads Report

Plugin Slug:
muzaara-adwords-optimize-dashboard

Vulnerability:
PHP Object Injection

Patched in Version:
No Fix

Severity Score:
Critical


The vulnerability has not been patched. You should deactivate the plugin.
Plugin:

my-related-posts

Plugin Slug:
my-related-posts

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

MyAnime Widget

Plugin:

MyAnime Widget

Plugin Slug:
myanime-widget

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

mybb Last Topics

Plugin:

mybb Last Topics

Plugin Slug:
mybb-last-topics

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

MyBookProgress by Stormhill Media

Plugin:

MyBookProgress by Stormhill Media

Plugin Slug:
mybookprogress

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Nativery

Plugin:

Nativery

Plugin Slug:
nativery

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Nite Shortcodes

Plugin:

Nite Shortcodes

Plugin Slug:
nite-shortcodes

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

NV Slider

Plugin:

NV Slider

Plugin Slug:
nv-slider

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

OrangeBox

Plugin:

OrangeBox

Plugin Slug:
orangebox

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Password Protect Plugin for WordPress

Plugin:

Password Protect Plugin for WordPress

Plugin Slug:
password-protect-plugin-for-wordpress

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Pastebin

Plugin:

Pastebin

Plugin Slug:
pastebin-embed

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

PayForm

Plugin:

PayForm

Plugin Slug:
payform

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

PayPal Marketing Solutions

Plugin:

PayPal Marketing Solutions

Plugin Slug:
paypal-promotions-and-insights

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

PDF.js Shortcode

Plugin:

PDF.js Shortcode

Plugin Slug:
pdfjs-shortcode

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.
Plugin:

Powie’s pLinks PagePeeker

Plugin Slug:
plinks

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Pod?l�nkov� inzerce

Plugin:

Pod?l�nkov� inzerce

Plugin Slug:
podclankova-inzerce

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Pootle button

Plugin:

Pootle button

Plugin Slug:
pootle-button

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Popliup

Plugin:

Popliup

Plugin Slug:
popliup

Vulnerability:
Local File Inclusion

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Post & Page Notes

Plugin:

Post & Page Notes

Plugin Slug:
post-page-notes

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

PPO Call To Actions

Plugin:

PPO Call To Actions

Plugin Slug:
ppo-call-to-actions

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Preloader Quotes

Plugin:

Preloader Quotes

Plugin Slug:
preloader-quotes

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Progress Tracker

Plugin:

Progress Tracker

Plugin Slug:
progress-tracker

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

QR Code Generator

Plugin:

QR Code Generator

Plugin Slug:
qrcode-wprhe

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Quick Count

Plugin:

Quick Count

Plugin Slug:
quick-count

Vulnerability:
PHP Object Injection

Patched in Version:
No Fix

Severity Score:
Critical


The vulnerability has not been patched. You should deactivate the plugin.

quote-posttype-plugin

Plugin:

quote-posttype-plugin

Plugin Slug:
quote-post-type-plugin

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

QuoteMedia Tools

Plugin:

QuoteMedia Tools

Plugin Slug:
quotemedia-tools

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

ReadMe Creator

Plugin:

ReadMe Creator

Plugin Slug:
readme-creator

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Realty Workstation

Plugin:

Realty Workstation

Plugin Slug:
realty-workstation

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

REDIRECTION PLUS

Plugin:

REDIRECTION PLUS

Plugin Slug:
redirection-plus

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

User Sync ActiveCampaign

Plugin:

User Sync ActiveCampaign

Plugin Slug:
registered-user-sync-activecampaign

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Rezdy Reloaded

Plugin:

Rezdy Reloaded

Plugin Slug:
reloaded-rezdy

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Rename Author Slug

Plugin:

Rename Author Slug

Plugin Slug:
rename-author-slug

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.
Plugin:

Links/Problem Reporter

Plugin Slug:
report-broken-links

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

ResAds

Plugin:

ResAds

Plugin Slug:
resads

Vulnerability:
SQL Injection

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Responsivity

Plugin:

Responsivity

Plugin Slug:
responsivity

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.
Plugin:

Rio Photo Gallery

Plugin Slug:
rio-photo-gallery

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Rollover Tab

Plugin:

Rollover Tab

Plugin Slug:
rollover-tab

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.
Plugin:

root Cookie

Plugin Slug:
root-cookie

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

RSS Icon Widget

Plugin:

RSS Icon Widget

Plugin Slug:
rss-icon-widget

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

RSS News Scroller

Plugin:

RSS News Scroller

Plugin Slug:
rss-news-scroller

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

RSV GMaps

Plugin:

RSV GMaps

Plugin Slug:
rsv-google-maps

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Salvador � AI Image Generator

Plugin:

Salvador � AI Image Generator

Plugin Slug:
salvador-ai-image-generator

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Scroll Top Advanced

Plugin:

Scroll Top Advanced

Plugin Slug:
scroll-top-advanced

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Secure CAPTCHA

Plugin:

Secure CAPTCHA

Plugin Slug:
secure-captcha

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Real Seguro Viagem

Plugin:

Real Seguro Viagem

Plugin Slug:
seguro-viagem

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Send to a Friend Addon

Plugin:

Send to a Friend Addon

Plugin Slug:
send-booking-invites-to-friends

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Send to Twitter

Plugin:

Send to Twitter

Plugin Slug:
send-to-twitter

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

SOCIAL.NINJA

Plugin:

SOCIAL.NINJA

Plugin Slug:
seo-meta

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

SexBundle

Plugin:

SexBundle

Plugin Slug:
sexbundle

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Shabbos and Yom Tov

Plugin:

Shabbos and Yom Tov

Plugin Slug:
shabbos-and-yom-tov

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Shockingly Big IE6 Warning

Plugin:

Shockingly Big IE6 Warning

Plugin Slug:
shockingly-big-ie6-warning

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Shortcode in Comment

Plugin:

Shortcode in Comment

Plugin Slug:
shortcode-in-comment

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Shoutcast and Icecast HTML5 Web Radio Player by YesStreaming.com

Plugin:

Shoutcast and Icecast HTML5 Web Radio Player by YesStreaming.com

Plugin Slug:
shoutcast-and-icecast-html5-web-radio-player-by-yesstreaming-com

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Sidebar-Content from Shortcode

Plugin:

Sidebar-Content from Shortcode

Plugin Slug:
sidebar-content-from-shortcode

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Simple Custom post type custom field

Plugin:

Simple Custom post type custom field

Plugin Slug:
simple-content-construction-kit

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Simple Project Manager

Plugin:

Simple Project Manager

Plugin Slug:
simple-project-managment

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Simple shortcode buttons

Plugin:

Simple shortcode buttons

Plugin Slug:
simple-shortcode-buttons

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Simple Vertical Timeline

Plugin:

Simple Vertical Timeline

Plugin Slug:
simple-vertical-timeline

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Slides & Presentations

Plugin:

Slides & Presentations

Plugin Slug:
slide

Vulnerability:
Content Injection

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Slider for Writers

Plugin:

Slider for Writers

Plugin Slug:
slider-for-writers

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Smallerik File Browser

Plugin:

Smallerik File Browser

Plugin Slug:
smallerik-file-browser

Vulnerability:
Arbitrary File Upload

Patched in Version:
No Fix

Severity Score:
Critical


The vulnerability has not been patched. You should deactivate the plugin.

Smooth Dynamic Slider

Plugin:

Smooth Dynamic Slider

Plugin Slug:
smooth-dynamic-slider

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Cache Sniper for Nginx

Plugin:

Cache Sniper for Nginx

Plugin Slug:
snipe-nginx-cache

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Snippy

Plugin:

Snippy

Plugin Slug:
snippy

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Social Analytics

Plugin:

Social Analytics

Plugin Slug:
social-analytics

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Social Pug: Author Box

Plugin:

Social Pug: Author Box

Plugin Slug:
social-pug-author-box

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Social2Blog

Plugin:

Social2Blog

Plugin Slug:
social2blog

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Solidres � Hotel booking plugin

Plugin:

Solidres � Hotel booking plugin

Plugin Slug:
solidres

Vulnerability:
SQL Injection

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Spiderpowa Embed PDF

Plugin:

Spiderpowa Embed PDF

Plugin Slug:
spiderpowa-embed-pdf

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

SEOReseller Partner

Plugin:

SEOReseller Partner

Plugin Slug:
sr-partner

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Staging CDN

Plugin:

Staging CDN

Plugin Slug:
staging-cdn

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Stars SMTP Mailer

Plugin:

Stars SMTP Mailer

Plugin Slug:
stars-smtp-mailer

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Strx Magic Floating Sidebar Maker

Plugin:

Strx Magic Floating Sidebar Maker

Plugin Slug:
strx-magic-floating-sidebar-maker

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Style Admin

Plugin:

Style Admin

Plugin Slug:
style-admin

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Sur.ly

Plugin:

Sur.ly

Plugin Slug:
surly

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Tab My Content

Plugin:

Tab My Content

Plugin Slug:
tab-my-content

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Tagesteller

Plugin:

Tagesteller

Plugin Slug:
tagesteller

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Team 118GROUP Agent

Plugin:

Team 118GROUP Agent

Plugin Slug:
team-118group-agent

Vulnerability:
Arbitrary Content Deletion

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Theme My Ontraport Smartform

Plugin:

Theme My Ontraport Smartform

Plugin Slug:
theme-my-ontraport-smartform

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Top Flash Embed

Plugin:

Top Flash Embed

Plugin Slug:
top-flash-embed

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Track Page Scroll

Plugin:

Track Page Scroll

Plugin Slug:
track-page-scroll

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Translation.Pro

Plugin:

Translation.Pro

Plugin Slug:
translation-pro

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

ts-tree

Plugin:

ts-tree

Plugin Slug:
ts-tree

Vulnerability:
Arbitrary Content Deletion

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Twitter Bootstrap Collapse aka Accordian Shortcode

Plugin:

Twitter Bootstrap Collapse aka Accordian Shortcode

Plugin Slug:
twitter-bootstrap-collapse-aka-accordian-shortcode

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Twitter Shortcode

Plugin:

Twitter Shortcode

Plugin Slug:
twitter-shortcode

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Twitter Post

Plugin:

Twitter Post

Plugin Slug:
twitterpost

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Ultimate Events

Plugin:

Ultimate Events

Plugin Slug:
ultimate-events

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Ultimate Subscribe

Plugin:

Ultimate Subscribe

Plugin Slug:
ultimate-subscribe

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Unique UX

Plugin:

Unique UX

Plugin Slug:
unique-ux

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Universal Analytics Injector

Plugin:

Universal Analytics Injector

Plugin Slug:
universal-analytics-injector

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

UpDownUpDown

Plugin:

UpDownUpDown

Plugin Slug:
updownupdown-postcomment-voting

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

user files

Plugin:

user files

Plugin Slug:
user-files

Vulnerability:
Arbitrary File Upload

Patched in Version:
No Fix

Severity Score:
Critical


The vulnerability has not been patched. You should deactivate the plugin.

Utilities for MTG

Plugin:

Utilities for MTG

Plugin Slug:
utilities-for-mtg

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Nature FlipBook

Plugin:

Nature FlipBook

Plugin Slug:
vertical-diamond-flipbook-flash

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

ViewMedica 9

Plugin:

ViewMedica 9

Plugin Slug:
viewmedica

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.
Plugin:

Visit Site Link enhanced

Plugin Slug:
visit-site-link-enhanced

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

W3SPEEDSTER

Plugin:

W3SPEEDSTER

Plugin Slug:
w3speedster-wp

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

WCS QR Code Generator

Plugin:

WCS QR Code Generator

Plugin Slug:
wcs-qr-code-generator

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Weaver Themes Shortcode Compatibility

Plugin:

Weaver Themes Shortcode Compatibility

Plugin Slug:
weaver-themes-shortcode-compatibility

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Web Push

Plugin:

Web Push

Plugin Slug:
web-push

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Web Testimonials

Plugin:

Web Testimonials

Plugin Slug:
web-testimonials

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

WH Cache & Security

Plugin:

WH Cache & Security

Plugin Slug:
wh-cache-and-security

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Wibstats

Plugin:

Wibstats

Plugin Slug:
wibstats-statistics-for-wordpress-mu

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Winning Portfolio

Plugin:

Winning Portfolio

Plugin Slug:
winning-portfolio

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

WM Options Import Export

Plugin:

WM Options Import Export

Plugin Slug:
wm-options-import-export

Vulnerability:
Sensitive Data Exposure

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Woo Tuner

Plugin:

Woo Tuner

Plugin Slug:
woo-tuner

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.
Plugin:

WooCommerce Order Search

Plugin Slug:
woocommerce-order-searching

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

WOOEXIM

Plugin:

WOOEXIM

Plugin Slug:
wooexim

Vulnerability:
PHP Object Injection

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Word Freshener

Plugin:

Word Freshener

Plugin Slug:
word-freshener

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

WordPress Custom Sidebar

Plugin:

WordPress Custom Sidebar

Plugin Slug:
wordpress-custom-sidebar

Vulnerability:
SQL Injection

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

WordPress Data Guard

Plugin:

WordPress Data Guard

Plugin Slug:
wordpress-data-guards

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.
Plugin:

WordPress Gallery Plugin

Plugin Slug:
wordpress-gallery-plugin

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

WordPress Logging Service

Plugin:

WordPress Logging Service

Plugin Slug:
wordpress-logging-service

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

WP All Import Pro

Plugin:

WP All Import Pro

Plugin Slug:
wp-all-import-pro

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

wp_amaps

Plugin:

wp_amaps

Plugin Slug:
wp-amaps

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

WP-Announcements

Plugin:

WP-Announcements

Plugin Slug:
wp-announcements

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

WP Background Tile

Plugin:

WP Background Tile

Plugin Slug:
wp-background-tile

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

WP-BlackCheck

Plugin:

WP-BlackCheck

Plugin Slug:
wp-blackcheck

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

WP Block Pack

Plugin:

WP Block Pack

Plugin Slug:
wp-block-pack

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

WP Bulletin Board

Plugin:

WP Bulletin Board

Plugin Slug:
wp-bulletin-board

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

WP Cookies Alert

Plugin:

WP Cookies Alert

Plugin Slug:
wp-cookies-alert

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.
Plugin:

WP Custom Google Search

Plugin Slug:
wp-custom-google-search

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

WP Download Codes

Plugin:

WP Download Codes

Plugin Slug:
wp-download-codes

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

WP FixTag

Plugin:

WP FixTag

Plugin Slug:
wp-fixtag

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

WP IMAP Auth

Plugin:

WP IMAP Auth

Plugin Slug:
wp-imap-authentication

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

WP Intro.JS

Plugin:

WP Intro.JS

Plugin Slug:
wp-intro-js-tours

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

WP krpano

Plugin:

WP krpano

Plugin Slug:
wp-krpano

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.
Plugin:

Lijit Search

Plugin Slug:
wp-lijit-wijit

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.
Plugin:

WP Load Gallery

Plugin Slug:
wp-load-gallery

Vulnerability:
Arbitrary File Upload

Patched in Version:
No Fix

Severity Score:
Critical


The vulnerability has not been patched. You should deactivate the plugin.

WP Meetup

Plugin:

WP Meetup

Plugin Slug:
wp-meetup

Vulnerability:
Settings Change

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

WP News Sliders

Plugin:

WP News Sliders

Plugin Slug:
wp-news-sliders

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

WP Options Editor

Plugin:

WP Options Editor

Plugin Slug:
wp-options-editor

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
Critical


The vulnerability has not been patched. You should deactivate the plugin.

wp-pano

Plugin:

wp-pano

Plugin Slug:
wp-pano

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

WP Panoramio

Plugin:

WP Panoramio

Plugin Slug:
wp-panoramio

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

WP Photo Sphere

Plugin:

WP Photo Sphere

Plugin Slug:
wp-photo-sphere

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

WP-Player

Plugin:

WP-Player

Plugin Slug:
wp-player

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

WP PT-Viewer

Plugin:

WP PT-Viewer

Plugin Slug:
wp-ptviewer

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

WP-Revive Adserver

Plugin:

WP-Revive Adserver

Plugin Slug:
wp-revive-adserver

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Wp-Scribd-List

Plugin:

Wp-Scribd-List

Plugin Slug:
wp-scribd-list

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

SendGrid for WordPress

Plugin:

SendGrid for WordPress

Plugin Slug:
wp-sendgrid-mailer

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

WP Service Payment Form With Authorize.net

Plugin:

WP Service Payment Form With Authorize.net

Plugin Slug:
wp-service-payment-form-with-authorizenet

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

WP2APP

Plugin:

WP2APP

Plugin Slug:
wp2appir

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

WPDB to Sql

Plugin:

WPDB to Sql

Plugin Slug:
wpdb-to-sql

Vulnerability:
Sensitive Data Exposure

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.
Plugin:

WpF Ultimate Carousel

Plugin Slug:
wpf-ultimate-carousel

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.
Plugin:

WordPress File Search

Plugin Slug:
wpfilesearch

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

WP Journal

Plugin:

WP Journal

Plugin Slug:
wpjournal

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

WP Lyrics

Plugin:

WP Lyrics

Plugin Slug:
wplyrics

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

XLSXviewer

Plugin:

XLSXviewer

Plugin Slug:
xlsx-viewer

Vulnerability:
Arbitrary File Deletion

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Xola

Plugin:

Xola

Plugin Slug:
xola-bookings-for-tours-activities

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Yet Another Countdown

Plugin:

Yet Another Countdown

Plugin Slug:
yacp

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

yCyclista

Plugin:

yCyclista

Plugin Slug:
ycyclista

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Zarinpal Paid Download

Plugin:

Zarinpal Paid Download

Plugin Slug:
zarinpal-paid-downloads

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

UpdraftPlus: WP Backup & Migration Plugin

Plugin Slug:
updraftplus

Installations
3,000,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.25.1

Severity Score:
High


The vulnerability has been patched, so you should update to version 1.25.1.

W3 Total Cache

Plugin Slug:
w3-total-cache

Installations
1,000,000+

Vulnerability:
Sensitive Data Exposure

Patched in Version:
2.8.2

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.8.2.

W3 Total Cache

Plugin Slug:
w3-total-cache

Installations
1,000,000+

Vulnerability:
Broken Access Control

Patched in Version:
2.8.2

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.8.2.

W3 Total Cache

Plugin Slug:
w3-total-cache

Installations
1,000,000+

Vulnerability:
Broken Access Control

Patched in Version:
2.8.2

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.8.2.

Page Builder by SiteOrigin

Plugin Slug:
siteorigin-panels

Installations
600,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.31.1

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.31.1.

Royal Elementor Addons and Templates

Plugin Slug:
royal-elementor-addons

Installations
500,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.7.1007

Severity Score:
High


The vulnerability has been patched, so you should update to version 1.7.1007.

Elementor Addon Elements

Plugin Slug:
addon-elements-for-elementor-page-builder

Installations
100,000+

Vulnerability:
Sensitive Data Exposure

Patched in Version:
1.14

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.14.

List category posts

Plugin Slug:
list-category-posts

Installations
90,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
0.90.3

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 0.90.3.

Kubio AI Page Builder

Plugin Slug:
kubio

Installations
80,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.4.0

Severity Score:
High


The vulnerability has been patched, so you should update to version 2.4.0.

WP ULike � All-in-One Engagement Toolkit

Plugin Slug:
wp-ulike

Installations
80,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
4.7.7

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 4.7.7.

WP Booking Calendar

Plugin Slug:
booking

Installations
50,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
10.9.3

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 10.9.3.

Piotnet Addons For Elementor

Plugin Slug:
piotnet-addons-for-elementor

Installations
40,000+

Vulnerability:
Broken Access Control

Patched in Version:
2.4.33

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.4.33.

Post Grid and Gutenberg Blocks � ComboBlocks

Plugin Slug:
post-grid

Installations
40,000+

Vulnerability:
Privilege Escalation

Patched in Version:
2.3.4

Severity Score:
Critical


The vulnerability has been patched, so you should update to version 2.3.4.

VOD Infomaniak

Plugin Slug:
vod-infomaniak

Installations
30,000+

Vulnerability:
Broken Access Control

Patched in Version:
1.5.10

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.5.10.
Plugin Slug:
link-library

Installations
10,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
7.7.3

Severity Score:
High


The vulnerability has been patched, so you should update to version 7.7.3.

Multi Step Form

Plugin Slug:
multi-step-form

Installations
10,000+

Vulnerability:
Broken Access Control

Patched in Version:
1.7.24

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.7.24.

Payment Button for PayPal

Plugin Slug:
wp-paypal

Installations
10,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.2.3.36

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.2.3.36.

WP User Profile Avatar

Plugin Slug:
wp-user-profile-avatar

Installations
10,000+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
1.0.6

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.0.6.

Motors � Car Dealer, Classifieds & Listing

Plugin Slug:
motors-car-dealership-classified-listings

Installations
9,000+

Vulnerability:
Arbitrary Code Execution

Patched in Version:
1.4.44

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.4.44.

WP Hotel Booking

Plugin Slug:
wp-hotel-booking

Installations
8,000+

Vulnerability:
Broken Access Control

Patched in Version:
2.1.6

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.1.6.

Proofreading

Plugin Slug:
proofreading

Installations
6,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.2.2

Severity Score:
High


The vulnerability has been patched, so you should update to version 1.2.2.

ElementInvader Addons for Elementor

Plugin Slug:
elementinvader-addons-for-elementor

Installations
5,000+

Vulnerability:
Local File Inclusion

Patched in Version:
1.2.7

Severity Score:
High


The vulnerability has been patched, so you should update to version 1.2.7.

Podlove Podcast Publisher

Plugin Slug:
podlove-podcasting-plugin-for-wordpress

Installations
5,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
4.2.0

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 4.2.0.

ApplyOnline � Application Form Builder and Manager

Plugin Slug:
apply-online

Installations
3,000+

Vulnerability:
Broken Access Control

Patched in Version:
2.6.7.2

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.6.7.2.

Eventer

Plugin:

Eventer

Plugin Slug:
eventer

Installations
2,000+

Vulnerability:
Arbitrary File Download

Patched in Version:
3.9.8

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 3.9.8.

Checkout for PayPal

Plugin Slug:
checkout-for-paypal

Installations
1,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.0.33

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.0.33.

Social proof testimonials and reviews by Repuso

Plugin Slug:
social-testimonials-and-reviews-widget

Installations
1,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
5.21

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 5.21.

WP Inventory Manager

Plugin Slug:
wp-inventory-manager

Installations
1,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.3.3

Severity Score:
High


The vulnerability has been patched, so you should update to version 2.3.3.

The Ultimate WordPress Toolkit � WP Extended

Plugin Slug:
wpextended

Installations
1,000+

Vulnerability:
SQL Injection

Patched in Version:
3.0.13

Severity Score:
Critical


The vulnerability has been patched, so you should update to version 3.0.13.

My Tickets � Accessible Event Ticketing

Plugin Slug:
my-tickets

Installations
900+

Vulnerability:
Broken Access Control

Patched in Version:
2.0.10

Severity Score:
High


The vulnerability has been patched, so you should update to version 2.0.10.

FireCask Like & Share Button

Plugin Slug:
facebook-like-send-button

Installations
600+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.3

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.3.

My auctions allegro

Plugin Slug:
my-auctions-allegro-free-edition

Installations
600+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
3.6.19

Severity Score:
High


The vulnerability has been patched, so you should update to version 3.6.19.

Verge3D Publishing and E-Commerce

Plugin Slug:
verge3d

Installations
600+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
4.8.1

Severity Score:
High


The vulnerability has been patched, so you should update to version 4.8.1.

PDF for WPForms + Drag and Drop Template Builder

Plugin Slug:
pdf-for-wpforms

Installations
500+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
4.8.0

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 4.8.0.

Simple:Press Forum

Plugin Slug:
simplepress

Installations
500+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
6.10.11

Severity Score:
High


The vulnerability has been patched, so you should update to version 6.10.11.

VikAppointments Services Booking Calendar

Plugin Slug:
vikappointments

Installations
500+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
1.2.17

Severity Score:
High


The vulnerability has been patched, so you should update to version 1.2.17.

Chamber Dashboard Business Directory

Plugin Slug:
chamber-dashboard-business-directory

Installations
400+

Vulnerability:
Broken Access Control

Patched in Version:
3.3.11

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 3.3.11.

Chamber Dashboard Business Directory

Plugin Slug:
chamber-dashboard-business-directory

Installations
400+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
3.3.10

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 3.3.10.

Stop Comment Spam

Plugin Slug:
stop-comment-spam

Installations
400+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
0.5.4

Severity Score:
High


The vulnerability has been patched, so you should update to version 0.5.4.

WP Smart TV

Plugin Slug:
wp-smart-tv

Installations
400+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.1.9

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.1.9.

ShipWorks Connector for Woocommerce

Plugin Slug:
shipworks-e-commerce-bridge

Installations
300+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
5.2.6

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 5.2.6.

turboSMTP

Plugin Slug:
turbosmtp

Installations
300+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
4.7

Severity Score:
High


The vulnerability has been patched, so you should update to version 4.7.

aDirectory � WordPress Directory Listing Plugin

Plugin Slug:
adirectory

Installations
200+

Vulnerability:
PHP Object Injection

Patched in Version:
1.9

Severity Score:
High


The vulnerability has been patched, so you should update to version 1.9.

Build Private Store For Woocommerce

Plugin Slug:
build-private-store-for-woocommerce

Installations
200+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
1.1

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.1.

Moving Users

Plugin Slug:
moving-users

Installations
100+

Vulnerability:
Sensitive Data Exposure

Patched in Version:
1.10

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.10.

Passwords Manager

Plugin Slug:
passwords-manager

Installations
100+

Vulnerability:
Broken Access Control

Patched in Version:
1.5.1

Severity Score:
High


The vulnerability has been patched, so you should update to version 1.5.1.

Passwords Manager

Plugin Slug:
passwords-manager

Installations
100+

Vulnerability:
SQL Injection

Patched in Version:
1.5.1

Severity Score:
High


The vulnerability has been patched, so you should update to version 1.5.1.

Passwords Manager

Plugin Slug:
passwords-manager

Installations
100+

Vulnerability:
SQL Injection

Patched in Version:
1.5.1

Severity Score:
Critical


The vulnerability has been patched, so you should update to version 1.5.1.

Video Share VOD � Turnkey Video Site Builder Script

Plugin Slug:
video-share-vod

Installations
100+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.6.32

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.6.32.

WP-BibTeX

Plugin Slug:
wp-bibtex

Installations
100+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
3.0.2

Severity Score:
High


The vulnerability has been patched, so you should update to version 3.0.2.

Webcamconsult

Plugin Slug:
webcamconsult

Installations
60+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.6.0

Severity Score:
High


The vulnerability has been patched, so you should update to version 1.6.0.

wp-greet

Plugin:

wp-greet

Plugin Slug:
wp-greet

Installations
60+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
6.3

Severity Score:
High


The vulnerability has been patched, so you should update to version 6.3.

JSM Screenshot Machine Shortcode

Plugin Slug:
screenshot-machine-shortcode

Installations
40+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
3.0.0

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 3.0.0.

WP Responsive Tabs

Plugin Slug:
wp-responsive-tabs

Installations
40+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.3.0

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.3.0.
Plugin Slug:
intelly-posts-footer-manager

Installations
20+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.2.0

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.2.0.

Adifier System

Plugin:

Adifier System

Plugin Slug:
adifier-system

Vulnerability:
Privilege Escalation

Patched in Version:
3.1.8

Severity Score:
Critical


The vulnerability has been patched, so you should update to version 3.1.8.

Gravity Forms

Plugin:

Gravity Forms

Plugin Slug:
gravityforms

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.9.2

Severity Score:
High


The vulnerability has been patched, so you should update to version 2.9.2.

JetElements For Elementor

Plugin:

JetElements For Elementor

Plugin Slug:
jet-elements

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.7.3

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.7.3.

JetEngine

Plugin:

JetEngine

Plugin Slug:
jet-engine

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
3.6.3

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 3.6.3.

Tamara Checkout

Plugin:

Tamara Checkout

Plugin Slug:
tamara-checkout

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.9.9.1

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.9.9.1.

WordPress Themes � 3 Patched / 22 Unpatched

Multifox

Theme Slug:
multifox

Downloads
5,014

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should switch themes.

my money

Theme Slug:
my-money

Downloads
20,130

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should switch themes.

The Ultralight

Theme Slug:
the-ultralight

Downloads
19,244

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should switch themes.

TIJAJI

Theme:

TIJAJI

Theme Slug:
tijaji

Downloads
13,991

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should switch themes.

CarZine

Theme:

CarZine

Theme Slug:
carzine

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should switch themes.

Envo Multipurpose

Theme:

Envo Multipurpose

Theme Slug:
envo-multipurpose

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should switch themes.

Flashy

Theme:

Flashy

Theme Slug:
flashy

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should switch themes.

ghostwriter

Theme:

ghostwriter

Theme Slug:
ghostwriter

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should switch themes.

Js O3 Lite

Theme:

Js O3 Lite

Theme Slug:
js-o3-lite

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should switch themes.

moseter

Theme:

moseter

Theme Slug:
moseter

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should switch themes.

my depressive

Theme:

my depressive

Theme Slug:
my-depressive

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should switch themes.

my engine

Theme:

my engine

Theme Slug:
my-engine

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should switch themes.

my white

Theme:

my white

Theme Slug:
my-white

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should switch themes.

my zebra

Theme:

my zebra

Theme Slug:
my-zebra

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should switch themes.

offset writing

Theme:

offset writing

Theme Slug:
offset-writing

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should switch themes.

polka dots

Theme:

polka dots

Theme Slug:
polka-dots

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should switch themes.

RealHomes

Theme:

RealHomes

Theme Slug:
realhomes

Vulnerability:
Privilege Escalation

Patched in Version:
No Fix

Severity Score:
Critical


The vulnerability has not been patched. You should switch themes.

Sandbox

Theme:

Sandbox

Theme Slug:
sandbox

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should switch themes.

Sandbox

Theme:

Sandbox

Theme Slug:
sandbox

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should switch themes.

Tantyyellow

Theme:

Tantyyellow

Theme Slug:
tantyyellow

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should switch themes.

Tiki Time

Theme:

Tiki Time

Theme Slug:
tiki-time

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should switch themes.

Tuaug4

Theme:

Tuaug4

Theme Slug:
tuaug4

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should switch themes.

Betheme

Theme:

Betheme

Theme Slug:
betheme

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
27.6.2

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 27.6.2.

Buzz Club

Theme:

Buzz Club

Theme Slug:
buzzclub

Vulnerability:
Broken Access Control

Patched in Version:
2.0.5

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.0.5.

DWT – Directory & Listing

Theme:

DWT – Directory & Listing

Theme Slug:
dwt-listing

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
3.3.4

Severity Score:
High


The vulnerability has been patched, so you should update to version 3.3.4.

Related articles

Wait! Get exclusive hosting insights

Subscribe to our newsletter and stay ahead of the competition with expert advice from our hosting pros.

Loading form…