Line illustration showing a black application window on a purple gradient background overlaid with a large exclamation point alert icon and three bugs.

WordPress Vulnerability Report � January 28, 2026

In this report, 225 vulnerabilities have been publicly disclosed. Security patches for 102 of these plugins and themes are now available. Please run these updates as soon as possible. If you’re a Solid Security Pro user, the version management tool may have already warned you and updated these plugins, depending on your settings.

Currently, 123 plugin and theme vulnerabilities remain unpatched. If you’re a Solid Security Pro user, those vulnerabilities are already protected by the Solid Security firewall. Virtual patches from Patchstack will be applied when a vulnerability is considered high or medium risk. If no patch is forthcoming from the vendor or the vulnerable software has been marked “closed” and dropped from the official WordPress repositories, you should deactivate it soon and look for alternative solutions.

WordPress Core

WordPress 6.9 “Gene” was released on December 2, 2025, adding Notes for block-level comments, an expanded Command Palette, and the new Abilities API to standardize permissions for future automation. It also includes performance improvements and new blocks and design tools to support faster, more flexible site building.

After any major release, don�t update live sites until you�ve taken backups and tested in a non-production environment.

WordPress Plugins � 89 Patched / 118 Unpatched

Ecwid by Lightspeed Ecommerce Shopping Cart

Plugin Slug:
ecwid-shopping-cart

Installations
20,000+

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

GeoDirectory � WP Business Directory Plugin and Classified Listings Directory

Plugin Slug:
geodirectory

Installations
10,000+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Kama Thumbnail

Plugin Slug:
kama-thumbnail

Installations
10,000+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Web Push Notifications � Webpushr

Plugin Slug:
webpushr-web-push-notifications

Installations
10,000+

Vulnerability:
Sensitive Data Exposure

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

CLP Varnish Cache

Plugin Slug:
clp-varnish-cache

Installations
9,000+

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

WP FullCalendar

Plugin Slug:
wp-fullcalendar

Installations
9,000+

Vulnerability:
Sensitive Data Exposure

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

WP Subscribe

Plugin Slug:
wp-subscribe

Installations
9,000+

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Booter � Bots & Crawlers Manager

Plugin Slug:
booter-bots-crawlers-manager

Installations
8,000+

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

HD Quiz

Plugin:

HD Quiz

Plugin Slug:
hd-quiz

Installations
7,000+

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Materialis Companion

Plugin Slug:
materialis-companion

Installations
7,000+

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

WP BackItUp Community Edition

Plugin Slug:
wp-backitup

Installations
7,000+

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

WP Term Order

Plugin Slug:
wp-term-order

Installations
7,000+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Monetag Official Plugin

Plugin Slug:
monetag-official

Installations
6,000+

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

BOX NOW Delivery

Plugin Slug:
box-now-delivery

Installations
5,000+

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Cloudinary � Deliver Images and Videos at Scale

Plugin Slug:
cloudinary-image-management-and-manipulation-in-the-cloud-cdn

Installations
5,000+

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Easy Property Listings

Plugin Slug:
easy-property-listings

Installations
5,000+

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Edwiser Bridge � WordPress Moodle Integration

Plugin Slug:
edwiser-bridge

Installations
5,000+

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Fraud Prevention For WooCommerce and EDD

Plugin Slug:
woo-blocker-lite-prevent-fake-orders-and-blacklist-fraud-customers

Installations
5,000+

Vulnerability:
Sensitive Data Exposure

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Ai Image Alt Text Generator for WP

Plugin Slug:
ai-image-alt-text-generator-for-wp

Installations
4,000+

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Ryviu � Product Reviews for WooCommerce

Plugin Slug:
ryviu

Installations
2,000+

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Admin login URL Change

Plugin Slug:
admin-login-url-change

Installations
1,000+

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Anything Order by Terms

Plugin Slug:
anything-order-by-terms

Installations
1,000+

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Contact Form 7 GetResponse Extension

Plugin Slug:
contact-form-7-getresponse-extension

Installations
1,000+

Vulnerability:
Sensitive Data Exposure

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

iNET Webkit

Plugin Slug:
inet-webkit

Installations
1,000+

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

SEO Booster

Plugin Slug:
seo-booster

Installations
1,000+

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

UX Flat

Plugin:

UX Flat

Plugin Slug:
ux-flat

Installations
1,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

WebP Conversion

Plugin Slug:
webp-conversion

Installations
1,000+

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Nova Blocks by Pixelgrade

Plugin Slug:
nova-blocks

Installations
900+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Omnipress

Plugin Slug:
omnipress

Installations
900+

Vulnerability:
Local File Inclusion

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Email Inquiry & Cart Options for WooCommerce

Plugin Slug:
woocommerce-email-inquiry-cart-options

Installations
900+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Quick Restaurant Reservations

Plugin Slug:
quick-restaurant-reservations

Installations
600+

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Textmetrics

Plugin Slug:
webtexttool

Installations
500+

Vulnerability:
Content Injection

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

My Post Order

Plugin Slug:
my-posts-order

Installations
400+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Table of Contents Creator

Plugin Slug:
table-of-contents-creator

Installations
400+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

iRobots.txt SEO

Plugin Slug:
irobotstxt-seo

Installations
300+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

ravpage

Plugin:

ravpage

Plugin Slug:
ravpage

Installations
300+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

amr cron manager

Plugin Slug:
amr-cron-manager

Installations
200+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

ArtPlacer Widget

Plugin Slug:
artplacer-widget

Installations
200+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

ExpressTechSoftwares Addon for MemberPress and Discord

Plugin Slug:
expresstechsoftwares-memberpress-discord-add-on

Installations
200+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

LifePress

Plugin Slug:
lifepress

Installations
200+

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Paid Downloads

Plugin Slug:
paid-downloads

Installations
100+

Vulnerability:
SQL Injection

Patched in Version:
No Fix

Severity Score:
Critical


The vulnerability has not been patched. You should deactivate the plugin.

wpCAS

Plugin:

wpCAS

Plugin Slug:
wpcas

Installations
100+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Dinatur

Plugin:

Dinatur

Plugin Slug:
dinatur

Installations
80+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

ABG Rich Pins

Plugin Slug:
abg-rich-pins

Installations
50+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Scalenut

Plugin:

Scalenut

Plugin Slug:
scalenut

Installations
40+

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

ShoutOut

Plugin:

ShoutOut

Plugin Slug:
shoutout

Installations
40+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Administrative Shortcodes

Plugin:

Administrative Shortcodes

Plugin Slug:
administrative-shortcodes

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Administrative Shortcodes

Plugin:

Administrative Shortcodes

Plugin Slug:
administrative-shortcodes

Vulnerability:
Local File Inclusion

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

AdminQuickbar

Plugin:

AdminQuickbar

Plugin Slug:
adminquickbar

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Alchemist Ajax Upload

Plugin:

Alchemist Ajax Upload

Plugin Slug:
alchemist-ajax-upload

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Alpha Blocks

Plugin:

Alpha Blocks

Plugin Slug:
alpha-blocks

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Canto Testimonials

Plugin:

Canto Testimonials

Plugin Slug:
canto-testimonials

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

CM CSS Columns

Plugin:

CM CSS Columns

Plugin Slug:
cm-css-columns

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.
Plugin:

Cookie consent for developers

Plugin Slug:
cookie-consent-for-developers

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Coven Core

Plugin:

Coven Core

Plugin Slug:
coven-core

Vulnerability:
SQL Injection

Patched in Version:
No Fix

Severity Score:
Critical


The vulnerability has not been patched. You should deactivate the plugin.

Directorist Booking

Plugin:

Directorist Booking

Plugin Slug:
directorist-booking

Vulnerability:
SQL Injection

Patched in Version:
No Fix

Severity Score:
Critical


The vulnerability has not been patched. You should deactivate the plugin.

Directorist Social Login

Plugin:

Directorist Social Login

Plugin Slug:
directorist-social-login

Vulnerability:
Privilege Escalation

Patched in Version:
No Fix

Severity Score:
Critical


The vulnerability has not been patched. You should deactivate the plugin.

E-xact Hosted Payment

Plugin:

E-xact Hosted Payment

Plugin Slug:
e-xact-hosted-payment

Vulnerability:
Arbitrary File Deletion

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Easy Theme Options

Plugin:

Easy Theme Options

Plugin Slug:
easy-theme-options

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Final User

Plugin:

Final User

Plugin Slug:
final-user

Vulnerability:
Privilege Escalation

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Final User

Plugin:

Final User

Plugin Slug:
final-user

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

fitness-trainer

Plugin:

fitness-trainer

Plugin Slug:
fitness-trainer

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

GZSEO

Plugin:

GZSEO

Plugin Slug:
gzseo

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Hospital Doctor Directory

Plugin:

Hospital Doctor Directory

Plugin Slug:
hospital-doctor-directory

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Hospital Doctor Directory

Plugin:

Hospital Doctor Directory

Plugin Slug:
hospital-doctor-directory

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Hospital Doctor Directory

Plugin:

Hospital Doctor Directory

Plugin Slug:
hospital-doctor-directory

Vulnerability:
Privilege Escalation

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Hotel Listing

Plugin:

Hotel Listing

Plugin Slug:
hotel-listing

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Hotel Listing

Plugin:

Hotel Listing

Plugin Slug:
hotel-listing

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Institutions Directory

Plugin:

Institutions Directory

Plugin Slug:
institutions-directory

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Institutions Directory

Plugin:

Institutions Directory

Plugin Slug:
institutions-directory

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Institutions Directory

Plugin:

Institutions Directory

Plugin Slug:
institutions-directory

Vulnerability:
Privilege Escalation

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Integrate Google Drive

Plugin:

Integrate Google Drive

Plugin Slug:
integrate-google-drive

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

JavaScript Notifier

Plugin:

JavaScript Notifier

Plugin Slug:
javascript-notifier

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

JobBank

Plugin:

JobBank

Plugin Slug:
jobbank

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

JustClick registration plugin

Plugin:

JustClick registration plugin

Plugin Slug:
justclick-subscriber

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Kalrav AI Agent

Plugin:

Kalrav AI Agent

Plugin Slug:
kalrav-ai-agent

Vulnerability:
Arbitrary File Upload

Patched in Version:
No Fix

Severity Score:
Critical


The vulnerability has not been patched. You should deactivate the plugin.

Lawyer Directory

Plugin:

Lawyer Directory

Plugin Slug:
lawyer-directory

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

ListingHub

Plugin:

ListingHub

Plugin Slug:
listinghub

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Login Page Editor

Plugin:

Login Page Editor

Plugin Slug:
login-page-editor

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Meta-box GalleryMeta

Plugin:

Meta-box GalleryMeta

Plugin Slug:
meta-box-gallerymeta

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
Low


The vulnerability has not been patched. You should deactivate the plugin.

Meta-box GalleryMeta

Plugin:

Meta-box GalleryMeta

Plugin Slug:
meta-box-gallerymeta

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Moderate Selected Posts

Plugin:

Moderate Selected Posts

Plugin Slug:
moderate-selected-posts

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Postalicious

Plugin:

Postalicious

Plugin Slug:
postalicious

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Radio Player

Plugin:

Radio Player

Plugin Slug:
radio-player

Vulnerability:
Server Side Request Forgery (SSRF)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Real Estate Pro

Plugin:

Real Estate Pro

Plugin Slug:
real-estate-pro

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Responsive Header

Plugin:

Responsive Header

Plugin Slug:
responsive-header

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Set Bulk Post Categories

Plugin:

Set Bulk Post Categories

Plugin Slug:
set-bulk-post-categories

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Simple Crypto Shortcodes

Plugin:

Simple Crypto Shortcodes

Plugin Slug:
simple-crypto-shortcodes

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Star Review Manager

Plugin:

Star Review Manager

Plugin Slug:
star-review-manager

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

ThemeRuby Multi Authors

Plugin:

ThemeRuby Multi Authors

Plugin Slug:
themeruby-multi-authors

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Ultra Portfolio

Plugin:

Ultra Portfolio

Plugin Slug:
ultra-portfolio

Vulnerability:
SQL Injection

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Alex User Counter

Plugin:

Alex User Counter

Plugin Slug:
user-counter

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Viet contact

Plugin:

Viet contact

Plugin Slug:
viet-contact

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

VK Google Job Posting Manager

Plugin:

VK Google Job Posting Manager

Plugin Slug:
vk-google-job-posting-manager

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Wise Analytics

Plugin:

Wise Analytics

Plugin Slug:
wise-analytics

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

WishList Member X

Plugin:

WishList Member X

Plugin Slug:
wishlist-member-x

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Wizit Gateway for WooCommerce

Plugin:

Wizit Gateway for WooCommerce

Plugin Slug:
wizit-gateway-for-woocommerce

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

WP-ClanWars

Plugin:

WP-ClanWars

Plugin Slug:
wp-clanwars

Vulnerability:
SQL Injection

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

WP Hello Bar

Plugin:

WP Hello Bar

Plugin Slug:
wp-hello-bar

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

WP Membership

Plugin:

WP Membership

Plugin Slug:
wp-membership

Vulnerability:
Privilege Escalation

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

WP Membership

Plugin:

WP Membership

Plugin Slug:
wp-membership

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.
Plugin:

WP Youtube Video Gallery

Plugin Slug:
wp-youtube-video-gallery

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

ZT Captcha

Plugin:

ZT Captcha

Plugin Slug:
zt-captcha

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

The Events Calendar

Plugin Slug:
the-events-calendar

Installations
700,000+

Vulnerability:
Broken Access Control

Patched in Version:
6.15.13.1

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 6.15.13.1.

Happy Addons for Elementor

Plugin Slug:
happy-elementor-addons

Installations
400,000+

Vulnerability:
SQL Injection

Patched in Version:
3.20.6

Severity Score:
High


The vulnerability has been patched, so you should update to version 3.20.6.

Custom Fonts � Host Your Fonts Locally

Plugin Slug:
custom-fonts

Installations
300,000+

Vulnerability:
Broken Access Control

Patched in Version:
2.1.17

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.1.17.

Newsletter � Send awesome emails from WordPress

Plugin Slug:
newsletter

Installations
300,000+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
9.1.1

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 9.1.1.

WP Go Maps (formerly WP Google Maps)

Plugin Slug:
wp-google-maps

Installations
300,000+

Vulnerability:
Broken Access Control

Patched in Version:
10.0.05

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 10.0.05.

Advanced Custom Fields: Extended

Plugin Slug:
acf-extended

Installations
100,000+

Vulnerability:
Privilege Escalation

Patched in Version:
0.9.2.2

Severity Score:
Critical


The vulnerability has been patched, so you should update to version 0.9.2.2.

BuddyPress

Plugin Slug:
buddypress

Installations
100,000+

Vulnerability:
Arbitrary Code Execution

Patched in Version:
14.3.4

Severity Score:
High


The vulnerability has been patched, so you should update to version 14.3.4.

Schema & Structured Data for WP & AMP

Plugin Slug:
schema-and-structured-data-for-wp

Installations
100,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.54.1

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.54.1.

Tutor LMS � eLearning and online course solution

Plugin Slug:
tutor

Installations
100,000+

Vulnerability:
Broken Access Control

Patched in Version:
3.9.5

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 3.9.5.

User Registration & Membership � Custom Registration Form Builder, Custom Login Form, User Profile, Content Restriction & Membership Plugin

Plugin Slug:
user-registration

Installations
60,000+

Vulnerability:
Broken Access Control

Patched in Version:
4.4.7

Severity Score:
High


The vulnerability has been patched, so you should update to version 4.4.7.

NotificationX � FOMO, Live Sales Notification, WooCommerce Sales Popup, GDPR, Social Proof, Announcement Banner & Floating Notification Bar

Plugin Slug:
notificationx

Installations
40,000+

Vulnerability:
Broken Access Control

Patched in Version:
3.2.1

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 3.2.1.

NotificationX � FOMO, Live Sales Notification, WooCommerce Sales Popup, GDPR, Social Proof, Announcement Banner & Floating Notification Bar

Plugin Slug:
notificationx

Installations
40,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
3.2.1

Severity Score:
High


The vulnerability has been patched, so you should update to version 3.2.1.

MailerLite � WooCommerce integration

Plugin Slug:
woo-mailerlite

Installations
30,000+

Vulnerability:
SQL Injection

Patched in Version:
3.1.3

Severity Score:
Critical


The vulnerability has been patched, so you should update to version 3.1.3.

Xpro Addons � 140+ Widgets for Elementor

Plugin Slug:
xpro-elementor-addons

Installations
30,000+

Vulnerability:
Arbitrary File Upload

Patched in Version:
1.4.20

Severity Score:
Critical


The vulnerability has been patched, so you should update to version 1.4.20.
Plugin Slug:
all-in-one-video-gallery

Installations
20,000+

Vulnerability:
Broken Access Control

Patched in Version:
4.7.1

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 4.7.1.
Plugin Slug:
all-in-one-video-gallery

Installations
20,000+

Vulnerability:
Broken Access Control

Patched in Version:
4.7.1

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 4.7.1.
Plugin Slug:
final-tiles-grid-gallery-lite

Installations
20,000+

Vulnerability:
Broken Access Control

Patched in Version:
3.6.10

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 3.6.10.

UPI QR Code Payment Gateway for WooCommerce

Plugin Slug:
upi-qr-code-payment-for-woocommerce

Installations
20,000+

Vulnerability:
Broken Access Control

Patched in Version:
1.6.1

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.6.1.

Demo Importer Plus

Plugin Slug:
demo-importer-plus

Installations
10,000+

Vulnerability:
Remote Code Execution (RCE)

Patched in Version:
2.0.10

Severity Score:
High


The vulnerability has been patched, so you should update to version 2.0.10.

FlatPM � Ad Manager, AdSense and Custom Code

Plugin Slug:
flatpm-wp

Installations
10,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
3.2.3

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 3.2.3.

Head Meta Data

Plugin Slug:
head-meta-data

Installations
10,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
20260105

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 20260105.

LA-Studio Element Kit for Elementor

Plugin Slug:
lastudio-element-kit

Installations
10,000+

Vulnerability:
Backdoor

Patched in Version:
1.6.0

Severity Score:
Critical


The vulnerability has been patched, so you should update to version 1.6.0.

Nexter Extension � Site Enhancements Toolkit

Plugin Slug:
nexter-extension

Installations
10,000+

Vulnerability:
PHP Object Injection

Patched in Version:
4.4.7

Severity Score:
Critical


The vulnerability has been patched, so you should update to version 4.4.7.

Recipe Card Blocks Lite

Plugin Slug:
recipe-card-blocks-by-wpzoom

Installations
10,000+

Vulnerability:
SQL Injection

Patched in Version:
3.4.13

Severity Score:
High


The vulnerability has been patched, so you should update to version 3.4.13.

WP DSGVO Tools (GDPR)

Plugin Slug:
shapepress-dsgvo

Installations
10,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
3.1.37

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 3.1.37.
Plugin Slug:
automatic-featured-images-from-videos

Installations
8,000+

Vulnerability:
Broken Access Control

Patched in Version:
1.2.8

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.2.8.

Protecci�n de datos � RGPD

Plugin Slug:
proteccion-datos-rgpd

Installations
7,000+

Vulnerability:
Broken Access Control

Patched in Version:
0.69

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 0.69.

Poll, Survey & Quiz Maker Plugin by Opinion Stage

Plugin Slug:
social-polls-by-opinionstage

Installations
7,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
19.6.25

Severity Score:
High


The vulnerability has been patched, so you should update to version 19.6.25.

Media Library File Size

Plugin Slug:
media-library-file-size

Installations
5,000+

Vulnerability:
Broken Access Control

Patched in Version:
1.6.8

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.6.8.

Booking Activities

Plugin Slug:
booking-activities

Installations
4,000+

Vulnerability:
Privilege Escalation

Patched in Version:
1.16.45

Severity Score:
High


The vulnerability has been patched, so you should update to version 1.16.45.

Tabby Checkout

Plugin Slug:
tabby-checkout

Installations
4,000+

Vulnerability:
Sensitive Data Exposure

Patched in Version:
5.9.1

Severity Score:
High


The vulnerability has been patched, so you should update to version 5.9.1.

AIKTP

Plugin:

AIKTP

Plugin Slug:
aiktp

Installations
3,000+

Vulnerability:
Broken Access Control

Patched in Version:
5.0.05

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 5.0.05.

Frontis Blocks � Block Library for the Block Editor

Plugin Slug:
frontis-blocks

Installations
3,000+

Vulnerability:
Server Side Request Forgery (SSRF)

Patched in Version:
1.1.7

Severity Score:
High


The vulnerability has been patched, so you should update to version 1.1.7.

Frontis Blocks � Block Library for the Block Editor

Plugin Slug:
frontis-blocks

Installations
3,000+

Vulnerability:
Server Side Request Forgery (SSRF)

Patched in Version:
1.1.6

Severity Score:
High


The vulnerability has been patched, so you should update to version 1.1.6.
Plugin Slug:
photoblocks-grid-gallery

Installations
3,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.3.3

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.3.3.

Salon Booking System � Free Version

Plugin Slug:
salon-booking-system

Installations
3,000+

Vulnerability:
Sensitive Data Exposure

Patched in Version:
10.30.4

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 10.30.4.

Same Category Posts

Plugin Slug:
same-category-posts

Installations
3,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.1.20

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.1.20.

WP Directory Kit

Plugin Slug:
wpdirectorykit

Installations
3,000+

Vulnerability:
Sensitive Data Exposure

Patched in Version:
1.5.0

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.5.0.

KiviCare � Clinic & Patient Management System (EHR)

Plugin Slug:
kivicare-clinic-management-system

Installations
2,000+

Vulnerability:
Broken Access Control

Patched in Version:
3.6.16

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 3.6.16.

Wallet System for WooCommerce � Digital Wallet, Buy Now Pay Later (BNPL), Instant Cashback, Referral program, Partial & Subscription Payments

Plugin Slug:
wallet-system-for-woocommerce

Installations
2,000+

Vulnerability:
Broken Access Control

Patched in Version:
2.7.3

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.7.3.

ElementCamp

Plugin Slug:
element-camp

Installations
1,000+

Vulnerability:
Broken Access Control

Patched in Version:
2.3.6

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.3.6.

Friendly Functions for Welcart

Plugin Slug:
friendly-functions-for-welcart

Installations
1,000+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
1.2.6

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.2.6.
Plugin Slug:
ninja-gdpr-compliance

Installations
1,000+

Vulnerability:
Broken Access Control

Patched in Version:
2.7.5

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.7.5.

Quick Contact Form

Plugin Slug:
quick-contact-form

Installations
1,000+

Vulnerability:
Broken Access Control

Patched in Version:
8.2.7

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 8.2.7.

Broadstreet

Plugin Slug:
broadstreet

Installations
700+

Vulnerability:
Broken Access Control

Patched in Version:
1.52.2

Severity Score:
High


The vulnerability has been patched, so you should update to version 1.52.2.

My auctions allegro

Plugin Slug:
my-auctions-allegro-free-edition

Installations
600+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
3.6.33

Severity Score:
High


The vulnerability has been patched, so you should update to version 3.6.33.

TaxCloud for WooCommerce

Plugin Slug:
simple-sales-tax

Installations
500+

Vulnerability:
Broken Access Control

Patched in Version:
8.4.0

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 8.4.0.

TableOn � WordPress Posts Table Filterable�

Plugin Slug:
posts-table-filterable

Installations
300+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.0.4.3

Severity Score:
High


The vulnerability has been patched, so you should update to version 1.0.4.3.

Thim Blocks

Plugin Slug:
thim-blocks

Installations
300+

Vulnerability:
Arbitrary File Download

Patched in Version:
1.0.2

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.0.2.
Plugin Slug:
invoice-payment-for-woocommerce

Installations
200+

Vulnerability:
Broken Access Control

Patched in Version:
2.8.1

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.8.1.

Melapress Role Editor

Plugin Slug:
melapress-role-editor

Installations
50+

Vulnerability:
Privilege Escalation

Patched in Version:
1.2.0

Severity Score:
High


The vulnerability has been patched, so you should update to version 1.2.0.

AdForest Elementor

Plugin:

AdForest Elementor

Plugin Slug:
adforest-elementor

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
3.0.12

Severity Score:
High


The vulnerability has been patched, so you should update to version 3.0.12.

Homey Core

Plugin:

Homey Core

Plugin Slug:
homey-core

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.4.4

Severity Score:
High


The vulnerability has been patched, so you should update to version 2.4.4.

Kentha Elementor Widgets

Plugin:

Kentha Elementor Widgets

Plugin Slug:
kentha-elementor

Vulnerability:
Local File Inclusion

Patched in Version:
3.1

Severity Score:
High


The vulnerability has been patched, so you should update to version 3.1.

Lawyer Directory

Plugin:

Lawyer Directory

Plugin Slug:
lawyer-directory

Vulnerability:
Broken Access Control

Patched in Version:
1.3.4

Severity Score:
High


The vulnerability has been patched, so you should update to version 1.3.4.

Lawyer Directory

Plugin:

Lawyer Directory

Plugin Slug:
lawyer-directory

Vulnerability:
Privilege Escalation

Patched in Version:
1.3.4

Severity Score:
High


The vulnerability has been patched, so you should update to version 1.3.4.

Listivo Core

Plugin:

Listivo Core

Plugin Slug:
listivo-core

Vulnerability:
Local File Inclusion

Patched in Version:
2.3.78

Severity Score:
High


The vulnerability has been patched, so you should update to version 2.3.78.

Movie Booking

Plugin:

Movie Booking

Plugin Slug:
movie-booking

Vulnerability:
Arbitrary File Deletion

Patched in Version:
1.1.6

Severity Score:
High


The vulnerability has been patched, so you should update to version 1.1.6.

MyHome Core

Plugin:

MyHome Core

Plugin Slug:
myhome-core

Vulnerability:
Local File Inclusion

Patched in Version:
4.1.1

Severity Score:
High


The vulnerability has been patched, so you should update to version 4.1.1.

Real Homes CRM

Plugin:

Real Homes CRM

Plugin Slug:
realhomes-crm

Vulnerability:
Arbitrary File Upload

Patched in Version:
1.0.1

Severity Score:
Critical


The vulnerability has been patched, so you should update to version 1.0.1.

Schedula � Smart Appointment Booking

Plugin Slug:
schedula-smart-appointment-booking

Vulnerability:
Broken Access Control

Patched in Version:
1.1

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.1.

WorkScout-Core

Plugin:

WorkScout-Core

Plugin Slug:
workscout-core

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.7.07

Severity Score:
High


The vulnerability has been patched, so you should update to version 1.7.07.

YouTube Feed Pro

Plugin:

YouTube Feed Pro

Plugin Slug:
youtube-feed-pro

Vulnerability:
Arbitrary File Download

Patched in Version:
2.6.1

Severity Score:
High


The vulnerability has been patched, so you should update to version 2.6.1.

WordPress Themes � 13 Patched / 5 Unpatched

EcoBlue

Theme:

EcoBlue

Theme Slug:
ecoblue

Vulnerability:
Local File Inclusion

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should switch themes.

Enfold

Theme:

Enfold

Theme Slug:
enfold

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should switch themes.

Listihub

Theme:

Listihub

Theme Slug:
listihub

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should switch themes.

PeakShops

Theme:

PeakShops

Theme Slug:
peakshops

Vulnerability:
PHP Object Injection

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should switch themes.

Prowess

Theme:

Prowess

Theme Slug:
prowess

Vulnerability:
Local File Inclusion

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should switch themes.

AdForest

Theme:

AdForest

Theme Slug:
adforest

Vulnerability:
Local File Inclusion

Patched in Version:
6.0.12

Severity Score:
High


The vulnerability has been patched, so you should update to version 6.0.12.

CarSpot

Theme:

CarSpot

Theme Slug:
carspot

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.4.6

Severity Score:
High


The vulnerability has been patched, so you should update to version 2.4.6.

Craft

Theme:

Craft

Theme Slug:
craftcoffee

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.3.7

Severity Score:
High


The vulnerability has been patched, so you should update to version 2.3.7.

DotLife

Theme:

DotLife

Theme Slug:
dotlife

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
4.9.5

Severity Score:
High


The vulnerability has been patched, so you should update to version 4.9.5.

Grand Magazine

Theme:

Grand Magazine

Theme Slug:
grandmagazine

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
3.5.8

Severity Score:
High


The vulnerability has been patched, so you should update to version 3.5.8.

Grand Spa

Theme:

Grand Spa

Theme Slug:
grandspa

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
3.5.6

Severity Score:
High


The vulnerability has been patched, so you should update to version 3.5.6.

Grand Tour

Theme:

Grand Tour

Theme Slug:
grandtour

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
5.6.2

Severity Score:
High


The vulnerability has been patched, so you should update to version 5.6.2.

Hostiko

Theme:

Hostiko

Theme Slug:
hostiko

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
94.3.6

Severity Score:
High


The vulnerability has been patched, so you should update to version 94.3.6.

Hoteller

Theme:

Hoteller

Theme Slug:
hoteller

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
6.8.9

Severity Score:
High


The vulnerability has been patched, so you should update to version 6.8.9.

PeakShops

Theme:

PeakShops

Theme Slug:
peakshops

Vulnerability:
Local File Inclusion

Patched in Version:
1.5.9

Severity Score:
High


The vulnerability has been patched, so you should update to version 1.5.9.

Traveler

Theme:

Traveler

Theme Slug:
traveler

Vulnerability:
SQL Injection

Patched in Version:
3.2.8

Severity Score:
High


The vulnerability has been patched, so you should update to version 3.2.8.

Werkstatt

Theme:

Werkstatt

Theme Slug:
werkstatt

Vulnerability:
Local File Inclusion

Patched in Version:
4.8.3

Severity Score:
High


The vulnerability has been patched, so you should update to version 4.8.3.

WorkScout

Theme:

WorkScout

Theme Slug:
workscout

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
4.1.08

Severity Score:
High


The vulnerability has been patched, so you should update to version 4.1.08.

Related articles

Wait! Get exclusive hosting insights

Subscribe to our newsletter and stay ahead of the competition with expert advice from our hosting pros.

Loading form…