Line illustration showing a black application window on a blue gradient background overlaid with a large exclamation point alert icon and three bugs.

WordPress Vulnerability Report � November 26, 2025

In this report, 164 vulnerabilities have been publicly disclosed. Security patches for 89 of these plugins and themes are now available. Please run these updates as soon as possible. If you’re a Solid Security Pro user, the version management tool may have already warned you and updated these plugins, depending on your settings.

Currently, 75 plugin and theme vulnerabilities remain unpatched. If you’re a Solid Security Pro user, those vulnerabilities are already protected by the Solid Security firewall. Virtual patches from Patchstack will be applied when a vulnerability is considered high or medium risk. If no patch is forthcoming from the vendor or the vulnerable software has been marked “closed” and dropped from the official WordPress repositories, you should deactivate it soon and look for alternative solutions.

WordPress Core

WordPress 6.8.3 was released on September 30, 2025. This is a security release that features two fixes. As this is a security release, we recommend updating your sites immediately. For more information on WordPress 6.8.3, please visit the version page on the HelpHub site.

WordPress 6.9 Release Candidate 3 (RC3) is now available for testing. This version is still under development and should not be installed on production or mission-critical websites. Instead, test RC2 on a staging or test site. You can read more on the WordPress Core blog for details on how to download and test this release.

The final release of WordPress 6.9 is scheduled for December 2, 2025. For updates, testing information, and release announcements, visit the Make WordPress Core blog.

WordPress Plugins � 89 Patched / 74 Unpatched

Image Hover Effects Ultimate

Plugin Slug:
image-hover-effects-ultimate

Installations
20,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Enable SVG, WebP, and ICO Upload

Plugin Slug:
enable-svg-webp-ico-upload

Installations
10,000+

Vulnerability:
Arbitrary File Upload

Patched in Version:
No Fix

Severity Score:
Critical


The vulnerability has not been patched. You should deactivate the plugin.

Enable SVG, WebP, and ICO Upload

Plugin Slug:
enable-svg-webp-ico-upload

Installations
10,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.
Plugin Slug:
gallery-with-thumbnail-slider

Installations
3,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

?????

Plugin:

?????

Plugin Slug:
keydatas

Installations
2,000+

Vulnerability:
Arbitrary File Download

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Simple User Import Export

Plugin:

Simple User Import Export

Plugin Slug:
a3-user-importer

Vulnerability:
CSV Injection

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Ace Post Type Builder

Plugin:

Ace Post Type Builder

Plugin Slug:
ace-post-type-builder

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

ACF Flexible Layouts Manager

Plugin:

ACF Flexible Layouts Manager

Plugin Slug:
acf-flexible-layouts-manager

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

OrderConvo

Plugin:

OrderConvo

Plugin Slug:
admin-and-client-message-after-order-for-woocommerce

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

OrderConvo

Plugin:

OrderConvo

Plugin Slug:
admin-and-client-message-after-order-for-woocommerce

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

ArtiBot

Plugin:

ArtiBot

Plugin Slug:
artibot

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Attention Bar

Plugin:

Attention Bar

Plugin Slug:
attention-bar

Vulnerability:
SQL Injection

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

AudioTube

Plugin:

AudioTube

Plugin Slug:
audiotube

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

AuthorSure

Plugin:

AuthorSure

Plugin Slug:
authorsure

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Autochat Automatic Conversation

Plugin:

Autochat Automatic Conversation

Plugin Slug:
auyautochat-for-wp

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

BigBuy Dropshipping Connector for WooCommerce

Plugin:

BigBuy Dropshipping Connector for WooCommerce

Plugin Slug:
bigbuy-wc-dropshipping-connector

Vulnerability:
Sensitive Data Exposure

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Bookme � Free Online Appointment Booking and Scheduling Plugin

Plugin:

Bookme � Free Online Appointment Booking and Scheduling Plugin

Plugin Slug:
bookme-free-appointment-booking-system

Vulnerability:
SQL Injection

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Restrictions for BuddyPress

Plugin:

Restrictions for BuddyPress

Plugin Slug:
bp-restrict

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

BrightTALK WordPress Shortcode

Plugin:

BrightTALK WordPress Shortcode

Plugin Slug:
brighttalk-wp-shortcode

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Bulma Shortcodes

Plugin:

Bulma Shortcodes

Plugin Slug:
bulma-shortcodes

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Category and Product Woocommerce Tabs

Plugin:

Category and Product Woocommerce Tabs

Plugin Slug:
category-and-product-woocommerce-tabs

Vulnerability:
Local File Inclusion

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Chamber Dashboard Business Directory

Plugin:

Chamber Dashboard Business Directory

Plugin Slug:
chamber-dashboard-business-directory

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Coil Web Monetization

Plugin:

Coil Web Monetization

Plugin Slug:
coil-web-monetization

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

CSV to SortTable

Plugin:

CSV to SortTable

Plugin Slug:
csv-to-sorttable

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Custom Post Type

Plugin:

Custom Post Type

Plugin Slug:
custom-post-type

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Display Pages Shortcode

Plugin:

Display Pages Shortcode

Plugin Slug:
display-pages-shortcode

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Download Panel (Biggiko Team)

Plugin:

Download Panel (Biggiko Team)

Plugin Slug:
download-panel

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

YouTube Subscribe

Plugin:

YouTube Subscribe

Plugin Slug:
easy-youtube-subscribe

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

everviz

Plugin:

everviz

Plugin Slug:
everviz

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Flo Forms

Plugin:

Flo Forms

Plugin Slug:
flo-forms

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

HotelRunner Booking Widget

Plugin:

HotelRunner Booking Widget

Plugin Slug:
hotelrunner

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Inline frame � Iframe

Plugin:

Inline frame � Iframe

Plugin Slug:
inline-frame-iframe

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Islamic Phrases

Plugin:

Islamic Phrases

Plugin Slug:
islamic-phrases

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Just Highlight

Plugin:

Just Highlight

Plugin Slug:
just-highlight

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

LightGallery WP

Plugin:

LightGallery WP

Plugin Slug:
lightgallerywp

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Like-it

Plugin:

Like-it

Plugin Slug:
like-it

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Local Syndication

Plugin:

Local Syndication

Plugin Slug:
local-syndication

Vulnerability:
Server Side Request Forgery (SSRF)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Locker Content

Plugin Slug:
locker-content

Vulnerability:
Sensitive Data Exposure

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Conditionnal Maintenance Mode for WordPress

Plugin:

Conditionnal Maintenance Mode for WordPress

Plugin Slug:
maintenance-mode-based-on-user-roles

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Make Email Customizer for WooCommerce

Plugin:

Make Email Customizer for WooCommerce

Plugin Slug:
make-email-customizer-for-woocommerce

Vulnerability:
Settings Change

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Meta Display Block

Plugin:

Meta Display Block

Plugin Slug:
meta-display-block

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Mstore Mobile App

Plugin:

Mstore Mobile App

Plugin Slug:
mstoreapp-mobile-app

Vulnerability:
Privilege Escalation

Patched in Version:
No Fix

Severity Score:
Critical


The vulnerability has not been patched. You should deactivate the plugin.

Multiple Roles per User

Plugin:

Multiple Roles per User

Plugin Slug:
multiple-roles-per-user

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Frontend File Manager

Plugin:

Frontend File Manager

Plugin Slug:
nmedia-user-file-uploader

Vulnerability:
Insecure Direct Object References (IDOR)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Peer Publish

Plugin:

Peer Publish

Plugin Slug:
peer-publish

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Drag & Drop Builder

Plugin:

Drag & Drop Builder

Plugin Slug:
pie-forms-for-wp

Vulnerability:
Arbitrary File Upload

Patched in Version:
No Fix

Severity Score:
Critical


The vulnerability has not been patched. You should deactivate the plugin.

Pollcaster Shortcode Plugin

Plugin:

Pollcaster Shortcode Plugin

Plugin Slug:
pollcaster-shortcode

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Premmerce Wholesale Pricing for WooCommerce

Plugin:

Premmerce Wholesale Pricing for WooCommerce

Plugin Slug:
premmerce-woocommerce-wholesale-pricing

Vulnerability:
SQL Injection

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Project Honey Pot Spam Trap

Plugin:

Project Honey Pot Spam Trap

Plugin Slug:
project-honey-pot-spam-trap

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

ProjectList

Plugin:

ProjectList

Plugin Slug:
projectlist

Vulnerability:
SQL Injection

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Realty Portal

Plugin:

Realty Portal

Plugin Slug:
realty-portal

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Refund Request for WooCommerce

Plugin:

Refund Request for WooCommerce

Plugin Slug:
refund-request-for-woocommerce

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Shortcodes Bootstrap

Plugin:

Shortcodes Bootstrap

Plugin Slug:
shortcodes-bootstrap

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Social Images Widget

Plugin:

Social Images Widget

Plugin Slug:
social-images-widget

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Stock Tools

Plugin:

Stock Tools

Plugin Slug:
stock-tools

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Surbma | MiniCRM Shortcode

Plugin:

Surbma | MiniCRM Shortcode

Plugin Slug:
surbma-minicrm-shortcode

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.
Plugin:

The Permalinks Cascade

Plugin Slug:
the-permalinks-cascade

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Tips Shortcode

Plugin:

Tips Shortcode

Plugin Slug:
tips-shortcode

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Cryptocurrency (Token), Launchpad (Presale), ICO & IDO, Airdrop by TokenICO

Plugin:

Cryptocurrency (Token), Launchpad (Presale), ICO & IDO, Airdrop by TokenICO

Plugin Slug:
tokenico-cryptocurrency-token-launchpad-presale-ico-ido-airdrop

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Cryptocurrency (Token), Launchpad (Presale), ICO & IDO, Airdrop by TokenICO

Plugin:

Cryptocurrency (Token), Launchpad (Presale), ICO & IDO, Airdrop by TokenICO

Plugin Slug:
tokenico-cryptocurrency-token-launchpad-presale-ico-ido-airdrop

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Top Friends

Plugin:

Top Friends

Plugin Slug:
top-friends

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Cryptocurrency Payment Gateway for WooCommerce

Plugin:

Cryptocurrency Payment Gateway for WooCommerce

Plugin Slug:
triplea-cryptocurrency-payment-gateway-for-woocommerce

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

WP Twitter Auto Publish

Plugin:

WP Twitter Auto Publish

Plugin Slug:
twitter-auto-publish

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Padlet Shortcode

Plugin:

Padlet Shortcode

Plugin Slug:
wallwisher-shortcode

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Mstore Mobile App

Plugin:

Mstore Mobile App

Plugin Slug:
woo-mstoreapp-mobile-app

Vulnerability:
Privilege Escalation

Patched in Version:
No Fix

Severity Score:
Critical


The vulnerability has not been patched. You should deactivate the plugin.

WP Admin Microblog

Plugin:

WP Admin Microblog

Plugin Slug:
wp-admin-microblog

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.
Plugin:

WP AUDIO GALLERY

Plugin Slug:
wp-audio-gallery

Vulnerability:
Arbitrary File Deletion

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

WP Company Info

Plugin:

WP Company Info

Plugin Slug:
wp-company-info

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Shortcode for Google Street View

Plugin:

Shortcode for Google Street View

Plugin Slug:
wp-google-street-view-shortcode

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

WPSite Shortcode

Plugin:

WPSite Shortcode

Plugin Slug:
wpsite-shortcode

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Zweb Social Mobile

Plugin:

Zweb Social Mobile

Plugin Slug:
zweb-social-mobile

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Code Snippets

Plugin Slug:
code-snippets

Installations
1,000,000+

Vulnerability:
Remote Code Execution (RCE)

Patched in Version:
3.9.2

Severity Score:
High


The vulnerability has been patched, so you should update to version 3.9.2.

W3 Total Cache

Plugin Slug:
w3-total-cache

Installations
1,000,000+

Vulnerability:
Remote Code Execution (RCE)

Patched in Version:
2.8.13

Severity Score:
Critical


The vulnerability has been patched, so you should update to version 2.8.13.

YITH WooCommerce Wishlist

Plugin Slug:
yith-woocommerce-wishlist

Installations
500,000+

Vulnerability:
Broken Access Control

Patched in Version:
4.10.1

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 4.10.1.

YITH WooCommerce Wishlist

Plugin Slug:
yith-woocommerce-wishlist

Installations
500,000+

Vulnerability:
Insecure Direct Object References (IDOR)

Patched in Version:
4.10.1

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 4.10.1.

SiteSEO � SEO Simplified

Plugin Slug:
siteseo

Installations
400,000+

Vulnerability:
Insecure Direct Object References (IDOR)

Patched in Version:
1.3.3

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.3.3.

SiteSEO � SEO Simplified

Plugin Slug:
siteseo

Installations
400,000+

Vulnerability:
Broken Authentication

Patched in Version:
1.3.3

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.3.3.

WP Go Maps (formerly WP Google Maps)

Plugin Slug:
wp-google-maps

Installations
300,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
9.0.48

Severity Score:
High


The vulnerability has been patched, so you should update to version 9.0.48.

Post Type Switcher

Plugin Slug:
post-type-switcher

Installations
200,000+

Vulnerability:
Insecure Direct Object References (IDOR)

Patched in Version:
4.0.1

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 4.0.1.

WP Migrate Lite � WordPress Migration Made Easy

Plugin Slug:
wp-migrate-db

Installations
200,000+

Vulnerability:
Server Side Request Forgery (SSRF)

Patched in Version:
2.7.7

Severity Score:
High


The vulnerability has been patched, so you should update to version 2.7.7.

AI Engine

Plugin Slug:
ai-engine

Installations
100,000+

Vulnerability:
Server Side Request Forgery (SSRF)

Patched in Version:
3.1.9

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 3.1.9.

Element Pack Addons for Elementor

Plugin Slug:
bdthemes-element-pack-lite

Installations
100,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
8.3.5

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 8.3.5.
Plugin Slug:
responsive-lightbox

Installations
100,000+

Vulnerability:
Server Side Request Forgery (SSRF)

Patched in Version:
2.5.4

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.5.4.

VK All in One Expansion Unit

Plugin Slug:
vk-all-in-one-expansion-unit

Installations
100,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
9.112.2

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 9.112.2.

HT Mega � Absolute Addons For Elementor

Plugin Slug:
ht-mega-for-elementor

Installations
80,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
3.0.1

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 3.0.1.

LearnPress � WordPress LMS Plugin

Plugin Slug:
learnpress

Installations
80,000+

Vulnerability:
Broken Access Control

Patched in Version:
4.3.0

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 4.3.0.

Live sales notification for WooCommerce

Plugin Slug:
live-sales-notifications-for-woocommerce

Installations
60,000+

Vulnerability:
Broken Access Control

Patched in Version:
2.3.40

Severity Score:
High


The vulnerability has been patched, so you should update to version 2.3.40.

Blog2Social: Social Media Auto Post & Scheduler

Plugin Slug:
blog2social

Installations
50,000+

Vulnerability:
Broken Access Control

Patched in Version:
8.7.1

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 8.7.1.

WP Duplicate Page

Plugin Slug:
wp-duplicate-page

Installations
50,000+

Vulnerability:
Broken Access Control

Patched in Version:
1.8

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.8.

OneClick Chat to Order

Plugin Slug:
oneclick-whatsapp-order

Installations
40,000+

Vulnerability:
Sensitive Data Exposure

Patched in Version:
1.0.9

Severity Score:
High


The vulnerability has been patched, so you should update to version 1.0.9.

RTMKit

Plugin:

RTMKit

Plugin Slug:
rometheme-for-elementor

Installations
40,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.6.6

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.6.6.

Custom Order Numbers for WooCommerce

Plugin Slug:
custom-order-numbers-for-woocommerce

Installations
20,000+

Vulnerability:
Broken Access Control

Patched in Version:
1.11.1

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.11.1.

New User Approve

Plugin Slug:
new-user-approve

Installations
20,000+

Vulnerability:
Sensitive Data Exposure

Patched in Version:
3.1.0

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 3.1.0.

Quiz Maker

Plugin Slug:
quiz-maker

Installations
20,000+

Vulnerability:
Sensitive Data Exposure

Patched in Version:
6.7.0.81

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 6.7.0.81.

PPOM � Product Addons & Custom Fields for WooCommerce

Plugin Slug:
woocommerce-product-addon

Installations
20,000+

Vulnerability:
Broken Access Control

Patched in Version:
33.0.17

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 33.0.17.

WP Import � Ultimate CSV XML Importer for WordPress

Plugin Slug:
wp-ultimate-csv-importer

Installations
20,000+

Vulnerability:
PHP Object Injection

Patched in Version:
7.34

Severity Score:
High


The vulnerability has been patched, so you should update to version 7.34.

Checkout Files Upload for WooCommerce

Plugin Slug:
checkout-files-upload-woocommerce

Installations
7,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.2.2

Severity Score:
High


The vulnerability has been patched, so you should update to version 2.2.2.

Return Refund and Exchange For WooCommerce

Plugin Slug:
woo-refund-and-exchange-lite

Installations
5,000+

Vulnerability:
Insecure Direct Object References (IDOR)

Patched in Version:
4.5.6

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 4.5.6.

Team Members Showcase

Plugin Slug:
wps-team

Installations
4,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
3.5.0

Severity Score:
High


The vulnerability has been patched, so you should update to version 3.5.0.

Property Hive

Plugin Slug:
propertyhive

Installations
3,000+

Vulnerability:
Broken Access Control

Patched in Version:
2.1.13

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.1.13.

WP Directory Kit

Plugin Slug:
wpdirectorykit

Installations
3,000+

Vulnerability:
SQL Injection

Patched in Version:
1.4.4

Severity Score:
Critical


The vulnerability has been patched, so you should update to version 1.4.4.

Accordion Slider

Plugin Slug:
accordion-slider

Installations
2,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.9.14

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.9.14.

Extensions for Leaflet Map

Plugin Slug:
extensions-leaflet-map

Installations
2,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
4.9

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 4.9.

Vitepos � Point of Sale (POS) for WooCommerce

Plugin Slug:
vitepos-lite

Installations
2,000+

Vulnerability:
Arbitrary File Upload

Patched in Version:
3.3.1

Severity Score:
Critical


The vulnerability has been patched, so you should update to version 3.3.1.

Appointment Booking Calendar

Plugin Slug:
appointment-booking-calendar

Installations
1,000+

Vulnerability:
Broken Access Control

Patched in Version:
1.3.97

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.3.97.

CBX Bookmark & Favorite

Plugin Slug:
cbxwpbookmark

Installations
1,000+

Vulnerability:
Broken Access Control

Patched in Version:
2.0.2

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.0.2.

CP Contact Form with PayPal

Plugin Slug:
cp-contact-form-with-paypal

Installations
1,000+

Vulnerability:
Broken Access Control

Patched in Version:
1.3.57

Severity Score:
High


The vulnerability has been patched, so you should update to version 1.3.57.

GSheetConnector For Ninja Forms

Plugin Slug:
gsheetconnector-ninja-forms

Installations
1,000+

Vulnerability:
Broken Access Control

Patched in Version:
2.0.2

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.0.2.

Tainacan

Plugin:

Tainacan

Plugin Slug:
tainacan

Installations
1,000+

Vulnerability:
Sensitive Data Exposure

Patched in Version:
1.0.1

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.0.1.

Tainacan

Plugin:

Tainacan

Plugin Slug:
tainacan

Installations
1,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.0.1

Severity Score:
High


The vulnerability has been patched, so you should update to version 1.0.1.
Plugin Slug:
tp-woocommerce-product-gallery

Installations
1,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.0.0

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.0.0.

Better Chat Support for Messenger

Plugin Slug:
better-chat-support

Installations
800+

Vulnerability:
Broken Access Control

Patched in Version:
1.2.19

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.2.19.

Booking Calendar Contact Form

Plugin Slug:
booking-calendar-contact-form

Installations
600+

Vulnerability:
Broken Access Control

Patched in Version:
1.2.61

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.2.61.

Show Variations as Single Products Woocommerce

Plugin Slug:
woo-show-single-variations-shop-category

Installations
500+

Vulnerability:
Broken Access Control

Patched in Version:
3.0

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 3.0.

Checkbox

Plugin:

Checkbox

Plugin Slug:
checkbox

Installations
400+

Vulnerability:
Broken Access Control

Patched in Version:
2.8.11

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.8.11.

ELEX WordPress HelpDesk & Customer Ticketing System

Plugin Slug:
elex-helpdesk-customer-support-ticket-system

Installations
300+

Vulnerability:
Broken Access Control

Patched in Version:
3.3.2

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 3.3.2.

ELEX WordPress HelpDesk & Customer Ticketing System

Plugin Slug:
elex-helpdesk-customer-support-ticket-system

Installations
300+

Vulnerability:
Insecure Direct Object References (IDOR)

Patched in Version:
3.3.0

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 3.3.0.

ELEX WordPress HelpDesk & Customer Ticketing System

Plugin Slug:
elex-helpdesk-customer-support-ticket-system

Installations
300+

Vulnerability:
Arbitrary File Upload

Patched in Version:
3.3.2

Severity Score:
Critical


The vulnerability has been patched, so you should update to version 3.3.2.

ELEX WordPress HelpDesk & Customer Ticketing System

Plugin Slug:
elex-helpdesk-customer-support-ticket-system

Installations
300+

Vulnerability:
Broken Access Control

Patched in Version:
3.3.1

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 3.3.1.

Simple User Registration

Plugin Slug:
wp-registration

Installations
300+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
6.7

Severity Score:
High


The vulnerability has been patched, so you should update to version 6.7.

WP Delete Post Copies

Plugin Slug:
etruel-del-post-copies

Installations
200+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
6.0.3

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 6.0.3.

WP Login and Register using JWT

Plugin Slug:
login-register-using-jwt

Installations
200+

Vulnerability:
Broken Access Control

Patched in Version:
3.1.0

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 3.1.0.

Time Slot � Booking and Appointment Scheduling

Plugin Slug:
timeslot

Installations
200+

Vulnerability:
Broken Access Control

Patched in Version:
1.4.8

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.4.8.

EchBay Admin Security

Plugin Slug:
echbay-admin-security

Installations
100+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.3.1

Severity Score:
High


The vulnerability has been patched, so you should update to version 1.3.1.

WP Dropzone

Plugin Slug:
wp-dropzone

Installations
100+

Vulnerability:
Arbitrary File Upload

Patched in Version:
1.1.1

Severity Score:
Critical


The vulnerability has been patched, so you should update to version 1.1.1.

Affiliate AI Lite

Plugin Slug:
affiliate-ai-lite

Installations
40+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.0.2

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.0.2.

WSChat � WordPress Live Chat

Plugin Slug:
wschat-live-chat

Installations
40+

Vulnerability:
Broken Access Control

Patched in Version:
3.1.7

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 3.1.7.

Community Events

Plugin Slug:
community-events

Installations
30+

Vulnerability:
SQL Injection

Patched in Version:
1.5.5

Severity Score:
Critical


The vulnerability has been patched, so you should update to version 1.5.5.

Pet-Manager � Petfinder

Plugin Slug:
tier-management-petfinder

Installations
20+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
3.6.2

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 3.6.2.

WPBookit

Plugin:

WPBookit

Plugin Slug:
wpbookit

Installations
20+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.0.7

Severity Score:
High


The vulnerability has been patched, so you should update to version 1.0.7.

atec Duplicate Page & Post

Plugin Slug:
atec-duplicate-page-post

Vulnerability:
Broken Access Control

Patched in Version:
1.2.21

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.2.21.

Gravity Forms

Plugin:

Gravity Forms

Plugin Slug:
gravityforms

Vulnerability:
Arbitrary File Upload

Patched in Version:
2.9.22

Severity Score:
Critical


The vulnerability has been patched, so you should update to version 2.9.22.

Zegen Core

Plugin:

Zegen Core

Plugin Slug:
zegen-core

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
2.0.2

Severity Score:
Critical


The vulnerability has been patched, so you should update to version 2.0.2.

WordPress Themes � 0 Patched / 1 Unpatched

OnePress

Theme Slug:
onepress

Downloads
2,469,341

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should switch themes.

Related articles

Wait! Get exclusive hosting insights

Subscribe to our newsletter and stay ahead of the competition with expert advice from our hosting pros.

Loading form…