Line illustration showing a black application window on a dark purple gradient background overlaid with a large exclamation point alert icon and three bugs.

WordPress Vulnerability Report � July 23, 2025

In this report, 167 vulnerabilities have been publicly disclosed. Security patches for 125 of these plugins and themes are available now, so run those updates as soon as possible. If you’re a Solid Security Pro user, the version management tool may have already warned you and updated these plugins, depending on your settings.

Additionally, there are 42 plugin and theme vulnerabilities, and no patch has been available yet. If you’re a Solid Security Pro user, those vulnerabilities are already protected by the Solid Security firewall. Virtual patches from Patchstack will be applied when a vulnerability is considered high or medium risk. If no patch is forthcoming from the vendor or the vulnerable software has been marked “closed” and dropped from the official WordPress repositories, you should deactivate it soon and look for alternative solutions.

WordPress Core

WordPress 6.8.2 is now available! This maintenance release includes fixes for 20 Core tickets and 15 Block Editor issues. For a full list of bug fixes, please refer to the release candidate announcement.

WordPress Plugins � 121 Patched / 41 Unpatched

URL Shortener Plugin For WordPress

Plugin Slug:
exact-links

Installations
600+

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

DB Backup

Plugin Slug:
db-backup

Installations
100+

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Nginx Cache Purge Preload

Plugin Slug:
fastcgi-cache-purge-and-preload-nginx

Installations
80+

Vulnerability:
Remote Code Execution (RCE)

Patched in Version:
No Fix

Severity Score:
Critical


The vulnerability has not been patched. You should deactivate the plugin.
Plugin Slug:
block-editor-gallery-slider

Installations
40+

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

aapanel WP Toolkit

Plugin:

aapanel WP Toolkit

Plugin Slug:
aapanel-wp-toolkit

Vulnerability:
Privilege Escalation

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Affiliate Reviews

Plugin:

Affiliate Reviews

Plugin Slug:
affiliate-reviews

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Alike – WordPress Custom Post Comparison

Plugin:

Alike – WordPress Custom Post Comparison

Plugin Slug:
alike

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Attachment Manager

Plugin:

Attachment Manager

Plugin Slug:
attachment-manager

Vulnerability:
Arbitrary File Deletion

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Avishi WP PayPal Payment Button

Plugin:

Avishi WP PayPal Payment Button

Plugin Slug:
avishi-wp-paypal-payment-button

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Amazon Affiliates Addon for WPBakery Page Builder (formerly Visual Composer)

Plugin:

Amazon Affiliates Addon for WPBakery Page Builder (formerly Visual Composer)

Plugin Slug:
azon-addon-js-composer

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

B1.lt for WooCommerce

Plugin:

B1.lt for WooCommerce

Plugin Slug:
b1-accounting

Vulnerability:
SQL Injection

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Birth Chart Compatibility

Plugin:

Birth Chart Compatibility

Plugin Slug:
birth-chart-compatibility

Vulnerability:
Full Path Disclosure (FPD)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Biteship

Plugin:

Biteship

Plugin Slug:
biteship

Vulnerability:
Insecure Direct Object References (IDOR)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Brandfolder

Plugin:

Brandfolder

Plugin Slug:
brandfolder

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

bSecure – Your Universal Checkout

Plugin:

bSecure – Your Universal Checkout

Plugin Slug:
bsecure

Vulnerability:
Privilege Escalation

Patched in Version:
No Fix

Severity Score:
Critical


The vulnerability has not been patched. You should deactivate the plugin.

Copymatic

Plugin:

Copymatic

Plugin Slug:
copymatic

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Counter live visitors for WooCommerce

Plugin:

Counter live visitors for WooCommerce

Plugin Slug:
counter-visitor-for-woocommerce

Vulnerability:
Arbitrary File Deletion

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Crowdfunding for WooCommerce

Plugin:

Crowdfunding for WooCommerce

Plugin Slug:
crowdfunding-for-woocommerce

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

FoodMenu

Plugin:

FoodMenu

Plugin Slug:
dzs-restaurantmenu

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

WooCommerce Shop Page Builder

Plugin:

WooCommerce Shop Page Builder

Plugin Slug:
dzs-wootable

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

EPay.bg Payments

Plugin:

EPay.bg Payments

Plugin Slug:
epaybg-payments

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

IDonatePro

Plugin:

IDonatePro

Plugin Slug:
idonate-pro

Vulnerability:
Local File Inclusion

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Latest Post Accordian Slider

Plugin:

Latest Post Accordian Slider

Plugin Slug:
latest-post-accordian-slider

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Multimedia Playlist Slider Addon for WPBakery Page Builder

Plugin:

Multimedia Playlist Slider Addon for WPBakery Page Builder

Plugin Slug:
lbg_vp_youtube_vimeo_addon_visual_composer

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Like & Share My Site

Plugin:

Like & Share My Site

Plugin Slug:
like-share-my-site

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Listly

Plugin:

Listly

Plugin Slug:
listly

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Live Stream Badger

Plugin:

Live Stream Badger

Plugin Slug:
live-stream-badger

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Map My Locations

Plugin:

Map My Locations

Plugin Slug:
map-my-locations

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Partnersk� syst�m Martinus

Plugin:

Partnersk� syst�m Martinus

Plugin Slug:
martinus-partnersky-system

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Mediabay – WordPress Media Library Folders

Plugin:

Mediabay – WordPress Media Library Folders

Plugin Slug:
mediabay

Vulnerability:
SQL Injection

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Orion Login with SMS

Plugin:

Orion Login with SMS

Plugin Slug:
orion-login-with-sms

Vulnerability:
Broken Authentication

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

The E-Commerce ERP

Plugin:

The E-Commerce ERP

Plugin Slug:
profitori

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Restrict File Access

Plugin:

Restrict File Access

Plugin Slug:
restrict-file-access

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Ruven Themes: Shortcodes

Plugin:

Ruven Themes: Shortcodes

Plugin Slug:
ruven-themes-shortcodes

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Temporarily Hidden Content

Plugin:

Temporarily Hidden Content

Plugin Slug:
temporarily-hidden-content

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Terms descriptions

Plugin:

Terms descriptions

Plugin Slug:
terms-descriptions

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Testimonial Post type

Plugin:

Testimonial Post type

Plugin Slug:
testimonial-post-type

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Useful Tab Block

Plugin:

Useful Tab Block

Plugin Slug:
useful-tab-block-responsive-amp-compatible

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.
Plugin:

Vertical scroll image slideshow gallery

Plugin Slug:
vertical-scroll-image-slideshow-gallery

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

WP JobHunt

Plugin:

WP JobHunt

Plugin Slug:
wp-jobhunt

Vulnerability:
Insecure Direct Object References (IDOR)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Zuppler Online Ordering

Plugin:

Zuppler Online Ordering

Plugin Slug:
zuppler-online-ordering

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

WP Shortcodes Plugin � Shortcodes Ultimate

Plugin Slug:
shortcodes-ultimate

Installations
500,000+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
7.4.3

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 7.4.3.

WP Shortcodes Plugin � Shortcodes Ultimate

Plugin Slug:
shortcodes-ultimate

Installations
500,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
7.4.3

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 7.4.3.

Post SMTP � WP SMTP Plugin with Email Logs and Mobile App for Failure Notifications � Gmail SMTP, Office 365, Brevo, Mailgun, Amazon SES and more

Plugin Slug:
post-smtp

Installations
400,000+

Vulnerability:
Broken Authentication

Patched in Version:
3.3.0

Severity Score:
High


The vulnerability has been patched, so you should update to version 3.3.0.

Strong Testimonials

Plugin Slug:
strong-testimonials

Installations
100,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
3.2.12

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 3.2.12.

JetFormBuilder � Dynamic Blocks Form Builder

Plugin Slug:
jetformbuilder

Installations
80,000+

Vulnerability:
PHP Object Injection

Patched in Version:
3.5.2

Severity Score:
High


The vulnerability has been patched, so you should update to version 3.5.2.

Media Library Assistant

Plugin Slug:
media-library-assistant

Installations
70,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
3.27

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 3.27.

User Registration & Membership � Custom Registration Form Builder, Custom Login Form, User Profile, Content Restriction & Membership Plugin

Plugin Slug:
user-registration

Installations
60,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
4.3.0

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 4.3.0.

WP-Members Membership Plugin

Plugin Slug:
wp-members

Installations
60,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
3.5.4.2

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 3.5.4.2.

Bold Page Builder

Plugin Slug:
bold-page-builder

Installations
50,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
5.4.2

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 5.4.2.

Companion Auto Update

Plugin Slug:
companion-auto-update

Installations
50,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
3.9.3

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 3.9.3.

Stop User Enumeration

Plugin Slug:
stop-user-enumeration

Installations
50,000+

Vulnerability:
Bypass Vulnerability

Patched in Version:
1.7.3

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.7.3.

SMTP2GO for WordPress � Email Made Easy

Plugin Slug:
smtp2go

Installations
20,000+

Vulnerability:
Broken Access Control

Patched in Version:
1.12.2

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.12.2.

Welcart e-Commerce

Plugin Slug:
usc-e-shop

Installations
20,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.11.17

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.11.17.

Videopack

Plugin Slug:
video-embed-thumbnail-generator

Installations
10,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
4.10.4

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 4.10.4.

AntiSpam for Contact Form 7

Plugin Slug:
cf7-antispam

Installations
9,000+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
0.6.4

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 0.6.4.

ProfileGrid � User Profiles, Groups and Communities

Plugin Slug:
profilegrid-user-profiles-groups-and-communities

Installations
7,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
5.9.5.5

Severity Score:
High


The vulnerability has been patched, so you should update to version 5.9.5.5.

Coupon Affiliates � Affiliate Plugin for WooCommerce

Plugin Slug:
woo-coupon-usage

Installations
5,000+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
6.4.1

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 6.4.1.

WPAdverts � Classifieds Plugin

Plugin Slug:
wpadverts

Installations
5,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.2.6

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.2.6.

ELEX WooCommerce Bulk Edit Products, Prices & Attributes (Basic)

Plugin Slug:
elex-bulk-edit-products-prices-attributes-for-woocommerce-basic

Installations
4,000+

Vulnerability:
SQL Injection

Patched in Version:
1.5.0

Severity Score:
High


The vulnerability has been patched, so you should update to version 1.5.0.

GSheetConnector for WC

Plugin Slug:
wc-gsheetconnector

Installations
4,000+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
1.4.0

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.4.0.

Restaurant Menu and Food Ordering

Plugin Slug:
mp-restaurant-menu

Installations
3,000+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
2.4.7

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.4.7.

News Kit Elementor Addons

Plugin Slug:
news-kit-elementor-addons

Installations
3,000+

Vulnerability:
Broken Access Control

Patched in Version:
1.3.5

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.3.5.

Newsletters

Plugin Slug:
newsletters-lite

Installations
3,000+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
4.11

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 4.11.

Animator � Scroll Triggered Animations

Plugin Slug:
scroll-triggered-animations

Installations
3,000+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
3.0.17

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 3.0.17.

SMTP for Amazon SES � YaySMTP

Plugin Slug:
smtp-amazon-ses

Installations
3,000+

Vulnerability:
SQL Injection

Patched in Version:
1.9.1

Severity Score:
High


The vulnerability has been patched, so you should update to version 1.9.1.

Theme Builder For Elementor

Plugin Slug:
theme-builder-for-elementor

Installations
3,000+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
1.2.4

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.2.4.

Wallet System for WooCommerce

Plugin Slug:
wallet-system-for-woocommerce

Installations
3,000+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
2.6.8

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.6.8.

WP Post Hide

Plugin Slug:
wp-post-hide

Installations
3,000+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
1.1.0

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.1.0.

Widget for Google Reviews

Plugin Slug:
business-reviews-wp

Installations
1,000+

Vulnerability:
Local File Inclusion

Patched in Version:
1.0.16

Severity Score:
High


The vulnerability has been patched, so you should update to version 1.0.16.

Custom API for WP

Plugin Slug:
custom-api-for-wp

Installations
1,000+

Vulnerability:
SQL Injection

Patched in Version:
4.2.3

Severity Score:
Critical


The vulnerability has been patched, so you should update to version 4.2.3.

Easy Elementor Addons

Plugin Slug:
easy-elementor-addons

Installations
1,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.2.6

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.2.6.

Ebook Store

Plugin Slug:
ebook-store

Installations
1,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
5.8013

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 5.8013.

SMTP for SendGrid � YaySMTP

Plugin Slug:
smtp-sendgrid

Installations
1,000+

Vulnerability:
SQL Injection

Patched in Version:
1.5.1

Severity Score:
High


The vulnerability has been patched, so you should update to version 1.5.1.

YayExtra � WooCommerce Extra Product Options

Plugin Slug:
yayextra

Installations
1,000+

Vulnerability:
SQL Injection

Patched in Version:
1.5.6

Severity Score:
High


The vulnerability has been patched, so you should update to version 1.5.6.

FG Drupal to WordPress

Plugin Slug:
fg-drupal-to-wp

Installations
900+

Vulnerability:
Server Side Request Forgery (SSRF)

Patched in Version:
3.90.1

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 3.90.1.

Ultimate WP Mail

Plugin Slug:
ultimate-wp-mail

Installations
900+

Vulnerability:
Privilege Escalation

Patched in Version:
1.3.7

Severity Score:
High


The vulnerability has been patched, so you should update to version 1.3.7.

Maya Business Plugin

Plugin Slug:
paymaya-checkout-for-woocommerce

Installations
600+

Vulnerability:
Insecure Direct Object References (IDOR)

Patched in Version:
1.3.0

Severity Score:
High


The vulnerability has been patched, so you should update to version 1.3.0.

Stop and Block bots plugin Anti bots

Plugin Slug:
antibots

Installations
500+

Vulnerability:
Broken Access Control

Patched in Version:
1.50

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.50.

Chatbox Manager

Plugin Slug:
wa-chatbox-manager

Installations
500+

Vulnerability:
Broken Access Control

Patched in Version:
1.2.6

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.2.6.

SMTP for Sendinblue � YaySMTP

Plugin Slug:
smtp-sendinblue

Installations
400+

Vulnerability:
SQL Injection

Patched in Version:
1.3.1

Severity Score:
High


The vulnerability has been patched, so you should update to version 1.3.1.

Formality

Plugin Slug:
formality

Installations
200+

Vulnerability:
Local File Inclusion

Patched in Version:
1.5.10

Severity Score:
High


The vulnerability has been patched, so you should update to version 1.5.10.

Image Wall

Plugin Slug:
image-wall

Installations
200+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
3.2

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 3.2.

Residential Address Detection

Plugin Slug:
residential-address-detection

Installations
200+

Vulnerability:
Broken Access Control

Patched in Version:
2.5.10

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.5.10.

Cloud SAML SSO � Single Sign On Login

Plugin Slug:
cloud-sso-single-sign-on

Installations
100+

Vulnerability:
Local File Inclusion

Patched in Version:
1.0.19

Severity Score:
High


The vulnerability has been patched, so you should update to version 1.0.19.

CRM and Lead Management by vcita

Plugin Slug:
crm-customer-relationship-management-by-vcita

Installations
100+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.8.0

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.8.0.

Import CDN-Remote Images

Plugin Slug:
import-cdn-remote-images

Installations
100+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
2.1.3

Severity Score:
High


The vulnerability has been patched, so you should update to version 2.1.3.

Knowledge Base

Plugin Slug:
knowledgebase

Installations
100+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.3.2

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.3.2.

MORKVA Vchasno Kasa Integration

Plugin Slug:
mrkv-vchasno-kasa

Installations
30+

Vulnerability:
Broken Access Control

Patched in Version:
1.0.4

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.0.4.

MORKVA Vchasno Kasa Integration

Plugin Slug:
mrkv-vchasno-kasa

Installations
30+

Vulnerability:
Broken Access Control

Patched in Version:
1.0.4

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.0.4.

Bears Backup

Plugin:

Bears Backup

Plugin Slug:
bears-backup

Vulnerability:
Remote Code Execution (RCE)

Patched in Version:
2.1.0

Severity Score:
Critical


The vulnerability has been patched, so you should update to version 2.1.0.

Foxypress

Plugin:

Foxypress

Plugin Slug:
foxypress

Vulnerability:
Arbitrary File Upload

Patched in Version:
0.4.2.2

Severity Score:
Critical


The vulnerability has been patched, so you should update to version 0.4.2.2.

Fusion Builder

Plugin:

Fusion Builder

Plugin Slug:
fusion-builder

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
3.12.2

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 3.12.2.

GymBase Theme Classes

Plugin:

GymBase Theme Classes

Plugin Slug:
gymbase_classes

Vulnerability:
SQL Injection

Patched in Version:
1.5

Severity Score:
High


The vulnerability has been patched, so you should update to version 1.5.

JetBlocks For Elementor

Plugin:

JetBlocks For Elementor

Plugin Slug:
jet-blocks

Vulnerability:
Sensitive Data Exposure

Patched in Version:
1.3.19

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.3.19.

JetBlocks For Elementor

Plugin:

JetBlocks For Elementor

Plugin Slug:
jet-blocks

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.3.19.1

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.3.19.1.

JetElements For Elementor

Plugin:

JetElements For Elementor

Plugin Slug:
jet-elements

Vulnerability:
Sensitive Data Exposure

Patched in Version:
2.7.7.1

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.7.7.1.

JetElements For Elementor

Plugin:

JetElements For Elementor

Plugin Slug:
jet-elements

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.7.7.1

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.7.7.1.

JetEngine

Plugin:

JetEngine

Plugin Slug:
jet-engine

Vulnerability:
Sensitive Data Exposure

Patched in Version:
3.7.1.1

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 3.7.1.1.

JetMenu

Plugin:

JetMenu

Plugin Slug:
jet-menu

Vulnerability:
Sensitive Data Exposure

Patched in Version:
2.4.11.2

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.4.11.2.

JetPopup

Plugin:

JetPopup

Plugin Slug:
jet-popup

Vulnerability:
Sensitive Data Exposure

Patched in Version:
2.0.15.1

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.0.15.1.

JetPopup

Plugin:

JetPopup

Plugin Slug:
jet-popup

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.0.16

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.0.16.

JetPopup

Plugin:

JetPopup

Plugin Slug:
jet-popup

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.0.15.1

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.0.15.1.

JetSearch

Plugin:

JetSearch

Plugin Slug:
jet-search

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
3.5.11

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 3.5.11.

JetSmartFilters

Plugin:

JetSmartFilters

Plugin Slug:
jet-smart-filters

Vulnerability:
Sensitive Data Exposure

Patched in Version:
3.6.7.1

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 3.6.7.1.

JetSmartFilters

Plugin:

JetSmartFilters

Plugin Slug:
jet-smart-filters

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
3.6.8.1

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 3.6.8.1.

JetTabs

Plugin:

JetTabs

Plugin Slug:
jet-tabs

Vulnerability:
Sensitive Data Exposure

Patched in Version:
2.2.9.1

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.2.9.1.

JetTabs

Plugin:

JetTabs

Plugin Slug:
jet-tabs

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.2.9.1

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.2.9.1.

JetTricks

Plugin:

JetTricks

Plugin Slug:
jet-tricks

Vulnerability:
Sensitive Data Exposure

Patched in Version:
1.5.4.2

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.5.4.2.

JetTricks

Plugin:

JetTricks

Plugin Slug:
jet-tricks

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.5.4.2

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.5.4.2.

JetWooBuilder

Plugin:

JetWooBuilder

Plugin Slug:
jet-woo-builder

Vulnerability:
Sensitive Data Exposure

Patched in Version:
2.1.20.1

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.1.20.1.

Radio Player Shoutcast & Icecast

Plugin:

Radio Player Shoutcast & Icecast

Plugin Slug:
lbg-audio4-html5-shoutcast

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
4.4.8

Severity Score:
High


The vulnerability has been patched, so you should update to version 4.4.8.

Apollo – Sticky Full Width HTML5 Audio Player

Plugin:

Apollo – Sticky Full Width HTML5 Audio Player

Plugin Slug:
lbg-audio5-html5-shoutcast-sticky

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
3.6.4

Severity Score:
High


The vulnerability has been patched, so you should update to version 3.6.4.

SHOUT – HTML5 Radio Player With Ads – ShoutCast and IceCast Support

Plugin:

SHOUT – HTML5 Radio Player With Ads – ShoutCast and IceCast Support

Plugin Slug:
lbg-audio8-html5-radio-ads

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
3.5.5

Severity Score:
High


The vulnerability has been patched, so you should update to version 3.5.5.

Universal Video Player – Addon for WPBakery Page Builder

Plugin:

Universal Video Player – Addon for WPBakery Page Builder

Plugin Slug:
lbg-universal-video-player-addon-visual-composer

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
3.2.2.0

Severity Score:
High


The vulnerability has been patched, so you should update to version 3.2.2.0.

HTML5 Radio Player – WPBakery Page Builder Addon

Plugin:

HTML5 Radio Player – WPBakery Page Builder Addon

Plugin Slug:
lbg_radio_player_addon_visual_composer

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.5.2

Severity Score:
High


The vulnerability has been patched, so you should update to version 2.5.2.

Universal Video Player – Addon for WPBakery Page Builder

Plugin:

Universal Video Player – Addon for WPBakery Page Builder

Plugin Slug:
lbg_universal_video_player_addon_visual_composer

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
3.2.2.0

Severity Score:
High


The vulnerability has been patched, so you should update to version 3.2.2.0.

LoginPress Pro

Plugin:

LoginPress Pro

Plugin Slug:
loginpress-pro

Vulnerability:
Broken Authentication

Patched in Version:
5.0.2

Severity Score:
Critical


The vulnerability has been patched, so you should update to version 5.0.2.

Madara � Responsive Manga Site

Plugin:

Madara � Responsive Manga Site

Plugin Slug:
madara-core

Vulnerability:
Arbitrary File Deletion

Patched in Version:
2.2.4

Severity Score:
High


The vulnerability has been patched, so you should update to version 2.2.4.

MasterStudy LMS Pro

Plugin:

MasterStudy LMS Pro

Plugin Slug:
masterstudy-lms-learning-management-system-pro

Vulnerability:
Arbitrary File Upload

Patched in Version:
4.7.10

Severity Score:
Critical


The vulnerability has been patched, so you should update to version 4.7.10.

Modern Events Calendar Lite

Plugin:

Modern Events Calendar Lite

Plugin Slug:
modern-events-calendar-lite

Vulnerability:
SQL Injection

Patched in Version:
6.4.0

Severity Score:
Critical


The vulnerability has been patched, so you should update to version 6.4.0.
Plugin:

Simple Link Directory

Plugin Slug:
qc-simple-link-directory

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
14.8.1

Severity Score:
High


The vulnerability has been patched, so you should update to version 14.8.1.

Cost Calculator

Plugin:

Cost Calculator

Plugin Slug:
ql-cost-calculator

Vulnerability:
Broken Access Control

Patched in Version:
7.5

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 7.5.

Revolution Video Player With Bottom Playlist

Plugin:

Revolution Video Player With Bottom Playlist

Plugin Slug:
revolution-video-player

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.9.3

Severity Score:
High


The vulnerability has been patched, so you should update to version 2.9.3.

School Management

Plugin:

School Management

Plugin Slug:
school-management

Vulnerability:
Local File Inclusion

Patched in Version:
1.93.1

Severity Score:
High


The vulnerability has been patched, so you should update to version 1.93.1.

The Plus Addons for Elementor Pro

Plugin:

The Plus Addons for Elementor Pro

Plugin Slug:
theplus_elementor_addon

Vulnerability:
Broken Access Control

Patched in Version:
6.3.7

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 6.3.7.

Transposh WordPress Translation

Plugin:

Transposh WordPress Translation

Plugin Slug:
transposh-translation-filter-for-wordpress

Vulnerability:
Broken Access Control

Patched in Version:
1.0.9.2

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.0.9.2.

Transposh WordPress Translation

Plugin:

Transposh WordPress Translation

Plugin Slug:
transposh-translation-filter-for-wordpress

Vulnerability:
SQL Injection

Patched in Version:
1.0.9.2

Severity Score:
High


The vulnerability has been patched, so you should update to version 1.0.9.2.

Transposh WordPress Translation

Plugin:

Transposh WordPress Translation

Plugin Slug:
transposh-translation-filter-for-wordpress

Vulnerability:
Remote Code Execution (RCE)

Patched in Version:
1.0.9.2

Severity Score:
High


The vulnerability has been patched, so you should update to version 1.0.9.2.

Transposh WordPress Translation

Plugin:

Transposh WordPress Translation

Plugin Slug:
transposh-translation-filter-for-wordpress

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
1.0.9.2

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.0.9.2.

Transposh WordPress Translation

Plugin:

Transposh WordPress Translation

Plugin Slug:
transposh-translation-filter-for-wordpress

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.0.8

Severity Score:
High


The vulnerability has been patched, so you should update to version 1.0.8.

Transposh WordPress Translation

Plugin:

Transposh WordPress Translation

Plugin Slug:
transposh-translation-filter-for-wordpress

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.0.8

Severity Score:
High


The vulnerability has been patched, so you should update to version 1.0.8.

ThemeREX Addons

Plugin:

ThemeREX Addons

Plugin Slug:
trx_addons

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.35.2.2

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.35.2.2.

Youtube Vimeo Video Player and Slider

Plugin:

Youtube Vimeo Video Player and Slider

Plugin Slug:
video_player_youtube_vimeo

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
3.9

Severity Score:
High


The vulnerability has been patched, so you should update to version 3.9.

WooCommerce Refund And Exchange with RMA

Plugin:

WooCommerce Refund And Exchange with RMA

Plugin Slug:
woocommerce-refund-and-exchange

Vulnerability:
Arbitrary File Upload

Patched in Version:
3.2.7

Severity Score:
Critical


The vulnerability has been patched, so you should update to version 3.2.7.

Pinterest Automatic Pin

Plugin:

Pinterest Automatic Pin

Plugin Slug:
wp-pinterest-automatic

Vulnerability:
SQL Injection

Patched in Version:
4.19.0

Severity Score:
High


The vulnerability has been patched, so you should update to version 4.19.0.

WordPress Themes � 4 Patched / 1 Unpatched

Theme:

Visual Art | Gallery WordPress Theme

Theme Slug:
visual-arts

Vulnerability:
PHP Object Injection

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should switch themes.

Hestia

Theme:

Hestia

Theme Slug:
hestia

Downloads
4,446,823

Vulnerability:
Broken Access Control

Patched in Version:
3.2.11

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 3.2.11.

Alone

Theme:

Alone

Theme Slug:
alone

Vulnerability:
Arbitrary File Upload

Patched in Version:
7.8.5

Severity Score:
Critical


The vulnerability has been patched, so you should update to version 7.8.5.

Alone

Theme:

Alone

Theme Slug:
alone

Vulnerability:
Arbitrary File Deletion

Patched in Version:
7.8.5

Severity Score:
High


The vulnerability has been patched, so you should update to version 7.8.5.

Houzez

Theme:

Houzez

Theme Slug:
houzez

Vulnerability:
Broken Access Control

Patched in Version:
4.1.1

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 4.1.1.

Related articles

Wait! Get exclusive hosting insights

Subscribe to our newsletter and stay ahead of the competition with expert advice from our hosting pros.

Loading form…