Line illustration showing a black application window on a dark purple gradient background overlaid with a large exclamation point alert icon and three bugs.

WordPress Vulnerability Report � November 12, 2025

In this report, 199 vulnerabilities have been publicly disclosed. Security patches for 104 of these plugins and themes are now available. Please run these updates as soon as possible. If you’re a Solid Security Pro user, the version management tool may have already warned you and updated these plugins, depending on your settings.

Currently, 95 plugin and theme vulnerabilities remain unpatched. If you’re a Solid Security Pro user, those vulnerabilities are already protected by the Solid Security firewall. Virtual patches from Patchstack will be applied when a vulnerability is considered high or medium risk. If no patch is forthcoming from the vendor or the vulnerable software has been marked “closed” and dropped from the official WordPress repositories, you should deactivate it soon and look for alternative solutions.

WordPress Core

WordPress 6.8.3 was released on September 30, 2025. This is a security release that features two fixes. As this is a security release, we recommend updating your sites immediately. For more information on WordPress 6.8.3, please visit the�version page on the HelpHub site.

WordPress 6.9 Release Candidate 1 (RC1) is now available for testing. This version is still under development and should not be installed on production or mission-critical websites. Instead, test RC1 on a staging or test site. You can read more on the WordPress Core blog for details on how to download and test this release.

The final release of WordPress 6.9 is scheduled for December 2, 2025. For updates, testing information, and release announcements, visit the Make WordPress Core blog.

WordPress Plugins � 103 Patched / 94 Unpatched

WP Snow Effect

Plugin Slug:
wp-snow-effect

Installations
1,000+

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Image Comparison Addon for Elementor

Plugin Slug:
image-comparison-elementor-addon

Installations
100+

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Magazine Companion

Plugin Slug:
bnm-blocks

Installations
50+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Content Locker for Elementor

Plugin Slug:
content-locker-for-elementor

Installations
40+

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Ace User Management

Plugin Slug:
ace-user-management

Vulnerability:
Broken Authentication

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Add Multiple Marker

Plugin:

Add Multiple Marker

Plugin Slug:
add-multiple-marker

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Ai Auto Tool Content Writing Assistant (Gemini Writer, ChatGPT ) All in One

Plugin:

Ai Auto Tool Content Writing Assistant (Gemini Writer, ChatGPT ) All in One

Plugin Slug:
ai-auto-tool

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.
Plugin:

Auto Amazon Links

Plugin Slug:
amazon-auto-links

Vulnerability:
Arbitrary File Download

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Authors List

Plugin:

Authors List

Plugin Slug:
authors-list

Vulnerability:
Sensitive Data Exposure

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Multi-language Responsive Portfolio

Plugin:

Multi-language Responsive Portfolio

Plugin Slug:
bootstrap-multi-language-responsive-portfolio

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Associados Amazon

Plugin:

Associados Amazon

Plugin Slug:
brzon

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

CE21 Suite

Plugin:

CE21 Suite

Plugin Slug:
ce21-suite

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
Critical


The vulnerability has not been patched. You should deactivate the plugin.

CE21 Suite

Plugin:

CE21 Suite

Plugin Slug:
ce21-suite

Vulnerability:
Privilege Escalation

Patched in Version:
No Fix

Severity Score:
Critical


The vulnerability has not been patched. You should deactivate the plugin.

Centangle Team Showcase

Plugin:

Centangle Team Showcase

Plugin Slug:
centangle-team

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Chart Expert

Plugin:

Chart Expert

Plugin Slug:
chart-expert

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Clubmember

Plugin:

Clubmember

Plugin Slug:
clubmember

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Coon Google Maps

Plugin:

Coon Google Maps

Plugin Slug:
coon-google-maps

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

WP????????? for CPI

Plugin:

WP????????? for CPI

Plugin Slug:
cpi-wp-migration

Vulnerability:
Arbitrary File Upload

Patched in Version:
No Fix

Severity Score:
Critical


The vulnerability has not been patched. You should deactivate the plugin.

Crypto

Plugin:

Crypto

Plugin Slug:
crypto

Vulnerability:
Sensitive Data Exposure

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Crypto

Plugin:

Crypto

Plugin Slug:
crypto

Vulnerability:
Arbitrary File Deletion

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Crypto Payment Gateway with Payeer for WooCommerce

Plugin:

Crypto Payment Gateway with Payeer for WooCommerce

Plugin Slug:
crypto-payment-gateway-with-payeer-for-woocommerce

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

CTL Arcade Lite

Plugin:

CTL Arcade Lite

Plugin Slug:
ctl-arcade-lite

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Document Pro Elementor

Plugin:

Document Pro Elementor

Plugin Slug:
document-pro-elementor

Vulnerability:
Sensitive Data Exposure

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

DominoKit

Plugin:

DominoKit

Plugin Slug:
dominokit

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Download Counter Button

Plugin:

Download Counter Button

Plugin Slug:
download-counter-button

Vulnerability:
Arbitrary File Download

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Elastic Theme Editor

Plugin:

Elastic Theme Editor

Plugin Slug:
elastic-theme-editor

Vulnerability:
Arbitrary File Upload

Patched in Version:
No Fix

Severity Score:
Critical


The vulnerability has not been patched. You should deactivate the plugin.

Elegance Menu

Plugin:

Elegance Menu

Plugin Slug:
elegance-menu

Vulnerability:
Local File Inclusion

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

EM Beer Manager

Plugin:

EM Beer Manager

Plugin Slug:
em-beer-manager

Vulnerability:
Arbitrary File Upload

Patched in Version:
No Fix

Severity Score:
Critical


The vulnerability has not been patched. You should deactivate the plugin.

Eventbee Ticketing Widget

Plugin:

Eventbee Ticketing Widget

Plugin Slug:
eventbee-ticketing-widget

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Find Unused Images

Plugin:

Find Unused Images

Plugin Slug:
find-unused-images

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Five9 Live Chat

Plugin:

Five9 Live Chat

Plugin Slug:
five9

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Fleet Manager

Plugin:

Fleet Manager

Plugin Slug:
fleet

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Free Quotation

Plugin:

Free Quotation

Plugin Slug:
free-quotation

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Geopost

Plugin:

Geopost

Plugin Slug:
geopost

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Astra Security Suite

Plugin:

Astra Security Suite

Plugin Slug:
getastra

Vulnerability:
Arbitrary File Upload

Patched in Version:
No Fix

Severity Score:
Critical


The vulnerability has not been patched. You should deactivate the plugin.

GitHub Gist Shortcode

Plugin:

GitHub Gist Shortcode

Plugin Slug:
github-gist-shortcode

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Holiday class post calendar

Plugin:

Holiday class post calendar

Plugin Slug:
holiday-class-post-calendar

Vulnerability:
Remote Code Execution (RCE)

Patched in Version:
No Fix

Severity Score:
Critical


The vulnerability has not been patched. You should deactivate the plugin.

Import Export For WooCommerce

Plugin:

Import Export For WooCommerce

Plugin Slug:
import-export-for-woocommerce

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Jeba Cute forkit

Plugin:

Jeba Cute forkit

Plugin Slug:
jeba-cute-forkit

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

KiotViet Sync

Plugin:

KiotViet Sync

Plugin Slug:
kiotvietsync

Vulnerability:
Arbitrary File Upload

Patched in Version:
No Fix

Severity Score:
Critical


The vulnerability has not been patched. You should deactivate the plugin.

KiotViet Sync

Plugin:

KiotViet Sync

Plugin Slug:
kiotvietsync

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

KiotViet Sync

Plugin:

KiotViet Sync

Plugin Slug:
kiotvietsync

Vulnerability:
Sensitive Data Exposure

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Label Plugins

Plugin:

Label Plugins

Plugin Slug:
label-plugins

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

LinkedIn Resume

Plugin:

LinkedIn Resume

Plugin Slug:
linkedin-resume

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Live Photos on WordPress

Plugin:

Live Photos on WordPress

Plugin Slug:
live-photos

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

LMB^Box Smileys

Plugin:

LMB^Box Smileys

Plugin Slug:
lmbbox-smileys

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

MapMap

Plugin:

MapMap

Plugin Slug:
mapmap

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

MeetingList

Plugin:

MeetingList

Plugin Slug:
meeting-list

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Mementor Core

Plugin:

Mementor Core

Plugin Slug:
mementor-core

Vulnerability:
Privilege Escalation

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

My Geo Posts Free

Plugin:

My Geo Posts Free

Plugin Slug:
my-geo-posts-free

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Nari Accountant

Plugin:

Nari Accountant

Plugin Slug:
nari-accountant

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Ninja Countdown

Plugin:

Ninja Countdown

Plugin Slug:
ninja-countdown

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Nonaki

Plugin:

Nonaki

Plugin Slug:
nonaki-email-template-customizer

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Twitter Feed

Plugin:

Twitter Feed

Plugin Slug:
ot-twitter-feed

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Pagerank Tools

Plugin:

Pagerank Tools

Plugin Slug:
pagerank-tools

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Paypal Donation Shortcode

Plugin:

Paypal Donation Shortcode

Plugin Slug:
paypal-donation-shortcode

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.
Plugin:

Posts Navigation Links for Sections and Headings

Plugin Slug:
posts-navigation-links-for-sections-and-headings-free-by-wp-masters

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Precise Columns

Plugin:

Precise Columns

Plugin Slug:
precise-columns

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Preload Current Images

Plugin:

Preload Current Images

Plugin Slug:
preload-current-images

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Progress Bar Blocks for Gutenberg

Plugin:

Progress Bar Blocks for Gutenberg

Plugin Slug:
progressmatify-blocks

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

RandomQuotr

Plugin:

RandomQuotr

Plugin Slug:
randomquotr

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Reuse Builder

Plugin:

Reuse Builder

Plugin Slug:
reuse-builder

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

SH Contextual Help

Plugin:

SH Contextual Help

Plugin Slug:
sh-contextual-help

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Share to Google Classroom

Plugin:

Share to Google Classroom

Plugin Slug:
share-to-google-classroom

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Shelf Planner

Plugin:

Shelf Planner

Plugin Slug:
shelf-planner

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Shelf Planner

Plugin:

Shelf Planner

Plugin Slug:
shelf-planner

Vulnerability:
Sensitive Data Exposure

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Simple Donate

Plugin:

Simple Donate

Plugin Slug:
simple-donate

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Simple User Capabilities

Plugin:

Simple User Capabilities

Plugin Slug:
simple-user-capabilities

Vulnerability:
Privilege Escalation

Patched in Version:
No Fix

Severity Score:
Critical


The vulnerability has not been patched. You should deactivate the plugin.

Simple User Capabilities

Plugin:

Simple User Capabilities

Plugin Slug:
simple-user-capabilities

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Skip to Timestamp

Plugin:

Skip to Timestamp

Plugin Slug:
skip-to-timestamp

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Slippy Slider

Plugin:

Slippy Slider

Plugin Slug:
slippy-slider-responsive-touch-navigation-slider

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

SMS for WordPress

Plugin:

SMS for WordPress

Plugin Slug:
sms4wp

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Squirrels Auto Inventory

Plugin:

Squirrels Auto Inventory

Plugin Slug:
squirrels-auto-inventory

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

The Total Book Project

Plugin Slug:
the-total-book-project

Vulnerability:
Insecure Direct Object References (IDOR)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Top Bar Notification

Plugin:

Top Bar Notification

Plugin Slug:
top-bar-notification

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Ungapped Widgets

Plugin:

Ungapped Widgets

Plugin Slug:
ungapped-widgets

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

USB Qr Code Scanner For Woocommerce

Plugin:

USB Qr Code Scanner For Woocommerce

Plugin Slug:
usb-qr-code-scanner-for-woocommerce

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

ViaAds

Plugin:

ViaAds

Plugin Slug:
viaads

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Wisly

Plugin:

Wisly

Plugin Slug:
wisly

Vulnerability:
Insecure Direct Object References (IDOR)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Woocommerce � Products By Custom Tax

Plugin:

Woocommerce � Products By Custom Tax

Plugin Slug:
woocommerce-products-by-custom-tax

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

WP BBCode

Plugin:

WP BBCode

Plugin Slug:
wp-bbcode

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

WP Bootstrap Tabs

Plugin:

WP Bootstrap Tabs

Plugin Slug:
wp-bootstrap-tabs

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

WP Carticon

Plugin:

WP Carticon

Plugin Slug:
wp-carticon

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

WP Count Down Timer

Plugin:

WP Count Down Timer

Plugin Slug:
wp-count-down-timer

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.
Plugin:

WP Custom Admin Login Page Logo

Plugin Slug:
wp-custom-login-page-logo

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Flickr Show

Plugin:

Flickr Show

Plugin Slug:
wp-flickrshow

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

WP Global Screen Options

Plugin:

WP Global Screen Options

Plugin Slug:
wp-global-screen-options

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

WP-Iconics

Plugin:

WP-Iconics

Plugin Slug:
wp-iconics

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

WP-OAuth

Plugin:

WP-OAuth

Plugin Slug:
wp-oauth

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

WP-Walla

Plugin:

WP-Walla

Plugin Slug:
wp-walla

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Social Media WPCF7 Stop Words

Plugin:

Social Media WPCF7 Stop Words

Plugin Slug:
wpcf7-stop-words

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

YSlider

Plugin:

YSlider

Plugin Slug:
yslider

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

TablePress � Tables in WordPress made easy

Plugin Slug:
tablepress

Installations
700,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
3.2.5

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 3.2.5.

The Events Calendar

Plugin Slug:
the-events-calendar

Installations
700,000+

Vulnerability:
SQL Injection

Patched in Version:
6.15.10

Severity Score:
Critical


The vulnerability has been patched, so you should update to version 6.15.10.

The Events Calendar

Plugin Slug:
the-events-calendar

Installations
700,000+

Vulnerability:
Sensitive Data Exposure

Patched in Version:
6.15.10

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 6.15.10.

SiteSEO � SEO Simplified

Plugin Slug:
siteseo

Installations
400,000+

Vulnerability:
Broken Access Control

Patched in Version:
1.3.2

Severity Score:
Low


The vulnerability has been patched, so you should update to version 1.3.2.

Ad Inserter � Ad Manager & AdSense Ads

Plugin Slug:
ad-inserter

Installations
300,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.8.8

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.8.8.

Blocksy Companion

Plugin Slug:
blocksy-companion

Installations
300,000+

Vulnerability:
Arbitrary File Upload

Patched in Version:
2.1.20

Severity Score:
Critical


The vulnerability has been patched, so you should update to version 2.1.20.

Advanced Ads ��Ad Manager & AdSense

Plugin Slug:
advanced-ads

Installations
100,000+

Vulnerability:
Arbitrary Code Execution

Patched in Version:
2.0.13

Severity Score:
High


The vulnerability has been patched, so you should update to version 2.0.13.

AI Engine

Plugin Slug:
ai-engine

Installations
100,000+

Vulnerability:
Privilege Escalation

Patched in Version:
3.1.4

Severity Score:
Critical


The vulnerability has been patched, so you should update to version 3.1.4.

Popup and Slider Builder by Depicter � Add Email collecting Popup, Popup Modal, Coupon Popup, Image Slider, Carousel Slider, Post Slider Carousel

Plugin Slug:
depicter

Installations
100,000+

Vulnerability:
Broken Access Control

Patched in Version:
4.0.5

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 4.0.5.

Download Manager

Plugin Slug:
download-manager

Installations
100,000+

Vulnerability:
Broken Access Control

Patched in Version:
3.3.31

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 3.3.31.
Plugin Slug:
envira-gallery-lite

Installations
100,000+

Vulnerability:
Broken Access Control

Patched in Version:
1.12.0

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.12.0.

Schema & Structured Data for WP & AMP

Plugin Slug:
schema-and-structured-data-for-wp

Installations
100,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.52

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.52.

Strong Testimonials

Plugin Slug:
strong-testimonials

Installations
90,000+

Vulnerability:
Content Injection

Patched in Version:
3.2.17

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 3.2.17.

List category posts

Plugin Slug:
list-category-posts

Installations
80,000+

Vulnerability:
Sensitive Data Exposure

Patched in Version:
0.93.0

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 0.93.0.

Greenshift � animation and page builder blocks

Plugin Slug:
greenshift-animation-and-page-builder-blocks

Installations
60,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
12.2.8

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 12.2.8.

Qi Blocks

Plugin Slug:
qi-blocks

Installations
60,000+

Vulnerability:
Broken Access Control

Patched in Version:
1.4.4

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.4.4.

Premium Portfolio Features for Phlox theme

Plugin Slug:
auxin-portfolio

Installations
50,000+

Vulnerability:
Local File Inclusion

Patched in Version:
2.3.12

Severity Score:
High


The vulnerability has been patched, so you should update to version 2.3.12.

Blog2Social: Social Media Auto Post & Scheduler

Plugin Slug:
blog2social

Installations
50,000+

Vulnerability:
Server Side Request Forgery (SSRF)

Patched in Version:
8.6.1

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 8.6.1.

Blog2Social: Social Media Auto Post & Scheduler

Plugin Slug:
blog2social

Installations
50,000+

Vulnerability:
Broken Access Control

Patched in Version:
8.6.1

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 8.6.1.
Plugin Slug:
quick-featured-images

Installations
50,000+

Vulnerability:
SQL Injection

Patched in Version:
13.7.4

Severity Score:
High


The vulnerability has been patched, so you should update to version 13.7.4.

Better Find and Replace � AI-Powered Suggestions

Plugin Slug:
real-time-auto-find-and-replace

Installations
50,000+

Vulnerability:
Arbitrary Code Execution

Patched in Version:
1.7.8

Severity Score:
High


The vulnerability has been patched, so you should update to version 1.7.8.

Better Find and Replace � AI-Powered Suggestions

Plugin Slug:
real-time-auto-find-and-replace

Installations
50,000+

Vulnerability:
Broken Access Control

Patched in Version:
1.7.8

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.7.8.

FunnelKit � Funnel Builder for WooCommerce Checkout

Plugin Slug:
funnel-builder

Installations
40,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
3.12.0.1

Severity Score:
High


The vulnerability has been patched, so you should update to version 3.12.0.1.

PowerPress Podcasting plugin by Blubrry

Plugin Slug:
powerpress

Installations
30,000+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
11.14

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 11.14.

Inactive Logout

Plugin Slug:
inactive-logout

Installations
20,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
3.6.0

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 3.6.0.

wpForo Forum

Plugin Slug:
wpforo

Installations
20,000+

Vulnerability:
SQL Injection

Patched in Version:
2.4.10

Severity Score:
High


The vulnerability has been patched, so you should update to version 2.4.10.

Asgaros Forum

Plugin Slug:
asgaros-forum

Installations
10,000+

Vulnerability:
SQL Injection

Patched in Version:
3.2.0

Severity Score:
Critical


The vulnerability has been patched, so you should update to version 3.2.0.

CSS & JavaScript Toolbox

Plugin Slug:
css-javascript-toolbox

Installations
10,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
12.0.6

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 12.0.6.

WP2Social Auto Publish

Plugin Slug:
facebook-auto-publish

Installations
10,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.4.8

Severity Score:
High


The vulnerability has been patched, so you should update to version 2.4.8.

Graphina � Charts and Graphs For Elementor

Plugin Slug:
graphina-elementor-charts-and-graphs

Installations
10,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
3.1.9

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 3.1.9.

Groups

Plugin:

Groups

Plugin Slug:
groups

Installations
10,000+

Vulnerability:
Insecure Direct Object References (IDOR)

Patched in Version:
3.8.0

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 3.8.0.

HTML Forms � Simple WordPress Forms Plugin

Plugin Slug:
html-forms

Installations
10,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.5.6

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.5.6.

Mang Board WP

Plugin Slug:
mangboard

Installations
10,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.3.2

Severity Score:
High


The vulnerability has been patched, so you should update to version 2.3.2.
Plugin Slug:
visual-link-preview

Installations
10,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.2.8

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.2.8.

WPeMatico RSS Feed Fetcher

Plugin Slug:
wpematico

Installations
10,000+

Vulnerability:
Server Side Request Forgery (SSRF)

Patched in Version:
2.8.12

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.8.12.

aThemes Addons for Elementor

Plugin Slug:
athemes-addons-for-elementor-lite

Installations
8,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.1.6

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.1.6.

EventPrime � Events Calendar, Bookings and Tickets

Plugin Slug:
eventprime-event-calendar-management

Installations
7,000+

Vulnerability:
Broken Access Control

Patched in Version:
4.2.0.1

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 4.2.0.1.

Insert Headers and Footers Code � HT Script

Plugin Slug:
insert-headers-and-footers-script

Installations
7,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.1.7

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.1.7.

ElementInvader Addons for Elementor

Plugin Slug:
elementinvader-addons-for-elementor

Installations
4,000+

Vulnerability:
Broken Access Control

Patched in Version:
1.4.1

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.4.1.

Document Library Lite

Plugin Slug:
document-library-lite

Installations
3,000+

Vulnerability:
Broken Access Control

Patched in Version:
1.1.7

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.1.7.

Extensions for Leaflet Map

Plugin Slug:
extensions-leaflet-map

Installations
2,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
4.8

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 4.8.

Footnotes Made Easy

Plugin Slug:
footnotes-made-easy

Installations
2,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
3.0.8

Severity Score:
High


The vulnerability has been patched, so you should update to version 3.0.8.

Page & Post Notes

Plugin Slug:
page-post-notes

Installations
2,000+

Vulnerability:
Broken Access Control

Patched in Version:
1.3.5

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.3.5.

Flexible Refund and Return Order for WooCommerce

Plugin Slug:
flexible-refund-and-return-order-for-woocommerce

Installations
1,000+

Vulnerability:
Broken Access Control

Patched in Version:
1.0.43

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.0.43.

Connector Wizard (formerly LC Wizard)

Plugin Slug:
ghl-wizard

Installations
1,000+

Vulnerability:
Privilege Escalation

Patched in Version:
1.4.0

Severity Score:
High


The vulnerability has been patched, so you should update to version 1.4.0.

WP Airbnb Review Slider

Plugin Slug:
wp-airbnb-review-slider

Installations
1,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
4.4

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 4.4.

WP Discourse

Plugin Slug:
wp-discourse

Installations
1,000+

Vulnerability:
Sensitive Data Exposure

Patched in Version:
2.6.0

Severity Score:
Low


The vulnerability has been patched, so you should update to version 2.6.0.

WPCOM Member

Plugin Slug:
wpcom-member

Installations
1,000+

Vulnerability:
Local File Inclusion

Patched in Version:
1.7.15

Severity Score:
High


The vulnerability has been patched, so you should update to version 1.7.15.

Smart Auto Upload Images � Import External Images

Plugin Slug:
smart-auto-upload-images

Installations
900+

Vulnerability:
Arbitrary File Upload

Patched in Version:
1.2.1

Severity Score:
Critical


The vulnerability has been patched, so you should update to version 1.2.1.

TNC Toolbox: Web Performance

Plugin Slug:
tnc-toolbox

Installations
800+

Vulnerability:
Privilege Escalation

Patched in Version:
2.0.0

Severity Score:
Critical


The vulnerability has been patched, so you should update to version 2.0.0.

Easy Upload Files During Checkout

Plugin Slug:
easy-upload-files-during-checkout

Installations
600+

Vulnerability:
Arbitrary File Upload

Patched in Version:
2.9.9

Severity Score:
High


The vulnerability has been patched, so you should update to version 2.9.9.

Contact Form 7 AWeber Extension

Plugin Slug:
integrate-contact-form-7-and-aweber

Installations
400+

Vulnerability:
Broken Access Control

Patched in Version:
0.1.43

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 0.1.43.

RealPress � Real Estate Plugin

Plugin Slug:
realpress

Installations
400+

Vulnerability:
Broken Access Control

Patched in Version:
1.1.0

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.1.0.

CYAN Backup

Plugin Slug:
cyan-backup

Installations
300+

Vulnerability:
Arbitrary File Deletion

Patched in Version:
2.5.5

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.5.5.

Alex Reservations: Smart Restaurant Booking

Plugin Slug:
alex-reservations

Installations
200+

Vulnerability:
Arbitrary File Upload

Patched in Version:
2.2.4

Severity Score:
High


The vulnerability has been patched, so you should update to version 2.2.4.

Simple Downloads List

Plugin Slug:
simple-downloads-list

Installations
100+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.5.0

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.5.0.

Image Hover Effects for Elementor

Plugin Slug:
image-hover-effects-elementor-addon

Installations
60+

Vulnerability:
Broken Access Control

Patched in Version:
1.0.2.4

Severity Score:
High


The vulnerability has been patched, so you should update to version 1.0.2.4.

Schema Scalpel

Plugin Slug:
schema-scalpel

Installations
50+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.6.2

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.6.2.

Community Events

Plugin Slug:
community-events

Installations
40+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.5.3

Severity Score:
High


The vulnerability has been patched, so you should update to version 1.5.3.

Easy Email Subscription

Plugin Slug:
email-subscription-with-secure-captcha

Installations
30+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
1.3.1

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.3.1.

Easy Email Subscription

Plugin Slug:
email-subscription-with-secure-captcha

Installations
30+

Vulnerability:
SQL Injection

Patched in Version:
1.3.1

Severity Score:
High


The vulnerability has been patched, so you should update to version 1.3.1.

Saphali LiqPay for donate

Plugin Slug:
saphali-liqpay-for-donate

Installations
30+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.0.3

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.0.3.

Folderly

Plugin:

Folderly

Plugin Slug:
folderly

Installations
10+

Vulnerability:
Broken Access Control

Patched in Version:
0.3.1

Severity Score:
Low


The vulnerability has been patched, so you should update to version 0.3.1.

Academy LMS Pro

Plugin:

Academy LMS Pro

Plugin Slug:
academy-pro

Vulnerability:
Sensitive Data Exposure

Patched in Version:
3.3.9

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 3.3.9.

SUMO Affiliates Pro

Plugin:

SUMO Affiliates Pro

Plugin Slug:
affs

Vulnerability:
Sensitive Data Exposure

Patched in Version:
11.1.0

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 11.1.0.

Doccure Core

Plugin:

Doccure Core

Plugin Slug:
doccure

Vulnerability:
Privilege Escalation

Patched in Version:
1.5.4

Severity Score:
Critical


The vulnerability has been patched, so you should update to version 1.5.4.

Everest Forms Pro

Plugin:

Everest Forms Pro

Plugin Slug:
everest-forms-pro

Vulnerability:
PHP Object Injection

Patched in Version:
1.9.8

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.9.8.

Gravity Forms

Plugin:

Gravity Forms

Plugin Slug:
gravityforms

Vulnerability:
Arbitrary File Upload

Patched in Version:
2.9.21

Severity Score:
Critical


The vulnerability has been patched, so you should update to version 2.9.21.

Integrate Google Drive

Plugin:

Integrate Google Drive

Plugin Slug:
integrate-google-drive

Vulnerability:
Sensitive Data Exposure

Patched in Version:
1.5.4

Severity Score:
High


The vulnerability has been patched, so you should update to version 1.5.4.

JetElements For Elementor

Plugin:

JetElements For Elementor

Plugin Slug:
jet-elements

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.7.12.1

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.7.12.1.

Ohio Extra

Plugin:

Ohio Extra

Plugin Slug:
ohio-extra

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
3.6.1

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 3.6.1.

Ovatheme Events Manager

Plugin:

Ovatheme Events Manager

Plugin Slug:
ova-events-manager

Vulnerability:
Broken Access Control

Patched in Version:
1.8.7

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.8.7.

Rey Core

Plugin:

Rey Core

Plugin Slug:
rey-core

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
3.1.9

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 3.1.9.

WordPress Themes � 1 Patched / 1 Unpatched

Kallyas

Theme:

Kallyas

Theme Slug:
kallyas

Vulnerability:
Remote Code Execution (RCE)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should switch themes.

Kallyas

Theme:

Kallyas

Theme Slug:
kallyas

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
4.24.0

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 4.24.0.

Related articles

Wait! Get exclusive hosting insights

Subscribe to our newsletter and stay ahead of the competition with expert advice from our hosting pros.

Loading form…