In this report, 113 vulnerabilities have been publicly disclosed. Security patches for 60 of these plugins and themes are available now, so run those updates as soon as possible. If you’re a Solid Security Pro user, the version management tool may have already warned you and updated these plugins, depending on your settings.

Additionally, there are 53 plugin and theme vulnerabilities, and no patch has been available yet. If you’re a Solid Security Pro user, those vulnerabilities are already protected by the Solid Security firewall. Virtual patches from Patchstack will be applied when a vulnerability is considered high or medium risk. If no patch is forthcoming from the vendor or the vulnerable software has been marked “closed” and dropped from the official WordPress repositories, you should deactivate it soon and look for alternative solutions.

Along with poor user account security, vulnerable plugins and themes are among the top reasons why WordPress websites get hacked. Unfortunately, cyberattacks are increasing in volume and sophistication. They’re also increasingly aimed at small to mid-sized businesses.

Our WordPress Vulnerability Report covers the latest emerging WordPress plugin, theme, and core vulnerabilities. Each vulnerability will have a severity rating of LowMediumHigh, or Critical. Responsible disclosure of vulnerabilities is essential to keeping the WordPress community safe. Please share this report to help spread the word and make WordPress — and the web — more secure.

WordPress Core

WordPress 6.8.2 was released on July 15, 2025. This maintenance release includes fixes for 20 Core tickets and 15 Block Editor issues. For a full list of bug fixes, please refer to the release candidate announcement.

No new core vulnerabilities were disclosed this week.

WordPress Plugins — 50 Patched / 50 Unpatched

Structured Content (JSON-LD) #wpsc

Plugin Slug:
structured-content

Installations
50,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Graphina – Elementor Charts and Graphs

Plugin Slug:
graphina-elementor-charts-and-graphs

Installations
10,000+

Vulnerability:
Local File Inclusion

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

WP Links Page

Plugin Slug:
wp-links-page

Installations
4,000+

Vulnerability:
SQL Injection

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Video Blogster Lite

Plugin Slug:
video-blogster-lite

Installations
1,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Featured Image Plus – Quick & Bulk Edit with Unsplash

Plugin Slug:
featured-image-plus

Installations
700+

Vulnerability:
Server Side Request Forgery (SSRF)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

WP Pipes

Plugin:

WP Pipes

Plugin Slug:
wp-pipes

Installations
500+

Vulnerability:
Local File Inclusion

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

CaptionPix

Plugin:

CaptionPix

Plugin Slug:
captionpix

Installations
100+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

ONLYOFFICE Docs

Plugin Slug:
onlyoffice

Installations
100+

Vulnerability:
Privilege Escalation

Patched in Version:
No Fix

Severity Score:
Critical


The vulnerability has not been patched. You should deactivate the plugin.

Nginx Cache Purge Preload

Plugin Slug:
fastcgi-cache-purge-and-preload-nginx

Installations
70+

Vulnerability:
Remote Code Execution (RCE)

Patched in Version:
No Fix

Severity Score:
Critical


The vulnerability has not been patched. You should deactivate the plugin.

Supreme Addons for Beaver Builder –

Plugin Slug:
supreme-addons-for-beaver-builder-lite

Installations
60+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

WP Get The Table

Plugin Slug:
wp-get-the-table

Installations
50+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

WooCommerce Point Of Sale (POS)

Plugin Slug:
woo-point-of-salepos

Installations
40+

Vulnerability:
SQL Injection

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Advanced Google Universal Analytics

Plugin:

Advanced Google Universal Analytics

Plugin Slug:
advanced-google-universal-analytics

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Affiliate Plus

Plugin:

Affiliate Plus

Plugin Slug:
affiliate-plus

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Post Grid Master

Plugin:

Post Grid Master

Plugin Slug:
ajax-filter-posts

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Birth Chart Compatibility

Plugin:

Birth Chart Compatibility

Plugin Slug:
birth-chart-compatibility

Vulnerability:
Full Path Disclosure (FPD)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

bSecure – Your Universal Checkout

Plugin:

bSecure – Your Universal Checkout

Plugin Slug:
bsecure

Vulnerability:
Privilege Escalation

Patched in Version:
No Fix

Severity Score:
Critical


The vulnerability has not been patched. You should deactivate the plugin.

Valuation Calculator

Plugin:

Valuation Calculator

Plugin Slug:
commercial-real-estate-valuation-calculator

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Droip

Plugin:

Droip

Plugin Slug:
droip

Vulnerability:
Arbitrary File Upload

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Droip

Plugin:

Droip

Plugin Slug:
droip

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Fan Page

Plugin:

Fan Page

Plugin Slug:
fan-page

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Fleetwire Fleet Management

Plugin:

Fleetwire Fleet Management

Plugin Slug:
fleetwire-fleet-management

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Get Youtube Subs

Plugin:

Get Youtube Subs

Plugin Slug:
get-youtube-subs

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

hiWeb Export Posts

Plugin:

hiWeb Export Posts

Plugin Slug:
hiweb-export-posts

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

iThoughts Advanced Code Editor

Plugin:

iThoughts Advanced Code Editor

Plugin Slug:
ithoughts-advanced-code-editor

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Latest Post Accordian Slider

Plugin:

Latest Post Accordian Slider

Plugin Slug:
latest-post-accordian-slider

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Like & Share My Site

Plugin:

Like & Share My Site

Plugin Slug:
like-share-my-site

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

LoginWP – Pro

Plugin:

LoginWP – Pro

Plugin Slug:
loginwp-pro

Vulnerability:
Settings Change

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Mine CloudVod

Plugin:

Mine CloudVod

Plugin Slug:
mine-cloudvod

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

muse.ai video embedding

Plugin:

muse.ai video embedding

Plugin Slug:
muse-ai

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

My Reservation System

Plugin:

My Reservation System

Plugin Slug:
my-reservation-system

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Omnishop

Plugin:

Omnishop

Plugin Slug:
omnishop

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Omnishop

Plugin:

Omnishop

Plugin Slug:
omnishop

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Orion Login with SMS

Plugin:

Orion Login with SMS

Plugin Slug:
orion-login-with-sms

Vulnerability:
Broken Authentication

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

The E-Commerce ERP

Plugin:

The E-Commerce ERP

Plugin Slug:
profitori

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Qwizcards

Plugin:

Qwizcards

Plugin Slug:
qwiz-online-quizzes-and-flashcards

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Realty Portal – Agent

Plugin:

Realty Portal – Agent

Plugin Slug:
realty-portal-agent

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

RT-Theme 18 | Extensions

Plugin:

RT-Theme 18 | Extensions

Plugin Slug:
rt18-extensions

Vulnerability:
Local File Inclusion

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Social Streams

Plugin:

Social Streams

Plugin Slug:
social-streams

Vulnerability:
Privilege Escalation

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Station Pro

Plugin:

Station Pro

Plugin Slug:
station-pro

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Supermalink

Plugin:

Supermalink

Plugin Slug:
supermalink

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Tablesome Table Premium

Plugin:

Tablesome Table Premium

Plugin Slug:
tablesome-premium

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Taeggie Feed

Plugin:

Taeggie Feed

Plugin Slug:
taeggie-feed

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Voltax Video Player

Plugin:

Voltax Video Player

Plugin Slug:
voltax-video-player

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

WP Applink

Plugin:

WP Applink

Plugin Slug:
wp-applink

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

WP JobHunt

Plugin:

WP JobHunt

Plugin Slug:
wp-jobhunt

Vulnerability:
Insecure Direct Object References (IDOR)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

WP Wallcreeper

Plugin:

WP Wallcreeper

Plugin Slug:
wp-wallcreeper

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

YANewsflash

Plugin:

YANewsflash

Plugin Slug:
yanewsflash

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

YouTube Embed – YouTube Gallery, Vimeo Gallery – WordPress Plugin

Plugin:

YouTube Embed – YouTube Gallery, Vimeo Gallery – WordPress Plugin

Plugin Slug:
youram-youtube-embed

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Elementor Website Builder – More Than Just a Page Builder

Plugin Slug:
elementor

Installations
10,000,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
3.30.3

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 3.30.3.

WP Shortcodes Plugin — Shortcodes Ultimate

Plugin Slug:
shortcodes-ultimate

Installations
500,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
7.4.3

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 7.4.3.

Post SMTP – WP SMTP Plugin with Email Logs and Mobile App for Failure Notifications – Gmail SMTP, Office 365, Brevo, Mailgun, Amazon SES and more

Plugin Slug:
post-smtp

Installations
400,000+

Vulnerability:
Broken Authentication

Patched in Version:
3.3.0

Severity Score:
High


The vulnerability has been patched, so you should update to version 3.3.0.

SureForms – Drag and Drop Form Builder for WordPress

Plugin Slug:
sureforms

Installations
200,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.7.2

Severity Score:
High


The vulnerability has been patched, so you should update to version 1.7.2.

AI Engine

Plugin:

AI Engine

Plugin Slug:
ai-engine

Installations
100,000+

Vulnerability:
Arbitrary File Download

Patched in Version:
2.9.5

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.9.5.

Brizy – Page Builder

Plugin Slug:
brizy

Installations
80,000+

Vulnerability:
Broken Access Control

Patched in Version:
2.6.21

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.6.21.

User Registration & Membership – Custom Registration Form Builder, Custom Login Form, User Profile, Content Restriction & Membership Plugin

Plugin Slug:
user-registration

Installations
60,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
4.3.0

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 4.3.0.

WP-Members Membership Plugin

Plugin Slug:
wp-members

Installations
60,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
3.5.4.2

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 3.5.4.2.

Advanced iFrame

Plugin Slug:
advanced-iframe

Installations
50,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2025.6

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2025.6.

Timber

Plugin:

Timber

Plugin Slug:
timber-library

Installations
30,000+

Vulnerability:
Other Vulnerability Type

Patched in Version:
1.23.3

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.23.3.

CSS & JavaScript Toolbox

Plugin Slug:
css-javascript-toolbox

Installations
10,000+

Vulnerability:
Local File Inclusion

Patched in Version:
12.0.3

Severity Score:
High


The vulnerability has been patched, so you should update to version 12.0.3.

Wonder Slider Lite

Plugin Slug:
wonderplugin-slider-lite

Installations
10,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
14.5

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 14.5.

WP REST Cache

Plugin Slug:
wp-rest-cache

Installations
10,000+

Vulnerability:
Local File Inclusion

Patched in Version:
2025.1.1

Severity Score:
High


The vulnerability has been patched, so you should update to version 2025.1.1.

WPeMatico RSS Feed Fetcher

Plugin Slug:
wpematico

Installations
10,000+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
2.8.8

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.8.8.

Security Ninja – WordPress Security Plugin & Firewall

Plugin Slug:
security-ninja

Installations
9,000+

Vulnerability:
Arbitrary File Download

Patched in Version:
5.243

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 5.243.

ProfileGrid – User Profiles, Groups and Communities

Plugin Slug:
profilegrid-user-profiles-groups-and-communities

Installations
7,000+

Vulnerability:
SQL Injection

Patched in Version:
5.9.5.4

Severity Score:
High


The vulnerability has been patched, so you should update to version 5.9.5.4.

Simple File List

Plugin Slug:
simple-file-list

Installations
6,000+

Vulnerability:
Arbitrary File Download

Patched in Version:
6.1.15

Severity Score:
High


The vulnerability has been patched, so you should update to version 6.1.15.

Geo Mashup

Plugin:

Geo Mashup

Plugin Slug:
geo-mashup

Installations
2,000+

Vulnerability:
Local File Inclusion

Patched in Version:
1.13.17

Severity Score:
Critical


The vulnerability has been patched, so you should update to version 1.13.17.

Melapress Login Security

Plugin Slug:
melapress-login-security

Installations
2,000+

Vulnerability:
Privilege Escalation

Patched in Version:
2.2.0

Severity Score:
Critical


The vulnerability has been patched, so you should update to version 2.2.0.

Custom API for WP

Plugin Slug:
custom-api-for-wp

Installations
1,000+

Vulnerability:
Privilege Escalation

Patched in Version:
4.2.3

Severity Score:
Critical


The vulnerability has been patched, so you should update to version 4.2.3.

Ebook Store

Plugin Slug:
ebook-store

Installations
1,000+

Vulnerability:
Arbitrary File Upload

Patched in Version:
5.8013

Severity Score:
Critical


The vulnerability has been patched, so you should update to version 5.8013.

Ebook Store

Plugin Slug:
ebook-store

Installations
1,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
5.8013

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 5.8013.

Frontend File Manager Plugin

Plugin Slug:
nmedia-user-file-uploader

Installations
1,000+

Vulnerability:
Broken Access Control

Patched in Version:
22.0

Severity Score:
High


The vulnerability has been patched, so you should update to version 22.0.

SEOPress for MainWP

Plugin Slug:
seopress-for-mainwp

Installations
1,000+

Vulnerability:
Local File Inclusion

Patched in Version:
1.5

Severity Score:
High


The vulnerability has been patched, so you should update to version 1.5.

StreamWeasels Twitch Integration

Plugin Slug:
streamweasels-twitch-integration

Installations
1,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.9.4

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.9.4.

SureDash

Plugin:

SureDash

Plugin Slug:
suredash

Installations
500+

Vulnerability:
Privilege Escalation

Patched in Version:
1.1.0

Severity Score:
High


The vulnerability has been patched, so you should update to version 1.1.0.

CRM and Lead Management by vcita

Plugin Slug:
crm-customer-relationship-management-by-vcita

Installations
100+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.8.0

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.8.0.

ReachShip WooCommerce Multi-Carrier & Conditional Shipping

Plugin Slug:
elex-reachship-multi-carrier-conditional-shipping

Installations
100+

Vulnerability:
Arbitrary File Upload

Patched in Version:
4.3.2

Severity Score:
Critical


The vulnerability has been patched, so you should update to version 4.3.2.

Dataverse Integration

Plugin Slug:
integration-cds

Installations
100+

Vulnerability:
Privilege Escalation

Patched in Version:
2.81.1

Severity Score:
High


The vulnerability has been patched, so you should update to version 2.81.1.

WPBookit

Plugin:

WPBookit

Plugin Slug:
wpbookit

Installations
30+

Vulnerability:
Arbitrary File Upload

Patched in Version:
1.0.7

Severity Score:
Critical


The vulnerability has been patched, so you should update to version 1.0.7.

Elite Video Player

Plugin:

Elite Video Player

Plugin Slug:
elite-video-player

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
10.0.7

Severity Score:
High


The vulnerability has been patched, so you should update to version 10.0.7.

Foxypress

Plugin:

Foxypress

Plugin Slug:
foxypress

Vulnerability:
Arbitrary File Upload

Patched in Version:
0.4.2.2

Severity Score:
Critical


The vulnerability has been patched, so you should update to version 0.4.2.2.

WPBakery Page Builder

Plugin:

WPBakery Page Builder

Plugin Slug:
js_composer

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
8.5

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 8.5.

Responsive HTML5 Audio Player PRO With Playlist

Plugin:

Responsive HTML5 Audio Player PRO With Playlist

Plugin Slug:
lbg-audio2-html5

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
3.5.9

Severity Score:
High


The vulnerability has been patched, so you should update to version 3.5.9.

Universal Video Player – Addon for WPBakery Page Builder

Plugin:

Universal Video Player – Addon for WPBakery Page Builder

Plugin Slug:
lbg-universal-video-player-addon-visual-composer

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
3.2.2.0

Severity Score:
High


The vulnerability has been patched, so you should update to version 3.2.2.0.

Simple Business Directory Pro

Plugin:

Simple Business Directory Pro

Plugin Slug:
simple-business-directory-pro

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
15.5.2

Severity Score:
High


The vulnerability has been patched, so you should update to version 15.5.2.

Support Board

Plugin:

Support Board

Plugin Slug:
supportboard

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
3.8.1

Severity Score:
High


The vulnerability has been patched, so you should update to version 3.8.1.

Support Board

Plugin:

Support Board

Plugin Slug:
supportboard

Vulnerability:
Local File Inclusion

Patched in Version:
3.8.1

Severity Score:
High


The vulnerability has been patched, so you should update to version 3.8.1.

Youtube Vimeo Video Player and Slider WP Plugin

Plugin:

Youtube Vimeo Video Player and Slider WP Plugin

Plugin Slug:
video-player-youtube-vimeo

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
3.9

Severity Score:
High


The vulnerability has been patched, so you should update to version 3.9.

Wonder Slider

Plugin:

Wonder Slider

Plugin Slug:
wonderplugin-slider

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
14.5

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 14.5.

WordPress Themes — 10 Patched / 3 Unpatched

Educenter

Theme Slug:
educenter

Downloads
175,744

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should switch themes.

News Magazine X

Theme Slug:
news-magazine-x

Downloads
27,720

Vulnerability:
Local File Inclusion

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should switch themes.

VidMov

Theme:

VidMov

Theme Slug:
vidmov

Vulnerability:
Local File Inclusion

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should switch themes.

Bricks Builder

Theme:

Bricks Builder

Theme Slug:
bricks

Vulnerability:
SQL Injection

Patched in Version:
2.0

Severity Score:
Critical


The vulnerability has been patched, so you should update to version 2.0.

Caliris

Theme:

Caliris

Theme Slug:
caliris-wp

Vulnerability:
Local File Inclusion

Patched in Version:
1.6

Severity Score:
High


The vulnerability has been patched, so you should update to version 1.6.

Cena Store

Theme:

Cena Store

Theme Slug:
cena

Vulnerability:
Local File Inclusion

Patched in Version:
2.11.27

Severity Score:
High


The vulnerability has been patched, so you should update to version 2.11.27.

KALLYAS – Creative eCommerce Multi-Purpose WordPress Theme

Theme:

KALLYAS – Creative eCommerce Multi-Purpose WordPress Theme

Theme Slug:
kallyas

Vulnerability:
Arbitrary File Deletion

Patched in Version:
4.22.0

Severity Score:
High


The vulnerability has been patched, so you should update to version 4.22.0.

KALLYAS – Creative eCommerce Multi-Purpose WordPress Theme

Theme:

KALLYAS – Creative eCommerce Multi-Purpose WordPress Theme

Theme Slug:
kallyas

Vulnerability:
Local File Inclusion

Patched in Version:
4.22.0

Severity Score:
High


The vulnerability has been patched, so you should update to version 4.22.0.

MediCenter – Health Medical Clinic

Theme:

MediCenter – Health Medical Clinic

Theme Slug:
medicenter

Vulnerability:
PHP Object Injection

Patched in Version:
15.2

Severity Score:
Critical


The vulnerability has been patched, so you should update to version 15.2.

MinimogWP

Theme:

MinimogWP

Theme Slug:
minimog

Vulnerability:
Content Injection

Patched in Version:
3.9.1

Severity Score:
High


The vulnerability has been patched, so you should update to version 3.9.1.

Jobmonster

Theme:

Jobmonster

Theme Slug:
noo-jobmonster

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
4.7.9

Severity Score:
High


The vulnerability has been patched, so you should update to version 4.7.9.

Platform

Theme:

Platform

Theme Slug:
platform

Vulnerability:
Broken Access Control

Patched in Version:
1.4.4

Severity Score:
Critical


The vulnerability has been patched, so you should update to version 1.4.4.

WoodMart

Theme:

WoodMart

Theme Slug:
woodmart

Vulnerability:
Broken Access Control

Patched in Version:
8.2.7

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 8.2.7.

Solid Security is part of Solid Suite — The best foundation for WordPress websites.

Every WordPress site needs security, backups, and management tools. That’s Solid Suite — an integrated bundle of three plugins: Solid Security, Solid Backups, and Solid Central. You also get access to Solid Academy’s learning resources for WordPress professionals. Build your next WordPress website on a solid foundation with Solid Suite!

Get Solid Security


The post WordPress Vulnerability Report — July 30, 2025 appeared first on SolidWP.

Click here to continue reading this article.