Line illustration showing a black application window on a dark black to purple gradient background overlaid with a large exclamation point alert icon and three bugs.

WordPress Vulnerability Report � March 5, 2025

In this report, 209 vulnerabilities have been publicly disclosed. Security patches for 104 of these plugins and themes are available now, so run those updates as soon as possible. If you’re a Solid Security Pro user, the version management tool may have already warned you and updated these plugins, depending on your settings.

Additionally, there are 105 plugin and theme vulnerabilities with no patch available yet. If you’re a Solid Security Pro user, those vulnerabilities are already protected by the Solid Security firewall. Virtual patches from Patchstack will be applied when a vulnerability is considered high or medium risk. If no patch is forthcoming from the vendor or the vulnerable software has been marked “closed” and dropped from the official WordPress repositories, you should deactivate it soon and look for alternative solutions.

WordPress Core

WordPress 6.8 Beta 1 is available for download and testing! This beta version of the WordPress software is under development. Please do not install, run, or test this version of WordPress on production or mission-critical websites. Instead, set up a test environment or a local site to explore the new features.

WordPress Plugins � 93 Patched / 104 Unpatched

SEO Plugin by Squirrly SEO

Plugin Slug:
squirrly-seo

Installations
100,000+

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Ibtana � WordPress Website Builder

Plugin Slug:
ibtana-visual-editor

Installations
20,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Forex Calculators

Plugin Slug:
fx-calculators

Installations
200+

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

PiwigoPress

Plugin Slug:
piwigopress

Installations
200+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.
Plugin Slug:
list-related-attachments-widget

Installations
100+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

URL Media Uploader

Plugin Slug:
url-media-uploader

Installations
100+

Vulnerability:
Server Side Request Forgery (SSRF)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

WHMCS Client Area for WordPress by WHMpress

Plugin:

WHMCS Client Area for WordPress by WHMpress

Plugin Slug:
WHMpress_Client_Area_Api

Vulnerability:
Privilege Escalation

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.
Plugin:

Add Linked Images To Gallery

Plugin Slug:
add-linked-images-to-gallery-v01

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

ADFO

Plugin:

ADFO

Plugin Slug:
admin-form

Vulnerability:
Deserialization of untrusted data

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Admin Menu Manager

Plugin:

Admin Menu Manager

Plugin Slug:
admin-menu-manager

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

All-In-One Cufon

Plugin:

All-In-One Cufon

Plugin Slug:
all-in-one-cufon

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Archive Page

Plugin:

Archive Page

Plugin Slug:
archive-page

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Ark Theme Core

Plugin:

Ark Theme Core

Plugin Slug:
ark-core

Vulnerability:
Remote Code Execution (RCE)

Patched in Version:
No Fix

Severity Score:
Critical


The vulnerability has not been patched. You should deactivate the plugin.
Plugin:

Auto Tag Links

Plugin Slug:
auto-tag-links

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Blightly Explorer

Plugin:

Blightly Explorer

Plugin Slug:
blighty-explorer

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Booknetic

Plugin:

Booknetic

Plugin Slug:
booknetic

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Bravo Search & Replace

Plugin:

Bravo Search & Replace

Plugin Slug:
bravo-search-and-replace

Vulnerability:
SQL Injection

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Bulk Content Creator

Plugin:

Bulk Content Creator

Plugin Slug:
bulk-content-creator

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Clicface Trombi

Plugin:

Clicface Trombi

Plugin Slug:
clicface-trombi

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Contact Form 7 Star Rating

Plugin:

Contact Form 7 Star Rating

Plugin Slug:
contact-form-7-star-rating

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Contact Form 7 Star Rating with font Awesome

Plugin:

Contact Form 7 Star Rating with font Awesome

Plugin Slug:
contact-form-7-star-rating-with-font-awersome

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Currency Switcher for WooCommerce

Plugin:

Currency Switcher for WooCommerce

Plugin Slug:
currency-switcher-woocommerce

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Download HTML TinyMCE Button

Plugin:

Download HTML TinyMCE Button

Plugin Slug:
download-html-tinymce-button

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

URL Shortener | Conversion Tracking | AB Testing | WooCommerce

Plugin:

URL Shortener | Conversion Tracking | AB Testing | WooCommerce

Plugin Slug:
easy-broken-link-checker

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

URL Shortener | Conversion Tracking | AB Testing | WooCommerce

Plugin:

URL Shortener | Conversion Tracking | AB Testing | WooCommerce

Plugin Slug:
easy-broken-link-checker

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Erima Zarinpal Donate

Plugin:

Erima Zarinpal Donate

Plugin Slug:
erima-zarinpal-donate

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

F12-Profiler

Plugin:

F12-Profiler

Plugin Slug:
f12-profiler

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Fresh Framework

Plugin:

Fresh Framework

Plugin Slug:
fresh-framework

Vulnerability:
Remote Code Execution (RCE)

Patched in Version:
No Fix

Severity Score:
Critical


The vulnerability has not been patched. You should deactivate the plugin.

FS Poster

Plugin:

FS Poster

Plugin Slug:
fs-poster

Vulnerability:
SQL Injection

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Google Maps for WordPress

Plugin:

Google Maps for WordPress

Plugin Slug:
google-maps-for-wordpress

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Hover Image Button

Plugin:

Hover Image Button

Plugin Slug:
hover-image-button

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

EZ InLinkz linkup

Plugin:

EZ InLinkz linkup

Plugin Slug:
inlinkz-scripter

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Just Variables

Plugin:

Just Variables

Plugin Slug:
just-wp-variables

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Limit Bio

Plugin:

Limit Bio

Plugin Slug:
limit-bio

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Limit Bio

Plugin:

Limit Bio

Plugin Slug:
limit-bio

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.
Plugin:

Link My Posts

Plugin Slug:
linkmyposts

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Phee’s LinkPreview

Plugin:

Phee’s LinkPreview

Plugin Slug:
linkpreview

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Local Search SEO Contact Page

Plugin:

Local Search SEO Contact Page

Plugin Slug:
local-search-seo-contact-page

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Woocommerce � Loi Hamon

Plugin:

Woocommerce � Loi Hamon

Plugin Slug:
loi-hamon

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

mEintopf

Plugin:

mEintopf

Plugin Slug:
meintopf

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Minimum Password Strength

Plugin:

Minimum Password Strength

Plugin Slug:
minimum-password-strength

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Modal Portfolio

Plugin:

Modal Portfolio

Plugin Slug:
modal-portfolio

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Multilevel Referral Affiliate Plugin for WooCommerce

Plugin:

Multilevel Referral Affiliate Plugin for WooCommerce

Plugin Slug:
multilevel-referral-plugin-for-woocommerce

Vulnerability:
SQL Injection

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

My Quota

Plugin:

My Quota

Plugin Slug:
my-quota

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Namaste! LMS

Plugin:

Namaste! LMS

Plugin Slug:
namaste-lms

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

NewsTicker

Plugin:

NewsTicker

Plugin Slug:
news-list

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

NHR Options Table Manager

Plugin:

NHR Options Table Manager

Plugin Slug:
nhrrob-options-table-manager

Vulnerability:
Deserialization of untrusted data

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Ninja Pages

Plugin:

Ninja Pages

Plugin Slug:
ninja-page-categories-and-tags

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Get Posts

Plugin:

Get Posts

Plugin Slug:
nurelm-get-posts

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Ohio Extra

Plugin:

Ohio Extra

Plugin Slug:
ohio-extra

Vulnerability:
Content Injection

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Om Stripe

Plugin:

Om Stripe

Plugin Slug:
om-stripe

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.
Plugin:

�nceki Yaz? Link

Plugin Slug:
onceki-yazi-linki

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

OneStore Sites

Plugin:

OneStore Sites

Plugin Slug:
onestore-sites

Vulnerability:
Server Side Request Forgery (SSRF)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Order Attachments for WooCommerce

Plugin:

Order Attachments for WooCommerce

Plugin Slug:
order-attachments-for-woocommerce

Vulnerability:
Sensitive Data Exposure

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Passbeemedia Web Push Notification

Plugin:

Passbeemedia Web Push Notification

Plugin Slug:
passbeemedia-web-push-notifications

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Pathomation

Plugin:

Pathomation

Plugin Slug:
pathomation

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.
Plugin:

Photo Gallery ( Responsive )

Plugin Slug:
photo-gallery-pearlbells

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Pricing Table by PickPlugins

Plugin:

Pricing Table by PickPlugins

Plugin Slug:
pricingtable

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

PrivateContent

Plugin:

PrivateContent

Plugin Slug:
private-content

Vulnerability:
SQL Injection

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

PrivateContent

Plugin:

PrivateContent

Plugin Slug:
private-content

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

PrivateContent

Plugin:

PrivateContent

Plugin Slug:
private-content

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

PrivateContent

Plugin:

PrivateContent

Plugin Slug:
private-content

Vulnerability:
Broken Authentication

Patched in Version:
No Fix

Severity Score:
Critical


The vulnerability has not been patched. You should deactivate the plugin.

Profile Widget Ninja

Plugin:

Profile Widget Ninja

Plugin Slug:
profile-widget-ninja

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Quiz Organizer

Plugin:

Quiz Organizer

Plugin Slug:
quiz-organizer

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

RAYS Grid

Plugin:

RAYS Grid

Plugin Slug:
rays-grid

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Reactive Mortgage Calculator

Plugin:

Reactive Mortgage Calculator

Plugin Slug:
reactive-mortgage-calculator

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

School Management System � SakolaWP

Plugin:

School Management System � SakolaWP

Plugin Slug:
sakolawp-lite

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Simple Google Sitemap

Plugin:

Simple Google Sitemap

Plugin Slug:
simple-google-sitemap

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Simple:Press

Plugin:

Simple:Press

Plugin Slug:
simplepress

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Smart Maintenance & Countdown

Plugin:

Smart Maintenance & Countdown

Plugin Slug:
smart-maintenance-countdown

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

SpotBot

Plugin:

SpotBot

Plugin Slug:
spotbot

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Live Streaming Video Player � by SRS Player

Plugin:

Live Streaming Video Player � by SRS Player

Plugin Slug:
srs-player

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Sticky Header On Scroll

Plugin:

Sticky Header On Scroll

Plugin Slug:
sticky-header-on-scroll

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Table of Contents Block

Plugin:

Table of Contents Block

Plugin Slug:
table-of-contents

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

BuddyHolis TableSearch

Plugin:

BuddyHolis TableSearch

Plugin Slug:
tablesearch

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Countdown Timer

Plugin:

Countdown Timer

Plugin Slug:
timer-countdown

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Ultra Addons Lite for Elementor

Plugin:

Ultra Addons Lite for Elementor

Plugin Slug:
ut-elementor-addons-lite

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

VG PostCarousel

Plugin:

VG PostCarousel

Plugin Slug:
vg-postcarousel

Vulnerability:
Local File Inclusion

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Video.js HLS Player

Plugin:

Video.js HLS Player

Plugin Slug:
videojs-hls-player

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

ViperBar

Plugin:

ViperBar

Plugin Slug:
viperbar

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Tabs for WooCommerce

Plugin:

Tabs for WooCommerce

Plugin Slug:
wc-tabs

Vulnerability:
PHP Object Injection

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Bitcoin / AltCoin Payment Gateway for WooCommerce

Plugin:

Bitcoin / AltCoin Payment Gateway for WooCommerce

Plugin Slug:
woo-altcoin-payment-gateway

Vulnerability:
SQL Injection

Patched in Version:
No Fix

Severity Score:
Critical


The vulnerability has not been patched. You should deactivate the plugin.

Direct Checkout Button for WooCommerce

Plugin:

Direct Checkout Button for WooCommerce

Plugin Slug:
woo-direct-checkout-button

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

WooCommerce Recargo de Equivalencia

Plugin:

WooCommerce Recargo de Equivalencia

Plugin Slug:
woo-recargo-de-equivalencia

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

WooCommerce Display Products by Tags

Plugin:

WooCommerce Display Products by Tags

Plugin Slug:
woocommerce-display-products-by-tags

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

WooCommerce Ultimate Gift Card – Create, Sell and Manage Gift Cards with Customized Email Templates

Plugin:

WooCommerce Ultimate Gift Card – Create, Sell and Manage Gift Cards with Customized Email Templates

Plugin Slug:
woocommerce-ultimate-gift-card

Vulnerability:
Arbitrary File Upload

Patched in Version:
No Fix

Severity Score:
Critical


The vulnerability has not been patched. You should deactivate the plugin.

WOW Entrance Effects (WEE!)

Plugin:

WOW Entrance Effects (WEE!)

Plugin Slug:
wow-entrance-effects-wee

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

WoWPth

Plugin:

WoWPth

Plugin Slug:
wowpth

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

WP About Author

Plugin:

WP About Author

Plugin Slug:
wp-about-author

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

WP-Asambleas

Plugin:

WP-Asambleas

Plugin Slug:
wp-asambleas

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

WP Click Info

Plugin:

WP Click Info

Plugin Slug:
wp-click-info

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

WP e-Customers Beta

Plugin:

WP e-Customers Beta

Plugin Slug:
wp-e-customers

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

JPG, PNG Compression and Optimization

Plugin:

JPG, PNG Compression and Optimization

Plugin Slug:
wp-post-459200 wp-image-compression

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

WP-PostRatings Cheater

Plugin:

WP-PostRatings Cheater

Plugin Slug:
wp-postratings-cheater

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

WP-PManager

Plugin:

WP-PManager

Plugin Slug:
wp-programmmanager

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

WP Sitemap

Plugin:

WP Sitemap

Plugin Slug:
wp-sitemap

Vulnerability:
SQL Injection

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

WP Social SEO Booster � Knowledge Graph Social Signals SEO

Plugin:

WP Social SEO Booster � Knowledge Graph Social Signals SEO

Plugin Slug:
wp-social-seo-booster

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

WP Video Posts

Plugin:

WP Video Posts

Plugin Slug:
wp-post-459200 wp-video-posts

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

????????

Plugin:

????????

Plugin Slug:
wumii-related-posts

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Yawave

Plugin:

Yawave

Plugin Slug:
yawave

Vulnerability:
SQL Injection

Patched in Version:
No Fix

Severity Score:
Critical


The vulnerability has not been patched. You should deactivate the plugin.

SVG Support

Plugin Slug:
svg-support

Installations
1,000,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.5.9

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.5.9.

Page Builder by SiteOrigin

Plugin Slug:
siteorigin-panels

Installations
600,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.31.5

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.31.5.

PixelYourSite � Your smart PIXEL (TAG) & API Manager

Plugin Slug:
pixelyoursite

Installations
500,000+

Vulnerability:
PHP Object Injection

Patched in Version:
10.1.1.2

Severity Score:
Critical


The vulnerability has been patched, so you should update to version 10.1.1.2.

WP Shortcodes Plugin � Shortcodes Ultimate

Plugin Slug:
shortcodes-ultimate

Installations
500,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
7.3.4

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 7.3.4.

Jeg Elementor Kit

Plugin Slug:
jeg-elementor-kit

Installations
300,000+

Vulnerability:
Sensitive Data Exposure

Patched in Version:
2.6.12

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.6.12.

Advanced Google reCAPTCHA

Plugin Slug:
advanced-google-recaptcha

Installations
200,000+

Vulnerability:
Bypass Vulnerability

Patched in Version:
1.28

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.28.

GenerateBlocks

Plugin Slug:
generateblocks

Installations
200,000+

Vulnerability:
Sensitive Data Exposure

Patched in Version:
2.0.0

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.0.0.

WP Activity Log

Plugin Slug:
wp-security-audit-log

Installations
200,000+

Vulnerability:
PHP Object Injection

Patched in Version:
5.3.3

Severity Score:
High


The vulnerability has been patched, so you should update to version 5.3.3.

GiveWP � Donation Plugin and Fundraising Platform

Plugin Slug:
give

Installations
100,000+

Vulnerability:
PHP Object Injection

Patched in Version:
3.20.0

Severity Score:
Critical


The vulnerability has been patched, so you should update to version 3.20.0.

LearnPress � WordPress LMS Plugin

Plugin Slug:
learnpress

Installations
90,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
4.2.7.5.1

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 4.2.7.5.1.

Simple Image Sizes

Plugin Slug:
simple-image-sizes

Installations
70,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
3.2.3

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 3.2.3.

Exclusive Addons for Elementor

Plugin Slug:
exclusive-addons-for-elementor

Installations
60,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.7.7

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.7.7.

Advanced AJAX Product Filters

Plugin Slug:
woocommerce-ajax-filters

Installations
60,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.6.8.2

Severity Score:
High


The vulnerability has been patched, so you should update to version 1.6.8.2.
Plugin Slug:
sina-extension-for-elementor

Installations
50,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
3.6.1

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 3.6.1.

Post Grid and Gutenberg Blocks � ComboBlocks

Plugin Slug:
post-grid

Installations
40,000+

Vulnerability:
Sensitive Data Exposure

Patched in Version:
2.3.7

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.3.7.

Accept Donations with PayPal & Stripe

Plugin Slug:
easy-paypal-donation

Installations
20,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.4.5

Severity Score:
High


The vulnerability has been patched, so you should update to version 1.4.5.
Plugin Slug:
final-tiles-grid-gallery-lite

Installations
20,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
3.6.1

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 3.6.1.

Secure Copy Content Protection and Content Locking

Plugin Slug:
secure-copy-content-protection

Installations
20,000+

Vulnerability:
Broken Access Control

Patched in Version:
4.4.8

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 4.4.8.

NextMove Lite � Thank You Page for WooCommerce

Plugin Slug:
woo-thank-you-page-nextmove-lite

Installations
20,000+

Vulnerability:
Broken Access Control

Patched in Version:
2.20.0

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.20.0.

Wp Social Login and Register Social Counter

Plugin Slug:
wp-social

Installations
20,000+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
3.1.1

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 3.1.1.

wpForo Forum

Plugin Slug:
wpforo

Installations
20,000+

Vulnerability:
Arbitrary File Download

Patched in Version:
2.4.2

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.4.2.

IP2Location Redirection

Plugin Slug:
ip2location-redirection

Installations
10,000+

Vulnerability:
Broken Access Control

Patched in Version:
1.33.4

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.33.4.

WPO365 | MICROSOFT 365 GRAPH MAILER

Plugin Slug:
wpo365-msgraphmailer

Installations
8,000+

Vulnerability:
Open Redirection

Patched in Version:
3.3

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 3.3.

Animated Text Block

Plugin Slug:
animated-text-block

Installations
5,000+

Vulnerability:
Broken Access Control

Patched in Version:
1.0.8

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.0.8.
Plugin Slug:
new-album-gallery

Installations
5,000+

Vulnerability:
PHP Object Injection

Patched in Version:
1.6.4

Severity Score:
High


The vulnerability has been patched, so you should update to version 1.6.4.

SMS Alert Order Notifications � WooCommerce

Plugin Slug:
sms-alert

Installations
5,000+

Vulnerability:
SQL Injection

Patched in Version:
3.7.9

Severity Score:
Critical


The vulnerability has been patched, so you should update to version 3.7.9.

Authors List

Plugin Slug:
authors-list

Installations
4,000+

Vulnerability:
Content Injection

Patched in Version:
2.0.6.1

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.0.6.1.

Card Elements for Elementor

Plugin Slug:
card-elements-for-elementor

Installations
4,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.2.7

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.2.7.
Plugin Slug:
wp-posts-carousel

Installations
4,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.3.8

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.3.8.

KiviCare � Clinic & Patient Management System (EHR)

Plugin Slug:
kivicare-clinic-management-system

Installations
3,000+

Vulnerability:
SQL Injection

Patched in Version:
3.6.8

Severity Score:
High


The vulnerability has been patched, so you should update to version 3.6.8.

Wallet System for WooCommerce

Plugin Slug:
wallet-system-for-woocommerce

Installations
3,000+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
2.6.3

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.6.3.

Wallet System for WooCommerce

Plugin Slug:
wallet-system-for-woocommerce

Installations
3,000+

Vulnerability:
Broken Access Control

Patched in Version:
2.6.3

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.6.3.

teachPress

Plugin Slug:
teachpress

Installations
2,000+

Vulnerability:
SQL Injection

Patched in Version:
9.0.8

Severity Score:
High


The vulnerability has been patched, so you should update to version 9.0.8.
Plugin Slug:
contest-gallery

Installations
1,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
26.0.1

Severity Score:
High


The vulnerability has been patched, so you should update to version 26.0.1.

Product Catalog Simple

Plugin Slug:
post-type-x

Installations
1,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.8.0

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.8.0.

Quotes llama

Plugin Slug:
quotes-llama

Installations
1,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
3.0.2

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 3.0.2.

Simple Download Counter

Plugin Slug:
simple-download-counter

Installations
1,000+

Vulnerability:
Arbitrary File Download

Patched in Version:
2.1

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.1.

Subscriptions & Memberships for PayPal

Plugin Slug:
subscriptions-memberships-for-paypal

Installations
1,000+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
1.1.7

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.1.7.

Ultimate WordPress Auction Plugin

Plugin Slug:
ultimate-auction

Installations
1,000+

Vulnerability:
Arbitrary Content Deletion

Patched in Version:
4.3.0

Severity Score:
High


The vulnerability has been patched, so you should update to version 4.3.0.

PlayerJS

Plugin:

PlayerJS

Plugin Slug:
playerjs

Installations
700+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.24

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.24.

m1.DownloadList

Plugin Slug:
m1downloadlist

Installations
500+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
0.20

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 0.20.

RateMyAgent Official

Plugin Slug:
ratemyagent-official

Installations
400+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
1.5.0

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.5.0.

Multiple Shipping And Billing Address For Woocommerce

Plugin Slug:
different-shipping-and-billing-address-for-woocommerce

Installations
200+

Vulnerability:
SQL Injection

Patched in Version:
1.5

Severity Score:
Critical


The vulnerability has been patched, so you should update to version 1.5.

DefendWP Firewall

Plugin Slug:
defend-wp-firewall

Installations
100+

Vulnerability:
Broken Access Control

Patched in Version:
1.1.1

Severity Score:
High


The vulnerability has been patched, so you should update to version 1.1.1.

MK Google Directions

Plugin Slug:
google-distance-calculator

Installations
100+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
3.1.1

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 3.1.1.

Activity Log WinterLock

Plugin Slug:
winterlock

Installations
70+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
1.2.5

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.2.5.

Academist Membership

Plugin:

Academist Membership

Plugin Slug:
academist-membership

Vulnerability:
Broken Authentication

Patched in Version:
1.2

Severity Score:
Critical


The vulnerability has been patched, so you should update to version 1.2.

Alloggio Membership

Plugin:

Alloggio Membership

Plugin Slug:
alloggio-membership

Vulnerability:
Broken Authentication

Patched in Version:
1.2

Severity Score:
Critical


The vulnerability has been patched, so you should update to version 1.2.

Animation Addons for Elementor Pro

Plugin:

Animation Addons for Elementor Pro

Plugin Slug:
animation-addons-for-elementor-pro

Vulnerability:
Broken Access Control

Patched in Version:
1.7

Severity Score:
High


The vulnerability has been patched, so you should update to version 1.7.

Buddyboss Platform

Plugin:

Buddyboss Platform

Plugin Slug:
buddyboss-platform

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.8.00

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.8.00.

DHVC Form

Plugin:

DHVC Form

Plugin Slug:
dhvc-form

Vulnerability:
Privilege Escalation

Patched in Version:
2.4.8

Severity Score:
Critical


The vulnerability has been patched, so you should update to version 2.4.8.

Edd Google Sheet Connector Pro

Plugin:

Edd Google Sheet Connector Pro

Plugin Slug:
edd-google-sheet-connector-pro

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
1.4

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.4.

Exertio Framework

Plugin:

Exertio Framework

Plugin Slug:
exertio-framework

Vulnerability:
Privilege Escalation

Patched in Version:
1.3.2

Severity Score:
High


The vulnerability has been patched, so you should update to version 1.3.2.

Easy Digital Downloads Google Sheet Connector

Plugin Slug:
gsheetconnector-easy-digital-downloads

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
1.6.6

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.6.6.

Pie Register Premium

Plugin:

Pie Register Premium

Plugin Slug:
pie-register-premium

Vulnerability:
Path Traversal

Patched in Version:
3.8.3.3

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 3.8.3.3.

Pie Register Premium

Plugin:

Pie Register Premium

Plugin Slug:
pie-register-premium

Vulnerability:
Broken Access Control

Patched in Version:
3.8.3.3

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 3.8.3.3.

SetSail Membership

Plugin:

SetSail Membership

Plugin Slug:
setsail-membership

Vulnerability:
Broken Authentication

Patched in Version:
1.1

Severity Score:
Critical


The vulnerability has been patched, so you should update to version 1.1.

Social Share And Social Locker

Plugin:

Social Share And Social Locker

Plugin Slug:
social-share-and-social-locker-arsocial

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.4.2

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.4.2.

SureMembers

Plugin:

SureMembers

Plugin Slug:
suremembers

Vulnerability:
Sensitive Data Exposure

Patched in Version:
1.10.7

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.10.7.

Templines Elementor Helper Core

Plugin:

Templines Elementor Helper Core

Plugin Slug:
templines-helper-core

Vulnerability:
Privilege Escalation

Patched in Version:
2.8

Severity Score:
High


The vulnerability has been patched, so you should update to version 2.8.

ThemeMakers PayPal Express Checkout

Plugin:

ThemeMakers PayPal Express Checkout

Plugin Slug:
tmm_paypal_checkout

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.2.0

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.2.0.

ThemeMakers Stripe Checkout

Plugin:

ThemeMakers Stripe Checkout

Plugin Slug:
tmm_stripe_checkout

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.0.2

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.0.2.

WHMpress

Plugin:

WHMpress

Plugin Slug:
whmpress

Vulnerability:
Local File Inclusion

Patched in Version:
6.3-revision-1

Severity Score:
Critical


The vulnerability has been patched, so you should update to version 6.3-revision-1.

WooCommerce Cart Count Shortcode

Plugin:

WooCommerce Cart Count Shortcode

Plugin Slug:
woo-cart-count-shortcode

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.1.0

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.1.0.

WordPress File Upload

Plugin:

WordPress File Upload

Plugin Slug:
wp-file-upload

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
4.25.3

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 4.25.3.

WordPress Themes � 11 Patched / 1 Unpatched

Traveler

Theme:

Traveler

Theme Slug:
traveler

Vulnerability:
Local File Inclusion

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should switch themes.

Newscrunch

Theme Slug:
newscrunch

Downloads
175,636

Vulnerability:
Arbitrary File Upload

Patched in Version:
1.8.4.1

Severity Score:
Critical


The vulnerability has been patched, so you should update to version 1.8.4.1.

Newscrunch

Theme Slug:
newscrunch

Downloads
175,636

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
1.8.4.1

Severity Score:
High


The vulnerability has been patched, so you should update to version 1.8.4.1.

VW Storefront

Theme Slug:
vw-storefront

Downloads
60,130

Vulnerability:
Broken Access Control

Patched in Version:
1.0.0

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.0.0.

Bricks Builder

Theme:

Bricks Builder

Theme Slug:
bricks

Vulnerability:
Privilege Escalation

Patched in Version:
1.9.7

Severity Score:
High


The vulnerability has been patched, so you should update to version 1.9.7.

Car Dealer

Theme:

Car Dealer

Theme Slug:
cardealer

Vulnerability:
Privilege Escalation

Patched in Version:
1.6.5

Severity Score:
High


The vulnerability has been patched, so you should update to version 1.6.5.

Car Dealer

Theme:

Car Dealer

Theme Slug:
cardealer

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
1.6.5

Severity Score:
High


The vulnerability has been patched, so you should update to version 1.6.5.

Car Dealer

Theme:

Car Dealer

Theme Slug:
cardealer

Vulnerability:
Broken Access Control

Patched in Version:
1.6.5

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.6.5.

Car Dealer

Theme:

Car Dealer

Theme Slug:
cardealer

Vulnerability:
Arbitrary File Deletion

Patched in Version:
1.6.4

Severity Score:
High


The vulnerability has been patched, so you should update to version 1.6.4.

Enfold

Theme:

Enfold

Theme Slug:
enfold

Vulnerability:
Server Side Request Forgery (SSRF)

Patched in Version:
7.0

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 7.0.

Enfold

Theme:

Enfold

Theme Slug:
enfold

Vulnerability:
Broken Access Control

Patched in Version:
7.0

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 7.0.

Nokri

Theme:

Nokri

Theme Slug:
nokri

Vulnerability:
Privilege Escalation

Patched in Version:
1.6.3

Severity Score:
Critical


The vulnerability has been patched, so you should update to version 1.6.3.

Related articles

Wait! Get exclusive hosting insights

Subscribe to our newsletter and stay ahead of the competition with expert advice from our hosting pros.

Loading form…