Line illustration showing a black application window on a dark black to purple gradient background overlaid with a large exclamation point alert icon and three bugs.

WordPress Vulnerability Report � October 15, 2025

In this report, 64 vulnerabilities have been publicly disclosed. Security patches for 46 of these plugins and themes are now available. Please run these updates as soon as possible. If you’re a Solid Security Pro user, the version management tool may have already warned you and updated these plugins, depending on your settings.

Currently, 18 plugin and theme vulnerabilities remain unpatched. If you’re a Solid Security Pro user, those vulnerabilities are already protected by the Solid Security firewall. Virtual patches from Patchstack will be applied when a vulnerability is considered high or medium risk. If no patch is forthcoming from the vendor or the vulnerable software has been marked “closed” and dropped from the official WordPress repositories, you should deactivate it soon and look for alternative solutions.

WordPress Core

WordPress 6.8.3 was released on September 30, 2025! This is a security release that features two fixes. As this is a security release, we recommend updating your sites immediately. For more information on WordPress 6.8.3, please visit the version page on the HelpHub site.

WordPress Plugins � 43 Patched / 18 Unpatched

WP Gmail SMTP

Plugin Slug:
wp-gmail-smtp

Installations
1,000+

Vulnerability:
Sensitive Data Exposure

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Block Country

Plugin Slug:
block-country

Installations
70+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Simple Stripe

Plugin Slug:
simple-stripe

Installations
70+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Slick Google Map

Plugin Slug:
slick-google-map

Installations
60+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Stock History & Reports Manager for WooCommerce

Plugin Slug:
stock-snapshot-for-woocommerce

Installations
60+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

wpNamedUsers

Plugin Slug:
wpnamedusers

Installations
60+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Code Quality Control Tool

Plugin:

Code Quality Control Tool

Plugin Slug:
code-quality-control-tool

Vulnerability:
Sensitive Data Exposure

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Course Redirects for Learndash

Plugin:

Course Redirects for Learndash

Plugin Slug:
course-redirects-for-learndash

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Custom 404 Pro

Plugin:

Custom 404 Pro

Plugin Slug:
custom-404-pro

Vulnerability:
SQL Injection

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Easy Plugin Stats

Plugin:

Easy Plugin Stats

Plugin Slug:
easy-plugin-stats

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Find Me On

Plugin:

Find Me On

Plugin Slug:
find-me-on

Vulnerability:
SQL Injection

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Page Blocks

Plugin:

Page Blocks

Plugin Slug:
page-blocks

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

TwentyFourth WP Scraper

Plugin:

TwentyFourth WP Scraper

Plugin Slug:
twentyfourth-wp-scraper

Vulnerability:
Server Side Request Forgery (SSRF)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

WooCommerce Designer Pro

Plugin:

WooCommerce Designer Pro

Plugin Slug:
wc-designer-pro

Vulnerability:
Arbitrary File Deletion

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

WidgetPack Comment System

Plugin:

WidgetPack Comment System

Plugin Slug:
widgetpack-comment-system

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

WP Easy Toggles

Plugin:

WP Easy Toggles

Plugin Slug:
wp-easy-toggles

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

WordPress Live Webcam Widget & Shortcode

Plugin:

WordPress Live Webcam Widget & Shortcode

Plugin Slug:
wp-webcam-widget-shortcode

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Enable Media Replace

Plugin Slug:
enable-media-replace

Installations
600,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
4.1.7

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 4.1.7.

WP Reset

Plugin:

WP Reset

Plugin Slug:
wp-reset

Installations
400,000+

Vulnerability:
Sensitive Data Exposure

Patched in Version:
2.06

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.06.

Blocksy Companion

Plugin Slug:
blocksy-companion

Installations
300,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.1.15

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.1.15.

WP Go Maps (formerly WP Google Maps)

Plugin Slug:
wp-google-maps

Installations
300,000+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
9.0.47

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 9.0.47.

Colibri Page Builder

Plugin Slug:
colibri-page-builder

Installations
100,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.0.335

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.0.335.
Plugin Slug:
responsive-lightbox

Installations
100,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.5.3

Severity Score:
High


The vulnerability has been patched, so you should update to version 2.5.3.

WPC Smart Wishlist for WooCommerce

Plugin Slug:
woo-smart-wishlist

Installations
100,000+

Vulnerability:
Insecure Direct Object References (IDOR)

Patched in Version:
5.0.4

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 5.0.4.
Plugin Slug:
featured-image-from-url

Installations
80,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
5.2.8

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 5.2.8.

All In One Login � WP Admin Login Page Security and Customization with Google reCAPTCHA, Social Login, Limit Login Attempt, 2FA, and more.

Plugin Slug:
change-wp-admin-login

Installations
70,000+

Vulnerability:
Bypass Vulnerability

Patched in Version:
2.0.9

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.0.9.

Search & Filter

Plugin Slug:
search-filter

Installations
50,000+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
1.2.18

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.2.18.

Welcart e-Commerce

Plugin Slug:
usc-e-shop

Installations
20,000+

Vulnerability:
SQL Injection

Patched in Version:
2.11.22

Severity Score:
High


The vulnerability has been patched, so you should update to version 2.11.22.

Web Accessibility by accessiBe

Plugin Slug:
accessibe

Installations
10,000+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
2.11

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.11.

Motors � Car Dealership & Classified Listings Plugin

Plugin Slug:
motors-car-dealership-classified-listings

Installations
10,000+

Vulnerability:
Arbitrary File Deletion

Patched in Version:
1.4.90

Severity Score:
High


The vulnerability has been patched, so you should update to version 1.4.90.

NEX-Forms � Ultimate Forms Plugin for WordPress

Plugin Slug:
nex-forms-express-wp-form-builder

Installations
9,000+

Vulnerability:
SQL Injection

Patched in Version:
9.1.7

Severity Score:
High


The vulnerability has been patched, so you should update to version 9.1.7.

Error Log Viewer by BestWebSoft

Plugin Slug:
error-log-viewer

Installations
6,000+

Vulnerability:
Arbitrary File Download

Patched in Version:
1.1.7

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.1.7.

Survey Maker

Plugin Slug:
survey-maker

Installations
6,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
5.1.8.9

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 5.1.8.9.

Chartify � WordPress Chart Plugin

Plugin Slug:
chart-builder

Installations
4,000+

Vulnerability:
Broken Access Control

Patched in Version:
3.6.0

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 3.6.0.
Plugin Slug:
cookie-notice-consent

Installations
1,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.6.6

Severity Score:
High


The vulnerability has been patched, so you should update to version 1.6.6.

GSheetConnector For Gravity Forms

Plugin Slug:
gsheetconnector-gravity-forms

Installations
1,000+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
1.3.24

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.3.24.

GSheetConnector For Gravity Forms

Plugin Slug:
gsheetconnector-gravity-forms

Installations
1,000+

Vulnerability:
Broken Access Control

Patched in Version:
1.3.28

Severity Score:
High


The vulnerability has been patched, so you should update to version 1.3.28.

My auctions allegro

Plugin Slug:
my-auctions-allegro-free-edition

Installations
500+

Vulnerability:
SQL Injection

Patched in Version:
3.6.32

Severity Score:
High


The vulnerability has been patched, so you should update to version 3.6.32.

Draft List

Plugin Slug:
simple-draft-list

Installations
50+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.6.2

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.6.2.

Community Events

Plugin Slug:
community-events

Installations
40+

Vulnerability:
SQL Injection

Patched in Version:
1.5.2

Severity Score:
Critical


The vulnerability has been patched, so you should update to version 1.5.2.

Lisfinity Core

Plugin:

Lisfinity Core

Plugin Slug:
lisfinity-core

Vulnerability:
Privilege Escalation

Patched in Version:
1.5.0

Severity Score:
High


The vulnerability has been patched, so you should update to version 1.5.0.

Ovatheme Events Manager

Plugin:

Ovatheme Events Manager

Plugin Slug:
ova-events-manager

Vulnerability:
Arbitrary File Upload

Patched in Version:
1.8.6

Severity Score:
Critical


The vulnerability has been patched, so you should update to version 1.8.6.

Slider Revolution

Plugin:

Slider Revolution

Plugin Slug:
revslider

Vulnerability:
Broken Access Control

Patched in Version:
6.7.38

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 6.7.38.

Service Finder Booking

Plugin:

Service Finder Booking

Plugin Slug:
sf-booking

Vulnerability:
Broken Authentication

Patched in Version:
6.1

Severity Score:
Critical


The vulnerability has been patched, so you should update to version 6.1.

Ultimate Addons for WPBakery Page Builder

Plugin:

Ultimate Addons for WPBakery Page Builder

Plugin Slug:
ultimate_vc_addons

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
3.21.1

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 3.21.1.

WP Freeio

Plugin:

WP Freeio

Plugin Slug:
wp-freeio

Vulnerability:
Privilege Escalation

Patched in Version:
1.2.22

Severity Score:
Critical


The vulnerability has been patched, so you should update to version 1.2.22.

WP JobHunt

Plugin:

WP JobHunt

Plugin Slug:
wp-jobhunt

Vulnerability:
Broken Authentication

Patched in Version:
7.7

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 7.7.

WP JobHunt

Plugin:

WP JobHunt

Plugin Slug:
wp-jobhunt

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
7.7

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 7.7.

WordPress Themes � 3 Patched / 0 Unpatched

Newsup

Theme:

Newsup

Theme Slug:
newsup

Downloads
2,613,735

Vulnerability:
Broken Access Control

Patched in Version:
5.0.11

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 5.0.11.

Betheme

Theme:

Betheme

Theme Slug:
betheme

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
28.1.7

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 28.1.7.

Search & Go

Theme:

Search & Go

Theme Slug:
search-and-go

Vulnerability:
Privilege Escalation

Patched in Version:
2.8

Severity Score:
Critical


The vulnerability has been patched, so you should update to version 2.8.

Related articles

Wait! Get exclusive hosting insights

Subscribe to our newsletter and stay ahead of the competition with expert advice from our hosting pros.

Loading form…