Line illustration showing a black application window on a red gradient background overlaid with a large exclamation point alert icon and three bugs.

WordPress Vulnerability Report � November 19, 2025

In this report, 149 vulnerabilities have been publicly disclosed. Security patches for 67 of these plugins and themes are now available. Please run these updates as soon as possible. If you’re a Solid Security Pro user, the version management tool may have already warned you and updated these plugins, depending on your settings.

Currently, 82 plugin and theme vulnerabilities remain unpatched. If you’re a Solid Security Pro user, those vulnerabilities are already protected by the Solid Security firewall. Virtual patches from Patchstack will be applied when a vulnerability is considered high or medium risk. If no patch is forthcoming from the vendor or the vulnerable software has been marked “closed” and dropped from the official WordPress repositories, you should deactivate it soon and look for alternative solutions.

WordPress Core

WordPress 6.8.3 was released on September 30, 2025. This is a security release that features two fixes. As this is a security release, we recommend updating your sites immediately. For more information on WordPress 6.8.3, please visit the version page on the HelpHub site.

WordPress 6.9 Release Candidate 2 (RC2) is now available for testing. This version is still under development and should not be installed on production or mission-critical websites. Instead, test RC2 on a staging or test site. You can read more on the WordPress Core blog for details on how to download and test this release.

The final release of WordPress 6.9 is scheduled for December 2, 2025. For updates, testing information, and release announcements, visit the Make WordPress Core blog.

WordPress Plugins � 67 Patched / 81 Unpatched

Enable SVG, WebP, and ICO Upload

Plugin Slug:
enable-svg-webp-ico-upload

Installations
10,000+

Vulnerability:
Arbitrary File Upload

Patched in Version:
No Fix

Severity Score:
Critical


The vulnerability has not been patched. You should deactivate the plugin.

Enable SVG, WebP, and ICO Upload

Plugin Slug:
enable-svg-webp-ico-upload

Installations
10,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Stock Management for WooCommerce by Shelf Planner

Plugin Slug:
shelf-planner

Installations
100+

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Stock Management for WooCommerce by Shelf Planner

Plugin Slug:
shelf-planner

Installations
100+

Vulnerability:
Sensitive Data Exposure

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Simple User Import Export

Plugin:

Simple User Import Export

Plugin Slug:
a3-user-importer

Vulnerability:
CSV Injection

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

ACF Flexible Layouts Manager

Plugin:

ACF Flexible Layouts Manager

Plugin Slug:
acf-flexible-layouts-manager

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Add Multiple Marker

Plugin:

Add Multiple Marker

Plugin Slug:
add-multiple-marker

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.
Plugin:

Auto Amazon Links

Plugin Slug:
amazon-auto-links

Vulnerability:
Arbitrary File Download

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

ArtiBot

Plugin:

ArtiBot

Plugin Slug:
artibot

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Authors List

Plugin:

Authors List

Plugin Slug:
authors-list

Vulnerability:
Sensitive Data Exposure

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Restrictions for BuddyPress

Plugin:

Restrictions for BuddyPress

Plugin Slug:
bp-restrict

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Category and Product Woocommerce Tabs

Plugin:

Category and Product Woocommerce Tabs

Plugin Slug:
category-and-product-woocommerce-tabs

Vulnerability:
Local File Inclusion

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Chart Expert

Plugin:

Chart Expert

Plugin Slug:
chart-expert

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Coil Web Monetization

Plugin:

Coil Web Monetization

Plugin Slug:
coil-web-monetization

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Coon Google Maps

Plugin:

Coon Google Maps

Plugin Slug:
coon-google-maps

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

WP????????? for CPI

Plugin:

WP????????? for CPI

Plugin Slug:
cpi-wp-migration

Vulnerability:
Arbitrary File Upload

Patched in Version:
No Fix

Severity Score:
Critical


The vulnerability has not been patched. You should deactivate the plugin.

Crypto

Plugin:

Crypto

Plugin Slug:
crypto

Vulnerability:
Sensitive Data Exposure

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Crypto

Plugin:

Crypto

Plugin Slug:
crypto

Vulnerability:
Arbitrary File Deletion

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

CSV to SortTable

Plugin:

CSV to SortTable

Plugin Slug:
csv-to-sorttable

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

CTL Arcade Lite

Plugin:

CTL Arcade Lite

Plugin Slug:
ctl-arcade-lite

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Document Pro Elementor

Plugin:

Document Pro Elementor

Plugin Slug:
document-pro-elementor

Vulnerability:
Sensitive Data Exposure

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Download Panel (Biggiko Team)

Plugin:

Download Panel (Biggiko Team)

Plugin Slug:
download-panel

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Elastic Theme Editor

Plugin:

Elastic Theme Editor

Plugin Slug:
elastic-theme-editor

Vulnerability:
Arbitrary File Upload

Patched in Version:
No Fix

Severity Score:
Critical


The vulnerability has not been patched. You should deactivate the plugin.

Eventbee Ticketing Widget

Plugin:

Eventbee Ticketing Widget

Plugin Slug:
eventbee-ticketing-widget

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

everviz

Plugin:

everviz

Plugin Slug:
everviz

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Find Unused Images

Plugin:

Find Unused Images

Plugin Slug:
find-unused-images

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Five9 Live Chat

Plugin:

Five9 Live Chat

Plugin Slug:
five9

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Fleet Manager

Plugin:

Fleet Manager

Plugin Slug:
fleet

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Geopost

Plugin:

Geopost

Plugin Slug:
geopost

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Astra Security Suite

Plugin:

Astra Security Suite

Plugin Slug:
getastra

Vulnerability:
Arbitrary File Upload

Patched in Version:
No Fix

Severity Score:
Critical


The vulnerability has not been patched. You should deactivate the plugin.

GitHub Gist Shortcode

Plugin:

GitHub Gist Shortcode

Plugin Slug:
github-gist-shortcode

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Holiday class post calendar

Plugin:

Holiday class post calendar

Plugin Slug:
holiday-class-post-calendar

Vulnerability:
Remote Code Execution (RCE)

Patched in Version:
No Fix

Severity Score:
Critical


The vulnerability has not been patched. You should deactivate the plugin.

Jeba Cute forkit

Plugin:

Jeba Cute forkit

Plugin Slug:
jeba-cute-forkit

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Like-it

Plugin:

Like-it

Plugin Slug:
like-it

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Live Photos on WordPress

Plugin:

Live Photos on WordPress

Plugin Slug:
live-photos

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Local Syndication

Plugin:

Local Syndication

Plugin Slug:
local-syndication

Vulnerability:
Server Side Request Forgery (SSRF)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Make Email Customizer for WooCommerce

Plugin:

Make Email Customizer for WooCommerce

Plugin Slug:
make-email-customizer-for-woocommerce

Vulnerability:
Settings Change

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Mementor Core

Plugin:

Mementor Core

Plugin Slug:
mementor-core

Vulnerability:
Privilege Escalation

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Meta Display Block

Plugin:

Meta Display Block

Plugin Slug:
meta-display-block

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Multiple Roles per User

Plugin:

Multiple Roles per User

Plugin Slug:
multiple-roles-per-user

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

My Geo Posts Free

Plugin:

My Geo Posts Free

Plugin Slug:
my-geo-posts-free

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Ninja Countdown

Plugin:

Ninja Countdown

Plugin Slug:
ninja-countdown

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Nonaki

Plugin:

Nonaki

Plugin Slug:
nonaki-email-template-customizer

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Twitter Feed

Plugin:

Twitter Feed

Plugin Slug:
ot-twitter-feed

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Paypal Donation Shortcode

Plugin:

Paypal Donation Shortcode

Plugin Slug:
paypal-donation-shortcode

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Drag & Drop Builder

Plugin:

Drag & Drop Builder

Plugin Slug:
pie-forms-for-wp

Vulnerability:
Arbitrary File Upload

Patched in Version:
No Fix

Severity Score:
Critical


The vulnerability has not been patched. You should deactivate the plugin.

Precise Columns

Plugin:

Precise Columns

Plugin Slug:
precise-columns

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Preload Current Images

Plugin:

Preload Current Images

Plugin Slug:
preload-current-images

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Premmerce Wholesale Pricing for WooCommerce

Plugin:

Premmerce Wholesale Pricing for WooCommerce

Plugin Slug:
premmerce-woocommerce-wholesale-pricing

Vulnerability:
SQL Injection

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Progress Bar Blocks for Gutenberg

Plugin:

Progress Bar Blocks for Gutenberg

Plugin Slug:
progressmatify-blocks

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Project Honey Pot Spam Trap

Plugin:

Project Honey Pot Spam Trap

Plugin Slug:
project-honey-pot-spam-trap

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Quicq

Plugin:

Quicq

Plugin Slug:
quicq

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

RandomQuotr

Plugin:

RandomQuotr

Plugin Slug:
randomquotr

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Save as PDF Button

Plugin:

Save as PDF Button

Plugin Slug:
save-as-pdf

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Share to Google Classroom

Plugin:

Share to Google Classroom

Plugin Slug:
share-to-google-classroom

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Simple Donate

Plugin:

Simple Donate

Plugin Slug:
simple-donate

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Skip to Timestamp

Plugin:

Skip to Timestamp

Plugin Slug:
skip-to-timestamp

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Slippy Slider

Plugin:

Slippy Slider

Plugin Slug:
slippy-slider-responsive-touch-navigation-slider

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Squirrels Auto Inventory

Plugin:

Squirrels Auto Inventory

Plugin Slug:
squirrels-auto-inventory

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.
Plugin:

The Permalinks Cascade

Plugin Slug:
the-permalinks-cascade

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

The Total Book Project

Plugin Slug:
the-total-book-project

Vulnerability:
Insecure Direct Object References (IDOR)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Top Friends

Plugin:

Top Friends

Plugin Slug:
top-friends

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Cryptocurrency Payment Gateway for WooCommerce

Plugin:

Cryptocurrency Payment Gateway for WooCommerce

Plugin Slug:
triplea-cryptocurrency-payment-gateway-for-woocommerce

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

WP Twitter Auto Publish

Plugin:

WP Twitter Auto Publish

Plugin Slug:
twitter-auto-publish

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Ungapped Widgets

Plugin:

Ungapped Widgets

Plugin Slug:
ungapped-widgets

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

USB Qr Code Scanner For Woocommerce

Plugin:

USB Qr Code Scanner For Woocommerce

Plugin Slug:
usb-qr-code-scanner-for-woocommerce

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Wisly

Plugin:

Wisly

Plugin Slug:
wisly

Vulnerability:
Insecure Direct Object References (IDOR)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Woocommerce � Products By Custom Tax

Plugin:

Woocommerce � Products By Custom Tax

Plugin Slug:
woocommerce-products-by-custom-tax

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

WP Admin Microblog

Plugin:

WP Admin Microblog

Plugin Slug:
wp-admin-microblog

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

WP BBCode

Plugin:

WP BBCode

Plugin Slug:
wp-bbcode

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

WP Bootstrap Tabs

Plugin:

WP Bootstrap Tabs

Plugin Slug:
wp-bootstrap-tabs

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

WP Count Down Timer

Plugin:

WP Count Down Timer

Plugin Slug:
wp-count-down-timer

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.
Plugin:

WP Custom Admin Login Page Logo

Plugin Slug:
wp-custom-login-page-logo

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Flickr Show

Plugin:

Flickr Show

Plugin Slug:
wp-flickrshow

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

WordPress Content Flipper

Plugin:

WordPress Content Flipper

Plugin Slug:
wp-flipper

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

WP-Iconics

Plugin:

WP-Iconics

Plugin Slug:
wp-iconics

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

WP-OAuth

Plugin:

WP-OAuth

Plugin Slug:
wp-oauth

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

WP Headless CMS Framework

Plugin:

WP Headless CMS Framework

Plugin Slug:
wp-rest-headless

Vulnerability:
Bypass Vulnerability

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

WP-Walla

Plugin:

WP-Walla

Plugin Slug:
wp-walla

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

YSlider

Plugin:

YSlider

Plugin Slug:
yslider

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Page Builder: Pagelayer � Drag and Drop website builder

Plugin Slug:
pagelayer

Installations
400,000+

Vulnerability:
Insecure Direct Object References (IDOR)

Patched in Version:
2.0.6

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.0.6.

Blocksy Companion

Plugin Slug:
blocksy-companion

Installations
300,000+

Vulnerability:
Arbitrary File Upload

Patched in Version:
2.1.20

Severity Score:
Critical


The vulnerability has been patched, so you should update to version 2.1.20.

WP Go Maps (formerly WP Google Maps)

Plugin Slug:
wp-google-maps

Installations
300,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
9.0.48

Severity Score:
High


The vulnerability has been patched, so you should update to version 9.0.48.

Post Type Switcher

Plugin Slug:
post-type-switcher

Installations
200,000+

Vulnerability:
Insecure Direct Object References (IDOR)

Patched in Version:
4.0.1

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 4.0.1.

WP Migrate Lite � WordPress Migration Made Easy

Plugin Slug:
wp-migrate-db

Installations
200,000+

Vulnerability:
Server Side Request Forgery (SSRF)

Patched in Version:
2.7.7

Severity Score:
High


The vulnerability has been patched, so you should update to version 2.7.7.

AI Engine

Plugin Slug:
ai-engine

Installations
100,000+

Vulnerability:
Server Side Request Forgery (SSRF)

Patched in Version:
3.1.9

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 3.1.9.

AI Engine

Plugin Slug:
ai-engine

Installations
100,000+

Vulnerability:
PHP Object Injection

Patched in Version:
3.1.9

Severity Score:
High


The vulnerability has been patched, so you should update to version 3.1.9.

Element Pack Addons for Elementor

Plugin Slug:
bdthemes-element-pack-lite

Installations
100,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
8.3.5

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 8.3.5.
Plugin Slug:
envira-gallery-lite

Installations
100,000+

Vulnerability:
Broken Access Control

Patched in Version:
1.12.1

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.12.1.
Plugin Slug:
modula-best-grid-gallery

Installations
100,000+

Vulnerability:
Broken Access Control

Patched in Version:
2.12.29

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.12.29.

VK All in One Expansion Unit

Plugin Slug:
vk-all-in-one-expansion-unit

Installations
100,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
9.112.2

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 9.112.2.

Import any XML, CSV or Excel File to WordPress

Plugin Slug:
wp-all-import

Installations
100,000+

Vulnerability:
Remote Code Execution (RCE)

Patched in Version:
4.0.0

Severity Score:
Critical


The vulnerability has been patched, so you should update to version 4.0.0.

Qi Blocks

Plugin Slug:
qi-blocks

Installations
60,000+

Vulnerability:
Broken Access Control

Patched in Version:
1.4.4

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.4.4.

Booking Calendar

Plugin Slug:
booking

Installations
50,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
10.14.8

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 10.14.8.

Live sales notification for WooCommerce

Plugin Slug:
live-sales-notifications-for-woocommerce

Installations
50,000+

Vulnerability:
Broken Access Control

Patched in Version:
2.3.40

Severity Score:
High


The vulnerability has been patched, so you should update to version 2.3.40.

WP Duplicate Page

Plugin Slug:
wp-duplicate-page

Installations
50,000+

Vulnerability:
Broken Access Control

Patched in Version:
1.8

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.8.

RTMKit

Plugin:

RTMKit

Plugin Slug:
rometheme-for-elementor

Installations
40,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.6.6

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.6.6.

Data Tables Generator by Supsystic

Plugin Slug:
data-tables-generator-by-supsystic

Installations
20,000+

Vulnerability:
Arbitrary File Deletion

Patched in Version:
1.10.46

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.10.46.

Welcart e-Commerce

Plugin Slug:
usc-e-shop

Installations
20,000+

Vulnerability:
Broken Access Control

Patched in Version:
2.11.25

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.11.25.

WP Import � Ultimate CSV XML Importer for WordPress

Plugin Slug:
wp-ultimate-csv-importer

Installations
20,000+

Vulnerability:
Broken Access Control

Patched in Version:
7.33.1

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 7.33.1.

Asgaros Forum

Plugin Slug:
asgaros-forum

Installations
10,000+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
3.3.0

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 3.3.0.

Contact Form Email

Plugin Slug:
contact-form-to-email

Installations
10,000+

Vulnerability:
Broken Access Control

Patched in Version:
1.3.59

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.3.59.

Passster � Password Protect Pages and Content

Plugin Slug:
content-protector

Installations
10,000+

Vulnerability:
Sensitive Data Exposure

Patched in Version:
4.2.20

Severity Score:
High


The vulnerability has been patched, so you should update to version 4.2.20.

Checkout Files Upload for WooCommerce

Plugin Slug:
checkout-files-upload-woocommerce

Installations
7,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.2.2

Severity Score:
High


The vulnerability has been patched, so you should update to version 2.2.2.

Survey Maker

Plugin Slug:
survey-maker

Installations
6,000+

Vulnerability:
Broken Access Control

Patched in Version:
5.1.9.5

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 5.1.9.5.

Survey Maker

Plugin Slug:
survey-maker

Installations
6,000+

Vulnerability:
Broken Access Control

Patched in Version:
5.1.9.5

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 5.1.9.5.

Booking Calendar | Appointment Booking | Bookit

Plugin Slug:
bookit

Installations
5,000+

Vulnerability:
Broken Access Control

Patched in Version:
2.5.1

Severity Score:
High


The vulnerability has been patched, so you should update to version 2.5.1.

Team Members Showcase

Plugin Slug:
wps-team

Installations
4,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
3.5.0

Severity Score:
High


The vulnerability has been patched, so you should update to version 3.5.0.

CoSchedule

Plugin Slug:
coschedule-by-todaymade

Installations
3,000+

Vulnerability:
Broken Access Control

Patched in Version:
3.4.1

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 3.4.1.

Payment Plugins Braintree For WooCommerce

Plugin Slug:
woo-payment-gateway

Installations
3,000+

Vulnerability:
Broken Access Control

Patched in Version:
3.2.79

Severity Score:
High


The vulnerability has been patched, so you should update to version 3.2.79.

WP Plugin Manager � Deactivate plugins per page

Plugin Slug:
wp-plugin-manager

Installations
3,000+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
1.4.8

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.4.8.

MembershipWorks � Membership, Events & Directory

Plugin Slug:
memberfindme

Installations
2,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
6.15

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 6.15.

Comment Edit Core � Simple Comment Editing

Plugin Slug:
simple-comment-editing

Installations
2,000+

Vulnerability:
Sensitive Data Exposure

Patched in Version:
3.2.0

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 3.2.0.

School Management System � WPSchoolPress

Plugin Slug:
wpschoolpress

Installations
2,000+

Vulnerability:
SQL Injection

Patched in Version:
2.2.24

Severity Score:
High


The vulnerability has been patched, so you should update to version 2.2.24.

Appointment Booking Calendar

Plugin Slug:
appointment-booking-calendar

Installations
1,000+

Vulnerability:
Broken Access Control

Patched in Version:
1.3.96

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.3.96.

Creta Testimonial Showcase

Plugin Slug:
creta-testimonial-showcase

Installations
1,000+

Vulnerability:
Local File Inclusion

Patched in Version:
1.2.4

Severity Score:
High


The vulnerability has been patched, so you should update to version 1.2.4.

TNC Toolbox: Web Performance

Plugin Slug:
tnc-toolbox

Installations
1,000+

Vulnerability:
Privilege Escalation

Patched in Version:
2.0.0

Severity Score:
Critical


The vulnerability has been patched, so you should update to version 2.0.0.

Thumbnail Slider With Lightbox

Plugin Slug:
wp-responsive-slider-with-lightbox

Installations
800+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.0.22

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.0.22.

Theater for WordPress

Plugin Slug:
theatre

Installations
600+

Vulnerability:
Broken Access Control

Patched in Version:
0.19

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 0.19.

SNORDIAN’s H5PxAPIkatchu

Plugin Slug:
h5pxapikatchu

Installations
500+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
0.4.18

Severity Score:
High


The vulnerability has been patched, so you should update to version 0.4.18.

WP Dropzone

Plugin Slug:
wp-dropzone

Installations
100+

Vulnerability:
Arbitrary File Upload

Patched in Version:
1.1.1

Severity Score:
Critical


The vulnerability has been patched, so you should update to version 1.1.1.

Wishlist and Save for later for Woocommerce

Plugin Slug:
aco-wishlist-for-woocommerce

Installations
80+

Vulnerability:
Insecure Direct Object References (IDOR)

Patched in Version:
1.1.23

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.1.23.

Magazine Companion

Plugin Slug:
bnm-blocks

Installations
60+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.2.4

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.2.4.

0 Day Analytics

Plugin Slug:
0-day-analytics

Installations
30+

Vulnerability:
SQL Injection

Patched in Version:
4.1.0

Severity Score:
High


The vulnerability has been patched, so you should update to version 4.1.0.

Easy Email Subscription

Plugin Slug:
email-subscription-with-secure-captcha

Installations
30+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.3.1

Severity Score:
High


The vulnerability has been patched, so you should update to version 1.3.1.

Gravity Forms

Plugin:

Gravity Forms

Plugin Slug:
gravityforms

Vulnerability:
Arbitrary File Upload

Patched in Version:
2.9.22

Severity Score:
Critical


The vulnerability has been patched, so you should update to version 2.9.22.

WordPress Themes � 0 Patched / 1 Unpatched

Angel

Theme:

Angel

Theme Slug:
angel

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should switch themes.

Related articles

Wait! Get exclusive hosting insights

Subscribe to our newsletter and stay ahead of the competition with expert advice from our hosting pros.

Loading form…