Line illustration showing a black application window on a dark orange to black gradient background overlaid with a large exclamation point alert icon and three bugs.

WordPress Vulnerability Report � October 22, 2025

In this report, 139 vulnerabilities have been publicly disclosed. Security patches for 87 of these plugins and themes are now available. Please run these updates as soon as possible. If you’re a Solid Security Pro user, the version management tool may have already warned you and updated these plugins, depending on your settings.

Currently, 52 plugin and theme vulnerabilities remain unpatched. If you’re a Solid Security Pro user, those vulnerabilities are already protected by the Solid Security firewall. Virtual patches from Patchstack will be applied when a vulnerability is considered high or medium risk. If no patch is forthcoming from the vendor or the vulnerable software has been marked “closed” and dropped from the official WordPress repositories, you should deactivate it soon and look for alternative solutions.

WordPress Core

WordPress 6.8.3 was released on September 30, 2025! This is a security release that features two fixes. As this is a security release, we recommend updating your sites immediately. For more information on WordPress 6.8.3, please visit the version page on the HelpHub site.

WordPress Plugins � 79 Patched / 50 Unpatched

Binary MLM Plan

Plugin Slug:
binary-mlm-plan

Installations
80+

Vulnerability:
Insecure Direct Object References (IDOR)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Block Country

Plugin Slug:
block-country

Installations
70+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Simple Stripe

Plugin Slug:
simple-stripe

Installations
70+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Stock History & Reports Manager for WooCommerce

Plugin Slug:
stock-snapshot-for-woocommerce

Installations
70+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

replyMail

Plugin Slug:
replymail

Installations
60+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Slick Google Map

Plugin Slug:
slick-google-map

Installations
60+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

wpNamedUsers

Plugin Slug:
wpnamedusers

Installations
60+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

WP BookWidgets

Plugin Slug:
wp-bookwidgets

Installations
50+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Woocommerce Category and Products Accordion Panel

Plugin:

Woocommerce Category and Products Accordion Panel

Plugin Slug:
accordion-panel-for-category-and-products

Vulnerability:
Local File Inclusion

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Code Quality Control Tool

Plugin:

Code Quality Control Tool

Plugin Slug:
code-quality-control-tool

Vulnerability:
Sensitive Data Exposure

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Course Redirects for Learndash

Plugin:

Course Redirects for Learndash

Plugin Slug:
course-redirects-for-learndash

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Custom 404 Pro

Plugin:

Custom 404 Pro

Plugin Slug:
custom-404-pro

Vulnerability:
SQL Injection

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Demo Import Kit

Plugin:

Demo Import Kit

Plugin Slug:
demo-import-kit

Vulnerability:
Arbitrary File Upload

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Dhivehi Text

Plugin:

Dhivehi Text

Plugin Slug:
dhivehi-text

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Digiseller

Plugin:

Digiseller

Plugin Slug:
digiseller

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

DocoDoco Store Locator

Plugin:

DocoDoco Store Locator

Plugin Slug:
docodoco-store-locator

Vulnerability:
Arbitrary File Upload

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Dynamically Display Posts

Plugin:

Dynamically Display Posts

Plugin Slug:
dynamically-display-posts

Vulnerability:
SQL Injection

Patched in Version:
No Fix

Severity Score:
Critical


The vulnerability has not been patched. You should deactivate the plugin.

External Login

Plugin:

External Login

Plugin Slug:
external-login

Vulnerability:
SQL Injection

Patched in Version:
No Fix

Severity Score:
Critical


The vulnerability has not been patched. You should deactivate the plugin.

External Login

Plugin:

External Login

Plugin Slug:
external-login

Vulnerability:
Sensitive Data Exposure

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Find And Replace content for WordPress

Plugin:

Find And Replace content for WordPress

Plugin Slug:
find-and-replace-content

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

FunKItools

Plugin:

FunKItools

Plugin Slug:
funkitools

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Keyy Two Factor Authentication (like Clef)

Plugin:

Keyy Two Factor Authentication (like Clef)

Plugin Slug:
keyy

Vulnerability:
Privilege Escalation

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Library Management System

Plugin:

Library Management System

Plugin Slug:
library-management-system

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

YourMembership Single Sign On

Plugin:

YourMembership Single Sign On

Plugin Slug:
login-with-yourmembership

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Memberlite Shortcodes

Plugin:

Memberlite Shortcodes

Plugin Slug:
memberlite-shortcodes

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Oceanpayment CreditCard Gateway

Plugin:

Oceanpayment CreditCard Gateway

Plugin Slug:
oceanpayment-creditcard-gateway

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

onOffice for WP-Websites

Plugin:

onOffice for WP-Websites

Plugin Slug:
onoffice-for-wp-websites

Vulnerability:
SQL Injection

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Orion SMS OTP Verification

Plugin:

Orion SMS OTP Verification

Plugin Slug:
orion-sms-otp-verification

Vulnerability:
Broken Authentication

Patched in Version:
No Fix

Severity Score:
Critical


The vulnerability has not been patched. You should deactivate the plugin.

OwnID Passwordless Login

Plugin:

OwnID Passwordless Login

Plugin Slug:
ownid-passwordless-login

Vulnerability:
Broken Authentication

Patched in Version:
No Fix

Severity Score:
Critical


The vulnerability has not been patched. You should deactivate the plugin.

Page Blocks

Plugin:

Page Blocks

Plugin Slug:
page-blocks

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Quick Social Login

Plugin:

Quick Social Login

Plugin Slug:
quick-login

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.
Plugin:

Related Posts Lite

Plugin Slug:
related-posts-lite

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Shortcode Button

Plugin:

Shortcode Button

Plugin Slug:
shortcode-button

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

TARIFFUXX

Plugin:

TARIFFUXX

Plugin Slug:
tariffuxx

Vulnerability:
SQL Injection

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Task Scheduler

Plugin:

Task Scheduler

Plugin Slug:
task-scheduler

Vulnerability:
Server Side Request Forgery (SSRF)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Theme Importer

Plugin:

Theme Importer

Plugin Slug:
theme-importer

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

TopBar

Plugin:

TopBar

Plugin Slug:
topbar

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Truelysell Core

Plugin:

Truelysell Core

Plugin Slug:
truelysell-core

Vulnerability:
Broken Authentication

Patched in Version:
No Fix

Severity Score:
Critical


The vulnerability has not been patched. You should deactivate the plugin.

TwentyFourth WP Scraper

Plugin:

TwentyFourth WP Scraper

Plugin Slug:
twentyfourth-wp-scraper

Vulnerability:
Server Side Request Forgery (SSRF)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

URLYar URL Shortner

Plugin:

URLYar URL Shortner

Plugin Slug:
urlyar

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

WooCommerce Designer Pro

Plugin:

WooCommerce Designer Pro

Plugin Slug:
wc-designer-pro

Vulnerability:
Arbitrary File Deletion

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

WidgetPack Comment System

Plugin:

WidgetPack Comment System

Plugin Slug:
widgetpack-comment-system

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

WP Dashboard Chat

Plugin:

WP Dashboard Chat

Plugin Slug:
wp-dashboard-chat

Vulnerability:
SQL Injection

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

WP Easy Toggles

Plugin:

WP Easy Toggles

Plugin Slug:
wp-easy-toggles

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

WP Google Map

Plugin:

WP Google Map

Plugin Slug:
wp-google-map

Vulnerability:
SQL Injection

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

WP jQuery Pager

Plugin:

WP jQuery Pager

Plugin Slug:
wp-jquery-pdf-paged

Vulnerability:
SQL Injection

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

WP Private Content Plus

Plugin:

WP Private Content Plus

Plugin Slug:
wp-private-content-plus

Vulnerability:
Broken Authentication

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

WordPress Live Webcam Widget & Shortcode

Plugin:

WordPress Live Webcam Widget & Shortcode

Plugin Slug:
wp-webcam-widget-shortcode

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Zip Attachments

Plugin:

Zip Attachments

Plugin Slug:
zip-attachments

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Zip Attachments

Plugin:

Zip Attachments

Plugin Slug:
zip-attachments

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Ally � Web Accessibility & Usability

Plugin Slug:
pojo-accessibility

Installations
400,000+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
3.8.1

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 3.8.1.

WP Go Maps (formerly WP Google Maps)

Plugin Slug:
wp-google-maps

Installations
300,000+

Vulnerability:
Content Injection

Patched in Version:
9.0.49

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 9.0.49.

Redirection for Contact Form 7

Plugin Slug:
wpcf7-redirect

Installations
300,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
3.2.7

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 3.2.7.

Element Pack Addons for Elementor

Plugin Slug:
bdthemes-element-pack-lite

Installations
100,000+

Vulnerability:
Server Side Request Forgery (SSRF)

Patched in Version:
8.2.6

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 8.2.6.

Colibri Page Builder

Plugin Slug:
colibri-page-builder

Installations
100,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.0.335

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.0.335.

WPC Smart Quick View for WooCommerce

Plugin Slug:
woo-smart-quick-view

Installations
100,000+

Vulnerability:
Insecure Direct Object References (IDOR)

Patched in Version:
4.2.6

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 4.2.6.

WPC Smart Wishlist for WooCommerce

Plugin Slug:
woo-smart-wishlist

Installations
100,000+

Vulnerability:
Broken Access Control

Patched in Version:
5.0.5

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 5.0.5.

Event Tickets and Registration

Plugin Slug:
event-tickets

Installations
90,000+

Vulnerability:
Broken Authentication

Patched in Version:
5.26.6

Severity Score:
High


The vulnerability has been patched, so you should update to version 5.26.6.

Event Tickets and Registration

Plugin Slug:
event-tickets

Installations
90,000+

Vulnerability:
Broken Access Control

Patched in Version:
5.26.4

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 5.26.4.

LearnPress � WordPress LMS Plugin

Plugin Slug:
learnpress

Installations
80,000+

Vulnerability:
Broken Access Control

Patched in Version:
4.2.9.4

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 4.2.9.4.

Media Library Assistant

Plugin Slug:
media-library-assistant

Installations
70,000+

Vulnerability:
Arbitrary File Download

Patched in Version:
3.30

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 3.30.
Plugin Slug:
quick-featured-images

Installations
50,000+

Vulnerability:
Insecure Direct Object References (IDOR)

Patched in Version:
13.7.3

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 13.7.3.

Theme Editor

Plugin Slug:
theme-editor

Installations
50,000+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
3.1

Severity Score:
High


The vulnerability has been patched, so you should update to version 3.1.

Advanced Coupons � WooCommerce Coupons & Store Credit

Plugin Slug:
advanced-coupons-for-woocommerce-free

Installations
20,000+

Vulnerability:
SQL Injection

Patched in Version:
4.6.9

Severity Score:
High


The vulnerability has been patched, so you should update to version 4.6.9.

One Page Express Companion

Plugin Slug:
one-page-express-companion

Installations
20,000+

Vulnerability:
Broken Access Control

Patched in Version:
1.6.44

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.6.44.

Pz-LinkCard

Plugin Slug:
pz-linkcard

Installations
20,000+

Vulnerability:
Server Side Request Forgery (SSRF)

Patched in Version:
2.5.7

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.5.7.

SmartCrawl SEO checker, analyzer & optimizer

Plugin Slug:
smartcrawl-seo

Installations
20,000+

Vulnerability:
Broken Access Control

Patched in Version:
3.14.4

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 3.14.4.

PPOM � Product Addons & Custom Fields for WooCommerce

Plugin Slug:
woocommerce-product-addon

Installations
20,000+

Vulnerability:
SQL Injection

Patched in Version:
33.0.16

Severity Score:
Critical


The vulnerability has been patched, so you should update to version 33.0.16.

PPOM � Product Addons & Custom Fields for WooCommerce

Plugin Slug:
woocommerce-product-addon

Installations
20,000+

Vulnerability:
Arbitrary File Upload

Patched in Version:
33.0.16

Severity Score:
Critical


The vulnerability has been patched, so you should update to version 33.0.16.

Web Accessibility by accessiBe

Plugin Slug:
accessibe

Installations
10,000+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
2.11

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.11.

Simple SEO

Plugin Slug:
cds-simple-seo

Installations
10,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.0.32

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.0.32.

E2Pdf � Export Pdf Tool for WordPress

Plugin Slug:
e2pdf

Installations
10,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.28.10

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.28.10.

Simple Job Board

Plugin Slug:
simple-job-board

Installations
10,000+

Vulnerability:
Sensitive Data Exposure

Patched in Version:
2.13.8

Severity Score:
High


The vulnerability has been patched, so you should update to version 2.13.8.

Error Log Viewer by BestWebSoft

Plugin Slug:
error-log-viewer

Installations
6,000+

Vulnerability:
Arbitrary File Download

Patched in Version:
1.1.7

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.1.7.

Kognetiks Chatbot

Plugin Slug:
chatbot-chatgpt

Installations
1,000+

Vulnerability:
Broken Access Control

Patched in Version:
2.3.6

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.3.6.

Event post

Plugin Slug:
event-post

Installations
1,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
5.10.4

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 5.10.4.

GSheetConnector For Gravity Forms

Plugin Slug:
gsheetconnector-gravity-forms

Installations
1,000+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
1.3.24

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.3.24.

GSheetConnector For Gravity Forms

Plugin Slug:
gsheetconnector-gravity-forms

Installations
1,000+

Vulnerability:
Broken Access Control

Patched in Version:
1.3.28

Severity Score:
High


The vulnerability has been patched, so you should update to version 1.3.28.

Events Calendar Made Simple � Pie Calendar

Plugin Slug:
pie-calendar

Installations
1,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.3.0

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.3.0.

Product Catalog Simple

Plugin Slug:
post-type-x

Installations
1,000+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
1.8.5

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.8.5.

Reviews Widgets for Google & 45+ platforms by Repuso

Plugin Slug:
social-testimonials-and-reviews-widget

Installations
1,000+

Vulnerability:
Broken Access Control

Patched in Version:
5.30

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 5.30.

Tab Ultimate

Plugin Slug:
tabs-pro

Installations
1,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.9

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.9.

MDTF � Meta Data and Taxonomies Filter

Plugin Slug:
wp-meta-data-filter-and-taxonomy-filter

Installations
1,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.3.3.9

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.3.3.9.

WP Travel Gutenberg Blocks

Plugin Slug:
wp-travel-blocks

Installations
1,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
3.9.3

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 3.9.3.

WPC Countdown Timer for WooCommerce

Plugin Slug:
wpc-countdown-timer

Installations
1,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
3.1.5

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 3.1.5.

WPCasa

Plugin:

WPCasa

Plugin Slug:
wpcasa

Installations
1,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.4.2

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.4.2.

Product Table For WooCommerce

Plugin Slug:
product-table-for-woocommerce

Installations
600+

Vulnerability:
PHP Object Injection

Patched in Version:
1.2.5

Severity Score:
High


The vulnerability has been patched, so you should update to version 1.2.5.

PowerBI Embed Reports

Plugin Slug:
embed-power-bi-reports

Installations
500+

Vulnerability:
Sensitive Data Exposure

Patched in Version:
1.2.1

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.2.1.

Front End Users

Plugin Slug:
front-end-only-users

Installations
500+

Vulnerability:
Broken Access Control

Patched in Version:
3.2.34

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 3.2.34.

UPC/EAN/GTIN Barcode Generator/Importer

Plugin Slug:
upc-ean-barcode-generator

Installations
500+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
2.0.3

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.0.3.

Content Writer

Plugin Slug:
content-writer

Installations
300+

Vulnerability:
Sensitive Data Exposure

Patched in Version:
3.6.9

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 3.6.9.

Acknowledgify

Plugin Slug:
acknowledgify

Installations
100+

Vulnerability:
Broken Access Control

Patched in Version:
1.1.4

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.1.4.

XX2WP Integration Tools

Plugin Slug:
fb2wp-integration-tools

Installations
30+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.0.0

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.0.0.

Flex QR Code Generator

Plugin Slug:
flex-qr-code-generator

Installations
30+

Vulnerability:
Arbitrary File Upload

Patched in Version:
1.2.6

Severity Score:
Critical


The vulnerability has been patched, so you should update to version 1.2.6.

BlindMatrix e-Commerce

Plugin Slug:
window-blinds-solution

Installations
10+

Vulnerability:
Local File Inclusion

Patched in Version:
3.1

Severity Score:
High


The vulnerability has been patched, so you should update to version 3.1.

Felan Framework

Plugin:

Felan Framework

Plugin Slug:
felan-framework

Vulnerability:
Broken Access Control

Patched in Version:
1.1.5

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.1.5.

Felan Framework

Plugin:

Felan Framework

Plugin Slug:
felan-framework

Vulnerability:
Broken Authentication

Patched in Version:
1.1.5

Severity Score:
Critical


The vulnerability has been patched, so you should update to version 1.1.5.

Houzez Theme – Functionality

Plugin:

Houzez Theme – Functionality

Plugin Slug:
houzez-theme-functionality

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
4.2.0

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 4.2.0.

Houzez Theme – Functionality

Plugin:

Houzez Theme – Functionality

Plugin Slug:
houzez-theme-functionality

Vulnerability:
Local File Inclusion

Patched in Version:
4.2.0

Severity Score:
High


The vulnerability has been patched, so you should update to version 4.2.0.

WPBakery Page Builder

Plugin:

WPBakery Page Builder

Plugin Slug:
js_composer

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
8.7

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 8.7.

WPBakery Page Builder

Plugin:

WPBakery Page Builder

Plugin Slug:
js_composer

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
8.7

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 8.7.

WPBakery Page Builder

Plugin:

WPBakery Page Builder

Plugin Slug:
js_composer

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
8.7

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 8.7.

Lisfinity Core

Plugin:

Lisfinity Core

Plugin Slug:
lisfinity-core

Vulnerability:
Privilege Escalation

Patched in Version:
1.5.0

Severity Score:
High


The vulnerability has been patched, so you should update to version 1.5.0.

Ova Advent

Plugin:

Ova Advent

Plugin Slug:
ova-advent

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.1.8

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.1.8.

SUMO Memberships for WooCommerce

Plugin:

SUMO Memberships for WooCommerce

Plugin Slug:
sumomemberships

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
7.8.0

Severity Score:
High


The vulnerability has been patched, so you should update to version 7.8.0.

tagDiv Cloud Library

Plugin:

tagDiv Cloud Library

Plugin Slug:
td-cloud-library

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
4.0

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 4.0.

tagDiv Composer

Plugin:

tagDiv Composer

Plugin Slug:
td-composer

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
5.4.2

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 5.4.2.

TheGem Theme Elements (for WPBakery)

Plugin:

TheGem Theme Elements (for WPBakery)

Plugin Slug:
thegem-elements

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
5.10.5.2

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 5.10.5.2.

UDesign Core

Plugin:

UDesign Core

Plugin Slug:
u-design-core

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
4.14.2

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 4.14.2.

WordPress Themes � 8 Patched / 2 Unpatched

ClassifiedPro

Theme:

ClassifiedPro

Theme Slug:
classified-pro

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should switch themes.

Rich Snippet Site Report

Theme:

Rich Snippet Site Report

Theme Slug:
easysnippet

Vulnerability:
SQL Injection

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should switch themes.

HomeLancer

Theme Slug:
homelancer

Downloads
3,788

Vulnerability:
Broken Access Control

Patched in Version:
1.0.2

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.0.2.

Newsup

Theme:

Newsup

Theme Slug:
newsup

Downloads
2,628,569

Vulnerability:
Broken Access Control

Patched in Version:
5.0.11

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 5.0.11.

Education WordPress Theme | HiStudy

Theme:

Education WordPress Theme | HiStudy

Theme Slug:
histudy

Vulnerability:
SQL Injection

Patched in Version:
3.1.0

Severity Score:
Critical


The vulnerability has been patched, so you should update to version 3.1.0.

Kallyas

Theme:

Kallyas

Theme Slug:
kallyas

Vulnerability:
Broken Access Control

Patched in Version:
4.23.0

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 4.23.0.

Kallyas

Theme:

Kallyas

Theme Slug:
kallyas

Vulnerability:
Broken Access Control

Patched in Version:
4.23.0

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 4.23.0.

Salient

Theme:

Salient

Theme Slug:
salient

Vulnerability:
Broken Access Control

Patched in Version:
17.4.0

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 17.4.0.

WoodMart

Theme:

WoodMart

Theme Slug:
woodmart

Vulnerability:
Local File Inclusion

Patched in Version:
8.3.2

Severity Score:
High


The vulnerability has been patched, so you should update to version 8.3.2.

XStore

Theme:

XStore

Theme Slug:
xstore

Vulnerability:
Local File Inclusion

Patched in Version:
9.6

Severity Score:
High


The vulnerability has been patched, so you should update to version 9.6.

Related articles

Wait! Get exclusive hosting insights

Subscribe to our newsletter and stay ahead of the competition with expert advice from our hosting pros.

Loading form…