WordPress Vulnerability Report � March 25, 2026

In this report, 331 vulnerabilities have been publicly disclosed. Security patches for 211 of these plugins and themes are now available. Please run these updates as soon as possible. If you’re a Solid Security Pro user, the version management tool may have already warned you and updated these plugins, depending on your settings.

Currently, 120 plugin and theme vulnerabilities remain unpatched. If you’re a Solid Security Pro user, those vulnerabilities are already protected by the Solid Security firewall. Virtual patches from Patchstack will be applied when a vulnerability is considered high or medium risk. If no patch is forthcoming from the vendor or the vulnerable software has been marked “closed” and dropped from the official WordPress repositories, you should deactivate it soon and look for alternative solutions.

WordPress Core

WordPress 6.9.4 is now available, addressing 10 security issues and a bug that affected template file loading on a limited number of sites. Because this is a security release, it is recommended that you update your sites immediately.

Also, WordPress 7.0 RC1 is ready for download and testing! As this is a pre-release version, it is intended for testing and development only and should not be installed on production or mission-critical sites. Organizations should use local or staging environments to evaluate compatibility and new features before the final rollout.

WordPress 7.0 is scheduled for release on April 9, 2026.

WordPress Plugins � 162 Patched / 113 Unpatched

Product Slider, Product Grid, Product Masonry

Plugin Slug:
woocommerce-products-slider

Installations
10,000+

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

WPCargo Track & Trace

Plugin Slug:
wpcargo

Installations
10,000+

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Booking calendar, Appointment Booking System

Plugin Slug:
booking-calendar

Installations
4,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Coinbase Commerce � Crypto Gateway for WooCommerce

Plugin Slug:
commerce-coinbase-for-woocommerce

Installations
1,000+

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

CP Multi View Events Calendar

Plugin Slug:
cp-multi-view-calendar

Installations
1,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

TotalPoll for Polls and Contests

Plugin Slug:
totalpoll-lite

Installations
1,000+

Vulnerability:
Remote Code Execution (RCE)

Patched in Version:
No Fix

Severity Score:
Critical


The vulnerability has not been patched. You should deactivate the plugin.

Gutenberg Blocks � Unlimited blocks For Gutenberg

Plugin Slug:
unlimited-blocks

Installations
1,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

GZSEO

Plugin:

GZSEO

Plugin Slug:
gzseo

Installations
600+

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

ViaBill � WooCommerce

Plugin Slug:
viabill-woocommerce

Installations
500+

Vulnerability:
Settings Change

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Vertex Addons for Elementor

Plugin Slug:
addons-for-elementor-builder

Installations
400+

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Product Rearrange for WooCommerce

Plugin Slug:
products-rearrange-woocommerce

Installations
400+

Vulnerability:
SQL Injection

Patched in Version:
No Fix

Severity Score:
Critical


The vulnerability has not been patched. You should deactivate the plugin.

Product Rearrange for WooCommerce

Plugin Slug:
products-rearrange-woocommerce

Installations
400+

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Remoji � Post/Comment Reaction and Enhancement

Plugin Slug:
remoji

Installations
400+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Widget Wrangler

Plugin Slug:
widget-wrangler

Installations
200+

Vulnerability:
Remote Code Execution (RCE)

Patched in Version:
No Fix

Severity Score:
Critical


The vulnerability has not been patched. You should deactivate the plugin.

File Uploader for WooCommerce

Plugin Slug:
file-uploader-for-woocommerce

Installations
100+

Vulnerability:
Path Traversal

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Admin Safety Guard � Login Security & 2FA

Plugin Slug:
admin-safety-guard

Installations
10+

Vulnerability:
Broken Authentication

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Ad Short

Plugin:

Ad Short

Plugin Slug:
ad-short

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Add Google Social Profiles to Knowledge Graph Box

Plugin:

Add Google Social Profiles to Knowledge Graph Box

Plugin Slug:
add-google-social-profiles-to-knowledge-graph-box

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

ACPT (Pro) – Custom Post Types Plugin for WordPress

Plugin:

ACPT (Pro) – Custom Post Types Plugin for WordPress

Plugin Slug:
advanced-custom-post-type

Vulnerability:
Remote Code Execution (RCE)

Patched in Version:
No Fix

Severity Score:
Critical


The vulnerability has not been patched. You should deactivate the plugin.

Alfie

Plugin:

Alfie

Plugin Slug:
alfie-the-productfeedtool-wp-plugin

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Any Post Slider

Plugin:

Any Post Slider

Plugin Slug:
any-post-slider

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

App Builder

Plugin:

App Builder

Plugin Slug:
app-builder

Vulnerability:
Privilege Escalation

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Reward Video Ad for WordPress

Plugin:

Reward Video Ad for WordPress

Plugin Slug:
applixir

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Appmax

Plugin:

Appmax

Plugin Slug:
appmax

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Ave Core

Plugin:

Ave Core

Plugin Slug:
ave-core

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Build App Online

Plugin:

Build App Online

Plugin Slug:
build-app-online

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Canto

Plugin:

Canto

Plugin Slug:
canto

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

CMS Commander

Plugin:

CMS Commander

Plugin Slug:
cms-commander-client

Vulnerability:
SQL Injection

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Comment SPAM Wiper

Plugin:

Comment SPAM Wiper

Plugin Slug:
comment-spam-wiper

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Company Posts for LinkedIn

Plugin:

Company Posts for LinkedIn

Plugin Slug:
company-posts-for-linkedin

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Content Syndication Toolkit

Plugin:

Content Syndication Toolkit

Plugin Slug:
content-syndication-toolkit

Vulnerability:
Server Side Request Forgery (SSRF)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Curly Core

Plugin:

Curly Core

Plugin Slug:
curly-core

Vulnerability:
Local File Inclusion

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

e-shot

Plugin:

e-shot

Plugin Slug:
e-shot-form-builder

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.
Plugin:

Easy Image Gallery

Plugin Slug:
easy-image-gallery

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Ecover Builder For Dummies

Plugin:

Ecover Builder For Dummies

Plugin Slug:
ecover-builder-for-dummies

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Ed’s Font Awesome

Plugin:

Ed’s Font Awesome

Plugin Slug:
eds-font-awesome

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Ed’s Social Share

Plugin:

Ed’s Social Share

Plugin Slug:
eds-social-share

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

ElementCamp

Plugin:

ElementCamp

Plugin Slug:
element-camp

Vulnerability:
SQL Injection

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Expire Users

Plugin:

Expire Users

Plugin Slug:
expire-users

Vulnerability:
Privilege Escalation

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Fonts Manager | Custom Fonts

Plugin:

Fonts Manager | Custom Fonts

Plugin Slug:
fonts-manager-custom-fonts

Vulnerability:
SQL Injection

Patched in Version:
No Fix

Severity Score:
Critical


The vulnerability has not been patched. You should deactivate the plugin.

FuseDesk

Plugin:

FuseDesk

Plugin Slug:
fusedesk

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

fyyd podcast shortcodes

Plugin:

fyyd podcast shortcodes

Plugin Slug:
fyyd-podcast-shortcodes

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Go Night Pro

Plugin:

Go Night Pro

Plugin Slug:
go-night-pro

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Hr Press Lite

Plugin:

Hr Press Lite

Plugin Slug:
hr-press-lite

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Integration with Hubspot Forms

Plugin:

Integration with Hubspot Forms

Plugin Slug:
integration-with-hubspot-forms

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Invelity Product Feeds

Plugin:

Invelity Product Feeds

Plugin Slug:
invelity-products-feeds

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

itsukaita

Plugin:

itsukaita

Plugin Slug:
itsukaita

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

iVysilani Shortcode

Plugin:

iVysilani Shortcode

Plugin Slug:
ivysilani-shortcode

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Jobica Core

Plugin:

Jobica Core

Plugin Slug:
jobica-core

Vulnerability:
Broken Authentication

Patched in Version:
No Fix

Severity Score:
Critical


The vulnerability has not been patched. You should deactivate the plugin.

Linksy Search and Replace

Plugin:

Linksy Search and Replace

Plugin Slug:
linksy-search-and-replace

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Listeo Core

Plugin:

Listeo Core

Plugin Slug:
listeo-core

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Lobot Slider Administrator

Plugin:

Lobot Slider Administrator

Plugin Slug:
lobot-slider-administrator

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

login_register

Plugin:

login_register

Plugin Slug:
login-register

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Mandatory Field

Plugin:

Mandatory Field

Plugin Slug:
mandatory-fields

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.
Plugin:

MimeTypes Link Icons

Plugin Slug:
mimetypes-link-icons

Vulnerability:
Server Side Request Forgery (SSRF)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.
Plugin:

MinhNhut Link Gateway

Plugin Slug:
minhnhut-link-gateway

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Modern Events Calendar

Plugin:

Modern Events Calendar

Plugin Slug:
modern-events-calendar

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Multi Functional Flexi Lightbox

Plugin:

Multi Functional Flexi Lightbox

Plugin Slug:
multi-functional-flexi-lightbox

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Multi Post Carousel by Category

Plugin:

Multi Post Carousel by Category

Plugin Slug:
multi-post-carousel

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

myLinksDump

Plugin:

myLinksDump

Plugin Slug:
mylinksdump

Vulnerability:
SQL Injection

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Neos Connector for Fakturama

Plugin:

Neos Connector for Fakturama

Plugin Slug:
neos-connector-for-fakturama

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Outgrow

Plugin:

Outgrow

Plugin Slug:
outgrow

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Paypal Shortcodes

Plugin:

Paypal Shortcodes

Plugin Slug:
paypal-shortcodes

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

PQ Addons � Creative Elementor Widgets

Plugin:

PQ Addons � Creative Elementor Widgets

Plugin Slug:
peacefulqode-elementzplus-widgets

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Performance Monitor

Plugin:

Performance Monitor

Plugin Slug:
performance-monitor

Vulnerability:
Server Side Request Forgery (SSRF)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Post Flagger

Plugin:

Post Flagger

Plugin Slug:
post-flagger

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Post Snippits

Plugin:

Post Snippits

Plugin Slug:
post-snippits

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Post Affiliate Pro

Plugin:

Post Affiliate Pro

Plugin Slug:
postaffiliatepro

Vulnerability:
Server Side Request Forgery (SSRF)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Pre* Party Resource Hints

Plugin:

Pre* Party Resource Hints

Plugin Slug:
pre-party-browser-hints

Vulnerability:
SQL Injection

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Punnel � Landing Page Builder

Plugin:

Punnel � Landing Page Builder

Plugin Slug:
punnel-landing-page-builder

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Quentn WP

Plugin:

Quentn WP

Plugin Slug:
quentn-wp

Vulnerability:
SQL Injection

Patched in Version:
No Fix

Severity Score:
Critical


The vulnerability has not been patched. You should deactivate the plugin.

Redirect countdown

Plugin:

Redirect countdown

Plugin Slug:
redirect-countdown

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

REST API TO MiniProgram

Plugin:

REST API TO MiniProgram

Plugin Slug:
rest-api-to-miniprogram

Vulnerability:
Insecure Direct Object References (IDOR)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Review Map by RevuKangaroo

Plugin:

Review Map by RevuKangaroo

Plugin Slug:
review-map-by-revukangaroo

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.
Plugin:

Ricerca � advanced search

Plugin Slug:
ricerca-smart-search

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

WooCommerce Infinite Scroll

Plugin:

WooCommerce Infinite Scroll

Plugin Slug:
sb-woocommerce-infinite-scroll

Vulnerability:
PHP Object Injection

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Schema Shortcode

Plugin:

Schema Shortcode

Plugin Slug:
schema-shortcode

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Sheets2Table

Plugin:

Sheets2Table

Plugin Slug:
sheets2table

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Sherk Custom Post Type Displays

Plugin:

Sherk Custom Post Type Displays

Plugin Slug:
sherk-custom-post-type-displays

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Weaver Show Posts

Plugin:

Weaver Show Posts

Plugin Slug:
show-posts

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Show Posts list

Plugin:

Show Posts list

Plugin Slug:
show-posts-shortcodes

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Simple Football Scoreboard

Plugin:

Simple Football Scoreboard

Plugin Slug:
simple-football-score-board

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Smarter Analytics

Plugin:

Smarter Analytics

Plugin Slug:
smarter-analytics

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Speedup Optimization

Plugin:

Speedup Optimization

Plugin Slug:
speedup-optimization

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

SR WP Minify HTML

Plugin:

SR WP Minify HTML

Plugin Slug:
sr-wp-minify-html

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Survey

Plugin:

Survey

Plugin Slug:
survey

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Task Manager

Plugin:

Task Manager

Plugin Slug:
task-manager

Vulnerability:
Arbitrary File Download

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Text Toggle

Plugin:

Text Toggle

Plugin Slug:
text-toggle

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

The Aisle Core

Plugin:

The Aisle Core

Plugin Slug:
theaisle-core

Vulnerability:
Local File Inclusion

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Tour & Activity Operator Plugin for TourCMS

Plugin:

Tour & Activity Operator Plugin for TourCMS

Plugin Slug:
tour-operator-plugin

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Tutor LMS Pro

Plugin:

Tutor LMS Pro

Plugin Slug:
tutor-pro

Vulnerability:
Broken Authentication

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Twitter Feeds

Plugin:

Twitter Feeds

Plugin Slug:
twitter-feeds

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Unlimited Elements for Elementor (Premium)

Plugin:

Unlimited Elements for Elementor (Premium)

Plugin Slug:
unlimited-elements-for-elementor-premium

Vulnerability:
Arbitrary File Upload

Patched in Version:
No Fix

Severity Score:
Critical


The vulnerability has not been patched. You should deactivate the plugin.

Vagaro Booking Widget

Plugin:

Vagaro Booking Widget

Plugin Slug:
vagaro-booking-widget

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Wikilookup

Plugin:

Wikilookup

Plugin Slug:
wikilookup

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

WishList Member X

Plugin:

WishList Member X

Plugin Slug:
wishlist-member-x

Vulnerability:
PHP Object Injection

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

WishList Member X

Plugin:

WishList Member X

Plugin Slug:
wishlist-member-x

Vulnerability:
Arbitrary File Upload

Patched in Version:
No Fix

Severity Score:
Critical


The vulnerability has not been patched. You should deactivate the plugin.

WZone

Plugin:

WZone

Plugin Slug:
woozone

Vulnerability:
SQL Injection

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

WZone

Plugin:

WZone

Plugin Slug:
woozone

Vulnerability:
Arbitrary File Deletion

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

WordPress PayPal Donation

Plugin:

WordPress PayPal Donation

Plugin Slug:
wordpress-paypal-donation

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

WP-Chatbot for Messenger

Plugin:

WP-Chatbot for Messenger

Plugin Slug:
wp-chatbot

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

WP Games Embed

Plugin:

WP Games Embed

Plugin Slug:
wp-games-embed

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

WP NG Weather

Plugin:

WP NG Weather

Plugin Slug:
wp-ng-weather

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

WP Posts Re-order

Plugin:

WP Posts Re-order

Plugin Slug:
wp-posts-re-order

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

WP Random Button

Plugin:

WP Random Button

Plugin Slug:
wp-random-button

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

WPBookit Pro

Plugin:

WPBookit Pro

Plugin Slug:
wpbookit-pro

Vulnerability:
Arbitrary File Upload

Patched in Version:
No Fix

Severity Score:
Critical


The vulnerability has not been patched. You should deactivate the plugin.

WPBookit Pro

Plugin:

WPBookit Pro

Plugin Slug:
wpbookit-pro

Vulnerability:
Privilege Escalation

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

WPFAQBlock

Plugin:

WPFAQBlock

Plugin Slug:
wpfaqblock

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Writeprint Stylometry

Plugin:

Writeprint Stylometry

Plugin Slug:
writeprint-stylometry

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Xhanch � My Advanced Settings

Plugin:

Xhanch � My Advanced Settings

Plugin Slug:
xhanch-my-advanced-settings

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Yoast Duplicate Post

Plugin Slug:
duplicate-post

Installations
4,000,000+

Vulnerability:
Broken Access Control

Patched in Version:
4.6

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 4.6.

Autoptimize

Plugin Slug:
autoptimize

Installations
900,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
3.1.15

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 3.1.15.

Autoptimize

Plugin Slug:
autoptimize

Installations
900,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
3.1.15

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 3.1.15.

WP Go Maps (formerly WP Google Maps)

Plugin Slug:
wp-google-maps

Installations
300,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
10.0.06

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 10.0.06.

Download Manager

Plugin Slug:
download-manager

Installations
100,000+

Vulnerability:
Broken Access Control

Patched in Version:
3.3.50

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 3.3.50.

Tutor LMS � eLearning and online course solution

Plugin Slug:
tutor

Installations
100,000+

Vulnerability:
Insecure Direct Object References (IDOR)

Patched in Version:
3.9.5

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 3.9.5.

JetFormBuilder � Dynamic Blocks Form Builder

Plugin Slug:
jetformbuilder

Installations
90,000+

Vulnerability:
Remote Code Execution (RCE)

Patched in Version:
3.5.6.2

Severity Score:
Critical


The vulnerability has been patched, so you should update to version 3.5.6.2.

SlimStat Analytics

Plugin Slug:
wp-slimstat

Installations
80,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
5.4.0

Severity Score:
High


The vulnerability has been patched, so you should update to version 5.4.0.

Online Scheduling and Appointment Booking System � Bookly

Plugin Slug:
bookly-responsive-appointment-booking-tool

Installations
70,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
26.8

Severity Score:
High


The vulnerability has been patched, so you should update to version 26.8.

SMTP Mailer

Plugin Slug:
smtp-mailer

Installations
70,000+

Vulnerability:
Sensitive Data Exposure

Patched in Version:
1.1.25

Severity Score:
High


The vulnerability has been patched, so you should update to version 1.1.25.
Plugin Slug:
contextual-related-posts

Installations
60,000+

Vulnerability:
Broken Access Control

Patched in Version:
4.2.2

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 4.2.2.

User Registration & Membership � Free & Paid Memberships, Subscriptions, Content Restriction, User Profile, Custom User Registration & Login Builder

Plugin Slug:
user-registration

Installations
60,000+

Vulnerability:
Privilege Escalation

Patched in Version:
5.1.3

Severity Score:
High


The vulnerability has been patched, so you should update to version 5.1.3.

Visual Portfolio, Photo Gallery & Post Grid

Plugin Slug:
visual-portfolio

Installations
60,000+

Vulnerability:
Local File Inclusion

Patched in Version:
3.5.2

Severity Score:
High


The vulnerability has been patched, so you should update to version 3.5.2.
Plugin Slug:
simply-gallery-block

Installations
40,000+

Vulnerability:
Arbitrary Code Execution

Patched in Version:
3.3.2.1

Severity Score:
Critical


The vulnerability has been patched, so you should update to version 3.3.2.1.

PPWP � Password Protect Pages

Plugin Slug:
password-protect-page

Installations
30,000+

Vulnerability:
Broken Access Control

Patched in Version:
1.9.16

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.9.16.

Ultimate Post Kit Addons for Elementor

Plugin Slug:
ultimate-post-kit

Installations
30,000+

Vulnerability:
Broken Access Control

Patched in Version:
4.0.22

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 4.0.22.

Print Invoice & Delivery Notes for WooCommerce

Plugin Slug:
woocommerce-delivery-notes

Installations
30,000+

Vulnerability:
Broken Access Control

Patched in Version:
6.0.0

Severity Score:
High


The vulnerability has been patched, so you should update to version 6.0.0.

WP Custom Admin Interface

Plugin Slug:
wp-custom-admin-interface

Installations
30,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
7.43

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 7.43.

Kali Forms � Contact Form & Drag-and-Drop Builder

Plugin Slug:
kali-forms

Installations
20,000+

Vulnerability:
Remote Code Execution (RCE)

Patched in Version:
2.4.10

Severity Score:
Critical


The vulnerability has been patched, so you should update to version 2.4.10.

New User Approve

Plugin Slug:
new-user-approve

Installations
20,000+

Vulnerability:
Broken Access Control

Patched in Version:
3.2.4

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 3.2.4.

Lead Form Builder & Contact Form

Plugin Slug:
lead-form-builder

Installations
10,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.0.2

Severity Score:
High


The vulnerability has been patched, so you should update to version 2.0.2.

Membership Plugin � Restrict Content

Plugin Slug:
restrict-content

Installations
10,000+

Vulnerability:
Broken Access Control

Patched in Version:
3.2.23

Severity Score:
High


The vulnerability has been patched, so you should update to version 3.2.23.

Membership Plugin � Restrict Content

Plugin Slug:
restrict-content

Installations
10,000+

Vulnerability:
Broken Authentication

Patched in Version:
3.2.25

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 3.2.25.

Code Embed

Plugin Slug:
simple-embed-code

Installations
10,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.5.2

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.5.2.

Subscriptions for WooCommerce

Plugin Slug:
subscriptions-for-woocommerce

Installations
10,000+

Vulnerability:
Broken Access Control

Patched in Version:
1.9.3

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.9.3.

Team � Team Members Showcase Plugin

Plugin Slug:
tlp-team

Installations
10,000+

Vulnerability:
Broken Access Control

Patched in Version:
5.0.12

Severity Score:
High


The vulnerability has been patched, so you should update to version 5.0.12.

Spam Protect for Contact Form 7

Plugin Slug:
wp-contact-form-7-spam-blocker

Installations
10,000+

Vulnerability:
Arbitrary File Deletion

Patched in Version:
1.2.10

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.2.10.

WP REST Cache

Plugin Slug:
wp-rest-cache

Installations
10,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2026.1.1

Severity Score:
High


The vulnerability has been patched, so you should update to version 2026.1.1.

WPVulnerability

Plugin Slug:
wpvulnerability

Installations
10,000+

Vulnerability:
Broken Access Control

Patched in Version:
4.2.1.1

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 4.2.1.1.

YML for Yandex Market

Plugin Slug:
yml-for-yandex-market

Installations
10,000+

Vulnerability:
Arbitrary File Deletion

Patched in Version:
5.3.0

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 5.3.0.

Contact Form Email

Plugin Slug:
contact-form-to-email

Installations
9,000+

Vulnerability:
Broken Access Control

Patched in Version:
1.3.64

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.3.64.

Event Booking Manager for WooCommerce

Plugin Slug:
mage-eventpress

Installations
8,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
5.1.5

Severity Score:
High


The vulnerability has been patched, so you should update to version 5.1.5.

WP TripAdvisor Review Slider

Plugin Slug:
wp-tripadvisor-review-slider

Installations
8,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
14.2

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 14.2.

EventPrime � Events Calendar, Bookings and Tickets

Plugin Slug:
eventprime-event-calendar-management

Installations
7,000+

Vulnerability:
Broken Access Control

Patched in Version:
4.2.8.4

Severity Score:
High


The vulnerability has been patched, so you should update to version 4.2.8.4.

EventPrime � Events Calendar, Bookings and Tickets

Plugin Slug:
eventprime-event-calendar-management

Installations
7,000+

Vulnerability:
PHP Object Injection

Patched in Version:
4.2.8.1

Severity Score:
Critical


The vulnerability has been patched, so you should update to version 4.2.8.1.

JS Help Desk � AI-Powered Support & Ticketing System

Plugin Slug:
js-support-ticket

Installations
7,000+

Vulnerability:
Insecure Direct Object References (IDOR)

Patched in Version:
3.0.4

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 3.0.4.

NEX-Forms � Ultimate Forms Plugin for WordPress

Plugin Slug:
nex-forms-express-wp-form-builder

Installations
7,000+

Vulnerability:
Broken Access Control

Patched in Version:
9.1.10

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 9.1.10.

NEX-Forms � Ultimate Forms Plugin for WordPress

Plugin Slug:
nex-forms-express-wp-form-builder

Installations
7,000+

Vulnerability:
Broken Access Control

Patched in Version:
9.1.10

Severity Score:
High


The vulnerability has been patched, so you should update to version 9.1.10.

WP Review Slider

Plugin Slug:
wp-facebook-reviews

Installations
7,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
14.0

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 14.0.

Get Use APIs � JSON Content Importer

Plugin Slug:
json-content-importer

Installations
6,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.0.10

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.0.10.

ProfileGrid � User Profiles, Groups and Communities

Plugin Slug:
profilegrid-user-profiles-groups-and-communities

Installations
6,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
5.9.8.2

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 5.9.8.2.

User Verification by PickPlugins

Plugin Slug:
user-verification

Installations
5,000+

Vulnerability:
Broken Authentication

Patched in Version:
2.0.46

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.0.46.

Fraud Prevention For WooCommerce and EDD

Plugin Slug:
woo-blocker-lite-prevent-fake-orders-and-blacklist-fraud-customers

Installations
5,000+

Vulnerability:
Arbitrary Content Deletion

Patched in Version:
2.3.4

Severity Score:
High


The vulnerability has been patched, so you should update to version 2.3.4.

ElementInvader Addons for Elementor

Plugin Slug:
elementinvader-addons-for-elementor

Installations
4,000+

Vulnerability:
SQL Injection

Patched in Version:
1.4.3

Severity Score:
High


The vulnerability has been patched, so you should update to version 1.4.3.

RSFirewall!

Plugin Slug:
rsfirewall

Installations
4,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.1.46

Severity Score:
High


The vulnerability has been patched, so you should update to version 1.1.46.

Abandoned Cart Recovery for WooCommerce

Plugin Slug:
woo-abandoned-cart-recovery

Installations
4,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.1.11

Severity Score:
High


The vulnerability has been patched, so you should update to version 1.1.11.

WPJAM Basic

Plugin Slug:
wpjam-basic

Installations
4,000+

Vulnerability:
Arbitrary File Upload

Patched in Version:
6.9.2.1

Severity Score:
Critical


The vulnerability has been patched, so you should update to version 6.9.2.1.
Plugin Slug:
wptelegram-widget

Installations
4,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.2.14

Severity Score:
High


The vulnerability has been patched, so you should update to version 2.2.14.

JS Archive List

Plugin Slug:
jquery-archive-list-widget

Installations
3,000+

Vulnerability:
PHP Object Injection

Patched in Version:
6.2.0

Severity Score:
High


The vulnerability has been patched, so you should update to version 6.2.0.

Kargo Takip

Plugin Slug:
kargo-takip-turkiye

Installations
3,000+

Vulnerability:
Broken Access Control

Patched in Version:
0.2.4

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 0.2.4.

Bit SMTP � Easy SMTP Solution with Email Logs

Plugin Slug:
bit-smtp

Installations
2,000+

Vulnerability:
Broken Authentication

Patched in Version:
1.2.3

Severity Score:
Critical


The vulnerability has been patched, so you should update to version 1.2.3.

Comments Import & Export

Plugin Slug:
comments-import-export-woocommerce

Installations
2,000+

Vulnerability:
Broken Access Control

Patched in Version:
2.5.0

Severity Score:
High


The vulnerability has been patched, so you should update to version 2.5.0.

Info Cards � Add Text and Media in Card Layouts

Plugin Slug:
info-cards

Installations
2,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.0.8

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.0.8.

KiviCare � Clinic & Patient Management System (EHR)

Plugin Slug:
kivicare-clinic-management-system

Installations
2,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
4.0.0

Severity Score:
High


The vulnerability has been patched, so you should update to version 4.0.0.

KiviCare � Clinic & Patient Management System (EHR)

Plugin Slug:
kivicare-clinic-management-system

Installations
2,000+

Vulnerability:
Broken Access Control

Patched in Version:
4.0.0

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 4.0.0.

KiviCare � Clinic & Patient Management System (EHR)

Plugin Slug:
kivicare-clinic-management-system

Installations
2,000+

Vulnerability:
Broken Access Control

Patched in Version:
4.1.3

Severity Score:
High


The vulnerability has been patched, so you should update to version 4.1.3.

KiviCare � Clinic & Patient Management System (EHR)

Plugin Slug:
kivicare-clinic-management-system

Installations
2,000+

Vulnerability:
Privilege Escalation

Patched in Version:
4.1.3

Severity Score:
Critical


The vulnerability has been patched, so you should update to version 4.1.3.

Photo Engine (Media Organizer & Lightroom)

Plugin Slug:
wplr-sync

Installations
2,000+

Vulnerability:
Arbitrary File Upload

Patched in Version:
6.5.0

Severity Score:
Critical


The vulnerability has been patched, so you should update to version 6.5.0.

avalex � Automatisch sichere Rechtstexte

Plugin Slug:
avalex

Installations
1,000+

Vulnerability:
Broken Access Control

Patched in Version:
3.1.4

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 3.1.4.

Contact List � Online Staff Directory & Address Book

Plugin Slug:
contact-list

Installations
1,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
3.0.19

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 3.0.19.

Flexmls� IDX Plugin

Plugin Slug:
flexmls-idx

Installations
1,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
3.15.10

Severity Score:
High


The vulnerability has been patched, so you should update to version 3.15.10.

Injection Guard

Plugin Slug:
injection-guard

Installations
1,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.3.0

Severity Score:
High


The vulnerability has been patched, so you should update to version 1.3.0.

My Tickets � Accessible Event Ticketing

Plugin Slug:
my-tickets

Installations
700+

Vulnerability:
Bypass Vulnerability

Patched in Version:
2.1.2

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.1.2.

Premmerce Redirect Manager

Plugin Slug:
premmerce-redirect-manager

Installations
600+

Vulnerability:
Broken Access Control

Patched in Version:
1.0.13

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.0.13.

VikRestaurants Table Reservations and Take-Away

Plugin Slug:
vikrestaurants

Installations
600+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.5.3

Severity Score:
High


The vulnerability has been patched, so you should update to version 1.5.3.

Taboola Pixel

Plugin Slug:
taboola-pixel

Installations
400+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.1.5

Severity Score:
High


The vulnerability has been patched, so you should update to version 1.1.5.

Keep Backup Daily

Plugin Slug:
keep-backup-daily

Installations
300+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.1.3

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.1.3.

Keep Backup Daily

Plugin Slug:
keep-backup-daily

Installations
300+

Vulnerability:
Path Traversal

Patched in Version:
2.1.3

Severity Score:
Low


The vulnerability has been patched, so you should update to version 2.1.3.

Helpdesk Support Ticket System for WooCommerce

Plugin Slug:
support-ticket-system-for-woocommerce

Installations
200+

Vulnerability:
Broken Access Control

Patched in Version:
2.1.3

Severity Score:
High


The vulnerability has been patched, so you should update to version 2.1.3.

ilGhera Carta Docente for WooCommerce

Plugin Slug:
wc-carta-docente

Installations
200+

Vulnerability:
Arbitrary File Deletion

Patched in Version:
1.5.1

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.5.1.

Contact Manager

Plugin Slug:
contact-manager

Installations
100+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
9.1.1

Severity Score:
High


The vulnerability has been patched, so you should update to version 9.1.1.

FAQ Builder AYS

Plugin Slug:
faq-builder-ays

Installations
100+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.8.3

Severity Score:
High


The vulnerability has been patched, so you should update to version 1.8.3.

LearnPress � Sepay Payment

Plugin Slug:
learnpress-sepay-payment

Installations
100+

Vulnerability:
Broken Authentication

Patched in Version:
4.0.1

Severity Score:
High


The vulnerability has been patched, so you should update to version 4.0.1.

Petitioner

Plugin Slug:
petitioner

Installations
100+

Vulnerability:
Broken Access Control

Patched in Version:
0.7.4

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 0.7.4.

Product File Upload for WooCommerce

Plugin Slug:
products-file-upload-for-woocommerce

Installations
100+

Vulnerability:
Arbitrary File Deletion

Patched in Version:
2.2.5

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.2.5.

Add Custom Fields to Media

Plugin Slug:
add-custom-fields-to-media

Installations
90+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
2.0.4

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.0.4.

Draft List

Plugin Slug:
simple-draft-list

Installations
80+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.6.3

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.6.3.

Filestack WP Upload

Plugin Slug:
filestack-upload

Installations
60+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
3.0.0

Severity Score:
High


The vulnerability has been patched, so you should update to version 3.0.0.

Activity Log for WordPress

Plugin Slug:
winterlock

Installations
60+

Vulnerability:
Broken Access Control

Patched in Version:
1.2.8

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.2.8.

Scoreboard for HTML5 Games Lite

Plugin Slug:
scoreboard-for-html5-game-lite

Installations
20+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.3

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.3.
Plugin Slug:
crpaid-link-manager

Installations
10+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
0.6

Severity Score:
High


The vulnerability has been patched, so you should update to version 0.6.

RockPress

Plugin Slug:
ft-rockpress

Installations
10+

Vulnerability:
Broken Access Control

Patched in Version:
1.0.18

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.0.18.

WP Cost Estimation & Payment Forms Builder

Plugin:

WP Cost Estimation & Payment Forms Builder

Plugin Slug:
WP_Estimation_Form

Vulnerability:
Broken Access Control

Patched in Version:
10.3.0

Severity Score:
High


The vulnerability has been patched, so you should update to version 10.3.0.

Addon Jobsearch Chat

Plugin:

Addon Jobsearch Chat

Plugin Slug:
addon-jobsearch-chat

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
3.1

Severity Score:
High


The vulnerability has been patched, so you should update to version 3.1.

Addon Jobsearch Chat

Plugin:

Addon Jobsearch Chat

Plugin Slug:
addon-jobsearch-chat

Vulnerability:
SQL Injection

Patched in Version:
3.1

Severity Score:
Critical


The vulnerability has been patched, so you should update to version 3.1.

SUMO Affiliates Pro

Plugin:

SUMO Affiliates Pro

Plugin Slug:
affs

Vulnerability:
PHP Object Injection

Patched in Version:
11.4.0

Severity Score:
Critical


The vulnerability has been patched, so you should update to version 11.4.0.

Aimogen Pro

Plugin:

Aimogen Pro

Plugin Slug:
aimogen-pro

Vulnerability:
Privilege Escalation

Patched in Version:
2.7.6

Severity Score:
Critical


The vulnerability has been patched, so you should update to version 2.7.6.

Elated Listing

Plugin:

Elated Listing

Plugin Slug:
eltd-listing

Vulnerability:
Broken Access Control

Patched in Version:
1.5

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.5.

XStore Core

Plugin:

XStore Core

Plugin Slug:
et-core-plugin

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
5.6.5

Severity Score:
High


The vulnerability has been patched, so you should update to version 5.6.5.

Fusion Builder

Plugin:

Fusion Builder

Plugin Slug:
fusion-builder

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
3.15.0

Severity Score:
High


The vulnerability has been patched, so you should update to version 3.15.0.

Gyan Elements

Plugin:

Gyan Elements

Plugin Slug:
gyan-elements

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.2.2

Severity Score:
High


The vulnerability has been patched, so you should update to version 2.2.2.

Green Downloads

Plugin:

Green Downloads

Plugin Slug:
halfdata-paypal-green-downloads

Vulnerability:
Arbitrary File Upload

Patched in Version:
2.09

Severity Score:
Critical


The vulnerability has been patched, so you should update to version 2.09.

Ultimate Membership Pro

Plugin:

Ultimate Membership Pro

Plugin Slug:
indeed-membership-pro

Vulnerability:
Broken Authentication

Patched in Version:
13.7.1

Severity Score:
High


The vulnerability has been patched, so you should update to version 13.7.1.

Jobica Core

Plugin:

Jobica Core

Plugin Slug:
jobica-core

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.4.2

Severity Score:
High


The vulnerability has been patched, so you should update to version 1.4.2.

Jobica Core

Plugin:

Jobica Core

Plugin Slug:
jobica-core

Vulnerability:
PHP Object Injection

Patched in Version:
1.4.2

Severity Score:
High


The vulnerability has been patched, so you should update to version 1.4.2.

Lumise Product Designer

Plugin:

Lumise Product Designer

Plugin Slug:
lumise

Vulnerability:
SQL Injection

Patched in Version:
2.0.9

Severity Score:
Critical


The vulnerability has been patched, so you should update to version 2.0.9.

Miraculous Core Plugin

Plugin:

Miraculous Core Plugin

Plugin Slug:
miraculouscore

Vulnerability:
SQL Injection

Patched in Version:
2.1.2

Severity Score:
High


The vulnerability has been patched, so you should update to version 2.1.2.

Motta Addons

Plugin:

Motta Addons

Plugin Slug:
motta-addons

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.6.1

Severity Score:
High


The vulnerability has been patched, so you should update to version 1.6.1.

NaturaLife Extensions

Plugin:

NaturaLife Extensions

Plugin Slug:
naturalife-extensions

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.2

Severity Score:
High


The vulnerability has been patched, so you should update to version 2.2.

NaturaLife Extensions

Plugin:

NaturaLife Extensions

Plugin Slug:
naturalife-extensions

Vulnerability:
Local File Inclusion

Patched in Version:
2.2

Severity Score:
High


The vulnerability has been patched, so you should update to version 2.2.

Organici Library

Plugin:

Organici Library

Plugin Slug:
noo-organici-library

Vulnerability:
SQL Injection

Patched in Version:
2.1.3

Severity Score:
High


The vulnerability has been patched, so you should update to version 2.1.3.

Organici Library

Plugin:

Organici Library

Plugin Slug:
noo-organici-library

Vulnerability:
PHP Object Injection

Patched in Version:
2.1.3

Severity Score:
High


The vulnerability has been patched, so you should update to version 2.1.3.

Organici Library

Plugin:

Organici Library

Plugin Slug:
noo-organici-library

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.1.3

Severity Score:
High


The vulnerability has been patched, so you should update to version 2.1.3.

Visionary Core

Plugin:

Visionary Core

Plugin Slug:
noo-visionary-core

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.5.0

Severity Score:
High


The vulnerability has been patched, so you should update to version 1.5.0.

Visionary Core

Plugin:

Visionary Core

Plugin Slug:
noo-visionary-core

Vulnerability:
PHP Object Injection

Patched in Version:
1.5.0

Severity Score:
High


The vulnerability has been patched, so you should update to version 1.5.0.

Phox Hosting

Plugin:

Phox Hosting

Plugin Slug:
phox-host

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.0.9

Severity Score:
High


The vulnerability has been patched, so you should update to version 2.0.9.

Salon Booking System Pro

Plugin:

Salon Booking System Pro

Plugin Slug:
salon-booking-plugin-pro

Vulnerability:
Broken Authentication

Patched in Version:
10.30.12

Severity Score:
High


The vulnerability has been patched, so you should update to version 10.30.12.

tagDiv Opt-In Builder

Plugin:

tagDiv Opt-In Builder

Plugin Slug:
td-subscription

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.7.4

Severity Score:
High


The vulnerability has been patched, so you should update to version 1.7.4.

The Grid

Plugin:

The Grid

Plugin Slug:
the-grid

Vulnerability:
Broken Access Control

Patched in Version:
2.8.0

Severity Score:
High


The vulnerability has been patched, so you should update to version 2.8.0.

The Grid

Plugin:

The Grid

Plugin Slug:
the-grid

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.8.0

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.8.0.

UpSolution Core

Plugin:

UpSolution Core

Plugin Slug:
us-core

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
8.42

Severity Score:
High


The vulnerability has been patched, so you should update to version 8.42.

WooCommerce Support Ticket System

Plugin:

WooCommerce Support Ticket System

Plugin Slug:
woocommerce-support-ticket-system

Vulnerability:
Arbitrary File Deletion

Patched in Version:
18.5

Severity Score:
High


The vulnerability has been patched, so you should update to version 18.5.

WP Configurator Pro

Plugin:

WP Configurator Pro

Plugin Slug:
wp-configurator-pro

Vulnerability:
Broken Access Control

Patched in Version:
3.8.0

Severity Score:
High


The vulnerability has been patched, so you should update to version 3.8.0.

JobSearch

Plugin:

JobSearch

Plugin Slug:
wp-jobsearch

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
3.2.2

Severity Score:
High


The vulnerability has been patched, so you should update to version 3.2.2.

WordPress Themes � 49 Patched / 7 Unpatched

Apicona

Theme:

Apicona

Theme Slug:
apicona

Vulnerability:
PHP Object Injection

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should switch themes.

Jannah

Theme:

Jannah

Theme Slug:
jannah

Vulnerability:
Local File Inclusion

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should switch themes.

Kentha

Theme:

Kentha

Theme Slug:
kentha

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should switch themes.

Mixtape

Theme:

Mixtape

Theme Slug:
mixtape

Vulnerability:
Local File Inclusion

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should switch themes.

Moments

Theme:

Moments

Theme Slug:
moments

Vulnerability:
Local File Inclusion

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should switch themes.

Photography

Theme:

Photography

Theme Slug:
photography

Vulnerability:
Arbitrary File Upload

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should switch themes.

The League

Theme:

The League

Theme Slug:
the-league

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should switch themes.

Education Zone

Theme Slug:
education-zone

Downloads
483,880

Vulnerability:
Broken Access Control

Patched in Version:
1.3.9

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.3.9.

Ona

Theme:

Ona

Theme Slug:
ona

Downloads
243,101

Vulnerability:
Arbitrary File Upload

Patched in Version:
1.24

Severity Score:
Critical


The vulnerability has been patched, so you should update to version 1.24.

Archicon

Theme:

Archicon

Theme Slug:
archicon

Vulnerability:
PHP Object Injection

Patched in Version:
1.7

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.7.

Borgholm

Theme:

Borgholm

Theme Slug:
borgholm-marketing-agency-theme

Vulnerability:
PHP Object Injection

Patched in Version:
1.6

Severity Score:
Critical


The vulnerability has been patched, so you should update to version 1.6.

Car Dealer

Theme:

Car Dealer

Theme Slug:
cardealer

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.6.8

Severity Score:
High


The vulnerability has been patched, so you should update to version 1.6.8.

Feedy

Theme:

Feedy

Theme Slug:
feedy

Vulnerability:
Local File Inclusion

Patched in Version:
2.1.5

Severity Score:
High


The vulnerability has been patched, so you should update to version 2.1.5.

Gaea

Theme:

Gaea

Theme Slug:
gaea

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
3.8

Severity Score:
High


The vulnerability has been patched, so you should update to version 3.8.

Goldish

Theme:

Goldish

Theme Slug:
goldish

Vulnerability:
PHP Object Injection

Patched in Version:
3.47

Severity Score:
Critical


The vulnerability has been patched, so you should update to version 3.47.

Golo

Theme:

Golo

Theme Slug:
golo

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.7.5

Severity Score:
High


The vulnerability has been patched, so you should update to version 1.7.5.

Gracey

Theme:

Gracey

Theme Slug:
gracey

Vulnerability:
PHP Object Injection

Patched in Version:
1.4

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.4.

Halstein

Theme:

Halstein

Theme Slug:
halstein

Vulnerability:
PHP Object Injection

Patched in Version:
1.8

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.8.

IdealAuto

Theme:

IdealAuto

Theme Slug:
idealauto

Vulnerability:
Local File Inclusion

Patched in Version:
3.8.6

Severity Score:
High


The vulnerability has been patched, so you should update to version 3.8.6.

Jaroti

Theme:

Jaroti

Theme Slug:
jaroti

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.4.8

Severity Score:
High


The vulnerability has been patched, so you should update to version 1.4.8.

Kamperen

Theme:

Kamperen

Theme Slug:
kamperen

Vulnerability:
PHP Object Injection

Patched in Version:
1.3

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.3.

Kiddy

Theme:

Kiddy

Theme Slug:
kiddy

Vulnerability:
Local File Inclusion

Patched in Version:
2.0.9

Severity Score:
High


The vulnerability has been patched, so you should update to version 2.0.9.

KIDZ

Theme:

KIDZ

Theme Slug:
kidz

Vulnerability:
PHP Object Injection

Patched in Version:
5.25

Severity Score:
Critical


The vulnerability has been patched, so you should update to version 5.25.

Kunco

Theme:

Kunco

Theme Slug:
kunco

Vulnerability:
Local File Inclusion

Patched in Version:
1.4.5

Severity Score:
High


The vulnerability has been patched, so you should update to version 1.4.5.

Boutique

Theme:

Boutique

Theme Slug:
kute-boutique

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.4.6

Severity Score:
High


The vulnerability has been patched, so you should update to version 2.4.6.

Leroux

Theme:

Leroux

Theme Slug:
leroux

Vulnerability:
PHP Object Injection

Patched in Version:
1.4

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.4.

Loobek

Theme:

Loobek

Theme Slug:
loobek

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.5.2

Severity Score:
High


The vulnerability has been patched, so you should update to version 1.5.2.

LoveDate

Theme:

LoveDate

Theme Slug:
lovedate

Vulnerability:
Local File Inclusion

Patched in Version:
3.8.6

Severity Score:
High


The vulnerability has been patched, so you should update to version 3.8.6.

Meloo

Theme:

Meloo

Theme Slug:
meloo

Vulnerability:
PHP Object Injection

Patched in Version:
2.8.2

Severity Score:
High


The vulnerability has been patched, so you should update to version 2.8.2.

MetaMax

Theme:

MetaMax

Theme Slug:
metamax

Vulnerability:
Local File Inclusion

Patched in Version:
1.1.5

Severity Score:
High


The vulnerability has been patched, so you should update to version 1.1.5.

Miraculous

Theme:

Miraculous

Theme Slug:
miraculous

Vulnerability:
Broken Access Control

Patched in Version:
2.1.2

Severity Score:
High


The vulnerability has been patched, so you should update to version 2.1.2.

Miti

Theme:

Miti

Theme Slug:
miti

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.5.3

Severity Score:
High


The vulnerability has been patched, so you should update to version 1.5.3.

Molla

Theme:

Molla

Theme Slug:
molla

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.5.19

Severity Score:
High


The vulnerability has been patched, so you should update to version 1.5.19.

MyDecor

Theme:

MyDecor

Theme Slug:
mydecor

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.5.9

Severity Score:
High


The vulnerability has been patched, so you should update to version 1.5.9.

MyMedi

Theme:

MyMedi

Theme Slug:
mymedi

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.7.7

Severity Score:
High


The vulnerability has been patched, so you should update to version 1.7.7.

CitiLights

Theme:

CitiLights

Theme Slug:
noo-citilights

Vulnerability:
PHP Object Injection

Patched in Version:
3.7.2

Severity Score:
High


The vulnerability has been patched, so you should update to version 3.7.2.

CitiLights

Theme:

CitiLights

Theme Slug:
noo-citilights

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
3.7.2

Severity Score:
High


The vulnerability has been patched, so you should update to version 3.7.2.

Jobmonster

Theme:

Jobmonster

Theme Slug:
noo-jobmonster

Vulnerability:
SQL Injection

Patched in Version:
4.8.4

Severity Score:
Critical


The vulnerability has been patched, so you should update to version 4.8.4.

Nooni

Theme:

Nooni

Theme Slug:
nooni

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.5.1

Severity Score:
High


The vulnerability has been patched, so you should update to version 1.5.1.

Pelicula

Theme:

Pelicula

Theme Slug:
pelicula-video-production-and-movie-theme

Vulnerability:
PHP Object Injection

Patched in Version:
1.10

Severity Score:
Critical


The vulnerability has been patched, so you should update to version 1.10.

Pendulum

Theme:

Pendulum

Theme Slug:
pendulum

Vulnerability:
PHP Object Injection

Patched in Version:
3.1.5

Severity Score:
High


The vulnerability has been patched, so you should update to version 3.1.5.

Reebox

Theme:

Reebox

Theme Slug:
reebox

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.4.8

Severity Score:
High


The vulnerability has been patched, so you should update to version 1.4.8.

Ricky

Theme:

Ricky

Theme Slug:
ricky

Vulnerability:
PHP Object Injection

Patched in Version:
2.31

Severity Score:
Critical


The vulnerability has been patched, so you should update to version 2.31.

Riode

Theme:

Riode

Theme Slug:
riode

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.6.29

Severity Score:
High


The vulnerability has been patched, so you should update to version 1.6.29.

Sanzo

Theme:

Sanzo

Theme Slug:
sanzo

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.4.3

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.4.3.

Scape

Theme:

Scape

Theme Slug:
scape

Vulnerability:
Arbitrary File Deletion

Patched in Version:
1.5.16

Severity Score:
High


The vulnerability has been patched, so you should update to version 1.5.16.

St�l

Theme:

St�l

Theme Slug:
stal

Vulnerability:
PHP Object Injection

Patched in Version:
1.7

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.7.

StreamVid

Theme:

StreamVid

Theme Slug:
streamvid

Vulnerability:
Local File Inclusion

Patched in Version:
6.8.6

Severity Score:
High


The vulnerability has been patched, so you should update to version 6.8.6.

Tasty Daily

Theme:

Tasty Daily

Theme Slug:
tastydaily

Vulnerability:
PHP Object Injection

Patched in Version:
1.27

Severity Score:
Critical


The vulnerability has been patched, so you should update to version 1.27.

Traveler

Theme:

Traveler

Theme Slug:
traveler

Vulnerability:
PHP Object Injection

Patched in Version:
3.2.8.1

Severity Score:
Critical


The vulnerability has been patched, so you should update to version 3.2.8.1.

Trendustry

Theme:

Trendustry

Theme Slug:
trendustry

Vulnerability:
Local File Inclusion

Patched in Version:
1.1.5

Severity Score:
High


The vulnerability has been patched, so you should update to version 1.1.5.

Vayvo

Theme:

Vayvo

Theme Slug:
vayvo-progression

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
6.8

Severity Score:
High


The vulnerability has been patched, so you should update to version 6.8.

Vex

Theme:

Vex

Theme Slug:
vex

Vulnerability:
PHP Object Injection

Patched in Version:
1.2.9

Severity Score:
High


The vulnerability has been patched, so you should update to version 1.2.9.

VintWood

Theme:

VintWood

Theme Slug:
vintwood

Vulnerability:
Local File Inclusion

Patched in Version:
1.1.9

Severity Score:
High


The vulnerability has been patched, so you should update to version 1.1.9.

WoodMart

Theme:

WoodMart

Theme Slug:
woodmart

Vulnerability:
PHP Object Injection

Patched in Version:
8.3.9

Severity Score:
High


The vulnerability has been patched, so you should update to version 8.3.9.

Yobazar

Theme:

Yobazar

Theme Slug:
yobazar

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.6.7

Severity Score:
High


The vulnerability has been patched, so you should update to version 1.6.7.

Related articles

Wait! Get exclusive hosting insights

Subscribe to our newsletter and stay ahead of the competition with expert advice from our hosting pros.

Loading form…