In this report, 191 vulnerabilities have been publicly disclosed. Security patches for 93 of these plugins and themes are now available, so please run those updates as soon as possible. If you’re a Solid Security Pro user, the version management tool may have already warned you and updated these plugins, depending on your settings.

Additionally, there are 98 plugin and theme vulnerabilities, and no patch has been available yet. If you’re a Solid Security Pro user, those vulnerabilities are already protected by the Solid Security firewall. Virtual patches from Patchstack will be applied when a vulnerability is considered high or medium risk. If no patch is forthcoming from the vendor or the vulnerable software has been marked “closed” and dropped from the official WordPress repositories, you should deactivate it soon and look for alternative solutions.

Along with poor user account security, vulnerable plugins and themes are among the top reasons why WordPress websites get hacked. Unfortunately, cyberattacks are increasing in volume and sophistication. They’re also increasingly aimed at small to mid-sized businesses.

Our WordPress Vulnerability Report covers the latest emerging WordPress plugin, theme, and core vulnerabilities. Each vulnerability will have a severity rating of LowMediumHigh, or Critical. Responsible disclosure of vulnerabilities is essential to keeping the WordPress community safe. Please share this report to help spread the word and make WordPress — and the web — more secure.

WordPress Core

WordPress 6.8.2 was released on July 15, 2025. This maintenance release includes fixes for 20 Core tickets and 15 Block Editor issues. For a full list of bug fixes, please refer to the release candidate announcement.

No new core vulnerabilities were disclosed this week.

WordPress Plugins — 81 Patched / 93 Unpatched

Awesome Support – WordPress HelpDesk & Support Plugin

Plugin Slug:
awesome-support

Installations
8,000+

Vulnerability:
Sensitive Data Exposure

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

EventON – Events Calendar

Plugin Slug:
eventon-lite

Installations
6,000+

Vulnerability:
Sensitive Data Exposure

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Simple Login Log

Plugin Slug:
simple-login-log

Installations
6,000+

Vulnerability:
PHP Object Injection

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

WP Emmet

Plugin:

WP Emmet

Plugin Slug:
wp-emmet

Installations
3,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Contact Info Widget

Plugin Slug:
simple-contact-info-widget

Installations
2,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

StoryChief

Plugin:

StoryChief

Plugin Slug:
story-chief

Installations
1,000+

Vulnerability:
Arbitrary File Upload

Patched in Version:
No Fix

Severity Score:
Critical


The vulnerability has not been patched. You should deactivate the plugin.

Cookie Warning

Plugin Slug:
cookie-warning

Installations
900+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Cookie Warning

Plugin Slug:
cookie-warning

Installations
900+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Page Transition

Plugin Slug:
page-transition

Installations
900+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

WP Discord Post Plus – Supports Unlimited Channels

Plugin Slug:
wp-discord-post-plus

Installations
900+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

AL Pack

Plugin:

AL Pack

Plugin Slug:
alpack

Installations
800+

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

DigitalOcean Spaces Sync

Plugin Slug:
do-spaces-sync

Installations
800+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Inspectlet – User Session Recording and Heatmaps

Plugin Slug:
inspectlet-heatmaps-and-user-session-recording

Installations
800+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Terms of Service & Privacy Policy Generator

Plugin Slug:
terms-of-service-and-privacy-policy

Installations
800+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

iframe Wrapper

Plugin Slug:
iframe-wrapper

Installations
600+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Essential Doo Components for Visual Composer

Plugin Slug:
animated-icon-banner-for-visual-composer

Installations
500+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Build App Online

Plugin Slug:
build-app-online

Installations
500+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Custom Menu

Plugin Slug:
custom-menu

Installations
500+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Hide Text Shortcode

Plugin Slug:
hide-text-shortcode

Installations
500+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Laposta WooCommerce

Plugin Slug:
laposta-woocommerce

Installations
500+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

WP Pipes

Plugin:

WP Pipes

Plugin Slug:
wp-pipes

Installations
500+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

CF7 Spreadsheets

Plugin Slug:
cf7-spreadsheets

Installations
400+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

CodeablePress: Simple Frontend Profile Picture Upload

Plugin Slug:
codeablepress-simple-frontend-profile-picture-upload

Installations
100+

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Embed Bokun

Plugin Slug:
embed-bokun

Installations
100+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Forms

Plugin:

Forms

Plugin Slug:
forms-by-made-it

Installations
100+

Vulnerability:
Arbitrary File Upload

Patched in Version:
No Fix

Severity Score:
Critical


The vulnerability has not been patched. You should deactivate the plugin.

Netease Music

Plugin Slug:
netease-music

Installations
100+

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Project Cost Calculator

Plugin Slug:
project-cost-calculator

Installations
100+

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Time Sheets

Plugin Slug:
time-sheets

Installations
100+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

WP-Database-Optimizer-Tools

Plugin Slug:
wp-database-optimizer-tools

Installations
100+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

WP Dynamic Links

Plugin Slug:
wp-dynamic-links

Installations
90+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Authentication and xmlrpc log writer

Plugin Slug:
authentication-and-xmlrpc-log-writer

Installations
80+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Infility Global

Plugin Slug:
infility-global

Installations
80+

Vulnerability:
Arbitrary File Download

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Premium Addons for KingComposer

Plugin Slug:
premium-addons-for-kingcomposer

Installations
70+

Vulnerability:
Local File Inclusion

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Simplified Plugin

Plugin Slug:
simplified

Installations
70+

Vulnerability:
Server Side Request Forgery (SSRF)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

WP Voting

Plugin:

WP Voting

Plugin Slug:
wp-voting

Installations
70+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Jenga Payment Gateway for WooCommerce

Plugin Slug:
woo-jenga-payment-gateway

Installations
50+

Vulnerability:
SQL Injection

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

WordPress StoryMap Plugin

Plugin Slug:
wp-storymap

Installations
50+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

AWStats Script

Plugin Slug:
awstats-script

Installations
40+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Custom Comment

Plugin Slug:
customcomment

Installations
40+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

WP Airdrop Manager

Plugin Slug:
airdrop

Installations
30+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Elizaibots

Plugin:

Elizaibots

Plugin Slug:
elizaibot-chatbots

Installations
20+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Vertical scroll slideshow gallery v2

Plugin Slug:
vertical-scroll-slideshow-gallery-v2

Installations
20+

Vulnerability:
SQL Injection

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Dropshix

Plugin:

Dropshix

Plugin Slug:
dropshipping-xox

Installations
10+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Simple Poll

Plugin Slug:
simple-poll

Installations
10+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

SoundSt SEO Search

Plugin Slug:
soundst-seo-search

Installations
10+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Video Expander

Plugin Slug:
video-expander

Installations
10+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Add User Meta

Plugin:

Add User Meta

Plugin Slug:
add-user-meta

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Simple Responsive Slider

Plugin:

Simple Responsive Slider

Plugin Slug:
addi-simple-slider

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Alobaidi Captcha

Plugin:

Alobaidi Captcha

Plugin Slug:
alobaidi-captcha

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Anber Elementor Addon

Plugin:

Anber Elementor Addon

Plugin Slug:
anber-elementor-addon

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Assistant for NextGEN Gallery

Plugin:

Assistant for NextGEN Gallery

Plugin Slug:
assistant-for-nextgen-gallery

Vulnerability:
Path Traversal

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

bizcalendar-web

Plugin:

bizcalendar-web

Plugin Slug:
bizcalendar-web

Vulnerability:
Local File Inclusion

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Blog Designer PRO

Plugin:

Blog Designer PRO

Plugin Slug:
blog-designer-pro

Vulnerability:
Local File Inclusion

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

CBX Restaurant Booking

Plugin:

CBX Restaurant Booking

Plugin Slug:
cbx-restaurant-booking

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

CleverReach® WP

Plugin:

CleverReach® WP

Plugin Slug:
cleverreach-wp

Vulnerability:
SQL Injection

Patched in Version:
No Fix

Severity Score:
Critical


The vulnerability has not been patched. You should deactivate the plugin.

CleverReach® WP

Plugin:

CleverReach® WP

Plugin Slug:
cleverreach-wp

Vulnerability:
SQL Injection

Patched in Version:
No Fix

Severity Score:
Critical


The vulnerability has not been patched. You should deactivate the plugin.

Earnware Connect

Plugin:

Earnware Connect

Plugin Slug:
earnware-connect

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

elink – Embed Content

Plugin:

elink – Embed Content

Plugin Slug:
elink-embed-content

Vulnerability:
Other Vulnerability Type

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

flexo-social-gallery

Plugin:

flexo-social-gallery

Plugin Slug:
flexo-social-gallery

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Ultimate Video Player

Plugin:

Ultimate Video Player

Plugin Slug:
fwduvp

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Gestion de tarifs

Plugin:

Gestion de tarifs

Plugin Slug:
gestion-tarifs

Vulnerability:
SQL Injection

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

GMap Generator

Plugin:

GMap Generator

Plugin Slug:
gmap-venturit

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

WPGYM

Plugin:

WPGYM

Plugin Slug:
gym-management

Vulnerability:
Local File Inclusion

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

WPGYM

Plugin:

WPGYM

Plugin Slug:
gym-management

Vulnerability:
Privilege Escalation

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Icons Factory

Plugin:

Icons Factory

Plugin Slug:
icons-factory

Vulnerability:
Arbitrary File Deletion

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Inline Stock Quotes

Plugin:

Inline Stock Quotes

Plugin Slug:
inline-stock-quotes

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Intl DateTime Calendar

Plugin:

Intl DateTime Calendar

Plugin Slug:
intl-datetime-calendar

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Last.fm Recent Album Artwork

Plugin:

Last.fm Recent Album Artwork

Plugin Slug:
lastfm-recent-album-artwork

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

LatestCheckins

Plugin:

LatestCheckins

Plugin Slug:
latestcheckins

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Linux Promotional Plugin

Plugin:

Linux Promotional Plugin

Plugin Slug:
linux-promotional-plugin

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Mosaic Generator

Plugin:

Mosaic Generator

Plugin Slug:
mosaic-generator

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

NetInsight Analytics Implementation Plugin

Plugin:

NetInsight Analytics Implementation Plugin

Plugin Slug:
netinsight-analytics-implementation-plugin

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

NetInsight Analytics Implementation Plugin

Plugin:

NetInsight Analytics Implementation Plugin

Plugin Slug:
netinsight-analytics-implementation-plugin

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Pending Order Bot

Plugin Slug:
pending-order-bot

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Radius Blocks

Plugin:

Radius Blocks

Plugin Slug:
radius-blocks

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

RT Easy Builder – Advanced addons for Elementor

Plugin:

RT Easy Builder – Advanced addons for Elementor

Plugin Slug:
rt-easy-builder-advanced-addons-for-elementor

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

School Management

Plugin:

School Management

Plugin Slug:
school-management

Vulnerability:
SQL Injection

Patched in Version:
No Fix

Severity Score:
Critical


The vulnerability has not been patched. You should deactivate the plugin.

School Management

Plugin:

School Management

Plugin Slug:
school-management

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

School Management

Plugin:

School Management

Plugin Slug:
school-management

Vulnerability:
Insecure Direct Object References (IDOR)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

School Management

Plugin:

School Management

Plugin Slug:
school-management

Vulnerability:
SQL Injection

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

School Management

Plugin:

School Management

Plugin Slug:
school-management

Vulnerability:
Arbitrary File Upload

Patched in Version:
No Fix

Severity Score:
Critical


The vulnerability has not been patched. You should deactivate the plugin.

ServerBuddy by PluginBuddy.com

Plugin:

ServerBuddy by PluginBuddy.com

Plugin Slug:
serverbuddy-by-pluginbuddy

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Surbma | Recent Comments Shortcode

Plugin:

Surbma | Recent Comments Shortcode

Plugin Slug:
surbma-recent-comments-shortcode

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Thim Core

Plugin:

Thim Core

Plugin Slug:
thim-core

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Thim Core

Plugin:

Thim Core

Plugin Slug:
thim-core

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

WooCommerce Purchase Orders

Plugin:

WooCommerce Purchase Orders

Plugin Slug:
wc-purchase-orders

Vulnerability:
Arbitrary File Deletion

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

weichuncai(WP???)

Plugin:

weichuncai(WP???)

Plugin Slug:
weichuncai

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Wp chart generator

Plugin:

Wp chart generator

Plugin Slug:
wp-chart-generator

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

JobSearch

Plugin:

JobSearch

Plugin Slug:
wp-jobsearch

Vulnerability:
Local File Inclusion

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

WP Private Content Plus

Plugin:

WP Private Content Plus

Plugin Slug:
wp-private-content-plus

Vulnerability:
Sensitive Data Exposure

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Plugin README Parser

Plugin:

Plugin README Parser

Plugin Slug:
wp-readme-parser

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

File Manager Pro – Filester

Plugin Slug:
filester

Installations
100,000+

Vulnerability:
Arbitrary File Deletion

Patched in Version:
1.9

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.9.

Kadence WooCommerce Email Designer

Plugin Slug:
kadence-woocommerce-email-designer

Installations
100,000+

Vulnerability:
Privilege Escalation

Patched in Version:
1.5.17

Severity Score:
High


The vulnerability has been patched, so you should update to version 1.5.17.

Simple Local Avatars

Plugin Slug:
simple-local-avatars

Installations
100,000+

Vulnerability:
Broken Access Control

Patched in Version:
2.8.5

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.8.5.

Media Library Assistant

Plugin Slug:
media-library-assistant

Installations
70,000+

Vulnerability:
Arbitrary File Deletion

Patched in Version:
3.28

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 3.28.

WPC Smart Compare for WooCommerce

Plugin Slug:
woo-smart-compare

Installations
70,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
6.4.8

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 6.4.8.

Drag and Drop Multiple File Upload for Contact Form 7

Plugin Slug:
drag-and-drop-multiple-file-upload-contact-form-7

Installations
60,000+

Vulnerability:
Directory Traversal

Patched in Version:
1.3.9.1

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.3.9.1.

WP Table Builder – WordPress Table Plugin

Plugin Slug:
wp-table-builder

Installations
60,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.0.13

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.0.13.

Advanced iFrame

Plugin Slug:
advanced-iframe

Installations
50,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2025.7

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2025.7.

Structured Content (JSON-LD) #wpsc

Plugin Slug:
structured-content

Installations
50,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.7.0

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.7.0.

Visual Composer Website Builder

Plugin Slug:
visualcomposer

Installations
50,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
45.15.0

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 45.15.0.

BetterDocs – Advanced AI-Driven Documentation, FAQ & Knowledge Base Tool for Elementor & Gutenberg with Encyclopedia, AI Support, Instant Answers

Plugin Slug:
betterdocs

Installations
40,000+

Vulnerability:
Broken Access Control

Patched in Version:
4.1.2

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 4.1.2.

Quiz and Survey Master (QSM) – Easy Quiz and Survey Maker

Plugin Slug:
quiz-master-next

Installations
40,000+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
10.2.3

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 10.2.3.

UiCore Elements – Free Elementor widgets and templates

Plugin Slug:
uicore-elements

Installations
40,000+

Vulnerability:
Arbitrary File Download

Patched in Version:
1.3.1

Severity Score:
High


The vulnerability has been patched, so you should update to version 1.3.1.

FunnelKit – Funnel Builder for WooCommerce Checkout

Plugin Slug:
funnel-builder

Installations
30,000+

Vulnerability:
Privilege Escalation

Patched in Version:
3.11.1

Severity Score:
High


The vulnerability has been patched, so you should update to version 3.11.1.

Welcart e-Commerce

Plugin Slug:
usc-e-shop

Installations
20,000+

Vulnerability:
PHP Object Injection

Patched in Version:
2.11.17

Severity Score:
High


The vulnerability has been patched, so you should update to version 2.11.17.

Frontend Admin by DynamiApps

Plugin Slug:
acf-frontend-form-element

Installations
10,000+

Vulnerability:
SQL Injection

Patched in Version:
3.28.5

Severity Score:
High


The vulnerability has been patched, so you should update to version 3.28.5.

Graphina – Elementor Charts and Graphs

Plugin Slug:
graphina-elementor-charts-and-graphs

Installations
10,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
3.1.4

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 3.1.4.

Quttera Web Malware Scanner

Plugin Slug:
quttera-web-malware-scanner

Installations
10,000+

Vulnerability:
Server Side Request Forgery (SSRF)

Patched in Version:
3.5.2.1

Severity Score:
Low


The vulnerability has been patched, so you should update to version 3.5.2.1.

Shortcode Redirect

Plugin Slug:
shortcode-redirect

Installations
10,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.0.03

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.0.03.

Flexible Map

Plugin Slug:
wp-flexible-map

Installations
8,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.19.0

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.19.0.

Dynamic Pricing With Discount Rules for WooCommerce

Plugin Slug:
aco-woo-dynamic-pricing

Installations
7,000+

Vulnerability:
Arbitrary Code Execution

Patched in Version:
4.5.10

Severity Score:
Critical


The vulnerability has been patched, so you should update to version 4.5.10.

B Slider – Responsive Image Slider

Plugin Slug:
b-slider

Installations
5,000+

Vulnerability:
Server Side Request Forgery (SSRF)

Patched in Version:
2.0.1

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.0.1.

B Slider – Responsive Image Slider

Plugin Slug:
b-slider

Installations
5,000+

Vulnerability:
Sensitive Data Exposure

Patched in Version:
2.0.1

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.0.1.

Embedder for Google Reviews

Plugin Slug:
embedder-for-google-reviews

Installations
3,000+

Vulnerability:
Broken Access Control

Patched in Version:
1.7.4

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.7.4.

WP Shopify

Plugin:

WP Shopify

Plugin Slug:
wp-shopify

Installations
3,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.5.4

Severity Score:
High


The vulnerability has been patched, so you should update to version 1.5.4.

Premium Packages – Sell Digital Products Securely

Plugin Slug:
wpdm-premium-packages

Installations
3,000+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
6.0.3

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 6.0.3.

Online Booking & Scheduling Calendar for WordPress by vcita

Plugin Slug:
meeting-scheduler-by-vcita

Installations
2,000+

Vulnerability:
Arbitrary File Upload

Patched in Version:
4.5.5

Severity Score:
Critical


The vulnerability has been patched, so you should update to version 4.5.5.

oik

Plugin:

oik

Plugin Slug:
oik

Installations
2,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
4.15.3

Severity Score:
High


The vulnerability has been patched, so you should update to version 4.15.3.

Order Tip for WooCommerce

Plugin Slug:
order-tip-woo

Installations
2,000+

Vulnerability:
Other Vulnerability Type

Patched in Version:
1.5.5

Severity Score:
High


The vulnerability has been patched, so you should update to version 1.5.5.

Easy Elementor Addons

Plugin Slug:
easy-elementor-addons

Installations
1,000+

Vulnerability:
Broken Access Control

Patched in Version:
2.2.8

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.2.8.

AnWP Football Leagues

Plugin Slug:
football-leagues-by-anwppro

Installations
1,000+

Vulnerability:
CSV Injection

Patched in Version:
0.16.18

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 0.16.18.

Injection Guard

Plugin Slug:
injection-guard

Installations
1,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.2.8

Severity Score:
High


The vulnerability has been patched, so you should update to version 1.2.8.

Markup Markdown

Plugin Slug:
markup-markdown

Installations
1,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
3.20.7

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 3.20.7.

Membership For WooCommerce – WordPress Membership Plugin, Restrict Content, Build Online Communities, Paywall & Content Dripping

Plugin Slug:
membership-for-woocommerce

Installations
1,000+

Vulnerability:
Broken Access Control

Patched in Version:
3.0.0

Severity Score:
High


The vulnerability has been patched, so you should update to version 3.0.0.

MDTF – Meta Data and Taxonomies Filter

Plugin Slug:
wp-meta-data-filter-and-taxonomy-filter

Installations
1,000+

Vulnerability:
SQL Injection

Patched in Version:
1.3.3.8

Severity Score:
Critical


The vulnerability has been patched, so you should update to version 1.3.3.8.

12 Step Meeting List

Plugin Slug:
12-step-meeting-list

Installations
800+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
3.18.4

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 3.18.4.

RSS Feed Pro

Plugin Slug:
rss-feed-pro

Installations
500+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.1.9

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.1.9.

WordLift – AI powered SEO – Schema

Plugin Slug:
wordlift

Installations
500+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
3.54.6

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 3.54.6.

Easy restaurant menu manager

Plugin Slug:
easy-pdf-restaurant-menu-upload

Installations
300+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
2.0.3

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.0.3.

WooCommerce Fortnox Integration

Plugin Slug:
woocommerce-fortnox-integration

Installations
300+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
4.5.7

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 4.5.7.

Primer MyData for Woocommerce

Plugin Slug:
primer-mydata

Installations
100+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
4.2.6

Severity Score:
High


The vulnerability has been patched, so you should update to version 4.2.6.

Neon Channel Product Customizer Free

Plugin Slug:
neon-channel-product-customizer-free

Installations
40+

Vulnerability:
Arbitrary Content Deletion

Patched in Version:
3.0

Severity Score:
High


The vulnerability has been patched, so you should update to version 3.0.

Billplz Addon for Contact Form 7

Plugin Slug:
billplz-for-contact-form-7

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.2.1

Severity Score:
High


The vulnerability has been patched, so you should update to version 1.2.1.

WordPress Event Manager, Event Calendar and Booking Plugin

Plugin:

WordPress Event Manager, Event Calendar and Booking Plugin

Plugin Slug:
eventin-pro

Vulnerability:
Arbitrary Content Deletion

Patched in Version:
4.0.25

Severity Score:
High


The vulnerability has been patched, so you should update to version 4.0.25.

WordPress Event Manager, Event Calendar and Booking Plugin

Plugin:

WordPress Event Manager, Event Calendar and Booking Plugin

Plugin Slug:
eventin-pro

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
4.0.25

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 4.0.25.

JetElements For Elementor

Plugin:

JetElements For Elementor

Plugin Slug:
jet-elements

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.7.9.1

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.7.9.1.

JetProductGallery

Plugin:

JetProductGallery

Plugin Slug:
jet-woo-product-gallery

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.2.0.3

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.2.0.3.

Login with phone number

Plugin:

Login with phone number

Plugin Slug:
login-with-phone-number

Vulnerability:
Broken Authentication

Patched in Version:
1.8.48

Severity Score:
High


The vulnerability has been patched, so you should update to version 1.8.48.

Real Estate Manager Pro

Plugin:

Real Estate Manager Pro

Plugin Slug:
real-estate-manager-pro

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
12.7.4

Severity Score:
High


The vulnerability has been patched, so you should update to version 12.7.4.

Responsive Posts Carousel WordPress Plugin

Plugin:

Responsive Posts Carousel WordPress Plugin

Plugin Slug:
responsive-posts-carousel-pro

Vulnerability:
Local File Inclusion

Patched in Version:
15.1

Severity Score:
High


The vulnerability has been patched, so you should update to version 15.1.

Templatera

Plugin:

Templatera

Plugin Slug:
templatera

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.4.0

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.4.0.

Tutor LMS Pro

Plugin:

Tutor LMS Pro

Plugin Slug:
tutor-pro

Vulnerability:
SQL Injection

Patched in Version:
3.7.1

Severity Score:
High


The vulnerability has been patched, so you should update to version 3.7.1.

File Manager Pro

Plugin:

File Manager Pro

Plugin Slug:
wp-file-manager-pro

Vulnerability:
Arbitrary File Deletion

Patched in Version:
8.4.3

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 8.4.3.

WP Membership

Plugin:

WP Membership

Plugin Slug:
wp-membership

Vulnerability:
Settings Change

Patched in Version:
1.6.4

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.6.4.

WordPress Themes — 12 Patched / 5 Unpatched

modernize

Theme Slug:
modernize

Downloads
59,351

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should switch themes.

modernize

Theme Slug:
modernize

Downloads
59,351

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should switch themes.

Kalium

Theme:

Kalium

Theme Slug:
kalium

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should switch themes.

Stratus

Theme:

Stratus

Theme Slug:
stratus

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should switch themes.

WP Rentals

Theme:

WP Rentals

Theme Slug:
wprentals

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should switch themes.

Blocksy

Theme:

Blocksy

Theme Slug:
blocksy

Downloads
4,877,063

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.1.7

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.1.7.

OceanWP

Theme:

OceanWP

Theme Slug:
oceanwp

Downloads
8,737,187

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
4.1.2

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 4.1.2.

The7

Theme:

The7

Theme Slug:
dt-the7

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
12.7.0

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 12.7.0.

Findgo

Theme:

Findgo

Theme Slug:
findgo

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
1.3.58

Severity Score:
High


The vulnerability has been patched, so you should update to version 1.3.58.

Makeaholic

Theme:

Makeaholic

Theme Slug:
makeaholic

Vulnerability:
Local File Inclusion

Patched in Version:
1.8.5

Severity Score:
High


The vulnerability has been patched, so you should update to version 1.8.5.

Real Spaces

Theme:

Real Spaces

Theme Slug:
real-spaces

Vulnerability:
Privilege Escalation

Patched in Version:
3.6.1

Severity Score:
Critical


The vulnerability has been patched, so you should update to version 3.6.1.

Real Spaces

Theme:

Real Spaces

Theme Slug:
real-spaces

Vulnerability:
Privilege Escalation

Patched in Version:
3.6

Severity Score:
High


The vulnerability has been patched, so you should update to version 3.6.

Savoy

Theme:

Savoy

Theme Slug:
savoy

Vulnerability:
Sensitive Data Exposure

Patched in Version:
3.0.9

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 3.0.9.

Soledad

Theme:

Soledad

Theme Slug:
soledad

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
8.6.8

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 8.6.8.

Soledad

Theme:

Soledad

Theme Slug:
soledad

Vulnerability:
Local File Inclusion

Patched in Version:
8.6.8

Severity Score:
High


The vulnerability has been patched, so you should update to version 8.6.8.

Soledad

Theme:

Soledad

Theme Slug:
soledad

Vulnerability:
Content Injection

Patched in Version:
8.6.8

Severity Score:
High


The vulnerability has been patched, so you should update to version 8.6.8.

Unicamp

Theme:

Unicamp

Theme Slug:
unicamp

Vulnerability:
Local File Inclusion

Patched in Version:
2.6.4

Severity Score:
High


The vulnerability has been patched, so you should update to version 2.6.4.

Solid Security is part of Solid Suite — The best foundation for WordPress websites.

Every WordPress site needs security, backups, and management tools. That’s Solid Suite — an integrated bundle of three plugins: Solid Security, Solid Backups, and Solid Central. You also get access to Solid Academy’s learning resources for WordPress professionals. Build your next WordPress website on a solid foundation with Solid Suite!

Get Solid Security


The post WordPress Vulnerability Report — August 20, 2025 appeared first on SolidWP.

Click here to continue reading this article.