Line illustration showing a black application window on a red gradient background overlaid with a large exclamation point alert icon and three bugs.

WordPress Vulnerability Report � September 24, 2025

In this report, 354 vulnerabilities have been publicly disclosed. Security patches for 89 of these plugins and themes are now available, so please run those updates as soon as possible. If you’re a Solid Security Pro user, the version management tool may have already warned you and updated these plugins, depending on your settings.

Additionally, there are 265 WordPress Core, plugin, and theme vulnerabilities, and no patch has been available yet. If you’re a Solid Security Pro user, those vulnerabilities are already protected by the Solid Security firewall. Virtual patches from Patchstack will be applied when a vulnerability is considered high or medium risk. If no patch is forthcoming from the vendor or the vulnerable software has been marked “closed” and dropped from the official WordPress repositories, you should deactivate it soon and look for alternative solutions.

WordPress Core

Patchstack�s bug-bounty program recently disclosed two WordPress Core vulnerabilities. Both are assessed as low severity and require an attacker to have a compromised Contributor-level account on the site to exploit, making widespread abuse unlikely. No virtual patch is available or required; the WordPress Core security team is actively investigating and coordinating fixes.

WordPress Core

Vulnerability:
Sensitive Data Exposure

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched.

WordPress Core

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched.

WordPress Plugins � 85 Patched / 254 Unpatched

All in One SEO � Powerful SEO Plugin to Boost SEO Rankings & Increase Traffic

Plugin Slug:
all-in-one-seo-pack

Installations
3,000,000+

Vulnerability:
Sensitive Data Exposure

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Sticky Header Effects for Elementor

Plugin Slug:
sticky-header-effects-for-elementor

Installations
300,000+

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Nextend Social Login and Register

Plugin Slug:
nextend-facebook-connect

Installations
200,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

TI WooCommerce Wishlist

Plugin Slug:
ti-woocommerce-wishlist

Installations
100,000+

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Jupiter X Core

Plugin Slug:
jupiterx-core

Installations
80,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Master Slider � Responsive Touch Slider

Plugin Slug:
master-slider

Installations
70,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Getwid � Gutenberg Blocks

Plugin Slug:
getwid

Installations
50,000+

Vulnerability:
Sensitive Data Exposure

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Image Hover Effects � Elementor Addon

Plugin Slug:
image-hover-effects-addon-for-elementor

Installations
50,000+

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Perfect Brands for WooCommerce

Plugin Slug:
perfect-woocommerce-brands

Installations
50,000+

Vulnerability:
SQL Injection

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Better Find and Replace � AI-Powered Suggestions

Plugin Slug:
real-time-auto-find-and-replace

Installations
50,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

DethemeKit for Elementor

Plugin Slug:
dethemekit-for-elementor

Installations
40,000+

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Page-list

Plugin Slug:
page-list

Installations
40,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Ads by Quads � Adsense Ads, Banner Ads, Popup Ads

Plugin Slug:
quick-adsense-reloaded

Installations
30,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Trustpilot Reviews

Plugin Slug:
trustpilot-reviews

Installations
30,000+

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

WP Events Manager

Plugin Slug:
wp-events-manager

Installations
30,000+

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Geolocation IP Detection

Plugin Slug:
geoip-detect

Installations
20,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Custom Block Builder � Lazy Blocks

Plugin Slug:
lazy-blocks

Installations
20,000+

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Quiz Maker

Plugin Slug:
quiz-maker

Installations
20,000+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Quiz Maker

Plugin Slug:
quiz-maker

Installations
20,000+

Vulnerability:
Sensitive Data Exposure

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Uncanny Toolkit for LearnDash

Plugin Slug:
uncanny-learndash-toolkit

Installations
20,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Blog Designer

Plugin Slug:
blog-designer

Installations
10,000+

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Passster � Password Protect Pages and Content

Plugin Slug:
content-protector

Installations
10,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Translate WordPress with ConveyThis

Plugin Slug:
conveythis-translate

Installations
10,000+

Vulnerability:
PHP Object Injection

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Dashboard Notepad

Plugin Slug:
dashboard-notepad

Installations
10,000+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.
Plugin Slug:
gallery-lightbox-slider

Installations
10,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Open User Map

Plugin Slug:
open-user-map

Installations
10,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.
Plugin Slug:
portfolio-elementor

Installations
10,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Qubely � Advanced Gutenberg Blocks

Plugin Slug:
qubely

Installations
10,000+

Vulnerability:
Sensitive Data Exposure

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Qubely � Advanced Gutenberg Blocks

Plugin Slug:
qubely

Installations
10,000+

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Team � Team Members Showcase Plugin

Plugin Slug:
tlp-team

Installations
10,000+

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

WP Subtitle

Plugin Slug:
wp-subtitle

Installations
10,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

WPeMatico RSS Feed Fetcher

Plugin Slug:
wpematico

Installations
10,000+

Vulnerability:
Sensitive Data Exposure

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Convert WordPress to app | AppMySite

Plugin Slug:
appmysite

Installations
9,000+

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.
Plugin Slug:
mihdan-no-external-links

Installations
9,000+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

WP Compress � Instant Performance & Speed Optimization

Plugin Slug:
wp-compress-image-optimizer

Installations
9,000+

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.
Plugin Slug:
wp-mailto-links

Installations
9,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Awesome Support � WordPress HelpDesk & Support Plugin

Plugin Slug:
awesome-support

Installations
8,000+

Vulnerability:
Deserialization of untrusted data

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Participants Database

Plugin Slug:
participants-database

Installations
8,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Flexible PDF Invoices for WooCommerce & WordPress

Plugin Slug:
flexible-invoices

Installations
6,000+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

WP Social Widget

Plugin Slug:
wp-social-widget

Installations
5,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

WPKoi Templates for Elementor

Plugin Slug:
wpkoi-templates-for-elementor

Installations
5,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Mail Subscribe List

Plugin Slug:
mail-subscribe-list

Installations
4,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Post Carousel Slider for Elementor

Plugin Slug:
post-carousel-slider-for-elementor

Installations
4,000+

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Cecabank WooCommerce Plugin

Plugin Slug:
cecabank-woocommerce

Installations
3,000+

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

E-namad & Shamed Logo Manager

Plugin Slug:
e-namad-shamed-logo-manager

Installations
3,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Interact: Embed A Quiz On Your Site

Plugin Slug:
interact-quiz-embed

Installations
3,000+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Login-Logout

Plugin Slug:
login-logout

Installations
3,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Designil PDPA Thailand

Plugin Slug:
pdpa-thailand

Installations
3,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Piotnet Forms

Plugin Slug:
piotnetforms

Installations
3,000+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Podlove Subscribe button

Plugin Slug:
podlove-subscribe-button

Installations
3,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Text To Speech TTS Accessibility

Plugin Slug:
text-to-audio

Installations
3,000+

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

CardCom Payment Gateway

Plugin Slug:
woo-cardcom-payment-gateway

Installations
3,000+

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Compact Archives

Plugin Slug:
compact-archives

Installations
2,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Estonian Shipping Methods for WooCommerce

Plugin Slug:
estonian-shipping-methods-for-woocommerce

Installations
2,000+

Vulnerability:
Sensitive Data Exposure

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.
Plugin Slug:
gallery-photo-gallery

Installations
2,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

GD bbPress Tools

Plugin Slug:
gd-bbpress-tools

Installations
2,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Import Markdown � Versatile Markdown Importer

Plugin Slug:
import-markdown

Installations
2,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Sitekit

Plugin:

Sitekit

Plugin Slug:
sitekit

Installations
2,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Quick View for WooCommerce

Plugin Slug:
woo-quickview

Installations
2,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Bitly’s WordPress Plugin

Plugin Slug:
wp-bitly

Installations
2,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Advanced Appointment Booking & Scheduling

Plugin Slug:
advanced-appointment-booking-scheduling

Installations
1,000+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Append extensions on Pages

Plugin Slug:
append-extensions-on-pages

Installations
1,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.
Plugin Slug:
append-link-on-copy

Installations
1,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

AuthorSure

Plugin Slug:
authorsure

Installations
1,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

BP Disable Activation Reloaded

Plugin Slug:
bp-disable-activation-reloaded

Installations
1,000+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Clariti

Plugin:

Clariti

Plugin Slug:
clariti

Installations
1,000+

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Classic Widgets with Block-based Widgets

Plugin Slug:
classic-widgets-with-block-based-widgets

Installations
1,000+

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Content Mask

Plugin Slug:
content-mask

Installations
1,000+

Vulnerability:
Server Side Request Forgery (SSRF)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Content Mask

Plugin Slug:
content-mask

Installations
1,000+

Vulnerability:
Insecure Direct Object References (IDOR)

Patched in Version:
No Fix

Severity Score:
Low


The vulnerability has not been patched. You should deactivate the plugin.

CP Multi View Event Calendar

Plugin Slug:
cp-multi-view-calendar

Installations
1,000+

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
Low


The vulnerability has not been patched. You should deactivate the plugin.

Emergency Password Reset

Plugin Slug:
emergency-password-reset

Installations
1,000+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Fastly

Plugin:

Fastly

Plugin Slug:
fastly

Installations
1,000+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Flexible FAQ

Plugin Slug:
flexible-faq

Installations
1,000+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Force Update Translations

Plugin Slug:
force-update-translations

Installations
1,000+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Genesis Club Lite

Plugin Slug:
genesis-club-lite

Installations
1,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Connector Wizard (formerly LC Wizard)

Plugin Slug:
ghl-wizard

Installations
1,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Hide WP Toolbar

Plugin Slug:
hide-wp-toolbar

Installations
1,000+

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

HT Mega � Absolute Addons for WPBakery Page Builder

Plugin Slug:
ht-mega-for-wpbakery

Installations
1,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Beaf � Photo Comparison Block

Plugin Slug:
image-compare-block

Installations
1,000+

Vulnerability:
Server Side Request Forgery (SSRF)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Kama Click Counter

Plugin Slug:
kama-clic-counter

Installations
1,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Last Updated Shortcode

Plugin Slug:
last-updated-shortcode

Installations
1,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

MakeStories (for Google Web Stories)

Plugin Slug:
makestories-helper

Installations
1,000+

Vulnerability:
Server Side Request Forgery (SSRF)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Memberful � Membership Plugin

Plugin Slug:
memberful-wp

Installations
1,000+

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Frontend File Manager Plugin

Plugin Slug:
nmedia-user-file-uploader

Installations
1,000+

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

PilotPress

Plugin Slug:
pilotpress

Installations
1,000+

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

PilotPress

Plugin Slug:
pilotpress

Installations
1,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Plugin Security Scanner

Plugin Slug:
plugin-security-scanner

Installations
1,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Quantities and Units for WooCommerce

Plugin Slug:
quantities-and-units-for-woocommerce

Installations
1,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Safety Exit

Plugin Slug:
safety-exit

Installations
1,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

SALESmanago & Leadoo

Plugin Slug:
salesmanago

Installations
1,000+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

SALESmanago & Leadoo

Plugin Slug:
salesmanago

Installations
1,000+

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

SiteNarrator Text-to-Speech Widget

Plugin Slug:
sitespeaker-widget

Installations
1,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.
Plugin Slug:
skimlinks

Installations
1,000+

Vulnerability:
Server Side Request Forgery (SSRF)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.
Plugin Slug:
skimlinks

Installations
1,000+

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Skyword XMLRPC publishing

Plugin Slug:
skyword-plugin

Installations
1,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.
Plugin Slug:
slightly-troublesome-permalink

Installations
1,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

SV Proven Expert

Plugin Slug:
sv-provenexpert

Installations
1,000+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Travel Map

Plugin Slug:
travelmap-blog

Installations
1,000+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Ultimate Watermark � Advanced Image Watermarking

Plugin Slug:
ultimate-watermark

Installations
1,000+

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Upcoming Events Lists

Plugin Slug:
upcoming-events-lists

Installations
1,000+

Vulnerability:
Insecure Direct Object References (IDOR)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Draft � Tailwind CSS for WordPress.

Plugin Slug:
website-builder

Installations
1,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Website Chat Button: Kommo integration

Plugin Slug:
website-chat-button-kommo-integration

Installations
1,000+

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

WPB Quick View Popup for WooCommerce

Plugin Slug:
woocommerce-lightbox

Installations
1,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

WP Advanced PDF

Plugin Slug:
wp-advanced-pdf

Installations
1,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Category Dropdown by GCS Design

Plugin Slug:
wp-category-dropdown

Installations
1,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

WP Compiler

Plugin Slug:
wp-compiler

Installations
1,000+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

WP Delete User Accounts

Plugin Slug:
wp-delete-user-accounts

Installations
1,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Subresource Integrity (SRI) Manager

Plugin Slug:
wp-sri

Installations
1,000+

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

xili-tidy-tags

Plugin Slug:
xili-tidy-tags

Installations
1,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

BMI Adult & Kid Calculator

Plugin Slug:
bmi-adultkid-calculator

Installations
900+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Bot Block � Stop Spam Referrals in Google Analytics

Plugin Slug:
bot-block-stop-spam-google-analytics-referrals

Installations
900+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

CashBill.pl � P?atno?ci WooCommerce

Plugin Slug:
cashbill-payment-method

Installations
900+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Developer

Plugin Slug:
developer

Installations
900+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Highlight and Share � Social Text and Image Sharing

Plugin Slug:
highlight-and-share

Installations
900+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

LWS Affiliation

Plugin Slug:
lws-affiliation

Installations
900+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Mail Baby SMTP

Plugin Slug:
mail-baby-smtp

Installations
900+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

PlayerJS

Plugin:

PlayerJS

Plugin Slug:
playerjs

Installations
900+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.
Plugin Slug:
seo-backlink-monitor

Installations
900+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.
Plugin Slug:
seo-backlink-monitor

Installations
900+

Vulnerability:
Server Side Request Forgery (SSRF)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

TOCHAT.BE

Plugin Slug:
tochat-be

Installations
900+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Ultimate WP Mail

Plugin Slug:
ultimate-wp-mail

Installations
900+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

WP System Information

Plugin Slug:
wp-system-info

Installations
900+

Vulnerability:
Sensitive Data Exposure

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

BuddyPress Notification Widget

Plugin Slug:
buddypress-notifications-widget

Installations
800+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.
Plugin Slug:
category-featured-images

Installations
800+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

StylePress for Elementor

Plugin Slug:
full-site-builder-for-elementor

Installations
800+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Gianism

Plugin:

Gianism

Plugin Slug:
gianism

Installations
800+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Image Editor by Pixo

Plugin Slug:
image-editor-by-pixo

Installations
800+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Pinterest Pinboard Widget

Plugin Slug:
pinterest-pinboard-widget

Installations
800+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Events Manager � OpenStreetMaps

Plugin Slug:
stonehenge-em-osm

Installations
800+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

xili-language

Plugin Slug:
xili-language

Installations
800+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.
Plugin Slug:
carousel

Installations
700+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

JS Job Manager

Plugin Slug:
js-jobs

Installations
700+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

SQL Chart Builder

Plugin Slug:
sql-chart-builder

Installations
700+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Buckets

Plugin:

Buckets

Plugin Slug:
buckets

Installations
600+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Easy Quotes

Plugin Slug:
easy-quotes

Installations
600+

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Genealogical Tree � WordPress Family Tree

Plugin Slug:
genealogical-tree

Installations
600+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Shortcode

Plugin Slug:
shortcode

Installations
600+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

SnapWidget Social Photo Feed Widget

Plugin Slug:
snapwidget-wp-instagram-widget

Installations
600+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Theater for WordPress

Plugin Slug:
theatre

Installations
600+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

VikRestaurants Table Reservations and Take-Away

Plugin Slug:
vikrestaurants

Installations
600+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

VikRestaurants Table Reservations and Take-Away

Plugin Slug:
vikrestaurants

Installations
600+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

WooMS

Plugin:

WooMS

Plugin Slug:
wooms

Installations
600+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

WooMS

Plugin:

WooMS

Plugin Slug:
wooms

Installations
600+

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

WordPress Widgets Shortcode

Plugin Slug:
wp-widgets-shortcode

Installations
600+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

AgreeMe Checkboxes For WooCommerce

Plugin Slug:
agreeme-checkboxes-for-woocommerce

Installations
500+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Card Elements for WPBakery

Plugin Slug:
card-elements-for-wpbakery

Installations
500+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.
Plugin Slug:
category-featured-images-extended

Installations
500+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

DELUCKS SEO

Plugin Slug:
delucks-seo

Installations
500+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Epeken All Kurir Plugin for Woocommerce Full Version

Plugin Slug:
epeken-all-kurir

Installations
500+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Front End Users

Plugin Slug:
front-end-only-users

Installations
500+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Heureka

Plugin:

Heureka

Plugin Slug:
heureka

Installations
500+

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Library Bookshelves

Plugin Slug:
library-bookshelves

Installations
500+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Maps for WP

Plugin Slug:
maps-for-wp

Installations
500+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.
Plugin Slug:
ngg-smart-image-search

Installations
500+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

payOS

Plugin:

payOS

Plugin Slug:
payos

Installations
500+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Behance Portfolio Manager

Plugin Slug:
portfolio-manager-powered-by-behance

Installations
500+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Product Time Countdown for WooCommerce

Plugin Slug:
product-countdown-for-woocommerce

Installations
500+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Tapfiliate

Plugin Slug:
tapfiliate

Installations
500+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

UK Address Postcode Validation

Plugin Slug:
uk-address-postcode-validation

Installations
500+

Vulnerability:
Sensitive Data Exposure

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Deliver via Shipos for WooCommerce

Plugin Slug:
wc-shipos-delivery

Installations
500+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

JSM file_get_contents() Shortcode

Plugin Slug:
wp-file-get-contents

Installations
500+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

WP Proposals

Plugin Slug:
wp-proposals

Installations
500+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Zoho Billing � Embed Payment Form

Plugin Slug:
zoho-subscriptions

Installations
500+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

WP Gravity Forms Keap/Infusionsoft

Plugin Slug:
gf-infusionsoft

Installations
400+

Vulnerability:
Open Redirection

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Helpdesk Support Ticket System for WooCommerce

Plugin Slug:
support-ticket-system-for-woocommerce

Installations
400+

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.
Plugin Slug:
tz-plus-gallery

Installations
400+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Sales Count Manager for WooCommerce

Plugin Slug:
wc-sales-count-manager

Installations
400+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Additional Fees For WooCommerce Checkout (Free)

Plugin Slug:
woo-additional-fees-on-checkout-wordpress

Installations
400+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Goracash

Plugin:

Goracash

Plugin Slug:
goracash

Installations
300+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

AnyClip Luminous Studio

Plugin Slug:
anyclip-media

Installations
200+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

AnyClip Luminous Studio

Plugin Slug:
anyclip-media

Installations
200+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Easy Pricing Table WP

Plugin Slug:
easy-pricing-table-wp

Installations
200+

Vulnerability:
Local File Inclusion

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Form Generator for WordPress

Plugin Slug:
form-generator-powered-by-jotform

Installations
200+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

immonex Kickstart Team

Plugin Slug:
immonex-kickstart-team

Installations
200+

Vulnerability:
Local File Inclusion

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

VoucherPress

Plugin Slug:
voucherpress

Installations
200+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Auction Feed

Plugin Slug:
auction-feed

Installations
100+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Editor Custom Color Palette

Plugin Slug:
editor-custom-color-palette

Installations
100+

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Magento 2 WordPress Integration

Plugin Slug:
m2wp

Installations
100+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Mavis HTTPS to HTTP Redirection

Plugin Slug:
mavis-https-to-http-redirect

Installations
100+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

NIX Anti-Spam Light

Plugin Slug:
nix-anti-spam-light

Installations
100+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

eZee Online Hotel Booking Engine

Plugin Slug:
online-booking-engine

Installations
100+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Proof Factor � Social Proof Notifications

Plugin Slug:
proof-factor-social-proof-notifications

Installations
100+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Sweet Energy Efficiency

Plugin Slug:
sweet-energy-efficiency

Installations
100+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Verowa Connect

Plugin Slug:
verowa-connect

Installations
100+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

LinkedInclude

Plugin Slug:
linkedinclude

Installations
90+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Mobi2Go

Plugin:

Mobi2Go

Plugin Slug:
mobi2go

Installations
90+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

GSheets Connector

Plugin Slug:
sheetlink

Installations
90+

Vulnerability:
PHP Object Injection

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Stock Message

Plugin Slug:
stock-message

Installations
90+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

WP Content Protection

Plugin Slug:
wp-content-protection

Installations
90+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

WPMK PDF Generator

Plugin Slug:
wpmk-pdf-generator

Installations
90+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

WordPress Adverts Plugin � Adverts Click Tracker

Plugin Slug:
adverts-click-tracker

Installations
80+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Current Age Plugin

Plugin Slug:
current-age

Installations
80+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Grid

Plugin:

Grid

Plugin Slug:
grid

Installations
80+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

HORIZONTAL SLIDER

Plugin Slug:
horizontal-slider

Installations
80+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

ShrinkTheWeb (STW) Website Previews Plugin

Plugin Slug:
shrinktheweb-website-preview-plugin

Installations
80+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Casengo Live Chat Support

Plugin Slug:
the-casengo-chat-widget

Installations
80+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Show Pages List

Plugin Slug:
show-pages-list

Installations
70+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Simple Restaurant Menu

Plugin Slug:
simple-restaurant-menu

Installations
70+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Doliconnect

Plugin Slug:
doliconnect

Installations
60+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Wide Banner

Plugin Slug:
wide-banner

Installations
50+

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

DOAJ Export

Plugin Slug:
doaj-export

Installations
40+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Gravitate Automated Tester

Plugin Slug:
gravitate-automated-tester

Installations
40+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

SAPO Feed

Plugin Slug:
sapo-feed

Installations
40+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Bg Church Memos

Plugin Slug:
bg-church-memos

Installations
30+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Wp tabber widget

Plugin Slug:
wp-tabber-widget

Installations
20+

Vulnerability:
SQL Injection

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Custom Post Type Images

Plugin Slug:
custom-post-types-image

Installations
10+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
Critical


The vulnerability has not been patched. You should deactivate the plugin.

Dialogity Free Live Chat

Plugin Slug:
dialogity-website-chat

Installations
10+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Service Finder SMS System

Plugin:

Service Finder SMS System

Plugin Slug:
aone-sms

Vulnerability:
Broken Authentication

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Browser Sniff

Plugin:

Browser Sniff

Plugin Slug:
browser-sniff

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Custom Login And Signup Widget

Plugin:

Custom Login And Signup Widget

Plugin Slug:
custom-login-and-signup-widget

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Directory Pro

Plugin:

Directory Pro

Plugin Slug:
directory-pro

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Event Rocket

Plugin:

Event Rocket

Plugin Slug:
event-rocket

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Printeers Print & Ship

Plugin:

Printeers Print & Ship

Plugin Slug:
invition-print-ship

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Javo Core

Plugin:

Javo Core

Plugin Slug:
javo-core

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

ListingPro Reviews

Plugin:

ListingPro Reviews

Plugin Slug:
listingpro-reviews

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Miniorange OTP Verification with Firebase

Plugin:

Miniorange OTP Verification with Firebase

Plugin Slug:
miniorange-firebase-sms-otp-verification

Vulnerability:
Privilege Escalation

Patched in Version:
No Fix

Severity Score:
Critical


The vulnerability has not been patched. You should deactivate the plugin.

Oshine Core

Plugin:

Oshine Core

Plugin Slug:
oshine-core

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

osTicket WP Bridge

Plugin:

osTicket WP Bridge

Plugin Slug:
osticket-wp-bridge

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Accordion FAQ

Plugin:

Accordion FAQ

Plugin Slug:
pressapps-accordion-faq

Vulnerability:
Local File Inclusion

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Robcore Netatmo

Plugin:

Robcore Netatmo

Plugin Slug:
robcore-netatmo

Vulnerability:
SQL Injection

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Service Finder Booking

Plugin:

Service Finder Booking

Plugin Slug:
sf-booking

Vulnerability:
Privilege Escalation

Patched in Version:
No Fix

Severity Score:
Critical


The vulnerability has not been patched. You should deactivate the plugin.

The Events Calendar

Plugin Slug:
the-events-calendar

Installations
700,000+

Vulnerability:
Broken Access Control

Patched in Version:
6.15.3

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 6.15.3.

Blocksy Companion

Plugin Slug:
blocksy-companion

Installations
300,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.1.11

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.1.11.

Admin and Site Enhancements (ASE)

Plugin Slug:
admin-site-enhancements

Installations
200,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
7.9.8

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 7.9.8.

Colibri Page Builder

Plugin Slug:
colibri-page-builder

Installations
100,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.0.334

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.0.334.

Download Manager

Plugin Slug:
download-manager

Installations
100,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
3.3.24

Severity Score:
High


The vulnerability has been patched, so you should update to version 3.3.24.

Kubio AI Page Builder

Plugin Slug:
kubio

Installations
100,000+

Vulnerability:
Broken Access Control

Patched in Version:
2.6.5

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.6.5.

Make Column Clickable for Elementor

Plugin Slug:
make-column-clickable-elementor

Installations
100,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.6.1

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.6.1.

Comments � wpDiscuz

Plugin Slug:
wpdiscuz

Installations
80,000+

Vulnerability:
Broken Access Control

Patched in Version:
7.6.34

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 7.6.34.

Media Library Assistant

Plugin Slug:
media-library-assistant

Installations
70,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
3.29

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 3.29.

WP-Members Membership Plugin

Plugin Slug:
wp-members

Installations
60,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
3.5.4.3

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 3.5.4.3.

Ajax Load More � Infinite Scroll

Plugin Slug:
ajax-load-more

Installations
40,000+

Vulnerability:
Sensitive Data Exposure

Patched in Version:
7.6.1

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 7.6.1.

Ibtana � WordPress Website Builder

Plugin Slug:
ibtana-visual-editor

Installations
20,000+

Vulnerability:
Arbitrary Content Deletion

Patched in Version:
1.2.5.4

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.2.5.4.

Quiz Maker

Plugin Slug:
quiz-maker

Installations
20,000+

Vulnerability:
SQL Injection

Patched in Version:
6.7.0.57

Severity Score:
Critical


The vulnerability has been patched, so you should update to version 6.7.0.57.

WP Import � Ultimate CSV XML Importer for WordPress

Plugin Slug:
wp-ultimate-csv-importer

Installations
20,000+

Vulnerability:
Remote Code Execution (RCE)

Patched in Version:
7.29

Severity Score:
Critical


The vulnerability has been patched, so you should update to version 7.29.

WP Import � Ultimate CSV XML Importer for WordPress

Plugin Slug:
wp-ultimate-csv-importer

Installations
20,000+

Vulnerability:
Arbitrary File Deletion

Patched in Version:
7.28

Severity Score:
High


The vulnerability has been patched, so you should update to version 7.28.

Blaze Demo Importer

Plugin Slug:
blaze-demo-importer

Installations
10,000+

Vulnerability:
Broken Access Control

Patched in Version:
1.0.13

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.0.13.
Plugin Slug:
seo-automated-link-building

Installations
10,000+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
3.0.2

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 3.0.2.

WP Hotel Booking

Plugin Slug:
wp-hotel-booking

Installations
8,000+

Vulnerability:
Content Injection

Patched in Version:
2.2.3

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.2.3.

CubeWP � All-in-One Dynamic Content Framework

Plugin Slug:
cubewp-framework

Installations
5,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.1.27

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.1.27.
Plugin Slug:
termageddon-usercentrics

Installations
5,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.8.2

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.8.2.

Etsy Shop

Plugin Slug:
etsy-shop

Installations
4,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
3.0.7

Severity Score:
High


The vulnerability has been patched, so you should update to version 3.0.7.

Podlove Podcast Publisher

Plugin Slug:
podlove-podcasting-plugin-for-wordpress

Installations
4,000+

Vulnerability:
Arbitrary File Upload

Patched in Version:
4.2.7

Severity Score:
Critical


The vulnerability has been patched, so you should update to version 4.2.7.

Smart Blocks

Plugin Slug:
smart-blocks

Installations
2,000+

Vulnerability:
Broken Access Control

Patched in Version:
2.5

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.5.

Payrexx Payment Gateway for WooCommerce

Plugin Slug:
woo-payrexx-gateway

Installations
2,000+

Vulnerability:
Broken Access Control

Patched in Version:
3.1.6

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 3.1.6.

Password Reset with Code for WordPress REST API

Plugin Slug:
bdvs-password-reset

Installations
1,000+

Vulnerability:
Other Vulnerability Type

Patched in Version:
0.0.17

Severity Score:
High


The vulnerability has been patched, so you should update to version 0.0.17.

Chained Quiz

Plugin Slug:
chained-quiz

Installations
1,000+

Vulnerability:
Insecure Direct Object References (IDOR)

Patched in Version:
1.3.6

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.3.6.

Custom Login URL

Plugin Slug:
custom-login-url

Installations
1,000+

Vulnerability:
Broken Access Control

Patched in Version:
1.0.3

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.0.3.

Easy Elementor Addons

Plugin Slug:
easy-elementor-addons

Installations
1,000+

Vulnerability:
Local File Inclusion

Patched in Version:
2.2.9

Severity Score:
High


The vulnerability has been patched, so you should update to version 2.2.9.

GetResponse Forms by Optin Cat

Plugin Slug:
getresponse

Installations
1,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.6.1

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.6.1.

Markup Markdown

Plugin Slug:
markup-markdown

Installations
1,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
3.20.10

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 3.20.10.

Product Catalog Simple

Plugin Slug:
post-type-x

Installations
1,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.8.3

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.8.3.

Save as PDF Plugin by PDFCrowd

Plugin Slug:
save-as-pdf-by-pdfcrowd

Installations
1,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
4.5.3

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 4.5.3.

WPCasa

Plugin:

WPCasa

Plugin Slug:
wpcasa

Installations
1,000+

Vulnerability:
Remote Code Execution (RCE)

Patched in Version:
1.4.2

Severity Score:
Critical


The vulnerability has been patched, so you should update to version 1.4.2.

WPComplete

Plugin Slug:
wpcomplete

Installations
1,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.9.5.3

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.9.5.3.
Plugin Slug:
affiliatewp-external-referral-links

Installations
900+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.2.2

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.2.2.
Plugin Slug:
fusion-extension-gallery

Installations
700+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.7.7

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.7.7.

List Child Pages Shortcode

Plugin Slug:
list-child-pages-shortcode

Installations
600+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.4.0

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.4.0.

Publitio

Plugin:

Publitio

Plugin Slug:
publitio

Installations
500+

Vulnerability:
Server Side Request Forgery (SSRF)

Patched in Version:
2.2.2

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.2.2.

The Hack Repair Guy’s Plugin Archiver

Plugin Slug:
hackrepair-plugin-archiver

Installations
400+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
3.1.1

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 3.1.1.

IP Based Login

Plugin Slug:
ip-based-login

Installations
400+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.4.4

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.4.4.

Developer Loggers for Simple History

Plugin Slug:
developer-loggers-for-simple-history

Installations
300+

Vulnerability:
Local File Inclusion

Patched in Version:
0.5.1

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 0.5.1.

Secure Passkeys

Plugin Slug:
secure-passkeys

Installations
300+

Vulnerability:
Broken Access Control

Patched in Version:
1.2.2

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.2.2.

User Sync

Plugin Slug:
user-sync

Installations
200+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
1.0.3

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.0.3.

Appointmind

Plugin Slug:
appointmind

Installations
100+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
4.2.0

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 4.2.0.

Catch Dark Mode

Plugin Slug:
catch-dark-mode

Installations
50+

Vulnerability:
Local File Inclusion

Patched in Version:
2.0.1

Severity Score:
High


The vulnerability has been patched, so you should update to version 2.0.1.

Draft List

Plugin Slug:
simple-draft-list

Installations
50+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.6.1

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.6.1.

Social Media Shortcodes

Plugin Slug:
social-media-shortcodes

Installations
50+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.3.2

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.3.2.

USS Upyun

Plugin Slug:
uss-upyun

Installations
50+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
1.5.1

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.5.1.

Embed PDF for WPForms

Plugin Slug:
embed-pdf-wpforms

Installations
40+

Vulnerability:
Arbitrary File Upload

Patched in Version:
1.1.6

Severity Score:
Critical


The vulnerability has been patched, so you should update to version 1.1.6.

Widget Options – Extended

Plugin:

Widget Options – Extended

Plugin Slug:
extended-widget-options

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
5.2.2

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 5.2.2.

Penci Filter Everything

Plugin:

Penci Filter Everything

Plugin Slug:
penci-filter-everything

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.7

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.7.

Penci Podcast

Plugin:

Penci Podcast

Plugin Slug:
penci-podcast

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.7

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.7.

Penci Portfolio

Plugin:

Penci Portfolio

Plugin Slug:
penci-portfolio

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
3.6

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 3.6.

Penci Recipe

Plugin:

Penci Recipe

Plugin Slug:
penci-recipe

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
4.1

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 4.1.

Penci Shortcodes & Performance

Plugin:

Penci Shortcodes & Performance

Plugin Slug:
penci-shortcodes

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
6.1

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 6.1.

Uni CPO (Premium)

Plugin:

Uni CPO (Premium)

Plugin Slug:
uni-woo-custom-product-options-premium

Vulnerability:
Arbitrary File Upload

Patched in Version:
4.9.55

Severity Score:
Critical


The vulnerability has been patched, so you should update to version 4.9.55.

WorkScout-Core

Plugin:

WorkScout-Core

Plugin Slug:
workscout-core

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
1.7.06

Severity Score:
High


The vulnerability has been patched, so you should update to version 1.7.06.

WP Attractive Donations System

Plugin:

WP Attractive Donations System

Plugin Slug:
wp-attractive-donations-system-easy-stripe-paypal-donations

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
1.29

Severity Score:
High


The vulnerability has been patched, so you should update to version 1.29.

WordPress Themes � 4 Patched / 9 Unpatched

Constructo

Theme:

Constructo

Theme Slug:
constructo

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should switch themes.

CouponXxL

Theme:

CouponXxL

Theme Slug:
couponxxl

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should switch themes.

DriCub

Theme:

DriCub

Theme Slug:
dricub-driving-school

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should switch themes.

DriCub

Theme:

DriCub

Theme Slug:
dricub-driving-school

Vulnerability:
Server Side Request Forgery (SSRF)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should switch themes.

Entrada

Theme:

Entrada

Theme Slug:
entrada

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should switch themes.

Findgo

Theme:

Findgo

Theme Slug:
fingo

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should switch themes.

imEvent

Theme:

imEvent

Theme Slug:
imevent

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should switch themes.

Nokri

Theme:

Nokri

Theme Slug:
nokri

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should switch themes.

WPLMS

Theme:

WPLMS

Theme Slug:
wplms

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should switch themes.

Sydney

Theme:

Sydney

Theme Slug:
sydney

Downloads
4,661,099

Vulnerability:
Broken Access Control

Patched in Version:
2.57

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.57.

Leblix

Theme:

Leblix

Theme Slug:
leblix

Vulnerability:
Local File Inclusion

Patched in Version:
2.5

Severity Score:
High


The vulnerability has been patched, so you should update to version 2.5.

Soledad

Theme:

Soledad

Theme Slug:
soledad

Vulnerability:
Local File Inclusion

Patched in Version:
8.6.9

Severity Score:
High


The vulnerability has been patched, so you should update to version 8.6.9.

Soledad

Theme:

Soledad

Theme Slug:
soledad

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
8.6.9

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 8.6.9.

Related articles

Wait! Get exclusive hosting insights

Subscribe to our newsletter and stay ahead of the competition with expert advice from our hosting pros.

Loading form…