In this report, 83 vulnerabilities have been publicly disclosed. Security patches for 51 of these plugins and themes are now available, so please run those updates as soon as possible. If you’re a Solid Security Pro user, the version management tool may have already warned you and updated these plugins, depending on your settings.

Additionally, there are 32 plugin and theme vulnerabilities, and no patch has been available yet. If you’re a Solid Security Pro user, those vulnerabilities are already protected by the Solid Security firewall. Virtual patches from Patchstack will be applied when a vulnerability is considered high or medium risk. If no patch is forthcoming from the vendor or the vulnerable software has been marked “closed” and dropped from the official WordPress repositories, you should deactivate it soon and look for alternative solutions.

Along with poor user account security, vulnerable plugins and themes are among the top reasons why WordPress websites get hacked. Unfortunately, cyberattacks are increasing in volume and sophistication. They’re also increasingly aimed at small to mid-sized businesses.

Our WordPress Vulnerability Report covers the latest emerging WordPress plugin, theme, and core vulnerabilities. Each vulnerability will have a severity rating of LowMediumHigh, or Critical. Responsible disclosure of vulnerabilities is essential to keeping the WordPress community safe. Please share this report to help spread the word and make WordPress — and the web — more secure.

WordPress Core

WordPress 6.8.2 was released on July 15, 2025. This maintenance release includes fixes for 20 Core tickets and 15 Block Editor issues. For a full list of bug fixes, please refer to the release candidate announcement.

No new core vulnerabilities were disclosed this week.

WordPress Plugins — 46 Patched / 31 Unpatched

Eventer

Plugin:

Eventer

Plugin Slug:
eventer

Installations
1,000+

Vulnerability:
Content Injection

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Porn Videos Embed

Plugin Slug:
porn-videos-embed

Installations
1,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

CF7 Spreadsheets

Plugin Slug:
cf7-spreadsheets

Installations
400+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Flex Guten – Multile Blocks

Plugin Slug:
flex-guten

Installations
400+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

WooCommerce Fortnox Integration

Plugin Slug:
woocommerce-fortnox-integration

Installations
300+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

SMM API

Plugin:

SMM API

Plugin Slug:
smm-api

Installations
200+

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Project Cost Calculator

Plugin Slug:
project-cost-calculator

Installations
100+

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

WP-jScrollPane

Plugin Slug:
wp-jscrollpane

Installations
100+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

BaiduXZH Submit(?????)

Plugin Slug:
i3geek-baiduxzh

Installations
90+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

????????

Plugin:

????????

Plugin Slug:
duoshuo

Installations
80+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

User Language Switch

Plugin Slug:
user-language-switch

Installations
80+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Visit Counter

Plugin Slug:
visit-counter

Installations
80+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Premium Addons for KingComposer

Plugin Slug:
premium-addons-for-kingcomposer

Installations
70+

Vulnerability:
Local File Inclusion

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Simple Responsive Slider

Plugin:

Simple Responsive Slider

Plugin Slug:
addi-simple-slider

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

CBX Restaurant Booking

Plugin:

CBX Restaurant Booking

Plugin Slug:
cbx-restaurant-booking

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

CleverReach® WP

Plugin:

CleverReach® WP

Plugin Slug:
cleverreach-wp

Vulnerability:
SQL Injection

Patched in Version:
No Fix

Severity Score:
Critical


The vulnerability has not been patched. You should deactivate the plugin.

CleverReach® WP

Plugin:

CleverReach® WP

Plugin Slug:
cleverreach-wp

Vulnerability:
SQL Injection

Patched in Version:
No Fix

Severity Score:
Critical


The vulnerability has not been patched. You should deactivate the plugin.

esri-map-view

Plugin:

esri-map-view

Plugin Slug:
esri-map-view

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

GMap Generator

Plugin:

GMap Generator

Plugin Slug:
gmap-venturit

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

IDonatePro

Plugin:

IDonatePro

Plugin Slug:
idonate-pro

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Inline Stock Quotes

Plugin:

Inline Stock Quotes

Plugin Slug:
inline-stock-quotes

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

WP Lead Capturing Pages

Plugin:

WP Lead Capturing Pages

Plugin Slug:
leadcapture

Vulnerability:
Arbitrary Content Deletion

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Mmm Unity Loader

Plugin:

Mmm Unity Loader

Plugin Slug:
mmm-unity-loader

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Mosaic Generator

Plugin:

Mosaic Generator

Plugin Slug:
mosaic-generator

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

RT Easy Builder – Advanced addons for Elementor

Plugin:

RT Easy Builder – Advanced addons for Elementor

Plugin Slug:
rt-easy-builder-advanced-addons-for-elementor

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

OpenStreetMap for Gutenberg and WPBakery Page Builder (formerly Visual Composer)

Plugin:

OpenStreetMap for Gutenberg and WPBakery Page Builder (formerly Visual Composer)

Plugin Slug:
stepbyteservice-openstreetmap

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

WooCommerce Purchase Orders

Plugin:

WooCommerce Purchase Orders

Plugin Slug:
wc-purchase-orders

Vulnerability:
Arbitrary File Deletion

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Wp chart generator

Plugin:

Wp chart generator

Plugin Slug:
wp-chart-generator

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

WP Private Content Plus

Plugin:

WP Private Content Plus

Plugin Slug:
wp-private-content-plus

Vulnerability:
Sensitive Data Exposure

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

WP Tournament Registration

Plugin:

WP Tournament Registration

Plugin Slug:
wp-tournament-registration

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Advanced Custom Fields (ACF®)

Plugin Slug:
advanced-custom-fields

Installations
2,000,000+

Vulnerability:
Remote Code Execution (RCE)

Patched in Version:
3.5.2

Severity Score:
Low


The vulnerability has been patched, so you should update to version 3.5.2.

Qi Addons For Elementor

Plugin Slug:
qi-addons-for-elementor

Installations
200,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.9.3

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.9.3.

Simple Local Avatars

Plugin Slug:
simple-local-avatars

Installations
100,000+

Vulnerability:
Broken Access Control

Patched in Version:
2.8.5

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.8.5.

Ocean Social Sharing

Plugin Slug:
ocean-social-sharing

Installations
80,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.2.2

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.2.2.

Exclusive Addons for Elementor

Plugin Slug:
exclusive-addons-for-elementor

Installations
60,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.7.9.5

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.7.9.5.

WP Import Export Lite

Plugin Slug:
wp-import-export-lite

Installations
50,000+

Vulnerability:
Arbitrary File Upload

Patched in Version:
3.9.30

Severity Score:
Critical


The vulnerability has been patched, so you should update to version 3.9.30.

WP Import Export Lite

Plugin Slug:
wp-import-export-lite

Installations
50,000+

Vulnerability:
Arbitrary File Upload

Patched in Version:
3.9.29

Severity Score:
Critical


The vulnerability has been patched, so you should update to version 3.9.29.

UiCore Elements – Free Elementor widgets and templates

Plugin Slug:
uicore-elements

Installations
40,000+

Vulnerability:
Arbitrary File Download

Patched in Version:
1.3.1

Severity Score:
High


The vulnerability has been patched, so you should update to version 1.3.1.

Coupon Affiliates – Affiliate Plugin for WooCommerce

Plugin Slug:
woo-coupon-usage

Installations
4,000+

Vulnerability:
Settings Change

Patched in Version:
6.4.2

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 6.4.2.

GravityWP – Merge Tags

Plugin Slug:
gravitywp-merge-tags

Installations
2,000+

Vulnerability:
Local File Inclusion

Patched in Version:
1.4.5

Severity Score:
High


The vulnerability has been patched, so you should update to version 1.4.5.

AnWP Football Leagues

Plugin Slug:
football-leagues-by-anwppro

Installations
1,000+

Vulnerability:
CSV Injection

Patched in Version:
0.16.18

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 0.16.18.

Prevent files / folders access

Plugin Slug:
prevent-file-access

Installations
1,000+

Vulnerability:
Path Traversal

Patched in Version:
2.6.1

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.6.1.

FundEngine – Donation and Crowdfunding Platform

Plugin Slug:
wp-fundraising-donation

Installations
1,000+

Vulnerability:
Local File Inclusion

Patched in Version:
1.7.5

Severity Score:
High


The vulnerability has been patched, so you should update to version 1.7.5.

B Blocks – The ultimate block collection

Plugin Slug:
b-blocks

Installations
800+

Vulnerability:
Privilege Escalation

Patched in Version:
2.0.7

Severity Score:
Critical


The vulnerability has been patched, so you should update to version 2.0.7.

Code Engine

Plugin Slug:
code-engine

Installations
600+

Vulnerability:
Remote Code Execution (RCE)

Patched in Version:
0.3.4

Severity Score:
Critical


The vulnerability has been patched, so you should update to version 0.3.4.

Form Block

Plugin:

Form Block

Plugin Slug:
form-block

Installations
200+

Vulnerability:
Arbitrary File Upload

Patched in Version:
1.5.6

Severity Score:
Critical


The vulnerability has been patched, so you should update to version 1.5.6.

RentSyst – CRM solution for fleet management

Plugin Slug:
rentsyst

Installations
100+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.0.101

Severity Score:
High


The vulnerability has been patched, so you should update to version 2.0.101.

Download Counter

Plugin Slug:
download-counter

Installations
40+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.4

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.4.

Brave Conversion Engine (PRO)

Plugin:

Brave Conversion Engine (PRO)

Plugin Slug:
bravepopup-pro

Vulnerability:
Broken Authentication

Patched in Version:
0.8.0

Severity Score:
Critical


The vulnerability has been patched, so you should update to version 0.8.0.

WordPress Event Manager, Event Calendar and Booking Plugin

Plugin:

WordPress Event Manager, Event Calendar and Booking Plugin

Plugin Slug:
eventin-pro

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
4.0.25

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 4.0.25.

Global Gallery

Plugin:

Global Gallery

Plugin Slug:
global-gallery

Vulnerability:
Broken Access Control

Patched in Version:
9.2.4

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 9.2.4.

Groundhogg

Plugin:

Groundhogg

Plugin Slug:
groundhogg

Vulnerability:
PHP Object Injection

Patched in Version:
4.2.2.1

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 4.2.2.1.

WPBakery Page Builder

Plugin:

WPBakery Page Builder

Plugin Slug:
js_composer

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
8.6

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 8.6.

Multimedia Playlist Slider Addon for WPBakery Page Builder

Plugin:

Multimedia Playlist Slider Addon for WPBakery Page Builder

Plugin Slug:
lbg_vp_youtube_vimeo_addon_visual_composer

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.2

Severity Score:
High


The vulnerability has been patched, so you should update to version 2.2.

MapSVG

Plugin:

MapSVG

Plugin Slug:
mapsvg

Vulnerability:
SQL Injection

Patched in Version:
8.7.4

Severity Score:
Critical


The vulnerability has been patched, so you should update to version 8.7.4.

Cost Calculator

Plugin:

Cost Calculator

Plugin Slug:
ql-cost-calculator

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
7 .5

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 7 .5.

Reveal Listing

Plugin:

Reveal Listing

Plugin Slug:
reveal-listing

Vulnerability:
Privilege Escalation

Patched in Version:
3.4

Severity Score:
Critical


The vulnerability has been patched, so you should update to version 3.4.

Use-your-Drive

Plugin:

Use-your-Drive

Plugin Slug:
use-your-drive

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
3.3.2

Severity Score:
High


The vulnerability has been patched, so you should update to version 3.3.2.

Woffice Core

Plugin:

Woffice Core

Plugin Slug:
woffice-core

Vulnerability:
Arbitrary File Deletion

Patched in Version:
5.4.27

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 5.4.27.

WordPress Themes — 5 Patched / 1 Unpatched

Shopo

Theme:

Shopo

Theme Slug:
shopo

Vulnerability:
Arbitrary File Upload

Patched in Version:
No Fix

Severity Score:
Critical


The vulnerability has not been patched. You should switch themes.

Zakra

Theme:

Zakra

Theme Slug:
zakra

Downloads
1,935,472

Vulnerability:
Broken Access Control

Patched in Version:
4.1.6

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 4.1.6.

Betheme

Theme:

Betheme

Theme Slug:
betheme

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
28.1.4

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 28.1.4.

The7

Theme:

The7

Theme Slug:
dt-the7

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
12.7.0

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 12.7.0.

Urna

Theme:

Urna

Theme Slug:
urna

Vulnerability:
Local File Inclusion

Patched in Version:
2.5.8

Severity Score:
High


The vulnerability has been patched, so you should update to version 2.5.8.

Xinterio

Theme:

Xinterio

Theme Slug:
xinterio

Vulnerability:
Local File Inclusion

Patched in Version:
4.3

Severity Score:
High


The vulnerability has been patched, so you should update to version 4.3.

Solid Security is part of Solid Suite — The best foundation for WordPress websites.

Every WordPress site needs security, backups, and management tools. That’s Solid Suite — an integrated bundle of three plugins: Solid Security, Solid Backups, and Solid Central. You also get access to Solid Academy’s learning resources for WordPress professionals. Build your next WordPress website on a solid foundation with Solid Suite!

Get Solid Security


The post WordPress Vulnerability Report — August 13, 2025 appeared first on SolidWP.

Click here to continue reading this article.