Line illustration showing a black application window on a dark blue gradient background overlaid with a large exclamation point alert icon and three bugs.

WordPress Vulnerability Report � May 21, 2025

In this report, 359 vulnerabilities have been publicly disclosed. Security patches for 194 of these plugins and themes are available now, so run those updates as soon as possible. If you’re a Solid Security Pro user, the version management tool may have already warned you and updated these plugins, depending on your settings.

Additionally, there are 165 plugin and theme vulnerabilities, and no patch has been available yet. If you’re a Solid Security Pro user, those vulnerabilities are already protected by the Solid Security firewall. Virtual patches from Patchstack will be applied when a vulnerability is considered high or medium risk. If no patch is forthcoming from the vendor or the vulnerable software has been marked “closed” and dropped from the official WordPress repositories, you should deactivate it soon and look for alternative solutions.

WordPress Core

WordPress 6.8.1 has been released! This maintenance release includes fixes for 15 bugs throughout Core and the Block Editor, addressing issues affecting multiple areas of WordPress, including the block editor, multisite, and REST API. For a full list, refer to the release candidate announcement.

Plus, WordCamp Europe 2025 lands in Basel, Switzerland, June 5-7! Connect with WordPress enthusiasts, developers, and pros for three days of learning, networking, and collaboration with the global community.

WordPress Plugins � 191 Patched / 150 Unpatched

TI WooCommerce Wishlist

Plugin Slug:
ti-woocommerce-wishlist

Installations
100,000+

Vulnerability:
Arbitrary File Upload

Patched in Version:
No Fix

Severity Score:
Critical


The vulnerability has not been patched. You should deactivate the plugin.

TI WooCommerce Wishlist

Plugin Slug:
ti-woocommerce-wishlist

Installations
100,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

WP Tabs � Responsive Tabs and Custom Product Tabs

Plugin Slug:
wp-expand-tabs-free

Installations
10,000+

Vulnerability:
PHP Object Injection

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

WooCommerce POS � Point of Sale

Plugin Slug:
woocommerce-pos

Installations
6,000+

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Eventer

Plugin:

Eventer

Plugin Slug:
eventer

Installations
2,000+

Vulnerability:
SQL Injection

Patched in Version:
No Fix

Severity Score:
Critical


The vulnerability has not been patched. You should deactivate the plugin.

Eventer

Plugin:

Eventer

Plugin Slug:
eventer

Installations
2,000+

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Estatik Mortgage Calculator

Plugin Slug:
estatik-mortgage-calculator

Installations
1,000+

Vulnerability:
Local File Inclusion

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Simplelightbox

Plugin Slug:
simplelightbox

Installations
1,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

WP Notes Widget

Plugin Slug:
wp-notes-widget

Installations
1,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.
Plugin Slug:
ultraaddons-elementor-lite

Installations
900+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

ValidateCertify Free

Plugin Slug:
validar-certificados-de-cursos

Installations
900+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

MapSVG � Vector maps, Image maps, Google Maps

Plugin Slug:
mapsvg-lite-interactive-vector-maps

Installations
800+

Vulnerability:
Content Injection

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Broadstreet

Plugin Slug:
broadstreet

Installations
700+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Dynamic Pricing & Discounts Lite for WooCommerce

Plugin Slug:
woo-dynamic-pricing-discounts-lite

Installations
600+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Push notification for Mobile and Web app

Plugin Slug:
push-notification-mobile-and-web-app

Installations
500+

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Wishlist

Plugin:

Wishlist

Plugin Slug:
wishlist

Installations
500+

Vulnerability:
Sensitive Data Exposure

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Wishlist

Plugin:

Wishlist

Plugin Slug:
wishlist

Installations
500+

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Import Export For WooCommerce

Plugin Slug:
import-export-for-woocommerce

Installations
300+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

STAGGS � Product Configurator Toolkit

Plugin Slug:
staggs

Installations
300+

Vulnerability:
Arbitrary File Upload

Patched in Version:
No Fix

Severity Score:
Critical


The vulnerability has not been patched. You should deactivate the plugin.

Embed and Integrate Etsy Shop

Plugin Slug:
embed-and-integrate-etsy-shop

Installations
200+

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

SEO Flow by LupsOnline

Plugin Slug:
lupsonline-link-netwerk

Installations
200+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

X Addons for Elementor

Plugin Slug:
x-addons-elementor

Installations
200+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Aptivada for WP

Plugin Slug:
aptivada-for-wp

Installations
100+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Dot html,php,xml etc pages

Plugin Slug:
dot-htmlphpxml-etc-pages

Installations
100+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Facturante � Facturaci�n Electr�nica

Plugin Slug:
facturante

Installations
100+

Vulnerability:
SQL Injection

Patched in Version:
No Fix

Severity Score:
Critical


The vulnerability has not been patched. You should deactivate the plugin.

6Storage Rentals

Plugin Slug:
6storage-rentals

Installations
60+

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Interview

Plugin Slug:
interview

Installations
40+

Vulnerability:
SQL Injection

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

BNS Twitter Follow Button

Plugin Slug:
bns-twitter-follow-button

Installations
10+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Real WP Shop Lite Ajax eCommerce Shopping Cart

Plugin Slug:
real-wp-shop-lite

Installations
10+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

360 Product Rotation

Plugin:

360 Product Rotation

Plugin Slug:
360-product-rotation

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

WP Ultimate Tours Builder

Plugin:

WP Ultimate Tours Builder

Plugin Slug:
WP_UltimateToursBuilder

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Advance Post Prefix

Plugin:

Advance Post Prefix

Plugin Slug:
advance-post-prefix

Vulnerability:
SQL Injection

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Advance Post Prefix

Plugin:

Advance Post Prefix

Plugin Slug:
advance-post-prefix

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Advanced Page Visit Counter

Plugin:

Advanced Page Visit Counter

Plugin Slug:
advanced-page-visit-counter

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

AffiliateImporterEb

Plugin:

AffiliateImporterEb

Plugin Slug:
affiliateimportereb

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

AffiliateImporterEb

Plugin:

AffiliateImporterEb

Plugin Slug:
affiliateimportereb

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

AlT Monitoring

Plugin:

AlT Monitoring

Plugin Slug:
alt-monitoring

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Ads Pro Plugin

Plugin:

Ads Pro Plugin

Plugin Slug:
ap-plugin-scripteo

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Audio Comments

Plugin:

Audio Comments

Plugin Slug:
audio-comments

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Radio Player Shoutcast & Icecast WordPress Plugin

Plugin:

Radio Player Shoutcast & Icecast WordPress Plugin

Plugin Slug:
audio4-html5

Vulnerability:
SQL Injection

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

BabelZ

Plugin:

BabelZ

Plugin Slug:
babelz

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Backup Database

Plugin:

Backup Database

Plugin Slug:
backup-database

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Badgearoo

Plugin:

Badgearoo

Plugin Slug:
badgearoo

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Badgearoo

Plugin:

Badgearoo

Plugin Slug:
badgearoo

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

????SEO??(????/??/Bing/????)

Plugin:

????SEO??(????/??/Bing/????)

Plugin Slug:
baiduseo

Vulnerability:
Arbitrary File Upload

Patched in Version:
No Fix

Severity Score:
Critical


The vulnerability has not been patched. You should deactivate the plugin.

Element Pack Pro

Plugin:

Element Pack Pro

Plugin Slug:
bdthemes-element-pack

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Element Pack Pro

Plugin:

Element Pack Pro

Plugin Slug:
bdthemes-element-pack

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

BTEV

Plugin:

BTEV

Plugin Slug:
bluetrait-event-viewer

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Bon Toolkit

Plugin:

Bon Toolkit

Plugin Slug:
bon-toolkit

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

WPCHURCH

Plugin:

WPCHURCH

Plugin Slug:
church-management

Vulnerability:
Local File Inclusion

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

CountDown Pro WP Plugin

Plugin:

CountDown Pro WP Plugin

Plugin Slug:
circular_countdown

Vulnerability:
SQL Injection

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Clasify Classified Listing

Plugin:

Clasify Classified Listing

Plugin Slug:
clasify-classified-listing

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Clicksold IDX

Plugin:

Clicksold IDX

Plugin Slug:
clicksold-wordpress-plugin

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

ClipArt

Plugin:

ClipArt

Plugin Slug:
clipart

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Competition Form

Plugin:

Competition Form

Plugin Slug:
competition-form

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Countdown Timer

Plugin:

Countdown Timer

Plugin Slug:
countdown-timer-block

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

CSS3 Accordions for WordPress

Plugin:

CSS3 Accordions for WordPress

Plugin Slug:
css3_accordions

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

CSS3 Accordions for WordPress

Plugin:

CSS3 Accordions for WordPress

Plugin Slug:
css3_accordions

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

CSS3 Tooltips for WordPress

Plugin:

CSS3 Tooltips for WordPress

Plugin Slug:
css3_tooltips

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

CSS3 Compare Pricing Tables for WordPress

Plugin:

CSS3 Compare Pricing Tables for WordPress

Plugin Slug:
css3_web_pricing_tables_grids

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Custom Author Base

Plugin:

Custom Author Base

Plugin Slug:
custom-author-base

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Custom Field Manager

Plugin:

Custom Field Manager

Plugin Slug:
custom-field-manager

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

DL Verification

Plugin:

DL Verification

Plugin Slug:
dl-verification

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

DL Yandex Metrika

Plugin:

DL Yandex Metrika

Plugin Slug:
dl-yandex-metrika

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Dokan Pro

Plugin:

Dokan Pro

Plugin Slug:
dokan-pro

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

S3Player � WooCommerce & Elementor Integration

Plugin:

S3Player � WooCommerce & Elementor Integration

Plugin Slug:
drm-protected-video-streaming

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

EG-Series

Plugin:

EG-Series

Plugin Slug:
eg-series

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Event Calendar

Plugin:

Event Calendar

Plugin Slug:
event-calendars

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Event Calendar

Plugin:

Event Calendar

Plugin Slug:
event-calendars

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

EventON

Plugin:

EventON

Plugin Slug:
eventON

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

FAT Services Booking

Plugin:

FAT Services Booking

Plugin Slug:
fat-services-booking

Vulnerability:
Local File Inclusion

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

File Manager Advanced Shortcode

Plugin:

File Manager Advanced Shortcode

Plugin Slug:
file-manager-advanced-shortcode

Vulnerability:
Content Injection

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Front End Users

Plugin:

Front End Users

Plugin Slug:
front-end-only-users

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Full Screen (Page) Background Image Slideshow

Plugin:

Full Screen (Page) Background Image Slideshow

Plugin Slug:
full-screen-page-background-image-slideshow

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Geocache Stat Bar Widget

Plugin:

Geocache Stat Bar Widget

Plugin Slug:
geocache-stat-bar-widget

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

WPGYM

Plugin:

WPGYM

Plugin Slug:
gym-management

Vulnerability:
SQL Injection

Patched in Version:
No Fix

Severity Score:
Critical


The vulnerability has not been patched. You should deactivate the plugin.

JavaScript Logic

Plugin:

JavaScript Logic

Plugin Slug:
javascript-logic

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

JSP Store Locator

Plugin:

JSP Store Locator

Plugin Slug:
jsp-store-locator

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

JSP Store Locator

Plugin:

JSP Store Locator

Plugin Slug:
jsp-store-locator

Vulnerability:
SQL Injection

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

jwp-a11y

Plugin:

jwp-a11y

Plugin Slug:
jwp-a11y

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Chameleon HTML5 Audio Player With/Without Playlist

Plugin:

Chameleon HTML5 Audio Player With/Without Playlist

Plugin Slug:
lbg-audio1-html5

Vulnerability:
SQL Injection

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Responsive HTML5 Audio Player PRO With Playlist

Plugin:

Responsive HTML5 Audio Player PRO With Playlist

Plugin Slug:
lbg-audio2-html5

Vulnerability:
SQL Injection

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Sticky HTML5 Music Player

Plugin:

Sticky HTML5 Music Player

Plugin Slug:
lbg-audio3-html5

Vulnerability:
SQL Injection

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Sticky Radio Player

Plugin:

Sticky Radio Player

Plugin Slug:
lbg-audio5-html5-shoutcast_sticky

Vulnerability:
SQL Injection

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Apollo

Plugin:

Apollo

Plugin Slug:
lbg-audio7_html5_full_width_sticky_pro

Vulnerability:
SQL Injection

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

SHOUT

Plugin:

SHOUT

Plugin Slug:
lbg-audio8-html5-radio_ads

Vulnerability:
SQL Injection

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.
Plugin:

illi Link Party!

Plugin Slug:
link-party

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Connexion Logs

Plugin:

Connexion Logs

Plugin Slug:
logs-de-connexion

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Connexion Logs

Plugin:

Connexion Logs

Plugin Slug:
logs-de-connexion

Vulnerability:
SQL Injection

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.
Plugin:

Magic Responsive Slider and Carousel WordPress

Plugin Slug:
magic-carousel

Vulnerability:
SQL Injection

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

MapFig Studio

Plugin:

MapFig Studio

Plugin Slug:
mapfig-studio

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

MapSVG

Plugin:

MapSVG

Plugin Slug:
mapsvg

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

MapSVG

Plugin:

MapSVG

Plugin Slug:
mapsvg

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

MapSVG

Plugin:

MapSVG

Plugin Slug:
mapsvg

Vulnerability:
Content Injection

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.
Plugin:

Multimedia Responsive Carousel with Image Video Audio Support

Plugin Slug:
multimedia-carousel

Vulnerability:
SQL Injection

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Nasa Core

Plugin:

Nasa Core

Plugin Slug:
nasa-core

Vulnerability:
Local File Inclusion

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Ninja Tables Pro

Plugin:

Ninja Tables Pro

Plugin Slug:
ninja-tables-pro

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Nokaut Offers Box

Plugin:

Nokaut Offers Box

Plugin Slug:
nokaut-offers-box

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Nokaut Offers Box

Plugin:

Nokaut Offers Box

Plugin Slug:
nokaut-offers-box

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Ntz Antispam

Plugin:

Ntz Antispam

Plugin Slug:
ntzantispam

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

TNC FlipBook

Plugin:

TNC FlipBook

Plugin Slug:
pdf-viewer-for-wordpress

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

PeoplePond

Plugin:

PeoplePond

Plugin Slug:
peoplepond

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Pixel WordPress Form BuilderPlugin & Autoresponder

Plugin:

Pixel WordPress Form BuilderPlugin & Autoresponder

Plugin Slug:
pixel-formbuilder

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Planning Center Online Giving

Plugin:

Planning Center Online Giving

Plugin Slug:
planning-center-online-giving

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

profilepro

Plugin:

profilepro

Plugin Slug:
profilepro

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Panorama � WordPress Project Management Plugin

Plugin:

Panorama � WordPress Project Management Plugin

Plugin Slug:
project-panorama-lite

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

PVN Auth Popup

Plugin:

PVN Auth Popup

Plugin Slug:
pvn-auth-popup

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

PVN Auth Popup

Plugin:

PVN Auth Popup

Plugin Slug:
pvn-auth-popup

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.
Plugin:

Simple Link Directory Pro

Plugin Slug:
qc-simple-link-directory

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

QuickCal

Plugin:

QuickCal

Plugin Slug:
quickcal

Vulnerability:
Sensitive Data Exposure

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

QuickCal

Plugin:

QuickCal

Plugin Slug:
quickcal

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Rootspersona

Plugin:

Rootspersona

Plugin Slug:
rootspersona

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Rootspersona

Plugin:

Rootspersona

Plugin Slug:
rootspersona

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Sailthru Triggermail

Plugin Slug:
sailthru-triggermail

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Salon Booking Pro

Plugin:

Salon Booking Pro

Plugin Slug:
salon-booking-plugin-pro-cc

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Simple Nav Archives

Plugin:

Simple Nav Archives

Plugin Slug:
simple-nav-archives

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.
Plugin:

Smooth Gallery Replacement

Plugin Slug:
smooth-gallery-replacement

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Spiritual Gifts Survey

Plugin:

Spiritual Gifts Survey

Plugin Slug:
spiritual-gifts-survey

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Spotlight – Social Media Feeds (Premium)

Plugin:

Spotlight – Social Media Feeds (Premium)

Plugin Slug:
spotlight-social-photo-feeds-premium

Vulnerability:
Sensitive Data Exposure

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

The Plus Addons for Elementor Pro

Plugin:

The Plus Addons for Elementor Pro

Plugin Slug:
theplus_elementor_addon

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

TwitterPosts

Plugin:

TwitterPosts

Plugin Slug:
twitter-posts

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

UberSlider

Plugin:

UberSlider

Plugin Slug:
uber-classic

Vulnerability:
SQL Injection

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Video Player & FullScreen Video Background

Plugin:

Video Player & FullScreen Video Background

Plugin Slug:
universal-video-player-and-bg

Vulnerability:
SQL Injection

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

User Profile Meta Manager

Plugin:

User Profile Meta Manager

Plugin Slug:
user-profile-meta

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
Critical


The vulnerability has not been patched. You should deactivate the plugin.

Weluka Lite

Plugin:

Weluka Lite

Plugin Slug:
weluka-lite

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

WHMpress

Plugin:

WHMpress

Plugin Slug:
whmpress

Vulnerability:
Local File Inclusion

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

WHMpress

Plugin:

WHMpress

Plugin Slug:
whmpress

Vulnerability:
Local File Inclusion

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Widgets Reset

Plugin:

Widgets Reset

Plugin Slug:
widgets-reset

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

WolfNet IDX

Plugin:

WolfNet IDX

Plugin Slug:
wolfnet-idx-for-wordpress

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

CURCY

Plugin:

CURCY

Plugin Slug:
woocommerce-multi-currency

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

WOOEXIM

Plugin:

WOOEXIM

Plugin Slug:
wooexim

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

WordPress Auto Spinner

Plugin:

WordPress Auto Spinner

Plugin Slug:
wp-auto-spinner

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

WordPress????

Plugin:

WordPress????

Plugin Slug:
wp-connect

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

WP Content Security Plugin

Plugin:

WP Content Security Plugin

Plugin Slug:
wp-content-security-policy

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

WP DeskLite

Plugin:

WP DeskLite

Plugin Slug:
wp-desklite

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

WP JobHunt

Plugin:

WP JobHunt

Plugin Slug:
wp-jobhunt

Vulnerability:
Insecure Direct Object References (IDOR)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Pinterest Automatic Pin

Plugin:

Pinterest Automatic Pin

Plugin Slug:
wp-pinterest-automatic

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

WP-PManager

Plugin:

WP-PManager

Plugin Slug:
wp-programmmanager

Vulnerability:
SQL Injection

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

WP-PManager

Plugin:

WP-PManager

Plugin Slug:
wp-programmmanager

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

WPBot Pro WordPress Chatbot

Plugin:

WPBot Pro WordPress Chatbot

Plugin Slug:
wpbot-pro

Vulnerability:
PHP Object Injection

Patched in Version:
No Fix

Severity Score:
Critical


The vulnerability has not been patched. You should deactivate the plugin.

WordPress Events Calendar Registration & Tickets

Plugin:

WordPress Events Calendar Registration & Tickets

Plugin Slug:
wpeventplus

Vulnerability:
PHP Object Injection

Patched in Version:
No Fix

Severity Score:
Critical


The vulnerability has not been patched. You should deactivate the plugin.

Jetpack � WP Security, Backup, Speed, & Growth

Plugin Slug:
jetpack

Installations
4,000,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
13.8

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 13.8.

Jetpack � WP Security, Backup, Speed, & Growth

Plugin Slug:
jetpack

Installations
4,000,000+

Vulnerability:
Content Injection

Patched in Version:
13.8

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 13.8.

The Events Calendar

Plugin Slug:
the-events-calendar

Installations
700,000+

Vulnerability:
Broken Access Control

Patched in Version:
6.12.0

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 6.12.0.

The Events Calendar

Plugin Slug:
the-events-calendar

Installations
700,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
6.6.4

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 6.6.4.

Firelight Lightbox

Plugin Slug:
easy-fancybox

Installations
200,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.3.15

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.3.15.

Download Manager

Plugin Slug:
download-manager

Installations
100,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
3.2.99

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 3.2.99.

Floating Notification Bar, Sticky Menu on Scroll, Announcement Banner, and Sticky Header for Any Theme � My Sticky Bar (formerly myStickymenu)

Plugin Slug:
mystickymenu

Installations
100,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.6.8

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.6.8.
Plugin Slug:
relevanssi

Installations
100,000+

Vulnerability:
SQL Injection

Patched in Version:
4.24.5

Severity Score:
High


The vulnerability has been patched, so you should update to version 4.24.5.
Plugin Slug:
responsive-lightbox

Installations
100,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.5.1

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.5.1.

Simple Lightbox

Plugin Slug:
simple-lightbox

Installations
100,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.9.4

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.9.4.

Tracking Code Manager

Plugin Slug:
tracking-code-manager

Installations
100,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.3.0

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.3.0.

Social Media Share Buttons & Social Sharing Icons

Plugin Slug:
ultimate-social-media-icons

Installations
100,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.9.1

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.9.1.

Jupiter X Core

Plugin Slug:
jupiterx-core

Installations
90,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
4.9.1

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 4.9.1.

LearnPress � WordPress LMS Plugin

Plugin Slug:
learnpress

Installations
90,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
4.2.7.5.1

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 4.2.7.5.1.

Nested Pages

Plugin Slug:
wp-nested-pages

Installations
90,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
3.2.9

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 3.2.9.

Ajax Search Lite � Live Search & Filter

Plugin Slug:
ajax-search-lite

Installations
80,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
4.12.3

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 4.12.3.

ImageMagick Engine

Plugin Slug:
imagemagick-engine

Installations
70,000+

Vulnerability:
Remote Code Execution (RCE)

Patched in Version:
1.7.11

Severity Score:
Critical


The vulnerability has been patched, so you should update to version 1.7.11.

Exclusive Addons for Elementor

Plugin Slug:
exclusive-addons-for-elementor

Installations
60,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.7.9.1

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.7.9.1.

Qi Blocks

Plugin Slug:
qi-blocks

Installations
60,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.4

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.4.

WP-Members Membership Plugin

Plugin Slug:
wp-members

Installations
60,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
3.5.3

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 3.5.3.

WP Booking Calendar

Plugin Slug:
booking

Installations
50,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
10.11.2

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 10.11.2.

Ultimate Blocks � WordPress Blocks Plugin

Plugin Slug:
ultimate-blocks

Installations
50,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
3.3.1

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 3.3.1.

Visual Composer Website Builder

Plugin Slug:
visualcomposer

Installations
50,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
45.12.0

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 45.12.0.

MapPress Maps for WordPress

Plugin Slug:
mappress-google-maps-for-wordpress

Installations
40,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.93

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.93.
Plugin Slug:
robo-gallery

Installations
40,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
3.2.24

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 3.2.24.
Plugin Slug:
robo-gallery

Installations
40,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
3.2.22

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 3.2.22.

Hubbub Lite � Fast, Reliable Social Sharing Buttons

Plugin Slug:
social-pug

Installations
40,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.34.4

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.34.4.

LightPress Lightbox

Plugin Slug:
wp-jquery-lightbox

Installations
40,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.3.4

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.3.4.

Advanced Cron Manager � debug & control

Plugin Slug:
advanced-cron-manager

Installations
30,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.5.7

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.5.7.

Cost Calculator Builder

Plugin Slug:
cost-calculator-builder

Installations
30,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
3.5.0

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 3.5.0.

Social Slider Feed

Plugin Slug:
instagram-slider-widget

Installations
30,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.2.9

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.2.9.

Uncanny Toolkit for LearnDash

Plugin Slug:
uncanny-learndash-toolkit

Installations
30,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
3.7.0.3

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 3.7.0.3.

WP Google Review Slider

Plugin Slug:
wp-google-places-review-slider

Installations
30,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
15.6

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 15.6.

Maspik � Ultimate Spam Protection

Plugin Slug:
contact-forms-anti-spam

Installations
20,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.1.3

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.1.3.

Smart Post Show � Post Grid, Post Carousel, Post Slider, Post Timeline, Post Table, and List Category Posts, Latest Posts, Recent Posts, Popular Posts and More

Plugin Slug:
post-carousel

Installations
20,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.4.28

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.4.28.

PWA for WP � Progressive Web Apps Made Simple

Plugin Slug:
pwa-for-wp

Installations
20,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.7.72

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.7.72.

Quiz Maker

Plugin Slug:
quiz-maker

Installations
20,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
6.5.9.9

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 6.5.9.9.

Simple Job Board

Plugin Slug:
simple-job-board

Installations
20,000+

Vulnerability:
Sensitive Data Exposure

Patched in Version:
2.12.6

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.12.6.

Simple Job Board

Plugin Slug:
simple-job-board

Installations
20,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.12.2

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.12.2.

bunny.net � WordPress CDN Plugin

Plugin Slug:
bunnycdn

Installations
10,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.3.1

Severity Score:
High


The vulnerability has been patched, so you should update to version 2.3.1.

The GDPR Framework By Data443

Plugin Slug:
gdpr-framework

Installations
10,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.2.0

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.2.0.

Prisna GWT � Google Website Translator

Plugin Slug:
google-website-translator

Installations
10,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.4.14

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.4.14.

MB Custom Post Types & Custom Taxonomies

Plugin Slug:
mb-custom-post-type

Installations
10,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.7.7

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.7.7.

Mobile Contact Bar

Plugin Slug:
mobile-contact-bar

Installations
10,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
3.0.5

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 3.0.5.

Sensei LMS � Online Courses, Quizzes, & Learning

Plugin Slug:
sensei-lms

Installations
10,000+

Vulnerability:
Sensitive Data Exposure

Patched in Version:
4.20.0

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 4.20.0.

Simple Basic Contact Form

Plugin Slug:
simple-basic-contact-form

Installations
10,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
20250114

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 20250114.

Team � Team Members Showcase Plugin

Plugin Slug:
tlp-team

Installations
10,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
4.4.2

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 4.4.2.

Japanized for WooCommerce

Plugin Slug:
woocommerce-for-japan

Installations
10,000+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
2.6.41

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.6.41.

VikBooking Hotel Booking Engine & PMS

Plugin Slug:
vikbooking

Installations
9,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.7.2

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.7.2.

CM Tooltip Glossary

Plugin Slug:
enhanced-tooltipglossary

Installations
8,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
4.3.4

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 4.3.4.

If-So Dynamic Content Personalization

Plugin Slug:
if-so

Installations
8,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.8.0.3

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.8.0.3.

Travelpayouts: All Travel Brands in One Place

Plugin Slug:
travelpayouts

Installations
8,000+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
1.1.13

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.1.13.

Travelpayouts: All Travel Brands in One Place

Plugin Slug:
travelpayouts

Installations
8,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.1.14

Severity Score:
High


The vulnerability has been patched, so you should update to version 1.1.14.

AI ChatBot for WordPress � WPBot

Plugin Slug:
chatbot

Installations
7,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
6.2.4

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 6.2.4.

HD Quiz

Plugin:

HD Quiz

Plugin Slug:
hd-quiz

Installations
7,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.0.0

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.0.0.

ProfileGrid � User Profiles, Groups and Communities

Plugin Slug:
profilegrid-user-profiles-groups-and-communities

Installations
7,000+

Vulnerability:
Broken Access Control

Patched in Version:
5.9.5.2

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 5.9.5.2.

ProfileGrid � User Profiles, Groups and Communities

Plugin Slug:
profilegrid-user-profiles-groups-and-communities

Installations
7,000+

Vulnerability:
SQL Injection

Patched in Version:
5.9.5.1

Severity Score:
High


The vulnerability has been patched, so you should update to version 5.9.5.1.

Wise Chat

Plugin Slug:
wise-chat

Installations
7,000+

Vulnerability:
Sensitive Data Exposure

Patched in Version:
3.3.4

Severity Score:
High


The vulnerability has been patched, so you should update to version 3.3.4.

Back Button Widget

Plugin Slug:
back-button-widget

Installations
6,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.7.0

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.7.0.

Easy Property Listings

Plugin Slug:
easy-property-listings

Installations
6,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
3.5.4

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 3.5.4.

EventON � Events Calendar

Plugin Slug:
eventon-lite

Installations
6,000+

Vulnerability:
Broken Access Control

Patched in Version:
2.4.5

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.4.5.

EventPrime � Events Calendar, Bookings and Tickets

Plugin Slug:
eventprime-event-calendar-management

Installations
6,000+

Vulnerability:
Broken Access Control

Patched in Version:
3.5.0

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 3.5.0.

Arconix Shortcodes

Plugin Slug:
arconix-shortcodes

Installations
5,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.1.17

Severity Score:
High


The vulnerability has been patched, so you should update to version 2.1.17.

ElementInvader Addons for Elementor

Plugin Slug:
elementinvader-addons-for-elementor

Installations
5,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.3.6

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.3.6.

Podlove Podcast Publisher

Plugin Slug:
podlove-podcasting-plugin-for-wordpress

Installations
5,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
4.2.1

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 4.2.1.

Podlove Podcast Publisher

Plugin Slug:
podlove-podcasting-plugin-for-wordpress

Installations
5,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
4.1.24

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 4.1.24.
Plugin Slug:
responsive-gallery-grid

Installations
5,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.3.15

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.3.15.

SMS Alert Order Notifications � WooCommerce

Plugin Slug:
sms-alert

Installations
5,000+

Vulnerability:
Privilege Escalation

Patched in Version:
3.8.2

Severity Score:
High


The vulnerability has been patched, so you should update to version 3.8.2.

SMS Alert Order Notifications � WooCommerce

Plugin Slug:
sms-alert

Installations
5,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
3.8.2

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 3.8.2.

Melapress File Monitor

Plugin Slug:
website-file-changes-monitor

Installations
5,000+

Vulnerability:
SQL Injection

Patched in Version:
2.1.1

Severity Score:
High


The vulnerability has been patched, so you should update to version 2.1.1.

Melapress File Monitor

Plugin Slug:
website-file-changes-monitor

Installations
5,000+

Vulnerability:
SQL Injection

Patched in Version:
2.1.0

Severity Score:
High


The vulnerability has been patched, so you should update to version 2.1.0.

WPAdverts � Classifieds Plugin

Plugin Slug:
wpadverts

Installations
5,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.2.4

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.2.4.

Import Social Events

Plugin Slug:
import-facebook-events

Installations
4,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.8.6

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.8.6.

Ultimate Noindex Nofollow Tool II

Plugin Slug:
ultimate-noindex-nofollow-tool-ii

Installations
4,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.3.6

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.3.6.
Plugin Slug:
wp-auto-affiliate-links

Installations
4,000+

Vulnerability:
SQL Injection

Patched in Version:
6.4.7

Severity Score:
High


The vulnerability has been patched, so you should update to version 6.4.7.

Newsletters

Plugin Slug:
newsletters-lite

Installations
3,000+

Vulnerability:
SQL Injection

Patched in Version:
4.9.9.9

Severity Score:
High


The vulnerability has been patched, so you should update to version 4.9.9.9.

User Activity Tracking and Log

Plugin Slug:
user-activity-tracking-and-log

Installations
3,000+

Vulnerability:
Other Vulnerability Type

Patched in Version:
4.1.4

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 4.1.4.

Wishlist for WooCommerce: Multi Wishlists Per Customer

Plugin Slug:
wish-list-for-woocommerce

Installations
3,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
3.2.3

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 3.2.3.

Additional Custom Emails & Recipients for WooCommerce

Plugin Slug:
custom-emails-for-woocommerce

Installations
2,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
3.5.2

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 3.5.2.

SKT Blocks � Gutenberg based Page Builder

Plugin Slug:
skt-blocks

Installations
2,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.3

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.3.
Plugin Slug:
url-coupons-for-woocommerce-by-algoritmika

Installations
2,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.7.8

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.7.8.

Change Add to Cart Button Text for WooCommerce

Plugin Slug:
add-to-cart-button-labels-for-woocommerce

Installations
1,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.2.3

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.2.3.

Auto Prune Posts

Plugin Slug:
auto-prune-posts

Installations
1,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
3.0.0

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 3.0.0.

Falang multilanguage for WordPress

Plugin Slug:
falang

Installations
1,000+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
1.3.62

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.3.62.

WordPress Mega Menu Block

Plugin Slug:
getwid-megamenu

Installations
1,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.0.7

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.0.7.
Plugin Slug:
ninja-gdpr-compliance

Installations
1,000+

Vulnerability:
Broken Access Control

Patched in Version:
2.7.4

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.7.4.

Product Code for WooCommerce

Plugin Slug:
product-code-for-woocommerce

Installations
1,000+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
1.5.1

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.5.1.

Product Notes Tab & Private Admin Notes for WooCommerce

Plugin Slug:
product-notes-for-woocommerce

Installations
1,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
3.1.1

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 3.1.1.

Tainacan

Plugin:

Tainacan

Plugin Slug:
tainacan

Installations
1,000+

Vulnerability:
Arbitrary File Deletion

Patched in Version:
0.21.15

Severity Score:
High


The vulnerability has been patched, so you should update to version 0.21.15.

Year Make Model Search for WooCommerce

Plugin Slug:
ymm-search

Installations
1,000+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
1.0.12

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.0.12.

Polls CP

Plugin:

Polls CP

Plugin Slug:
cp-polls

Installations
800+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.0.77

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.0.77.

Frontend Dashboard

Plugin Slug:
frontend-dashboard

Installations
700+

Vulnerability:
Privilege Escalation

Patched in Version:
2.2.8

Severity Score:
High


The vulnerability has been patched, so you should update to version 2.2.8.

Secure Downloads

Plugin Slug:
secure-downloads

Installations
700+

Vulnerability:
Arbitrary File Download

Patched in Version:
1.2.3

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.2.3.

Drag and Drop File Upload for Elementor Forms

Plugin Slug:
drag-and-drop-file-upload-for-elementor-forms

Installations
600+

Vulnerability:
Arbitrary File Deletion

Patched in Version:
1.5.0

Severity Score:
High


The vulnerability has been patched, so you should update to version 1.5.0.

Sharespine Woocommerce Connector

Plugin Slug:
sharespine-woocommerce-connector

Installations
600+

Vulnerability:
Broken Access Control

Patched in Version:
4.8.56

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 4.8.56.

Xpro Addons For Beaver Builder � Lite

Plugin Slug:
xpro-addons-beaver-builder-elementor

Installations
600+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.5.6

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.5.6.

Affiliates Manager Google reCAPTCHA Integration

Plugin Slug:
affiliates-manager-google-recaptcha-integration

Installations
500+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
1.0.7

Severity Score:
High


The vulnerability has been patched, so you should update to version 1.0.7.

GamiPress � Reset User

Plugin Slug:
gamipress-reset-user

Installations
500+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
1.0.1

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.0.1.

Plugin Oficial � Getnet para WooCommerce

Plugin Slug:
wc-checkout-getnet

Installations
500+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.8.1

Severity Score:
High


The vulnerability has been patched, so you should update to version 1.8.1.

Plugin Oficial � Getnet para WooCommerce

Plugin Slug:
wc-checkout-getnet

Installations
500+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.8.1

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.8.1.

WP Mapa Politico Espa�a

Plugin Slug:
wp-mapa-politico-spain

Installations
500+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
3.8.1

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 3.8.1.

CYAN Backup

Plugin Slug:
cyan-backup

Installations
400+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.5.3

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.5.3.

Url Rewrite Analyzer

Plugin Slug:
url-rewrite-analyzer

Installations
400+

Vulnerability:
Broken Access Control

Patched in Version:
1.3.4

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.3.4.

Bot for Telegram on WooCommerce

Plugin Slug:
bot-for-telegram-on-woocommerce

Installations
300+

Vulnerability:
Broken Access Control

Patched in Version:
1.2.7

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.2.7.

Posts per Cat

Plugin Slug:
posts-per-cat

Installations
300+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.5.0

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.5.0.

Projectopia � WordPress Project Management

Plugin Slug:
projectopia-core

Installations
300+

Vulnerability:
Broken Access Control

Patched in Version:
5.1.18

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 5.1.18.

RSVPMaker

Plugin Slug:
rsvpmaker

Installations
300+

Vulnerability:
SQL Injection

Patched in Version:
11.5.7

Severity Score:
High


The vulnerability has been patched, so you should update to version 11.5.7.

Subaccounts for WooCommerce

Plugin Slug:
subaccounts-for-woocommerce

Installations
300+

Vulnerability:
Broken Authentication

Patched in Version:
1.6.7

Severity Score:
High


The vulnerability has been patched, so you should update to version 1.6.7.

Wholesale Market

Plugin Slug:
wholesale-market

Installations
300+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
2.2.2

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.2.2.

AWcode Toolkit

Plugin Slug:
awcode-toolkit

Installations
200+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
1.0.19

Severity Score:
High


The vulnerability has been patched, so you should update to version 1.0.19.

B2i Investor Tools

Plugin Slug:
b2i-investor-tools

Installations
200+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.0.8

Severity Score:
High


The vulnerability has been patched, so you should update to version 1.0.8.

Push Notification for Post and BuddyPress

Plugin Slug:
push-notification-for-post-and-buddypress

Installations
200+

Vulnerability:
SQL Injection

Patched in Version:
1.94

Severity Score:
Critical


The vulnerability has been patched, so you should update to version 1.94.

WP Image Mask

Plugin Slug:
wp-post-459212 wp-image-mask

Installations
200+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
3.1.3

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 3.1.3.

CTT Expresso para WooCommerce

Plugin Slug:
ctt-expresso-para-woocommerce

Installations
100+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
3.2.13

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 3.2.13.

LogDash Activity Log

Plugin Slug:
logdash-activity-log

Installations
100+

Vulnerability:
SQL Injection

Patched in Version:
1.1.4

Severity Score:
Critical


The vulnerability has been patched, so you should update to version 1.1.4.

Payment Gateway for Telcell

Plugin Slug:
payment-gateway-for-telcell

Installations
100+

Vulnerability:
Open Redirection

Patched in Version:
2.0.4

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.0.4.

JSFiddle Shortcode

Plugin Slug:
jsfiddle-shortcode

Installations
80+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.1.3

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.1.3.

TicketBAI Facturas para WooCommerce

Plugin Slug:
wp-ticketbai

Installations
80+

Vulnerability:
Arbitrary File Deletion

Patched in Version:
3.19

Severity Score:
High


The vulnerability has been patched, so you should update to version 3.19.

Z-Downloads

Plugin Slug:
z-downloads

Installations
70+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.11.6

Severity Score:
High


The vulnerability has been patched, so you should update to version 1.11.6.

Z-Downloads

Plugin Slug:
z-downloads

Installations
70+

Vulnerability:
Arbitrary File Upload

Patched in Version:
1.11.5

Severity Score:
Critical


The vulnerability has been patched, so you should update to version 1.11.5.

Z-Downloads

Plugin Slug:
z-downloads

Installations
70+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.11.7

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.11.7.

Tours

Plugin:

Tours

Plugin Slug:
tours

Installations
20+

Vulnerability:
Broken Access Control

Patched in Version:
1.0.1

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.0.1.

EKC Tournament Manager

Plugin Slug:
ekc-tournament-manager

Installations
10+

Vulnerability:
Arbitrary File Download

Patched in Version:
2.2.2

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.2.2.

EKC Tournament Manager

Plugin Slug:
ekc-tournament-manager

Installations
10+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
2.2.2

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.2.2.

KBucket: Your Curated Content in WordPress

Plugin Slug:
kbucket

Installations
10+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
4.1.5

Severity Score:
High


The vulnerability has been patched, so you should update to version 4.1.5.

KBucket: Your Curated Content in WordPress

Plugin Slug:
kbucket

Installations
10+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
4.1.6

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 4.1.6.

Offload Videos � Bunny.net, AWS S3

Plugin Slug:
offload-videos-bunny-netaws-s3

Installations
10+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
1.0.1

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.0.1.

Simple Video Directory

Plugin Slug:
simple-media-directory

Installations
10+

Vulnerability:
SQL Injection

Patched in Version:
1.4.3

Severity Score:
Critical


The vulnerability has been patched, so you should update to version 1.4.3.

File Manager Advanced Shortcode PRO

Plugin:

File Manager Advanced Shortcode PRO

Plugin Slug:
advanced-file-manager-pro-premium

Vulnerability:
Content Injection

Patched in Version:
2.6.0

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.6.0.

ARForms Form Builder

Plugin:

ARForms Form Builder

Plugin Slug:
arforms-form-builder

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.7.1

Severity Score:
High


The vulnerability has been patched, so you should update to version 1.7.1.

Buddyboss Platform

Plugin:

Buddyboss Platform

Plugin Slug:
buddyboss-platform

Vulnerability:
Insecure Direct Object References (IDOR)

Patched in Version:
2.7.60

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.7.60.

Crawlomatic Multisite Scraper Post Generator

Plugin:

Crawlomatic Multisite Scraper Post Generator

Plugin Slug:
crawlomatic-multipage-scraper-post-generator

Vulnerability:
Arbitrary File Upload

Patched in Version:
2.6.8.2

Severity Score:
Critical


The vulnerability has been patched, so you should update to version 2.6.8.2.

EventON

Plugin:

EventON

Plugin Slug:
eventON

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
4.9.7

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 4.9.7.

Jetpack Debug Tools

Plugin:

Jetpack Debug Tools

Plugin Slug:
jetpack-debug-helper

Vulnerability:
Broken Access Control

Patched in Version:
2.0.1

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.0.1.

Ninja Forms Webhooks

Plugin:

Ninja Forms Webhooks

Plugin Slug:
ninja-forms-webhooks

Vulnerability:
Server Side Request Forgery (SSRF)

Patched in Version:
3.0.8

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 3.0.8.

Opal Woo Custom Product Variation

Plugin:

Opal Woo Custom Product Variation

Plugin Slug:
opal-woo-custom-product-variation

Vulnerability:
Arbitrary File Deletion

Patched in Version:
1.2.1

Severity Score:
High


The vulnerability has been patched, so you should update to version 1.2.1.

PeepSo Core: File Uploads

Plugin:

PeepSo Core: File Uploads

Plugin Slug:
peepso-files

Vulnerability:
Insecure Direct Object References (IDOR)

Patched in Version:
6.4.6.1

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 6.4.6.1.

Relevanssi Premium

Plugin:

Relevanssi Premium

Plugin Slug:
relevanssi-premium

Vulnerability:
SQL Injection

Patched in Version:
2.27.5

Severity Score:
High


The vulnerability has been patched, so you should update to version 2.27.5.

Echo RSS Feed Post Generator Plugin for WordPress

Plugin:

Echo RSS Feed Post Generator Plugin for WordPress

Plugin Slug:
rss-feed-post-generator-echo

Vulnerability:
Arbitrary File Upload

Patched in Version:
5.4.8.2

Severity Score:
Critical


The vulnerability has been patched, so you should update to version 5.4.8.2.

tarteaucitron.js for WordPress

Plugin:

tarteaucitron.js for WordPress

Plugin Slug:
tarteaucitron-wp

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
0.3.0

Severity Score:
High


The vulnerability has been patched, so you should update to version 0.3.0.

tarteaucitron.js for WordPress

Plugin:

tarteaucitron.js for WordPress

Plugin Slug:
tarteaucitron-wp

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
0.3.0

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 0.3.0.

Rankie

Plugin:

Rankie

Plugin Slug:
valvepress-rankie

Vulnerability:
Broken Access Control

Patched in Version:
1.8.2

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.8.2.

WP Content Copy Protection & No Right Click (premium)

Plugin:

WP Content Copy Protection & No Right Click (premium)

Plugin Slug:
wccp-pro

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
15.3

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 15.3.

WP Content Copy Protection & No Right Click (premium)

Plugin:

WP Content Copy Protection & No Right Click (premium)

Plugin Slug:
wccp-pro

Vulnerability:
Open Redirection

Patched in Version:
15.3

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 15.3.
Plugin:

GDPR Cookie Consent

Plugin Slug:
webtoffee-gdpr-cookie-consent

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.6.1

Severity Score:
High


The vulnerability has been patched, so you should update to version 2.6.1.
Plugin:

GDPR Cookie Consent

Plugin Slug:
webtoffee-gdpr-cookie-consent

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
2.6.1

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.6.1.

WPBot Pro WordPress Chatbot

Plugin:

WPBot Pro WordPress Chatbot

Plugin Slug:
wpbot-pro

Vulnerability:
Arbitrary File Deletion

Patched in Version:
13.7.0

Severity Score:
High


The vulnerability has been patched, so you should update to version 13.7.0.

WordPress Themes � 3 Patched / 15 Unpatched

Acerola

Theme:

Acerola

Theme Slug:
acerola

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should switch themes.

AnyWhere Elementor Pro

Theme:

AnyWhere Elementor Pro

Theme Slug:
anywhere-elementor-pro

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should switch themes.

Bimber – Viral Magazine WordPress Theme

Theme:

Bimber – Viral Magazine WordPress Theme

Theme Slug:
bimber

Vulnerability:
Local File Inclusion

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should switch themes.

Bloggie

Theme:

Bloggie

Theme Slug:
bloggie

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should switch themes.

CouponXL

Theme:

CouponXL

Theme Slug:
couponxl

Vulnerability:
Privilege Escalation

Patched in Version:
No Fix

Severity Score:
Critical


The vulnerability has not been patched. You should switch themes.

Dash

Theme:

Dash

Theme Slug:
dash

Vulnerability:
PHP Object Injection

Patched in Version:
No Fix

Severity Score:
Critical


The vulnerability has not been patched. You should switch themes.

HotStar � Multi-Purpose Business Theme

Theme:

HotStar � Multi-Purpose Business Theme

Theme Slug:
hotstar

Vulnerability:
PHP Object Injection

Patched in Version:
No Fix

Severity Score:
Critical


The vulnerability has not been patched. You should switch themes.

HotStar � Multi-Purpose Business Theme

Theme:

HotStar � Multi-Purpose Business Theme

Theme Slug:
hotstar

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should switch themes.

Jarvis � Night Club, Concert, Festival WordPress

Theme:

Jarvis � Night Club, Concert, Festival WordPress

Theme Slug:
jarvis

Vulnerability:
PHP Object Injection

Patched in Version:
No Fix

Severity Score:
Critical


The vulnerability has not been patched. You should switch themes.

The Business

Theme:

The Business

Theme Slug:
nrgbusiness

Vulnerability:
PHP Object Injection

Patched in Version:
No Fix

Severity Score:
Critical


The vulnerability has not been patched. You should switch themes.

The Business

Theme:

The Business

Theme Slug:
nrgbusiness

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should switch themes.

Plant – Gardening & Houseplants WordPress Theme

Theme:

Plant – Gardening & Houseplants WordPress Theme

Theme Slug:
plant

Vulnerability:
Sensitive Data Exposure

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should switch themes.

Rozario

Theme:

Rozario

Theme Slug:
rozario

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should switch themes.

Seven Stars

Theme:

Seven Stars

Theme Slug:
sevenstars

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should switch themes.

Spare

Theme:

Spare

Theme Slug:
spare

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should switch themes.

Motors

Theme:

Motors

Theme Slug:
motors

Vulnerability:
Privilege Escalation

Patched in Version:
5.6.68

Severity Score:
Critical


The vulnerability has been patched, so you should update to version 5.6.68.

TheGem

Theme:

TheGem

Theme Slug:
thegem

Vulnerability:
Broken Access Control

Patched in Version:
5.10.3.1

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 5.10.3.1.

TheGem

Theme:

TheGem

Theme Slug:
thegem

Vulnerability:
Arbitrary File Upload

Patched in Version:
5.10.3.1

Severity Score:
High


The vulnerability has been patched, so you should update to version 5.10.3.1.

Related articles

Wait! Get exclusive hosting insights

Subscribe to our newsletter and stay ahead of the competition with expert advice from our hosting pros.

Loading form…