Line illustration showing a black application window on a purple gradient background overlaid with a large exclamation point alert icon and three bugs.

WordPress Vulnerability Report � June 18, 2025

In this report, 138 vulnerabilities have been publicly disclosed. Security patches for 75 of these plugins and themes are available now, so run those updates as soon as possible. If you’re a Solid Security Pro user, the version management tool may have already warned you and updated these plugins, depending on your settings.

Additionally, there are 63 plugin and theme vulnerabilities, and no patch has been available yet. If you’re a Solid Security Pro user, those vulnerabilities are already protected by the Solid Security firewall. Virtual patches from Patchstack will be applied when a vulnerability is considered high or medium risk. If no patch is forthcoming from the vendor or the vulnerable software has been marked “closed” and dropped from the official WordPress repositories, you should deactivate it soon and look for alternative solutions.

WordPress Core

WordPress 6.8.1 was released on April 30, 2025. This maintenance release includes fixes for 15 bugs throughout Core and the Block Editor, addressing issues affecting multiple areas of WordPress, including the block editor, multisite, and REST API. For a full list, refer to the release candidate announcement.

WordPress Plugins � 55 Patched / 46 Unpatched

Woocommerce Partial Shipment

Plugin Slug:
wc-partial-shipment

Installations
1,000+

Vulnerability:
SQL Injection

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Track, Analyze & Optimize by WP Tao

Plugin Slug:
wp-tao

Installations
700+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

IndieBlocks

Plugin Slug:
indieblocks

Installations
100+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

One-Login

Plugin Slug:
one-login

Installations
70+

Vulnerability:
Privilege Escalation

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

PostaPanduri

Plugin Slug:
postapanduri

Installations
40+

Vulnerability:
SQL Injection

Patched in Version:
No Fix

Severity Score:
Critical


The vulnerability has not been patched. You should deactivate the plugin.

AI Image Lab

Plugin:

AI Image Lab

Plugin Slug:
ai-image-generator-lab

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Auto Attachments

Plugin:

Auto Attachments

Plugin Slug:
auto-attachments

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Axle Demo Importer

Plugin:

Axle Demo Importer

Plugin Slug:
axle-demo-importer

Vulnerability:
Arbitrary File Upload

Patched in Version:
No Fix

Severity Score:
Critical


The vulnerability has not been patched. You should deactivate the plugin.

Bunny�s Print CSS

Plugin:

Bunny�s Print CSS

Plugin Slug:
bunnys-print-css

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Color Palette

Plugin:

Color Palette

Plugin Slug:
color-palette

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Contact Us page – Contact people LITE

Plugin:

Contact Us page – Contact people LITE

Plugin Slug:
contact-us-page-contact-people

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Digital Marketing and Agency Templates Addons for Elementor

Plugin:

Digital Marketing and Agency Templates Addons for Elementor

Plugin Slug:
digital-marketing-agency-templates-for-elementor

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Easy Flashcards

Plugin:

Easy Flashcards

Plugin Slug:
easy-flashcards

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

DIOT SCADA with MQTT

Plugin:

DIOT SCADA with MQTT

Plugin Slug:
ecava-diot-scada

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Elite Video Player

Plugin:

Elite Video Player

Plugin Slug:
elite-video-player

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

FW Food Menu

Plugin:

FW Food Menu

Plugin Slug:
fw-food-menu

Vulnerability:
Arbitrary File Upload

Patched in Version:
No Fix

Severity Score:
Critical


The vulnerability has not been patched. You should deactivate the plugin.
Plugin:

FW Gallery

Plugin Slug:
fw-gallery

Vulnerability:
Arbitrary File Deletion

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

WPGYM

Plugin:

WPGYM

Plugin Slug:
gym-management

Vulnerability:
Local File Inclusion

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Image Resizer On The Fly

Plugin:

Image Resizer On The Fly

Plugin Slug:
image-resizer-on-the-fly

Vulnerability:
Arbitrary File Deletion

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

REST API | Custom API Generator For Cross Platform And Import Export In WP

Plugin:

REST API | Custom API Generator For Cross Platform And Import Export In WP

Plugin Slug:
import-export-with-custom-rest-api

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
Critical


The vulnerability has not been patched. You should deactivate the plugin.

IRM Newsroom

Plugin:

IRM Newsroom

Plugin Slug:
irm-newsroom

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

kk Youtube Video

Plugin:

kk Youtube Video

Plugin Slug:
kk-youtube-video

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

CLEVER

Plugin:

CLEVER

Plugin Slug:
lbg-audio11-html5-shoutcast_history

Vulnerability:
Arbitrary File Download

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

MapSVG

Plugin:

MapSVG

Plugin Slug:
mapsvg

Vulnerability:
Arbitrary File Upload

Patched in Version:
No Fix

Severity Score:
Critical


The vulnerability has not been patched. You should deactivate the plugin.

MapSVG

Plugin:

MapSVG

Plugin Slug:
mapsvg

Vulnerability:
Privilege Escalation

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Nasa Core

Plugin:

Nasa Core

Plugin Slug:
nasa-core

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Ovatheme Events Manager

Plugin:

Ovatheme Events Manager

Plugin Slug:
ova-events-manager

Vulnerability:
Arbitrary File Upload

Patched in Version:
No Fix

Severity Score:
Critical


The vulnerability has not been patched. You should deactivate the plugin.

Reformer for Elementor

Plugin:

Reformer for Elementor

Plugin Slug:
reformer-elementor

Vulnerability:
Arbitrary File Upload

Patched in Version:
No Fix

Severity Score:
Critical


The vulnerability has not been patched. You should deactivate the plugin.

Restrict File Access

Plugin:

Restrict File Access

Plugin Slug:
restrict-file-access

Vulnerability:
Arbitrary File Download

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

School Management

Plugin:

School Management

Plugin Slug:
school-management

Vulnerability:
Local File Inclusion

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

School Management

Plugin:

School Management

Plugin Slug:
school-management

Vulnerability:
SQL Injection

Patched in Version:
No Fix

Severity Score:
Critical


The vulnerability has not been patched. You should deactivate the plugin.

Smart Notification

Plugin:

Smart Notification

Plugin Slug:
smio-push-notification

Vulnerability:
SQL Injection

Patched in Version:
No Fix

Severity Score:
Critical


The vulnerability has not been patched. You should deactivate the plugin.

Telegram for WP

Plugin:

Telegram for WP

Plugin Slug:
telegram-for-wp

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Userpro

Plugin:

Userpro

Plugin Slug:
userpro

Vulnerability:
Arbitrary File Download

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Widget Logic

Plugin:

Widget Logic

Plugin Slug:
widget-logic

Vulnerability:
Remote Code Execution (RCE)

Patched in Version:
No Fix

Severity Score:
Critical


The vulnerability has not been patched. You should deactivate the plugin.

WidgetKit Pro

Plugin:

WidgetKit Pro

Plugin Slug:
widgetkit-pro

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

WP Employee Attendance System

Plugin:

WP Employee Attendance System

Plugin Slug:
wp-employee-attendance-system

Vulnerability:
SQL Injection

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

WP Sliding Login/Dashboard Panel

Plugin:

WP Sliding Login/Dashboard Panel

Plugin Slug:
wp-sliding-logindashboard-panel

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

WP URL Shortener

Plugin:

WP URL Shortener

Plugin Slug:
wp-url-shortener

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

WP2HTML

Plugin:

WP2HTML

Plugin Slug:
wp2html

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

WPCRM – CRM for Contact form CF7 & WooCommerce

Plugin:

WPCRM – CRM for Contact form CF7 & WooCommerce

Plugin Slug:
wpcrm

Vulnerability:
SQL Injection

Patched in Version:
No Fix

Severity Score:
Critical


The vulnerability has not been patched. You should deactivate the plugin.

XiSearch bar

Plugin:

XiSearch bar

Plugin Slug:
xisearch-bar

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Yougler Blogger Profile Page

Plugin:

Yougler Blogger Profile Page

Plugin Slug:
yougler-blogger-profile-page

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Zen Sticky Social

Plugin:

Zen Sticky Social

Plugin Slug:
zen-social-sticky

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Zotpress

Plugin:

Zotpress

Plugin Slug:
zotpress

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Premium Addons for Elementor

Plugin Slug:
premium-addons-for-elementor

Installations
700,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
4.11.9

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 4.11.9.

The Events Calendar

Plugin Slug:
the-events-calendar

Installations
700,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
6.13.2.1

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 6.13.2.1.

File Manager Pro � Filester

Plugin Slug:
filester

Installations
100,000+

Vulnerability:
Arbitrary File Upload

Patched in Version:
1.8.9

Severity Score:
Critical


The vulnerability has been patched, so you should update to version 1.8.9.

Social Sharing Plugin � Sassy Social Share

Plugin Slug:
sassy-social-share

Installations
100,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
3.3.76

Severity Score:
High


The vulnerability has been patched, so you should update to version 3.3.76.

Meks Flexible Shortcodes

Plugin Slug:
meks-flexible-shortcodes

Installations
20,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.3.8

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.3.8.

Simple Newsletter Plugin � Noptin

Plugin Slug:
newsletter-optin-box

Installations
10,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
4.0.0

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 4.0.0.

Arconix FAQ

Plugin Slug:
arconix-faq

Installations
8,000+

Vulnerability:
Broken Access Control

Patched in Version:
1.9.7

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.9.7.

If-So Dynamic Content Personalization

Plugin Slug:
if-so

Installations
8,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.9.3.2

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.9.3.2.

WP Dummy Content Generator

Plugin Slug:
wp-dummy-content-generator

Installations
8,000+

Vulnerability:
Arbitrary Content Deletion

Patched in Version:
4.0.0

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 4.0.0.

Xagio SEO � AI Powered SEO

Plugin Slug:
xagio-seo

Installations
8,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
7.1.0.17

Severity Score:
High


The vulnerability has been patched, so you should update to version 7.1.0.17.

ProfileGrid � User Profiles, Groups and Communities

Plugin Slug:
profilegrid-user-profiles-groups-and-communities

Installations
7,000+

Vulnerability:
Server Side Request Forgery (SSRF)

Patched in Version:
5.9.5.3

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 5.9.5.3.

Arconix Shortcodes

Plugin Slug:
arconix-shortcodes

Installations
5,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.1.18

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.1.18.

CubeWP � All-in-One Dynamic Content Framework

Plugin Slug:
cubewp-framework

Installations
5,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.1.24

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.1.24.

CubeWP � All-in-One Dynamic Content Framework

Plugin Slug:
cubewp-framework

Installations
5,000+

Vulnerability:
Privilege Escalation

Patched in Version:
1.1.24

Severity Score:
High


The vulnerability has been patched, so you should update to version 1.1.24.

WPAdverts � Classifieds Plugin

Plugin Slug:
wpadverts

Installations
5,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.2.5

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.2.5.

CubeWP Forms � All-in-One Form Builder

Plugin Slug:
cubewp-forms

Installations
4,000+

Vulnerability:
Broken Access Control

Patched in Version:
1.1.6

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.1.6.

Responsive Blocks � WordPress Gutenberg Blocks

Plugin Slug:
responsive-block-editor-addons

Installations
4,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.0.6

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.0.6.

WP-DownloadManager

Plugin Slug:
wp-downloadmanager

Installations
3,000+

Vulnerability:
Arbitrary File Download

Patched in Version:
1.68.11

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.68.11.

WP Views Counter

Plugin Slug:
wpecounter

Installations
2,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.0.4

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.0.4.

YITH PayPal Express Checkout for WooCommerce

Plugin Slug:
yith-paypal-express-checkout-for-woocommerce

Installations
2,000+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
1.49.1

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.49.1.

Advanced Sermons

Plugin Slug:
advanced-sermons

Installations
1,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
3.7

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 3.7.

Ebook Store

Plugin Slug:
ebook-store

Installations
1,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
5.8009

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 5.8009.

Kama Click Counter

Plugin Slug:
kama-clic-counter

Installations
1,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
4.0.4

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 4.0.4.

Membership For WooCommerce

Plugin Slug:
membership-for-woocommerce

Installations
1,000+

Vulnerability:
Broken Access Control

Patched in Version:
2.8.2

Severity Score:
High


The vulnerability has been patched, so you should update to version 2.8.2.

AFS Analytics

Plugin Slug:
addfreestats

Installations
700+

Vulnerability:
Broken Access Control

Patched in Version:
4.22

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 4.22.

Broadstreet

Plugin Slug:
broadstreet

Installations
700+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.51.8

Severity Score:
High


The vulnerability has been patched, so you should update to version 1.51.8.

Traffic Monitor

Plugin Slug:
traffic-monitor

Installations
700+

Vulnerability:
Broken Access Control

Patched in Version:
3.2.3

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 3.2.3.

Ultimate Reviews

Plugin Slug:
ultimate-reviews

Installations
700+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
3.2.15

Severity Score:
High


The vulnerability has been patched, so you should update to version 3.2.15.

Advanced Settings 3

Plugin Slug:
advanced-settings

Installations
200+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
3.0.2

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 3.0.2.

ACF Onyx Poll

Plugin Slug:
acf-onyx-poll

Installations
100+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.2.0

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.2.0.

Game Review Block

Plugin Slug:
game-review-block

Installations
100+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
4.8.2

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 4.8.2.

TicketBAI Facturas para WooCommerce

Plugin Slug:
wp-ticketbai

Installations
90+

Vulnerability:
SQL Injection

Patched in Version:
3.21

Severity Score:
Critical


The vulnerability has been patched, so you should update to version 3.21.

OAuth Single Sign On – SSO (OAuth Client)

Plugin:

OAuth Single Sign On – SSO (OAuth Client)

Plugin Slug:
miniorange-oauth-oidc-single-sign-on

Vulnerability:
Sensitive Data Exposure

Patched in Version:
18.5.4

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 18.5.4.

NewsLetter

Plugin:

NewsLetter

Plugin Slug:
plugin-newsletter

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
8.8.5

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 8.8.5.

Abandoned Cart Pro for WooCommerce

Plugin:

Abandoned Cart Pro for WooCommerce

Plugin Slug:
woocommerce-abandon-cart-pro

Vulnerability:
Arbitrary File Upload

Patched in Version:
9.17.0

Severity Score:
Critical


The vulnerability has been patched, so you should update to version 9.17.0.

Workreap (theme’s plugin)

Plugin:

Workreap (theme’s plugin)

Plugin Slug:
workreap

Vulnerability:
Arbitrary File Upload

Patched in Version:
3.3.3

Severity Score:
High


The vulnerability has been patched, so you should update to version 3.3.3.

Workreap (theme’s plugin)

Plugin:

Workreap (theme’s plugin)

Plugin Slug:
workreap

Vulnerability:
Broken Authentication

Patched in Version:
3.3.2

Severity Score:
Critical


The vulnerability has been patched, so you should update to version 3.3.2.

Automatic

Plugin:

Automatic

Plugin Slug:
wp-automatic

Vulnerability:
Arbitrary File Upload

Patched in Version:
3.116.0

Severity Score:
Critical


The vulnerability has been patched, so you should update to version 3.116.0.

eForm – WordPress Form Builder

Plugin:

eForm – WordPress Form Builder

Plugin Slug:
wp-fsqm-pro

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
4.19.1

Severity Score:
High


The vulnerability has been patched, so you should update to version 4.19.1.

WordPress Themes � 20 Patched / 17 Unpatched

BodyCenter – Gym, Fitness WooCommerce WordPress Theme

Theme:

BodyCenter – Gym, Fitness WooCommerce WordPress Theme

Theme Slug:
bodycenter

Vulnerability:
Local File Inclusion

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should switch themes.

CraftXtore

Theme:

CraftXtore

Theme Slug:
bw-craftxtore

Vulnerability:
Local File Inclusion

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should switch themes.

Fitrush

Theme:

Fitrush

Theme Slug:
bw-fitrush

Vulnerability:
Local File Inclusion

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should switch themes.

GiftXtore

Theme:

GiftXtore

Theme Slug:
bw-giftxtore

Vulnerability:
Local File Inclusion

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should switch themes.

Petito

Theme:

Petito

Theme Slug:
bw-petito

Vulnerability:
Local File Inclusion

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should switch themes.

Zagg

Theme:

Zagg

Theme Slug:
bw-zagg

Vulnerability:
Local File Inclusion

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should switch themes.

DSK

Theme:

DSK

Theme Slug:
dsk

Vulnerability:
Local File Inclusion

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should switch themes.

Themify Edmin

Theme:

Themify Edmin

Theme Slug:
edmin

Vulnerability:
PHP Object Injection

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should switch themes.

Inset

Theme:

Inset

Theme Slug:
inset

Vulnerability:
Local File Inclusion

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should switch themes.

Photography

Theme:

Photography

Theme Slug:
photography

Vulnerability:
PHP Object Injection

Patched in Version:
No Fix

Severity Score:
Critical


The vulnerability has not been patched. You should switch themes.

SNS Anton

Theme:

SNS Anton

Theme Slug:
snsanton

Vulnerability:
Local File Inclusion

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should switch themes.

Avaz

Theme:

Avaz

Theme Slug:
snsavaz

Vulnerability:
Local File Inclusion

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should switch themes.

Evon

Theme:

Evon

Theme Slug:
snsevon

Vulnerability:
Local File Inclusion

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should switch themes.

Nitan

Theme:

Nitan

Theme Slug:
snsnitan

Vulnerability:
Local File Inclusion

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should switch themes.

Simen

Theme:

Simen

Theme Slug:
snssimen

Vulnerability:
Local File Inclusion

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should switch themes.

Spare

Theme:

Spare

Theme Slug:
spare

Vulnerability:
PHP Object Injection

Patched in Version:
No Fix

Severity Score:
Critical


The vulnerability has not been patched. You should switch themes.

Valen – Sport, Fashion WooCommerce WordPress Theme

Theme:

Valen – Sport, Fashion WooCommerce WordPress Theme

Theme Slug:
valen

Vulnerability:
Local File Inclusion

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should switch themes.

Aora

Theme:

Aora

Theme Slug:
aora

Vulnerability:
Local File Inclusion

Patched in Version:
1.3.10

Severity Score:
High


The vulnerability has been patched, so you should update to version 1.3.10.

Besa

Theme:

Besa

Theme Slug:
besa

Vulnerability:
Local File Inclusion

Patched in Version:
2.3.10

Severity Score:
High


The vulnerability has been patched, so you should update to version 2.3.10.

CozyStay

Theme:

CozyStay

Theme Slug:
cozystay

Vulnerability:
Local File Inclusion

Patched in Version:
1.7.1

Severity Score:
High


The vulnerability has been patched, so you should update to version 1.7.1.

CozyStay

Theme:

CozyStay

Theme Slug:
cozystay

Vulnerability:
PHP Object Injection

Patched in Version:
1.7.1

Severity Score:
Critical


The vulnerability has been patched, so you should update to version 1.7.1.

Diza

Theme:

Diza

Theme Slug:
diza

Vulnerability:
Local File Inclusion

Patched in Version:
1.3.9

Severity Score:
High


The vulnerability has been patched, so you should update to version 1.3.9.

Fana

Theme:

Fana

Theme Slug:
fana

Vulnerability:
Local File Inclusion

Patched in Version:
1.1.29

Severity Score:
High


The vulnerability has been patched, so you should update to version 1.1.29.

Flozen

Theme:

Flozen

Theme Slug:
flozen-theme

Vulnerability:
Arbitrary File Upload

Patched in Version:
1.5.1

Severity Score:
Critical


The vulnerability has been patched, so you should update to version 1.5.1.

GrandPrix

Theme:

GrandPrix

Theme Slug:
grandprix

Vulnerability:
Local File Inclusion

Patched in Version:
1.6.1

Severity Score:
High


The vulnerability has been patched, so you should update to version 1.6.1.

Grill and Chow

Theme:

Grill and Chow

Theme Slug:
grillandchow

Vulnerability:
Local File Inclusion

Patched in Version:
1.6.1

Severity Score:
High


The vulnerability has been patched, so you should update to version 1.6.1.

Hara

Theme:

Hara

Theme Slug:
hara

Vulnerability:
Local File Inclusion

Patched in Version:
1.2.11

Severity Score:
High


The vulnerability has been patched, so you should update to version 1.2.11.

Lasa

Theme:

Lasa

Theme Slug:
lasa

Vulnerability:
Local File Inclusion

Patched in Version:
1.1.1

Severity Score:
High


The vulnerability has been patched, so you should update to version 1.1.1.

Maia

Theme:

Maia

Theme Slug:
maia

Vulnerability:
Local File Inclusion

Patched in Version:
1.1.16

Severity Score:
High


The vulnerability has been patched, so you should update to version 1.1.16.

MediClinic

Theme:

MediClinic

Theme Slug:
mediclinic

Vulnerability:
Local File Inclusion

Patched in Version:
2.2

Severity Score:
High


The vulnerability has been patched, so you should update to version 2.2.

Nika

Theme:

Nika

Theme Slug:
nika

Vulnerability:
Local File Inclusion

Patched in Version:
1.2.9

Severity Score:
High


The vulnerability has been patched, so you should update to version 1.2.9.

RealHomes

Theme:

RealHomes

Theme Slug:
realhomes

Vulnerability:
Privilege Escalation

Patched in Version:
4.4.1

Severity Score:
High


The vulnerability has been patched, so you should update to version 4.4.1.

Ruza

Theme:

Ruza

Theme Slug:
ruza

Vulnerability:
Local File Inclusion

Patched in Version:
1.0.8

Severity Score:
High


The vulnerability has been patched, so you should update to version 1.0.8.

Sapa

Theme:

Sapa

Theme Slug:
sapa

Vulnerability:
Local File Inclusion

Patched in Version:
1.1.15

Severity Score:
High


The vulnerability has been patched, so you should update to version 1.1.15.

TinySalt

Theme:

TinySalt

Theme Slug:
tinysalt

Vulnerability:
PHP Object Injection

Patched in Version:
3.10.0

Severity Score:
Critical


The vulnerability has been patched, so you should update to version 3.10.0.

TinySalt

Theme:

TinySalt

Theme Slug:
tinysalt

Vulnerability:
Local File Inclusion

Patched in Version:
3.10.0

Severity Score:
High


The vulnerability has been patched, so you should update to version 3.10.0.

Zota

Theme:

Zota

Theme Slug:
zota

Vulnerability:
Local File Inclusion

Patched in Version:
1.3.9

Severity Score:
High


The vulnerability has been patched, so you should update to version 1.3.9.

Related articles

Wait! Get exclusive hosting insights

Subscribe to our newsletter and stay ahead of the competition with expert advice from our hosting pros.

Loading form…