Line illustration showing a black application window on a dark purple gradient background overlaid with a large exclamation point alert icon and three bugs.

WordPress Vulnerability Report � September 17, 2025

In this report, 199 vulnerabilities have been publicly disclosed. Security patches for 50 of these plugins and themes are now available, so please run those updates as soon as possible. If you’re a Solid Security Pro user, the version management tool may have already warned you and updated these plugins, depending on your settings.

Additionally, there are 149 plugin and theme vulnerabilities, and no patch has been available yet. If you’re a Solid Security Pro user, those vulnerabilities are already protected by the Solid Security firewall. Virtual patches from Patchstack will be applied when a vulnerability is considered high or medium risk. If no patch is forthcoming from the vendor or the vulnerable software has been marked “closed” and dropped from the official WordPress repositories, you should deactivate it soon and look for alternative solutions.

WordPress Core

WordPress 6.8.2 was released on July 15, 2025. This maintenance release includes fixes for 20 Core tickets and 15 Block Editor issues. For a full list of bug fixes, please refer to the release candidate announcement.

WordPress Plugins � 47 Patched / 50 Unpatched

Duplicate Page and Post

Plugin Slug:
duplicate-wp-page-post

Installations
90,000+

Vulnerability:
SQL Injection

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Categorify � WordPress Media Library Category & File Manager

Plugin Slug:
categorify

Installations
1,000+

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

WP Mailgun SMTP

Plugin Slug:
wp-mailgun-smtp

Installations
1,000+

Vulnerability:
Sensitive Data Exposure

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

WP SendGrid SMTP

Plugin Slug:
wp-sendgrid-smtp

Installations
1,000+

Vulnerability:
Sensitive Data Exposure

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

All in one Minifier

Plugin Slug:
all-in-one-minifier

Installations
10+

Vulnerability:
SQL Injection

Patched in Version:
No Fix

Severity Score:
Critical


The vulnerability has not been patched. You should deactivate the plugin.

Ultimate Classified Listings

Plugin Slug:
ultimate-classified-listings

Installations
10+

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Admin in English with Switch

Plugin:

Admin in English with Switch

Plugin Slug:
admin-in-english-with-switch

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Analytics Reduce Bounce Rate

Plugin:

Analytics Reduce Bounce Rate

Plugin Slug:
analytics-unbounce

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Auto Save Remote Images (Drafts)

Plugin:

Auto Save Remote Images (Drafts)

Plugin Slug:
auto-save-remote-images-drafts

Vulnerability:
Server Side Request Forgery (SSRF)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

AutoCatSet

Plugin:

AutoCatSet

Plugin Slug:
autocatset

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

azurecurve BBCode

Plugin:

azurecurve BBCode

Plugin Slug:
azurecurve-bbcode

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

BeyondCart Connector

Plugin:

BeyondCart Connector

Plugin Slug:
beyondcart

Vulnerability:
Privilege Escalation

Patched in Version:
No Fix

Severity Score:
Critical


The vulnerability has not been patched. You should deactivate the plugin.

Blog Designer For Elementor

Plugin:

Blog Designer For Elementor

Plugin Slug:
blog-designer-for-elementor

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Certifica WP

Plugin:

Certifica WP

Plugin Slug:
certifica-wp

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Contact Form 7 reCAPTCHA

Plugin:

Contact Form 7 reCAPTCHA

Plugin Slug:
contact-form-7-recaptcha

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Countdown Timer for Elementor

Plugin:

Countdown Timer for Elementor

Plugin Slug:
countdown-timer-for-elementor

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Coupon API

Plugin:

Coupon API

Plugin Slug:
couponapi

Vulnerability:
SQL Injection

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Digital Events Calendar

Plugin:

Digital Events Calendar

Plugin Slug:
digital-events-calendar

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Elements Plus!

Plugin:

Elements Plus!

Plugin Slug:
elements-plus

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Embed Google Datastudio

Plugin:

Embed Google Datastudio

Plugin Slug:
embed-google-data-studio

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Enhanced BibliPlug

Plugin:

Enhanced BibliPlug

Plugin Slug:
enhanced-bibliplug

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Evenium

Plugin:

Evenium

Plugin Slug:
evenium

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

WPGYM

Plugin:

WPGYM

Plugin Slug:
gym-management

Vulnerability:
Privilege Escalation

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

IndiaNIC Testimonial

Plugin:

IndiaNIC Testimonial

Plugin Slug:
indianic-testimonial

Vulnerability:
SQL Injection

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Catalog Importer, Scraper & Crawler

Plugin:

Catalog Importer, Scraper & Crawler

Plugin Slug:
intelligent-importer

Vulnerability:
Remote Code Execution (RCE)

Patched in Version:
No Fix

Severity Score:
Critical


The vulnerability has not been patched. You should deactivate the plugin.

jQuery Colorbox

Plugin:

jQuery Colorbox

Plugin Slug:
jquery-colorbox

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

The integration of the AMO.CRM

Plugin:

The integration of the AMO.CRM

Plugin Slug:
leads-for-amo-crm

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

LH Signing

Plugin:

LH Signing

Plugin Slug:
lh-signing

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Mitfahrgelegenheit

Plugin:

Mitfahrgelegenheit

Plugin Slug:
mitfahrgelegenheit

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Mixtape

Plugin:

Mixtape

Plugin Slug:
mixtape

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

My WP Translate

Plugin:

My WP Translate

Plugin Slug:
my-wp-translate

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

My WP Translate

Plugin:

My WP Translate

Plugin Slug:
my-wp-translate

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

PhpList Subber

Plugin:

PhpList Subber

Plugin Slug:
phpls

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Plugin updates blocker

Plugin:

Plugin updates blocker

Plugin Slug:
plugin-update-blocker

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Propovoice CRM

Plugin:

Propovoice CRM

Plugin Slug:
propovoice

Vulnerability:
Arbitrary File Download

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Publish Approval

Plugin:

Publish Approval

Plugin Slug:
publish-approval

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Resideo Plugin for Resideo

Plugin:

Resideo Plugin for Resideo

Plugin Slug:
resideo-plugin

Vulnerability:
Privilege Escalation

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Responsive Addons for Elementor

Plugin:

Responsive Addons for Elementor

Plugin Slug:
responsive-addons-for-elementor

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Run Log

Plugin:

Run Log

Plugin Slug:
run-log

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Salon booking system

Plugin:

Salon booking system

Plugin Slug:
salon-booking-system

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Seo Monster

Plugin:

Seo Monster

Plugin Slug:
seo-monster

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Side Slide Responsive Menu

Plugin:

Side Slide Responsive Menu

Plugin Slug:
side-slide-responsive-menu

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

eID Easy

Plugin:

eID Easy

Plugin Slug:
smart-id

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Smartcat Translator for WPML

Plugin:

Smartcat Translator for WPML

Plugin Slug:
smartcat-wpml

Vulnerability:
SQL Injection

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Spotify Embed Creator

Plugin:

Spotify Embed Creator

Plugin Slug:
spotify-embed-creator

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

ThemeLoom Widgets

Plugin:

ThemeLoom Widgets

Plugin Slug:
themeloom-widgets

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Ultimate Blogroll

Plugin:

Ultimate Blogroll

Plugin Slug:
ultimate-blogroll

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

User Meta

Plugin:

User Meta

Plugin Slug:
user-meta

Vulnerability:
Arbitrary File Deletion

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

WP Scriptcase

Plugin:

WP Scriptcase

Plugin Slug:
wp-scriptcase

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Workable Api

Plugin:

Workable Api

Plugin Slug:
wrapper-for-workable-api

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

The Events Calendar

Plugin Slug:
the-events-calendar

Installations
700,000+

Vulnerability:
Broken Access Control

Patched in Version:
6.15.3

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 6.15.3.

The Events Calendar

Plugin Slug:
the-events-calendar

Installations
700,000+

Vulnerability:
SQL Injection

Patched in Version:
6.15.1.1

Severity Score:
Critical


The vulnerability has been patched, so you should update to version 6.15.1.1.

Import any XML, CSV or Excel File to WordPress

Plugin Slug:
wp-all-import

Installations
100,000+

Vulnerability:
Arbitrary File Upload

Patched in Version:
3.9.4

Severity Score:
High


The vulnerability has been patched, so you should update to version 3.9.4.

WP-Members Membership Plugin

Plugin Slug:
wp-members

Installations
60,000+

Vulnerability:
Content Injection

Patched in Version:
3.5.4.3

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 3.5.4.3.

Maspik � Ultimate Spam Protection

Plugin Slug:
contact-forms-anti-spam

Installations
30,000+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
2.5.7

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.5.7.

Maspik � Ultimate Spam Protection

Plugin Slug:
contact-forms-anti-spam

Installations
30,000+

Vulnerability:
Broken Access Control

Patched in Version:
2.5.7

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.5.7.

Ditty � Responsive News Tickers, Sliders, and Lists

Plugin Slug:
ditty-news-ticker

Installations
30,000+

Vulnerability:
Server Side Request Forgery (SSRF)

Patched in Version:
3.1.58

Severity Score:
High


The vulnerability has been patched, so you should update to version 3.1.58.

Welcart e-Commerce

Plugin Slug:
usc-e-shop

Installations
20,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.11.21

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.11.21.

WP Import � Ultimate CSV XML Importer for WordPress

Plugin Slug:
wp-ultimate-csv-importer

Installations
20,000+

Vulnerability:
Sensitive Data Exposure

Patched in Version:
7.28

Severity Score:
High


The vulnerability has been patched, so you should update to version 7.28.

LWS Cleaner

Plugin Slug:
lws-cleaner

Installations
10,000+

Vulnerability:
Arbitrary File Deletion

Patched in Version:
2.4.2

Severity Score:
High


The vulnerability has been patched, so you should update to version 2.4.2.

AI ChatBot for WordPress � WPBot

Plugin Slug:
chatbot

Installations
7,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
7.1.0

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 7.1.0.

Export WP Page to Static HTML & PDF

Plugin Slug:
export-wp-page-to-static-html

Installations
5,000+

Vulnerability:
Broken Access Control

Patched in Version:
4.2.0

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 4.2.0.

Include Me

Plugin Slug:
include-me

Installations
4,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.3.3

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.3.3.

PagBank / PagSeguro Connect para WooCommerce

Plugin Slug:
pagbank-connect

Installations
4,000+

Vulnerability:
SQL Injection

Patched in Version:
4.44.4

Severity Score:
High


The vulnerability has been patched, so you should update to version 4.44.4.

PDF Generator for WordPress

Plugin Slug:
pdf-generator-for-wp

Installations
2,000+

Vulnerability:
Broken Access Control

Patched in Version:
1.5.5

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.5.5.

Responsive Filterable Portfolio

Plugin Slug:
responsive-filterable-portfolio

Installations
2,000+

Vulnerability:
Arbitrary File Upload

Patched in Version:
1.0.25

Severity Score:
Critical


The vulnerability has been patched, so you should update to version 1.0.25.

Dynamic Text Field For Contact Form 7

Plugin Slug:
dynamic-text-field-for-contact-form-7

Installations
1,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.1

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.1.

Falang multilanguage for WordPress

Plugin Slug:
falang

Installations
1,000+

Vulnerability:
PHP Object Injection

Patched in Version:
1.3.66

Severity Score:
High


The vulnerability has been patched, so you should update to version 1.3.66.

WP eBay Product Feeds

Plugin Slug:
ebay-feeds-for-wordpress

Installations
900+

Vulnerability:
Server Side Request Forgery (SSRF)

Patched in Version:
3.4.9

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 3.4.9.

Pixeline’s Email Protector

Plugin Slug:
pixelines-email-protector

Installations
900+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.4.0

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.4.0.

Football Pool

Plugin Slug:
football-pool

Installations
800+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.13.0

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.13.0.

My Tickets � Accessible Event Ticketing

Plugin Slug:
my-tickets

Installations
800+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.0.23

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.0.23.

Additional Custom Product Tabs for WooCommerce

Plugin Slug:
product-tabs-for-woocommerce

Installations
500+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.7.4

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.7.4.

The Hack Repair Guy’s Plugin Archiver

Plugin Slug:
hackrepair-plugin-archiver

Installations
400+

Vulnerability:
Arbitrary File Deletion

Patched in Version:
3.1.1

Severity Score:
High


The vulnerability has been patched, so you should update to version 3.1.1.

Advanced Settings 3

Plugin Slug:
advanced-settings

Installations
200+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
3.2.0

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 3.2.0.

Time Tracker

Plugin Slug:
time-tracker

Installations
60+

Vulnerability:
Broken Access Control

Patched in Version:
3.2.0

Severity Score:
High


The vulnerability has been patched, so you should update to version 3.2.0.

WP Blast | SEO & Performance Booster

Plugin Slug:
wpblast

Installations
40+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
1.8.7

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.8.7.

Heateor Login � Social Login Plugin

Plugin Slug:
heateor-login

Installations
30+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.1.10

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.1.10.

MyBrain Utilities

Plugin Slug:
mybrain-utilities

Installations
20+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.1.0

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.1.0.

Compress & Upload

Plugin Slug:
compress-then-upload

Installations
10+

Vulnerability:
Arbitrary File Upload

Patched in Version:
1.0.5

Severity Score:
Critical


The vulnerability has been patched, so you should update to version 1.0.5.

Mikado Core

Plugin:

Mikado Core

Plugin Slug:
mikado-core

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.6

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.6.

Wilmer Core

Plugin:

Wilmer Core

Plugin Slug:
wilmer-core

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.4.6

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.4.6.

WooCommerce Booking Bundle Hours

Plugin:

WooCommerce Booking Bundle Hours

Plugin Slug:
woo-booking-bundle-hours

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
0.7.5

Severity Score:
High


The vulnerability has been patched, so you should update to version 0.7.5.

WordPress Themes � 3 Patched / 99 Unpatched

ButterBelly

Theme Slug:
butterbelly

Downloads
70,694

Vulnerability:
Sensitive Data Exposure

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should switch themes.

Cloriato Lite

Theme Slug:
cloriato-lite

Downloads
111,776

Vulnerability:
Sensitive Data Exposure

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should switch themes.

ColorWay

Theme Slug:
colorway

Downloads
1,314,146

Vulnerability:
Sensitive Data Exposure

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should switch themes.

Compass

Theme:

Compass

Theme Slug:
compass

Downloads
65,712

Vulnerability:
Sensitive Data Exposure

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should switch themes.

Dzonia Lite

Theme Slug:
dzonia-lite

Downloads
114,483

Vulnerability:
Sensitive Data Exposure

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should switch themes.

Poloray

Theme:

Poloray

Theme Slug:
poloray

Downloads
71,063

Vulnerability:
Sensitive Data Exposure

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should switch themes.

Rethink

Theme:

Rethink

Theme Slug:
rethink

Downloads
42,070

Vulnerability:
Sensitive Data Exposure

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should switch themes.

Road Fighter

Theme Slug:
road-fighter

Downloads
82,748

Vulnerability:
Sensitive Data Exposure

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should switch themes.

Themia Lite

Theme Slug:
themia-lite

Downloads
194,918

Vulnerability:
Sensitive Data Exposure

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should switch themes.

Abogado

Theme:

Abogado

Theme Slug:
abogado

Vulnerability:
Local File Inclusion

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should switch themes.

Accalia

Theme:

Accalia

Theme Slug:
accalia

Vulnerability:
Local File Inclusion

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should switch themes.

Adrena

Theme:

Adrena

Theme Slug:
adrena

Vulnerability:
Local File Inclusion

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should switch themes.

Advice

Theme:

Advice

Theme Slug:
advice

Vulnerability:
Local File Inclusion

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should switch themes.

Agora

Theme:

Agora

Theme Slug:
agora

Vulnerability:
Local File Inclusion

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should switch themes.

Alanzo

Theme:

Alanzo

Theme Slug:
alanzo

Vulnerability:
Local File Inclusion

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should switch themes.

Albertino

Theme:

Albertino

Theme Slug:
albertino

Vulnerability:
Local File Inclusion

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should switch themes.

Alhambra

Theme:

Alhambra

Theme Slug:
alhambra

Vulnerability:
Local File Inclusion

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should switch themes.

A.Williams

Theme:

A.Williams

Theme Slug:
alisha-williams

Vulnerability:
Local File Inclusion

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should switch themes.

AlphaColor

Theme:

AlphaColor

Theme Slug:
alpha-color

Vulnerability:
Local File Inclusion

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should switch themes.

Anesta

Theme:

Anesta

Theme Slug:
anesta

Vulnerability:
Local File Inclusion

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should switch themes.

Angela

Theme:

Angela

Theme Slug:
angela

Vulnerability:
Local File Inclusion

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should switch themes.

AI ANN

Theme:

AI ANN

Theme Slug:
ann

Vulnerability:
Local File Inclusion

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should switch themes.

Anubia

Theme:

Anubia

Theme Slug:
anubia

Vulnerability:
Local File Inclusion

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should switch themes.

Artesia

Theme:

Artesia

Theme Slug:
artesia

Vulnerability:
Local File Inclusion

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should switch themes.

Asclepius

Theme:

Asclepius

Theme Slug:
asclepius

Vulnerability:
Local File Inclusion

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should switch themes.

Belicia

Theme:

Belicia

Theme Slug:
belicia

Vulnerability:
Local File Inclusion

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should switch themes.

BeYoga

Theme:

BeYoga

Theme Slug:
beyoga

Vulnerability:
Local File Inclusion

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should switch themes.

Birdily | Travel Agency & Tour Booking WordPress Theme

Theme:

Birdily | Travel Agency & Tour Booking WordPress Theme

Theme Slug:
birdily

Vulnerability:
Local File Inclusion

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should switch themes.

Bonko

Theme:

Bonko

Theme Slug:
bonko

Vulnerability:
Local File Inclusion

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should switch themes.

Booklovers

Theme:

Booklovers

Theme Slug:
booklovers

Vulnerability:
Local File Inclusion

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should switch themes.

Callie Britt

Theme:

Callie Britt

Theme Slug:
callie-britt

Vulnerability:
Local File Inclusion

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should switch themes.

Camelia

Theme:

Camelia

Theme Slug:
camelia

Vulnerability:
Local File Inclusion

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should switch themes.

Carlax

Theme:

Carlax

Theme Slug:
carlax

Vulnerability:
Local File Inclusion

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should switch themes.

Carz

Theme:

Carz

Theme Slug:
carz

Vulnerability:
Local File Inclusion

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should switch themes.

ChainPress

Theme:

ChainPress

Theme Slug:
chainpress

Vulnerability:
Local File Inclusion

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should switch themes.

Chakra

Theme:

Chakra

Theme Slug:
chakra

Vulnerability:
Local File Inclusion

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should switch themes.

Chardonnay

Theme:

Chardonnay

Theme Slug:
chardonnay

Vulnerability:
Local File Inclusion

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should switch themes.

Childy

Theme:

Childy

Theme Slug:
childly

Vulnerability:
Local File Inclusion

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should switch themes.

Chrimson

Theme:

Chrimson

Theme Slug:
chrimson

Vulnerability:
Local File Inclusion

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should switch themes.

City Hostel

Theme:

City Hostel

Theme Slug:
cityhostel

Vulnerability:
Local File Inclusion

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should switch themes.

69 Clothing

Theme:

69 Clothing

Theme Slug:
clothing69

Vulnerability:
Local File Inclusion

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should switch themes.

Corredo

Theme:

Corredo

Theme Slug:
corredo

Vulnerability:
Local File Inclusion

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should switch themes.

Credit Card Experience

Theme:

Credit Card Experience

Theme Slug:
creditcard

Vulnerability:
Local File Inclusion

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should switch themes.

Crework

Theme:

Crework

Theme Slug:
crework

Vulnerability:
Local File Inclusion

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should switch themes.

Custom Made

Theme:

Custom Made

Theme Slug:
custom-made

Vulnerability:
Local File Inclusion

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should switch themes.

Def

Theme:

Def

Theme Slug:
def

Vulnerability:
Local File Inclusion

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should switch themes.

Doccure

Theme:

Doccure

Theme Slug:
doccure

Vulnerability:
Arbitrary File Upload

Patched in Version:
No Fix

Severity Score:
Critical


The vulnerability has not been patched. You should switch themes.

Doccure

Theme:

Doccure

Theme Slug:
doccure

Vulnerability:
Broken Authentication

Patched in Version:
No Fix

Severity Score:
Critical


The vulnerability has not been patched. You should switch themes.

Doccure

Theme:

Doccure

Theme Slug:
doccure

Vulnerability:
Arbitrary File Upload

Patched in Version:
No Fix

Severity Score:
Critical


The vulnerability has not been patched. You should switch themes.

Drone Media

Theme:

Drone Media

Theme Slug:
drone-media

Vulnerability:
Local File Inclusion

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should switch themes.

Edema

Theme:

Edema

Theme Slug:
edema

Vulnerability:
Local File Inclusion

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should switch themes.

Elementra

Theme:

Elementra

Theme Slug:
elementra

Vulnerability:
Local File Inclusion

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should switch themes.

Fortunio

Theme:

Fortunio

Theme Slug:
fortunio

Vulnerability:
Local File Inclusion

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should switch themes.

Good Wine

Theme:

Good Wine

Theme Slug:
good-wine-shop

Vulnerability:
Local File Inclusion

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should switch themes.

Gravity

Theme:

Gravity

Theme Slug:
gravity

Vulnerability:
Local File Inclusion

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should switch themes.

Gutentype

Theme:

Gutentype

Theme Slug:
gutentype

Vulnerability:
Local File Inclusion

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should switch themes.

Hampton

Theme:

Hampton

Theme Slug:
hampton

Vulnerability:
Local File Inclusion

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should switch themes.

Happy Rider

Theme:

Happy Rider

Theme Slug:
happy-rider

Vulnerability:
Local File Inclusion

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should switch themes.

Healthy Blog

Theme:

Healthy Blog

Theme Slug:
healthy-blog

Vulnerability:
Local File Inclusion

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should switch themes.

Heaven11

Theme:

Heaven11

Theme Slug:
heaven11

Vulnerability:
Local File Inclusion

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should switch themes.

Hello Summer

Theme:

Hello Summer

Theme Slug:
hello-summer

Vulnerability:
Local File Inclusion

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should switch themes.

Hogwords

Theme:

Hogwords

Theme Slug:
hogwords

Vulnerability:
Local File Inclusion

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should switch themes.

HotLock

Theme:

HotLock

Theme Slug:
hotlock

Vulnerability:
Local File Inclusion

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should switch themes.

Insurance Ancora

Theme:

Insurance Ancora

Theme Slug:
insurance-ancora

Vulnerability:
Local File Inclusion

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should switch themes.

Jobify – Job Board WordPress Theme

Theme:

Jobify – Job Board WordPress Theme

Theme Slug:
jobify

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should switch themes.

Juno

Theme:

Juno

Theme Slug:
junotoys

Vulnerability:
Local File Inclusion

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should switch themes.

Kargo

Theme:

Kargo

Theme Slug:
kargo

Vulnerability:
Local File Inclusion

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should switch themes.

Lab

Theme:

Lab

Theme Slug:
lab

Vulnerability:
Local File Inclusion

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should switch themes.

Laundry City

Theme:

Laundry City

Theme Slug:
laundrycity

Vulnerability:
Local File Inclusion

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should switch themes.

MediaFlex

Theme:

MediaFlex

Theme Slug:
mediaflex

Vulnerability:
Local File Inclusion

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should switch themes.

Nazareth

Theme:

Nazareth

Theme Slug:
nazareth

Vulnerability:
Local File Inclusion

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should switch themes.

OldStory

Theme:

OldStory

Theme Slug:
oldstory

Vulnerability:
Local File Inclusion

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should switch themes.

Partiso

Theme:

Partiso

Theme Slug:
partiso

Vulnerability:
Local File Inclusion

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should switch themes.

PathWell

Theme:

PathWell

Theme Slug:
pathwell

Vulnerability:
Local File Inclusion

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should switch themes.

Planet Shakers

Theme:

Planet Shakers

Theme Slug:
planet-shakers

Vulnerability:
Local File Inclusion

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should switch themes.

Plastica

Theme:

Plastica

Theme Slug:
plastica

Vulnerability:
Local File Inclusion

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should switch themes.

Let’s Play

Theme:

Let’s Play

Theme Slug:
playhockey

Vulnerability:
Local File Inclusion

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should switch themes.

Podium

Theme:

Podium

Theme Slug:
podium

Vulnerability:
Local File Inclusion

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should switch themes.

Preston

Theme:

Preston

Theme Slug:
preston

Vulnerability:
Local File Inclusion

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should switch themes.

ProDent

Theme:

ProDent

Theme Slug:
prodent

Vulnerability:
Local File Inclusion

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should switch themes.

ProGuards

Theme:

ProGuards

Theme Slug:
proguards

Vulnerability:
Local File Inclusion

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should switch themes.

ProRange

Theme:

ProRange

Theme Slug:
prorange

Vulnerability:
Local File Inclusion

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should switch themes.

Qwery

Theme:

Qwery

Theme Slug:
qwery

Vulnerability:
Local File Inclusion

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should switch themes.

Samadhi

Theme:

Samadhi

Theme Slug:
samadhi

Vulnerability:
Local File Inclusion

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should switch themes.

Smart Casa

Theme:

Smart Casa

Theme Slug:
smart-casa

Vulnerability:
Local File Inclusion

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should switch themes.

SoccerClub

Theme:

SoccerClub

Theme Slug:
soccerclub

Vulnerability:
Local File Inclusion

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should switch themes.

Softic

Theme:

Softic

Theme Slug:
softic

Vulnerability:
Local File Inclusion

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should switch themes.

Solio

Theme:

Solio

Theme Slug:
solio

Vulnerability:
Local File Inclusion

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should switch themes.

StevenWatkins

Theme:

StevenWatkins

Theme Slug:
steven-watkins

Vulnerability:
Local File Inclusion

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should switch themes.

Stratego

Theme:

Stratego

Theme Slug:
stratego

Vulnerability:
Local File Inclusion

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should switch themes.

Studeon

Theme:

Studeon

Theme Slug:
studeon

Vulnerability:
Local File Inclusion

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should switch themes.

Tantra

Theme:

Tantra

Theme Slug:
tantra

Vulnerability:
Local File Inclusion

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should switch themes.

Tax Help

Theme:

Tax Help

Theme Slug:
tax-help

Vulnerability:
Local File Inclusion

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should switch themes.

Translang

Theme:

Translang

Theme Slug:
translang

Vulnerability:
Local File Inclusion

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should switch themes.

Travesia

Theme:

Travesia

Theme Slug:
travesia

Vulnerability:
Local File Inclusion

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should switch themes.

Vagabonds

Theme:

Vagabonds

Theme Slug:
vagabonds

Vulnerability:
Local File Inclusion

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should switch themes.

Wine House

Theme:

Wine House

Theme Slug:
wine-house

Vulnerability:
Local File Inclusion

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should switch themes.

Wise Move

Theme:

Wise Move

Theme Slug:
wisemove

Vulnerability:
Local File Inclusion

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should switch themes.

WotaHub

Theme:

WotaHub

Theme Slug:
wotahub

Vulnerability:
Local File Inclusion

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should switch themes.

Goza

Theme:

Goza

Theme Slug:
goza-theme

Vulnerability:
Arbitrary File Deletion

Patched in Version:
3.2.3

Severity Score:
High


The vulnerability has been patched, so you should update to version 3.2.3.

Goza

Theme:

Goza

Theme Slug:
goza-theme

Vulnerability:
Arbitrary File Upload

Patched in Version:
3.2.3

Severity Score:
Critical


The vulnerability has been patched, so you should update to version 3.2.3.

Mow

Theme:

Mow

Theme Slug:
mow

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
4.11

Severity Score:
Critical


The vulnerability has been patched, so you should update to version 4.11.

Related articles

Wait! Get exclusive hosting insights

Subscribe to our newsletter and stay ahead of the competition with expert advice from our hosting pros.

Loading form…