Line illustration showing a black application window on a dark red gradient background overlaid with a large exclamation point alert icon and three bugs.

WordPress Vulnerability Report � March 19, 2025

In this report, 173 vulnerabilities have been publicly disclosed. Security patches for 63 of these plugins and themes are available now, so run those updates as soon as possible. If you’re a Solid Security Pro user, the version management tool may have already warned you and updated these plugins, depending on your settings.

Additionally, there are 110 plugin and theme vulnerabilities with no patch available yet. If you’re a Solid Security Pro user, those vulnerabilities are already protected by the Solid Security firewall. Virtual patches from Patchstack will be applied when a vulnerability is considered high or medium risk. If no patch is forthcoming from the vendor or the vulnerable software has been marked “closed” and dropped from the official WordPress repositories, you should deactivate it soon and look for alternative solutions.

WordPress Core

WordPress 6.8 Beta 3 is ready for testing! This beta version of the WordPress software is under development. Please do not install, run, or test this version of WordPress on production or mission-critical websites. Instead, it is recommended you evaluate Beta 3 on a test server and site.

WordPress Plugins � 57 Patched / 105 Unpatched

Post Lockdown

Plugin Slug:
post-lockdown

Installations
1,000+

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.
Plugin Slug:
picture-gallery

Installations
400+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

CRM and Lead Management by vcita

Plugin Slug:
crm-customer-relationship-management-by-vcita

Installations
100+

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

WP Email Delivery

Plugin Slug:
wp-email-delivery

Installations
100+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

amoCRM WebForm

Plugin:

amoCRM WebForm

Plugin Slug:
amocrm-webform

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Another Events Calendar

Plugin:

Another Events Calendar

Plugin Slug:
another-events-calendar

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

ArielBrailovsky-ViralAd

Plugin:

ArielBrailovsky-ViralAd

Plugin Slug:
arielbrailovsky-viralad

Vulnerability:
SQL Injection

Patched in Version:
No Fix

Severity Score:
Critical


The vulnerability has not been patched. You should deactivate the plugin.

AS English Admin

Plugin:

AS English Admin

Plugin Slug:
as-english-admin

Vulnerability:
Open Redirection

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Awesome Surveys

Plugin:

Awesome Surveys

Plugin Slug:
awesome-surveys

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Back To Top

Plugin:

Back To Top

Plugin Slug:
backtotop

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Bee Layer Slider

Plugin:

Bee Layer Slider

Plugin Slug:
bee-layer-slider

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

binlayerpress

Plugin:

binlayerpress

Plugin Slug:
binlayerpress

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Block Spam By Math Reloaded

Plugin:

Block Spam By Math Reloaded

Plugin Slug:
block-spam-by-math-reloaded

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Block Spam By Math Reloaded

Plugin:

Block Spam By Math Reloaded

Plugin Slug:
block-spam-by-math-reloaded

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

W3Counter Free Real-Time Web Stats

Plugin:

W3Counter Free Real-Time Web Stats

Plugin Slug:
blog-stats-by-w3counter

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

BlogBuzzTime for WP

Plugin:

BlogBuzzTime for WP

Plugin Slug:
blogbuzztime-for-wp

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

CC-IMG-Shortcode

Plugin:

CC-IMG-Shortcode

Plugin Slug:
cc-img-shortcode

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Builder for Contact Form 7 by Webconstruct

Plugin:

Builder for Contact Form 7 by Webconstruct

Plugin Slug:
cf7-builder

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Contact Form 7 Select Box Editor Button

Plugin:

Contact Form 7 Select Box Editor Button

Plugin Slug:
contact-form-7-select-box-editor-button

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Contact Us By Lord Linus

Plugin:

Contact Us By Lord Linus

Plugin Slug:
contact-us-by-lord-linus

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Coronavirus (COVID-19) Notice Message

Plugin:

Coronavirus (COVID-19) Notice Message

Plugin Slug:
coronavirus-covid-19-notice-message

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Custom Dashboard Page

Plugin:

Custom Dashboard Page

Plugin Slug:
custom-dashboard-page

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

custom-field-list-widget

Plugin:

custom-field-list-widget

Plugin Slug:
custom-field-list-widget

Vulnerability:
Local File Inclusion

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Custom top bar

Plugin:

Custom top bar

Plugin Slug:
custom-top-bar

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Delete Original Image

Plugin:

Delete Original Image

Plugin Slug:
delete-original-image

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Display Template Name

Plugin:

Display Template Name

Plugin Slug:
display-template-name

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Domain Theme

Plugin:

Domain Theme

Plugin Slug:
domain-theme

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

DP ALTerminator – Missing ALT manager

Plugin:

DP ALTerminator – Missing ALT manager

Plugin Slug:
dp-alterminator-missing-alt-manager

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Easy Image Display

Plugin:

Easy Image Display

Plugin Slug:
easy-image-display

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Email Keep

Plugin:

Email Keep

Plugin Slug:
email-keep

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Email Keep

Plugin:

Email Keep

Plugin Slug:
email-keep

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.
Plugin:

Featured Posts Grid

Plugin Slug:
featured-posts-grid

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Frontpage category filter

Plugin:

Frontpage category filter

Plugin Slug:
frontpage-category-filter

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

FTP Sync

Plugin:

FTP Sync

Plugin Slug:
ftp-sync

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

GetShop ecommerce

Plugin:

GetShop ecommerce

Plugin Slug:
getshop-ecommerce

Vulnerability:
Local File Inclusion

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

GetSocial

Plugin:

GetSocial

Plugin Slug:
getsocial

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

GNUCommerce

Plugin:

GNUCommerce

Plugin Slug:
gnucommerce

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

GNUPress

Plugin:

GNUPress

Plugin Slug:
gnupress

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Go To Top

Plugin:

Go To Top

Plugin Slug:
go-to-top

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.
Plugin:

Google News Editors Picks Feed Generator

Plugin Slug:
google-news-editors-picks-news-feeds

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

In Stock Mailer for WooCommerce

Plugin:

In Stock Mailer for WooCommerce

Plugin Slug:
in-stock-mailer-for-woocommerce

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Insert Code

Plugin:

Insert Code

Plugin Slug:
insert-code

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.
Plugin:

Lava Ajax Search

Plugin Slug:
lava-ajax-search

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

LinkedIn Lite

Plugin:

LinkedIn Lite

Plugin Slug:
linkedin-lite

Vulnerability:
Local File Inclusion

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

List Mixcloud

Plugin:

List Mixcloud

Plugin Slug:
list-mixcloud

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

List of Posts from each Category plugin for WordPress

Plugin:

List of Posts from each Category plugin for WordPress

Plugin Slug:
list-posts-by-category

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Login Logger

Plugin:

Login Logger

Plugin Slug:
login-logger

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Lunar

Plugin:

Lunar

Plugin Slug:
lunar-sell-photos-online

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

MaxA/B

Plugin:

MaxA/B

Plugin Slug:
maxab

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Members page only for logged in users

Plugin:

Members page only for logged in users

Plugin Slug:
members-page-only-for-logged-in-users

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

PHP/MySQL CPU performance statistics

Plugin:

PHP/MySQL CPU performance statistics

Plugin Slug:
mywebtonet-performancestats

Vulnerability:
PHP Object Injection

Patched in Version:
No Fix

Severity Score:
Critical


The vulnerability has not been patched. You should deactivate the plugin.

No Disposable Email

Plugin:

No Disposable Email

Plugin Slug:
no-disposable-email

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

pixelstats

Plugin:

pixelstats

Plugin Slug:
pixelstats

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

PluginPass

Plugin:

PluginPass

Plugin Slug:
pluginpass-pro-plugintheme-licensing

Vulnerability:
Arbitrary File Download

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Plugins Last Updated Column

Plugin:

Plugins Last Updated Column

Plugin Slug:
plugins-last-updated-column

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Portfolio and Projects

Plugin:

Portfolio and Projects

Plugin Slug:
portfolio-and-projects

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Post Read Time

Plugin:

Post Read Time

Plugin Slug:
post-read-time

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

price-calc

Plugin:

price-calc

Plugin Slug:
price-calc

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Rankchecker.io Integration

Plugin:

Rankchecker.io Integration

Plugin Slug:
rankchecker-io-integration

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Comment Date and Gravatar remover

Plugin:

Comment Date and Gravatar remover

Plugin Slug:
remove-date-and-gravatar-under-comment

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Responsive Google Map

Plugin:

Responsive Google Map

Plugin Slug:
responsive-google-map

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

REST API TO MiniProgram

Plugin:

REST API TO MiniProgram

Plugin Slug:
rest-api-to-miniprogram

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

S3Bubble Media Streaming

Plugin:

S3Bubble Media Streaming

Plugin Slug:
s3bubble-amazon-web-services-oembed-media-streaming-support

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Schedule

Plugin:

Schedule

Plugin Slug:
schedule

Vulnerability:
SQL Injection

Patched in Version:
No Fix

Severity Score:
Critical


The vulnerability has not been patched. You should deactivate the plugin.

Schedule

Plugin:

Schedule

Plugin Slug:
schedule

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

SEO Tools

Plugin:

SEO Tools

Plugin Slug:
seo-automatic-seo-tools

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Simple Amazon Affiliate

Plugin:

Simple Amazon Affiliate

Plugin Slug:
simple-amazon-affiliate

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Social Snap

Plugin:

Social Snap

Plugin Slug:
socialsnap

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Spam Byebye

Plugin:

Spam Byebye

Plugin Slug:
spam-byebye

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Tabbed Login Widget

Plugin:

Tabbed Login Widget

Plugin Slug:
tabbed-login

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

TabGarb Pro

Plugin:

TabGarb Pro

Plugin Slug:
tabgarb

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

TBTestimonials

Plugin:

TBTestimonials

Plugin Slug:
tb-testimonials

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

ThemeEgg ToolKit

Plugin:

ThemeEgg ToolKit

Plugin Slug:
themeegg-toolkit

Vulnerability:
Arbitrary File Upload

Patched in Version:
No Fix

Severity Score:
Critical


The vulnerability has not been patched. You should deactivate the plugin.
Plugin:

Featured Image Thumbnail Grid

Plugin Slug:
thumbnail-grid

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

J�-J� Pagamentos for WooCommerce

Plugin:

J�-J� Pagamentos for WooCommerce

Plugin Slug:
wc-ja-ja-pagamentos-multicaixa-express

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

WP Add Active Class To Menu Item

Plugin:

WP Add Active Class To Menu Item

Plugin Slug:
wp-add-active-class-to-menu-item

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

WP Azure offload

Plugin:

WP Azure offload

Plugin Slug:
wp-azure-offload

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

WP Bulk Post Duplicator

Plugin:

WP Bulk Post Duplicator

Plugin Slug:
wp-bulk-post-duplicator

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

WP Compare Tables

Plugin:

WP Compare Tables

Plugin Slug:
wp-compare-tables

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

WP Crowdfunding

Plugin:

WP Crowdfunding

Plugin Slug:
wp-crowdfunding

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Hashtags

Plugin:

Hashtags

Plugin Slug:
wp-hashtags

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

WP Hide Admin Bar

Plugin:

WP Hide Admin Bar

Plugin Slug:
wp-hide-admin-bar

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

WP JobHunt

Plugin:

WP JobHunt

Plugin Slug:
wp-jobhunt

Vulnerability:
Broken Authentication

Patched in Version:
No Fix

Severity Score:
Critical


The vulnerability has not been patched. You should deactivate the plugin.

WP JobHunt

Plugin:

WP JobHunt

Plugin Slug:
wp-jobhunt

Vulnerability:
Privilege Escalation

Patched in Version:
No Fix

Severity Score:
Critical


The vulnerability has not been patched. You should deactivate the plugin.

WP JobHunt

Plugin:

WP JobHunt

Plugin Slug:
wp-jobhunt

Vulnerability:
Broken Authentication

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

WP Last Modified

Plugin:

WP Last Modified

Plugin Slug:
wp-last-modified

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

WP Login Control

Plugin:

WP Login Control

Plugin Slug:
wp-login-control

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Mobile Themes

Plugin:

Mobile Themes

Plugin Slug:
wp-mobile-themes

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

WP No-Bot Question

Plugin:

WP No-Bot Question

Plugin Slug:
wp-no-bot-question

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

WP Performance Pack

Plugin:

WP Performance Pack

Plugin Slug:
wp-performance-pack

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

wordpress login form to anywhere

Plugin:

wordpress login form to anywhere

Plugin Slug:
wp-show-login-form

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

WP Simple Slideshow

Plugin:

WP Simple Slideshow

Plugin Slug:
wp-simple-slideshow

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Skitter Slideshow

Plugin:

Skitter Slideshow

Plugin Slug:
wp-skitter-slideshow

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

WP SVG Upload

Plugin:

WP SVG Upload

Plugin Slug:
wp-svg-upload

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

WP jQuery Persian Datepicker

Plugin:

WP jQuery Persian Datepicker

Plugin Slug:
wpjqp-datepicker

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

WPSchoolPress

Plugin:

WPSchoolPress

Plugin Slug:
wpschoolpress

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

WPSchoolPress

Plugin:

WPSchoolPress

Plugin Slug:
wpschoolpress

Vulnerability:
SQL Injection

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

WPSchoolPress

Plugin:

WPSchoolPress

Plugin Slug:
wpschoolpress

Vulnerability:
SQL Injection

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

WPSchoolPress

Plugin:

WPSchoolPress

Plugin Slug:
wpschoolpress

Vulnerability:
Privilege Escalation

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

XV Random Quotes

Plugin:

XV Random Quotes

Plugin Slug:
xv-random-quotes

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

XV Random Quotes

Plugin:

XV Random Quotes

Plugin Slug:
xv-random-quotes

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

ZipList Recipe

Plugin:

ZipList Recipe

Plugin Slug:
ziplist-recipe-plugin

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Zoorum Comments

Plugin:

Zoorum Comments

Plugin Slug:
zoorum-comments

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

WooCommerce

Plugin Slug:
woocommerce

Installations
8,000,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
9.7.1

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 9.7.1.

All-in-One WP Migration and Backup

Plugin Slug:
all-in-one-wp-migration

Installations
5,000,000+

Vulnerability:
PHP Object Injection

Patched in Version:
7.90

Severity Score:
High


The vulnerability has been patched, so you should update to version 7.90.

Ad Inserter � Ad Manager & AdSense Ads

Plugin Slug:
ad-inserter

Installations
300,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.8.1

Severity Score:
High


The vulnerability has been patched, so you should update to version 2.8.1.

LoginPress | wp-login Custom Login Page Customizer

Plugin Slug:
loginpress

Installations
200,000+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
4.0.0

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 4.0.0.

Download Manager

Plugin Slug:
download-manager

Installations
100,000+

Vulnerability:
Path Traversal

Patched in Version:
3.3.09

Severity Score:
Low


The vulnerability has been patched, so you should update to version 3.3.09.

ShareThis Dashboard for Google Analytics

Plugin Slug:
googleanalytics

Installations
100,000+

Vulnerability:
Broken Access Control

Patched in Version:
3.2.2

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 3.2.2.

HUSKY � Products Filter Professional for WooCommerce

Plugin Slug:
woocommerce-products-filter

Installations
100,000+

Vulnerability:
Local File Inclusion

Patched in Version:
1.3.6.5

Severity Score:
High


The vulnerability has been patched, so you should update to version 1.3.6.5.

HUSKY � Products Filter Professional for WooCommerce

Plugin Slug:
woocommerce-products-filter

Installations
100,000+

Vulnerability:
Local File Inclusion

Patched in Version:
1.3.6.6

Severity Score:
High


The vulnerability has been patched, so you should update to version 1.3.6.6.

WP Recipe Maker

Plugin Slug:
wp-recipe-maker

Installations
50,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
9.8.1

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 9.8.1.

DethemeKit for Elementor

Plugin Slug:
dethemekit-for-elementor

Installations
40,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.1.10

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.1.10.

SecuPress Free � WordPress Security

Plugin Slug:
secupress

Installations
40,000+

Vulnerability:
Broken Access Control

Patched in Version:
2.3

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.3.

InstaWP Connect � 1-click WP Staging & Migration

Plugin Slug:
instawp-connect

Installations
20,000+

Vulnerability:
Local File Inclusion

Patched in Version:
0.1.0.84

Severity Score:
High


The vulnerability has been patched, so you should update to version 0.1.0.84.

WP Test Email

Plugin Slug:
wp-test-email

Installations
20,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.1.9

Severity Score:
High


The vulnerability has been patched, so you should update to version 1.1.9.

Qubely � Advanced Gutenberg Blocks

Plugin Slug:
qubely

Installations
10,000+

Vulnerability:
Sensitive Data Exposure

Patched in Version:
1.8.14

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.8.14.

Finale Lite � Sales Countdown Timer & Discount for WooCommerce

Plugin Slug:
finale-woocommerce-sales-countdown-timer-discount

Installations
6,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.20.0

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.20.0.
Plugin Slug:
wp-responsive-thumbnail-slider

Installations
2,000+

Vulnerability:
SQL Injection

Patched in Version:
1.0.5

Severity Score:
High


The vulnerability has been patched, so you should update to version 1.0.5.

WPCOM Member

Plugin Slug:
wpcom-member

Installations
2,000+

Vulnerability:
SQL Injection

Patched in Version:
1.7.7

Severity Score:
Critical


The vulnerability has been patched, so you should update to version 1.7.7.

AppPresser � Mobile App Framework

Plugin Slug:
apppresser

Installations
1,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
4.4.11

Severity Score:
High


The vulnerability has been patched, so you should update to version 4.4.11.

WPCS � WordPress Currency Switcher Professional

Plugin Slug:
currency-switcher

Installations
1,000+

Vulnerability:
Content Injection

Patched in Version:
1.2.0.5

Severity Score:
High


The vulnerability has been patched, so you should update to version 1.2.0.5.

Event post

Plugin Slug:
event-post

Installations
1,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
5.9.9

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 5.9.9.

Omnipress

Plugin Slug:
omnipress

Installations
1,000+

Vulnerability:
Broken Access Control

Patched in Version:
1.5.5

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.5.5.

Simple Photo Feed

Plugin Slug:
simple-photo-feed

Installations
1,000+

Vulnerability:
Broken Access Control

Patched in Version:
1.4.1

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.4.1.

Church Admin

Plugin Slug:
church-admin

Installations
900+

Vulnerability:
SQL Injection

Patched in Version:
5.0.19

Severity Score:
Critical


The vulnerability has been patched, so you should update to version 5.0.19.

Maintenance Notice

Plugin Slug:
maintenance-notice

Installations
800+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
1.0.7

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.0.7.

WATI Chat and Notification

Plugin Slug:
wati-chat-and-notification

Installations
700+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
1.1.5

Severity Score:
High


The vulnerability has been patched, so you should update to version 1.1.5.

Skrill � WooCommerce

Plugin Slug:
official-skrill-woocommerce

Installations
600+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
1.0.67

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.0.67.

Accounting for WooCommerce

Plugin Slug:
accounting-for-woocommerce

Installations
500+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.6.9

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.6.9.

IP Based Login

Plugin Slug:
ip-based-login

Installations
500+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
2.4.1

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.4.1.

IP Based Login

Plugin Slug:
ip-based-login

Installations
500+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.4.1

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.4.1.

pipDisqus � Lightweight Disqus Comments

Plugin Slug:
pipdisqus

Installations
400+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.7

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.7.

Formality

Plugin Slug:
formality

Installations
200+

Vulnerability:
Local File Inclusion

Patched in Version:
1.5.8

Severity Score:
High


The vulnerability has been patched, so you should update to version 1.5.8.

Appsero Helper

Plugin Slug:
appsero-helper

Installations
60+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
1.3.3

Severity Score:
High


The vulnerability has been patched, so you should update to version 1.3.3.

BP Email Assign Templates

Plugin Slug:
bp-email-assign-templates

Installations
50+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.7

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.7.

BP Email Assign Templates

Plugin Slug:
bp-email-assign-templates

Installations
50+

Vulnerability:
Other Vulnerability Type

Patched in Version:
1.8

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.8.

AnalyticsWP

Plugin:

AnalyticsWP

Plugin Slug:
analyticswp

Vulnerability:
SQL Injection

Patched in Version:
2.1.0

Severity Score:
Critical


The vulnerability has been patched, so you should update to version 2.1.0.

Gtbabel

Plugin:

Gtbabel

Plugin Slug:
gtbabel

Vulnerability:
Privilege Escalation

Patched in Version:
6.6.9

Severity Score:
High


The vulnerability has been patched, so you should update to version 6.6.9.

Realteo

Plugin:

Realteo

Plugin Slug:
realteo

Vulnerability:
Broken Authentication

Patched in Version:
1.2.9

Severity Score:
Critical


The vulnerability has been patched, so you should update to version 1.2.9.

Resido

Plugin:

Resido

Plugin Slug:
resido

Vulnerability:
Broken Access Control

Patched in Version:
3.6.1

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 3.6.1.

Search Filter Pro

Plugin:

Search Filter Pro

Plugin Slug:
search-filter-pro

Vulnerability:
Broken Access Control

Patched in Version:
2.5.20

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.5.20.

SoundRise Music

Plugin:

SoundRise Music

Plugin Slug:
soundrise-music

Vulnerability:
Broken Access Control

Patched in Version:
1.7.1

Severity Score:
High


The vulnerability has been patched, so you should update to version 1.7.1.

VidoRev Extensions

Plugin:

VidoRev Extensions

Plugin Slug:
vidorev-extensions

Vulnerability:
Broken Access Control

Patched in Version:
2.9.9.9.9.9.6

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.9.9.9.9.9.6.

WordPress Themes � 6 Patched / 5 Unpatched

Civi

Theme:

Civi

Theme Slug:
civi

Vulnerability:
Sensitive Data Exposure

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should switch themes.

Civi

Theme:

Civi

Theme Slug:
civi

Vulnerability:
Broken Authentication

Patched in Version:
No Fix

Severity Score:
Critical


The vulnerability has not been patched. You should switch themes.

Civi

Theme:

Civi

Theme Slug:
civi

Vulnerability:
Broken Authentication

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should switch themes.

JobCareer

Theme:

JobCareer

Theme Slug:
jobcareer

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should switch themes.

Zegen

Theme:

Zegen

Theme Slug:
zegen

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should switch themes.

Design Comuni Italia

Theme:

Design Comuni Italia

Theme Slug:
design-comuni-wordpress-theme

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.1.2

Severity Score:
High


The vulnerability has been patched, so you should update to version 1.1.2.

Eco Nature

Theme:

Eco Nature

Theme Slug:
eco-nature

Vulnerability:
Broken Access Control

Patched in Version:
2.1.0

Severity Score:
High


The vulnerability has been patched, so you should update to version 2.1.0.

Industrial

Theme:

Industrial

Theme Slug:
industrial

Vulnerability:
Broken Access Control

Patched in Version:
1.7.9

Severity Score:
High


The vulnerability has been patched, so you should update to version 1.7.9.

Traveler

Theme:

Traveler

Theme Slug:
traveler

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
3.1.9

Severity Score:
High


The vulnerability has been patched, so you should update to version 3.1.9.

Traveler

Theme:

Traveler

Theme Slug:
traveler

Vulnerability:
Local File Inclusion

Patched in Version:
3.1.9

Severity Score:
High


The vulnerability has been patched, so you should update to version 3.1.9.

Workreap

Theme:

Workreap

Theme Slug:
workreap

Vulnerability:
Privilege Escalation

Patched in Version:
3.2.6

Severity Score:
Critical


The vulnerability has been patched, so you should update to version 3.2.6.

Related articles

Wait! Get exclusive hosting insights

Subscribe to our newsletter and stay ahead of the competition with expert advice from our hosting pros.

Loading form…