WordPress Vulnerability Report � March 18, 2026

In this report, 159 vulnerabilities have been publicly disclosed. Security patches for 113 of these Core, plugins, and themes are now available. Please run these updates as soon as possible. If you’re a Solid Security Pro user, the version management tool may have already warned you and updated these plugins, depending on your settings.

Currently, 46 plugin and theme vulnerabilities remain unpatched. If you’re a Solid Security Pro user, those vulnerabilities are already protected by the Solid Security firewall. Virtual patches from Patchstack will be applied when a vulnerability is considered high or medium risk. If no patch is forthcoming from the vendor or the vulnerable software has been marked “closed” and dropped from the official WordPress repositories, you should deactivate it soon and look for alternative solutions.

WordPress Core

WordPress 6.9.4 is now available, addressing 10 security issues and a bug that affected template file loading on a limited number of sites. Because this is a security release,�it is recommended that you update your sites immediately.

Also, WordPress 7.0 Beta 5 is ready for download and testing! As this is a pre-release version, it is intended for�testing and development only�and should not be installed on production or mission-critical sites. Organizations should use local or staging environments to evaluate compatibility and new features before the final rollout.

WordPress 7.0 is scheduled for release on April 9, 2026.

WordPress Core

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
6.9.2

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 6.9.2.

WordPress Core

Vulnerability:
Server Side Request Forgery (SSRF)

Patched in Version:
6.9.2

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 6.9.2.

WordPress Core

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
6.9.2

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 6.9.2.

WordPress Core

Vulnerability:
XML External Entity (XXE)

Patched in Version:
6.9.4

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 6.9.4.

WordPress Core

Vulnerability:
Broken Access Control

Patched in Version:
6.9.4

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 6.9.4.

WordPress Core

Vulnerability:
Broken Access Control

Patched in Version:
6.9.2

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 6.9.2.

WordPress Plugins � 100 Patched / 30 Unpatched

Addi � Cuotas que se adaptan a ti

Plugin Slug:
buy-now-pay-later-addi

Installations
2,000+

Vulnerability:
Broken Authentication

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

TotalPoll for Polls and Contests

Plugin Slug:
totalpoll-lite

Installations
1,000+

Vulnerability:
Remote Code Execution (RCE)

Patched in Version:
No Fix

Severity Score:
Critical


The vulnerability has not been patched. You should deactivate the plugin.

ViaBill � WooCommerce

Plugin Slug:
viabill-woocommerce

Installations
500+

Vulnerability:
Settings Change

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Photo Contest | Competition | Video Contest

Plugin Slug:
totalcontest-lite

Installations
300+

Vulnerability:
PHP Object Injection

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Admin Safety Guard � Login Security & 2FA

Plugin Slug:
admin-safety-guard

Installations
10+

Vulnerability:
Broken Authentication

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

ACPT (Pro) – Custom Post Types Plugin for WordPress

Plugin:

ACPT (Pro) – Custom Post Types Plugin for WordPress

Plugin Slug:
advanced-custom-post-type

Vulnerability:
Remote Code Execution (RCE)

Patched in Version:
No Fix

Severity Score:
Critical


The vulnerability has not been patched. You should deactivate the plugin.

BuilderPress

Plugin:

BuilderPress

Plugin Slug:
builderpress

Vulnerability:
Local File Inclusion

Patched in Version:
No Fix

Severity Score:
Critical


The vulnerability has not been patched. You should deactivate the plugin.

Curly Core

Plugin:

Curly Core

Plugin Slug:
curly-core

Vulnerability:
Local File Inclusion

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Darna Framework

Plugin:

Darna Framework

Plugin Slug:
darna-framework

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

DukaPress

Plugin:

DukaPress

Plugin Slug:
dukapress

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Everest Forms Pro

Plugin:

Everest Forms Pro

Plugin Slug:
everest-forms-pro

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Handmade Framework

Plugin:

Handmade Framework

Plugin Slug:
handmade-framework

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Jobica Core

Plugin:

Jobica Core

Plugin Slug:
jobica-core

Vulnerability:
Broken Authentication

Patched in Version:
No Fix

Severity Score:
Critical


The vulnerability has not been patched. You should deactivate the plugin.

Legacy Admin

Plugin:

Legacy Admin

Plugin Slug:
legacy-admin

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

MetForm Pro

Plugin:

MetForm Pro

Plugin Slug:
metform-pro

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
Critical


The vulnerability has not been patched. You should deactivate the plugin.

Modern Events Calendar

Plugin:

Modern Events Calendar

Plugin Slug:
modern-events-calendar

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Penci Soledad Data Migrator

Plugin:

Penci Soledad Data Migrator

Plugin Slug:
penci-data-migrator

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

WooCommerce Infinite Scroll

Plugin:

WooCommerce Infinite Scroll

Plugin Slug:
sb-woocommerce-infinite-scroll

Vulnerability:
PHP Object Injection

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

The Aisle Core

Plugin:

The Aisle Core

Plugin Slug:
theaisle-core

Vulnerability:
Local File Inclusion

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

UiPress lite

Plugin:

UiPress lite

Plugin Slug:
uipress-lite

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Ultra WordPress Admin

Plugin:

Ultra WordPress Admin

Plugin Slug:
ultra-admin

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Unlimited Elements for Elementor (Premium)

Plugin:

Unlimited Elements for Elementor (Premium)

Plugin Slug:
unlimited-elements-for-elementor-premium

Vulnerability:
Arbitrary File Upload

Patched in Version:
No Fix

Severity Score:
Critical


The vulnerability has not been patched. You should deactivate the plugin.

Wolverine Framework

Plugin:

Wolverine Framework

Plugin Slug:
wolverine-framework

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

WZone

Plugin:

WZone

Plugin Slug:
woozone

Vulnerability:
SQL Injection

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

WZone

Plugin:

WZone

Plugin Slug:
woozone

Vulnerability:
Arbitrary File Deletion

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

WP App Bar

Plugin:

WP App Bar

Plugin Slug:
wp-app-bar

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

WooCommerce

Plugin Slug:
woocommerce

Installations
7,000,000+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
10.5.3

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 10.5.3.

MC4WP: Mailchimp for WordPress

Plugin Slug:
mailchimp-for-wp

Installations
1,000,000+

Vulnerability:
Broken Access Control

Patched in Version:
4.12.0

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 4.12.0.

The Events Calendar

Plugin Slug:
the-events-calendar

Installations
700,000+

Vulnerability:
Arbitrary File Download

Patched in Version:
6.15.17.1

Severity Score:
High


The vulnerability has been patched, so you should update to version 6.15.17.1.

Meta Box

Plugin:

Meta Box

Plugin Slug:
meta-box

Installations
500,000+

Vulnerability:
Arbitrary File Deletion

Patched in Version:
5.11.2

Severity Score:
High


The vulnerability has been patched, so you should update to version 5.11.2.

PixelYourSite � Your smart PIXEL (TAG) & API Manager

Plugin Slug:
pixelyoursite

Installations
500,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
11.2.0.1

Severity Score:
High


The vulnerability has been patched, so you should update to version 11.2.0.1.

Ally � Web Accessibility & Usability

Plugin Slug:
pojo-accessibility

Installations
500,000+

Vulnerability:
SQL Injection

Patched in Version:
4.1.0

Severity Score:
Critical


The vulnerability has been patched, so you should update to version 4.1.0.

Checkout Field Editor (Checkout Manager) for WooCommerce

Plugin Slug:
woo-checkout-field-editor-pro

Installations
500,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.1.8

Severity Score:
High


The vulnerability has been patched, so you should update to version 2.1.8.

Admin Menu Editor

Plugin Slug:
admin-menu-editor

Installations
400,000+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
1.15

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.15.

Happy Addons for Elementor

Plugin Slug:
happy-elementor-addons

Installations
400,000+

Vulnerability:
Insecure Direct Object References (IDOR)

Patched in Version:
3.21.1

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 3.21.1.

Happy Addons for Elementor

Plugin Slug:
happy-elementor-addons

Installations
400,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
3.21.1

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 3.21.1.

Unlimited Elements For Elementor

Plugin Slug:
unlimited-elements-for-elementor

Installations
300,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.0.6

Severity Score:
High


The vulnerability has been patched, so you should update to version 2.0.6.

Tutor LMS � eLearning and online course solution

Plugin Slug:
tutor

Installations
100,000+

Vulnerability:
Insecure Direct Object References (IDOR)

Patched in Version:
3.9.5

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 3.9.5.

Ultra Addons for Contact Form 7

Plugin Slug:
ultimate-addons-for-contact-form-7

Installations
60,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
3.5.37

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 3.5.37.

Advanced Product Fields (Product Addons) for WooCommerce

Plugin Slug:
advanced-product-fields-for-woocommerce

Installations
50,000+

Vulnerability:
Broken Access Control

Patched in Version:
1.6.19

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.6.19.

RTMKit

Plugin:

RTMKit

Plugin Slug:
rometheme-for-elementor

Installations
50,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.0.0

Severity Score:
High


The vulnerability has been patched, so you should update to version 2.0.0.

Calculated Fields Form

Plugin Slug:
calculated-fields-form

Installations
40,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
5.4.5.1

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 5.4.5.1.

Modular DS: Monitor, update, and backup multiple websites

Plugin Slug:
modular-connector

Installations
40,000+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
2.6.0

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.6.0.

NextScripts: Social Networks Auto-Poster

Plugin Slug:
social-networks-auto-poster-facebook-twitter-g

Installations
30,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
4.4.7

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 4.4.7.

Website LLMs.txt

Plugin Slug:
website-llms-txt

Installations
30,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
8.2.7

Severity Score:
High


The vulnerability has been patched, so you should update to version 8.2.7.

Job Postings

Plugin Slug:
job-postings

Installations
10,000+

Vulnerability:
Broken Access Control

Patched in Version:
2.8.1

Severity Score:
High


The vulnerability has been patched, so you should update to version 2.8.1.

Lead Form Builder & Contact Form

Plugin Slug:
lead-form-builder

Installations
10,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.0.2

Severity Score:
High


The vulnerability has been patched, so you should update to version 2.0.2.

Subscriptions for WooCommerce

Plugin Slug:
subscriptions-for-woocommerce

Installations
10,000+

Vulnerability:
Bypass Vulnerability

Patched in Version:
1.9.0

Severity Score:
High


The vulnerability has been patched, so you should update to version 1.9.0.

Xagio SEO � AI Powered SEO

Plugin Slug:
xagio-seo

Installations
10,000+

Vulnerability:
Privilege Escalation

Patched in Version:
7.1.0.31

Severity Score:
Critical


The vulnerability has been patched, so you should update to version 7.1.0.31.

EventPrime � Events Calendar, Bookings and Tickets

Plugin Slug:
eventprime-event-calendar-management

Installations
7,000+

Vulnerability:
Broken Access Control

Patched in Version:
4.2.7.0

Severity Score:
High


The vulnerability has been patched, so you should update to version 4.2.7.0.

NEX-Forms � Ultimate Forms Plugin for WordPress

Plugin Slug:
nex-forms-express-wp-form-builder

Installations
7,000+

Vulnerability:
Broken Access Control

Patched in Version:
9.1.10

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 9.1.10.

Reading progressbar

Plugin Slug:
reading-progress-bar

Installations
6,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.3.1

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.3.1.

Responsive Blocks � Page Builder for Blocks & Patterns

Plugin Slug:
responsive-block-editor-addons

Installations
4,000+

Vulnerability:
Broken Access Control

Patched in Version:
2.2.1

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.2.1.

JS Archive List

Plugin Slug:
jquery-archive-list-widget

Installations
3,000+

Vulnerability:
PHP Object Injection

Patched in Version:
6.2.0

Severity Score:
High


The vulnerability has been patched, so you should update to version 6.2.0.

Name Directory

Plugin Slug:
name-directory

Installations
3,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.33.0

Severity Score:
High


The vulnerability has been patched, so you should update to version 1.33.0.

Simple Ajax Chat � Add a Fast, Secure Chat Box

Plugin Slug:
simple-ajax-chat

Installations
2,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
20260301

Severity Score:
High


The vulnerability has been patched, so you should update to version 20260301.

Flexmls� IDX Plugin

Plugin Slug:
flexmls-idx

Installations
1,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
3.15.10

Severity Score:
High


The vulnerability has been patched, so you should update to version 3.15.10.

MDTF � Meta Data and Taxonomies Filter

Plugin Slug:
wp-meta-data-filter-and-taxonomy-filter

Installations
1,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.3.6

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.3.6.

Datalogics Ecommerce Delivery � Datalogics

Plugin Slug:
datalogics

Installations
400+

Vulnerability:
Privilege Escalation

Patched in Version:
2.6.60

Severity Score:
Critical


The vulnerability has been patched, so you should update to version 2.6.60.

PitchPrint

Plugin Slug:
pitchprint

Installations
400+

Vulnerability:
Arbitrary File Deletion

Patched in Version:
11.2.0

Severity Score:
High


The vulnerability has been patched, so you should update to version 11.2.0.

Court Reservation � Manage Your Court Bookings Online

Plugin Slug:
court-reservation

Installations
100+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
1.10.9

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.10.9.

LearnPress � Sepay Payment

Plugin Slug:
learnpress-sepay-payment

Installations
100+

Vulnerability:
Broken Authentication

Patched in Version:
4.0.1

Severity Score:
High


The vulnerability has been patched, so you should update to version 4.0.1.

Pix for WooCommerce

Plugin Slug:
payment-gateway-pix-for-woocommerce

Installations
100+

Vulnerability:
Arbitrary File Upload

Patched in Version:
1.6.0

Severity Score:
Critical


The vulnerability has been patched, so you should update to version 1.6.0.

Primer MyData for Woocommerce

Plugin Slug:
primer-mydata

Installations
100+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
4.2.2

Severity Score:
High


The vulnerability has been patched, so you should update to version 4.2.2.

ZIP Code Based Content Protection

Plugin Slug:
zip-code-based-content-protection

Installations
10+

Vulnerability:
SQL Injection

Patched in Version:
1.0.3

Severity Score:
Critical


The vulnerability has been patched, so you should update to version 1.0.3.

Divi Booster

Plugin:

Divi Booster

Plugin Slug:
divi-booster

Vulnerability:
PHP Object Injection

Patched in Version:
5.0.2

Severity Score:
Critical


The vulnerability has been patched, so you should update to version 5.0.2.

Elated Listing

Plugin:

Elated Listing

Plugin Slug:
eltd-listing

Vulnerability:
Broken Access Control

Patched in Version:
1.5

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.5.

Fusion Builder

Plugin:

Fusion Builder

Plugin Slug:
fusion-builder

Vulnerability:
Broken Access Control

Patched in Version:
3.15.0

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 3.15.0.

Fusion Builder

Plugin:

Fusion Builder

Plugin Slug:
fusion-builder

Vulnerability:
Broken Access Control

Patched in Version:
3.15.0

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 3.15.0.

Avada Core

Plugin:

Avada Core

Plugin Slug:
fusion-core

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
5.15.0

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 5.15.0.

Avada Core

Plugin:

Avada Core

Plugin Slug:
fusion-core

Vulnerability:
Broken Access Control

Patched in Version:
5.15.0

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 5.15.0.

Gravity Forms

Plugin:

Gravity Forms

Plugin Slug:
gravityforms

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.9.29

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.9.29.

JetBooking

Plugin:

JetBooking

Plugin Slug:
jet-booking

Vulnerability:
SQL Injection

Patched in Version:
4.0.3.1

Severity Score:
Critical


The vulnerability has been patched, so you should update to version 4.0.3.1.

Jobica Core

Plugin:

Jobica Core

Plugin Slug:
jobica-core

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.4.2

Severity Score:
High


The vulnerability has been patched, so you should update to version 1.4.2.

Jobica Core

Plugin:

Jobica Core

Plugin Slug:
jobica-core

Vulnerability:
PHP Object Injection

Patched in Version:
1.4.2

Severity Score:
High


The vulnerability has been patched, so you should update to version 1.4.2.

MetForm Pro

Plugin:

MetForm Pro

Plugin Slug:
metform-pro

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
3.9.7

Severity Score:
High


The vulnerability has been patched, so you should update to version 3.9.7.

Organici Library

Plugin:

Organici Library

Plugin Slug:
noo-organici-library

Vulnerability:
SQL Injection

Patched in Version:
2.1.3

Severity Score:
High


The vulnerability has been patched, so you should update to version 2.1.3.

Organici Library

Plugin:

Organici Library

Plugin Slug:
noo-organici-library

Vulnerability:
PHP Object Injection

Patched in Version:
2.1.3

Severity Score:
High


The vulnerability has been patched, so you should update to version 2.1.3.

Organici Library

Plugin:

Organici Library

Plugin Slug:
noo-organici-library

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.1.3

Severity Score:
High


The vulnerability has been patched, so you should update to version 2.1.3.

Visionary Core

Plugin:

Visionary Core

Plugin Slug:
noo-visionary-core

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.5.0

Severity Score:
High


The vulnerability has been patched, so you should update to version 1.5.0.

Visionary Core

Plugin:

Visionary Core

Plugin Slug:
noo-visionary-core

Vulnerability:
PHP Object Injection

Patched in Version:
1.5.0

Severity Score:
High


The vulnerability has been patched, so you should update to version 1.5.0.

PixelYourSite PRO

Plugin:

PixelYourSite PRO

Plugin Slug:
pixelyoursite-pro

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
12.4.0.3

Severity Score:
High


The vulnerability has been patched, so you should update to version 12.4.0.3.

tagDiv Composer

Plugin:

tagDiv Composer

Plugin Slug:
td-composer

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
5.4.3

Severity Score:
High


The vulnerability has been patched, so you should update to version 5.4.3.

tagDiv Opt-In Builder

Plugin:

tagDiv Opt-In Builder

Plugin Slug:
td-subscription

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.7.4

Severity Score:
High


The vulnerability has been patched, so you should update to version 1.7.4.

Tutor LMS Pro

Plugin:

Tutor LMS Pro

Plugin Slug:
tutor-pro

Vulnerability:
Broken Authentication

Patched in Version:
3.9.6

Severity Score:
Critical


The vulnerability has been patched, so you should update to version 3.9.6.

WordPress Themes � 7 Patched / 16 Unpatched

Amfissa

Theme:

Amfissa

Theme Slug:
amfissa

Vulnerability:
Local File Inclusion

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should switch themes.

Beelove

Theme:

Beelove

Theme Slug:
beelove

Vulnerability:
PHP Object Injection

Patched in Version:
No Fix

Severity Score:
Critical


The vulnerability has not been patched. You should switch themes.

Belfort

Theme:

Belfort

Theme Slug:
belfort

Vulnerability:
Local File Inclusion

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should switch themes.

Buisson

Theme:

Buisson

Theme Slug:
buisson

Vulnerability:
PHP Object Injection

Patched in Version:
No Fix

Severity Score:
Critical


The vulnerability has not been patched. You should switch themes.

Deston

Theme:

Deston

Theme Slug:
deston

Vulnerability:
Local File Inclusion

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should switch themes.

Emaurri

Theme:

Emaurri

Theme Slug:
emaurri

Vulnerability:
Local File Inclusion

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should switch themes.

Golo

Theme:

Golo

Theme Slug:
golo

Vulnerability:
Privilege Escalation

Patched in Version:
No Fix

Severity Score:
Critical


The vulnerability has not been patched. You should switch themes.

Jannah

Theme:

Jannah

Theme Slug:
jannah

Vulnerability:
Local File Inclusion

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should switch themes.

Love Story

Theme:

Love Story

Theme Slug:
lovestory

Vulnerability:
PHP Object Injection

Patched in Version:
No Fix

Severity Score:
Critical


The vulnerability has not been patched. You should switch themes.

LuxeDrive

Theme:

LuxeDrive

Theme Slug:
luxedrive

Vulnerability:
Local File Inclusion

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should switch themes.

Melody

Theme:

Melody

Theme Slug:
melodyschool

Vulnerability:
PHP Object Injection

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should switch themes.

MultiOffice

Theme:

MultiOffice

Theme Slug:
multioffice

Vulnerability:
Local File Inclusion

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should switch themes.

Photography

Theme:

Photography

Theme Slug:
photography

Vulnerability:
Arbitrary File Upload

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should switch themes.

Rosebud

Theme:

Rosebud

Theme Slug:
rosebud

Vulnerability:
Local File Inclusion

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should switch themes.

Work & Travel Company

Theme:

Work & Travel Company

Theme Slug:
work-travel-company

Vulnerability:
PHP Object Injection

Patched in Version:
No Fix

Severity Score:
Critical


The vulnerability has not been patched. You should switch themes.

Zorka

Theme:

Zorka

Theme Slug:
zorka

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should switch themes.

Astra

Theme:

Astra

Theme Slug:
astra

Downloads
21,720,242

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
4.12.4

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 4.12.4.

News Magazine X

Theme Slug:
news-magazine-x

Downloads
76,558

Vulnerability:
Broken Access Control

Patched in Version:
1.2.51

Severity Score:
High


The vulnerability has been patched, so you should update to version 1.2.51.

Energox

Theme:

Energox

Theme Slug:
energox

Vulnerability:
Arbitrary File Deletion

Patched in Version:
1.3

Severity Score:
High


The vulnerability has been patched, so you should update to version 1.3.

Instant VA

Theme:

Instant VA

Theme Slug:
instantva

Vulnerability:
Arbitrary File Deletion

Patched in Version:
1.0.2

Severity Score:
High


The vulnerability has been patched, so you should update to version 1.0.2.

CitiLights

Theme:

CitiLights

Theme Slug:
noo-citilights

Vulnerability:
PHP Object Injection

Patched in Version:
3.7.2

Severity Score:
High


The vulnerability has been patched, so you should update to version 3.7.2.

CitiLights

Theme:

CitiLights

Theme Slug:
noo-citilights

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
3.7.2

Severity Score:
High


The vulnerability has been patched, so you should update to version 3.7.2.

Search & Go

Theme:

Search & Go

Theme Slug:
searchgo

Vulnerability:
Privilege Escalation

Patched in Version:
2.8.1

Severity Score:
Critical


The vulnerability has been patched, so you should update to version 2.8.1.

Related articles

Wait! Get exclusive hosting insights

Subscribe to our newsletter and stay ahead of the competition with expert advice from our hosting pros.

Loading form…