In this report, 169 vulnerabilities have been publicly disclosed. Security patches for 71 of these plugins and themes are now available, so please run those updates as soon as possible. If you’re a Solid Security Pro user, the version management tool may have already warned you and updated these plugins, depending on your settings.

Additionally, there are 98 plugin and theme vulnerabilities, and no patch has been available yet. If you’re a Solid Security Pro user, those vulnerabilities are already protected by the Solid Security firewall. Virtual patches from Patchstack will be applied when a vulnerability is considered high or medium risk. If no patch is forthcoming from the vendor or the vulnerable software has been marked “closed” and dropped from the official WordPress repositories, you should deactivate it soon and look for alternative solutions.

Along with poor user account security, vulnerable plugins and themes are among the top reasons why WordPress websites get hacked. Unfortunately, cyberattacks are increasing in volume and sophistication. They’re also increasingly aimed at small to mid-sized businesses.

Our WordPress Vulnerability Report covers the latest emerging WordPress plugin, theme, and core vulnerabilities. Each vulnerability will have a severity rating of LowMediumHigh, or Critical. Responsible disclosure of vulnerabilities is essential to keeping the WordPress community safe. Please share this report to help spread the word and make WordPress — and the web — more secure.

WordPress Core

WordPress 6.8.2 was released on July 15, 2025. This maintenance release includes fixes for 20 Core tickets and 15 Block Editor issues. For a full list of bug fixes, please refer to the release candidate announcement.

No new core vulnerabilities were disclosed this week.

WordPress Plugins — 58 Patched / 87 Unpatched

Site Offline Or Coming Soon Or Maintenance Mode

Plugin Slug:
site-offline

Installations
30,000+

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Video Gallery – Vimeo and YouTube Gallery

Plugin Slug:
smart-grid-gallery

Installations
8,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Statify Widget

Plugin Slug:
statify-widget

Installations
4,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Add Code To Head

Plugin Slug:
add-code-to-head

Installations
3,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Popup for CF7 with Sweet Alert

Plugin Slug:
cf7-sweet-alert-popup

Installations
3,000+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

AutoWP – AI Content Writer & Rewriter

Plugin Slug:
autowp-ai-content-writer-rewriter

Installations
1,000+

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Backup Bolt

Plugin Slug:
backup-bolt

Installations
1,000+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Century ToolKit

Plugin Slug:
century-toolkit

Installations
1,000+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Post Type Converter

Plugin Slug:
post-type-converter

Installations
1,000+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Varnish/Nginx Proxy Caching

Plugin Slug:
vcaching

Installations
1,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

WP Mailgun SMTP

Plugin Slug:
wp-mailgun-smtp

Installations
1,000+

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

??????.??? ?????? / Yandex Site search pinger

Plugin Slug:
yandex-pinger

Installations
1,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Admin Menu Groups

Plugin Slug:
admin-menu-groups

Installations
900+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Cookie Warning

Plugin Slug:
cookie-warning

Installations
900+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Cookie Warning

Plugin Slug:
cookie-warning

Installations
900+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Link View

Plugin:

Link View

Plugin Slug:
link-view

Installations
900+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Link View

Plugin:

Link View

Plugin Slug:
link-view

Installations
900+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Page Transition

Plugin Slug:
page-transition

Installations
900+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

WordPress HTML

Plugin Slug:
custom-html-bodyhead

Installations
800+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Responsive Mobile-Friendly Tooltip

Plugin Slug:
responsive-mobile-friendly-tooltip

Installations
800+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Terms of Service & Privacy Policy Generator

Plugin Slug:
terms-of-service-and-privacy-policy

Installations
800+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

WPAvatar

Plugin:

WPAvatar

Plugin Slug:
wpavatar

Installations
800+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

bxSlider integration for WordPress

Plugin Slug:
bxslider-integration

Installations
600+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

iFrame Block

Plugin Slug:
iframe-block

Installations
600+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

iframe Wrapper

Plugin Slug:
iframe-wrapper

Installations
600+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Risk Free Cash On Delivery (COD) – WooCommerce

Plugin Slug:
risk-free-cash-on-delivery-cod-woocommerce

Installations
600+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Essential Doo Components for Visual Composer

Plugin Slug:
animated-icon-banner-for-visual-composer

Installations
500+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Hesabfa Accounting

Plugin Slug:
hesabfa-accounting

Installations
500+

Vulnerability:
Sensitive Data Exposure

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Hesabfa Accounting

Plugin Slug:
hesabfa-accounting

Installations
500+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Better Post & Filter Widgets for Elementor

Plugin Slug:
better-post-filter-widgets-for-elementor

Installations
400+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

TC Testimonials

Plugin Slug:
tc-testimonial

Installations
400+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

LifePress

Plugin:

LifePress

Plugin Slug:
lifepress

Installations
200+

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Tripadvisor Shortcode

Plugin Slug:
tripadvisor-shortcode

Installations
200+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

??????

Plugin:

??????

Plugin Slug:
baidushare-wp

Installations
100+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

BetPress

Plugin:

BetPress

Plugin Slug:
betpress

Installations
100+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Comments Capcha Box

Plugin Slug:
comments-capcha-box

Installations
100+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

e-Boekhouden.nl

Plugin Slug:
e-boekhoudennl-connector

Installations
100+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Invisible Optin

Plugin Slug:
invisible-optin

Installations
100+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

NextGEN Gallery Search

Plugin Slug:
nextgen-gallery-search-galleries

Installations
100+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Page Manager for Elementor

Plugin Slug:
page-manager-for-elementor

Installations
100+

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Theme Switcher Reloaded

Plugin Slug:
theme-switcher-reloaded

Installations
100+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Ultimate twitter profile widget

Plugin Slug:
ultimate-twitter-profile-widget

Installations
100+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Table Editor

Plugin Slug:
wp-table-editor

Installations
100+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

ATT YouTube Widget

Plugin Slug:
att-youtube

Installations
90+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Google XML News Sitemap plugin

Plugin Slug:
gn-xml-sitemap

Installations
90+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Kento Splash Screen

Plugin Slug:
kento-splash-screen

Installations
90+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

SEO For Images

Plugin Slug:
seo-for-images

Installations
90+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

????????

Plugin:

????????

Plugin Slug:
duoshuo

Installations
80+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Newsletter subscription optin module

Plugin Slug:
newsletter-subscription-widget-for-sendblaster

Installations
70+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

WP Admin Theme

Plugin Slug:
wp-admin-theme

Installations
70+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

XM-Backup

Plugin:

XM-Backup

Plugin Slug:
xm-backup

Installations
70+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Clickbank WordPress Plugin (Niche Storefront)

Plugin Slug:
clickbank-niche-storefronts

Installations
60+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

WPMU Ldap Authentication

Plugin Slug:
wpmuldap

Installations
60+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

bidorbuy Store Integrator

Plugin Slug:
bidorbuystoreintegrator

Installations
50+

Vulnerability:
Remote Code Execution (RCE)

Patched in Version:
No Fix

Severity Score:
Critical


The vulnerability has not been patched. You should deactivate the plugin.

rajce

Plugin:

rajce

Plugin Slug:
rajce

Installations
50+

Vulnerability:
Server Side Request Forgery (SSRF)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Savyour Affiliate Partner

Plugin Slug:
savyour-affiliate-partner

Installations
50+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

SensorPress

Plugin Slug:
sensorpress-uptime-monitoring

Installations
50+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Custom Comment

Plugin Slug:
customcomment

Installations
40+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Simpler Checkout

Plugin Slug:
simpler-checkout

Installations
40+

Vulnerability:
Broken Authentication

Patched in Version:
No Fix

Severity Score:
Critical


The vulnerability has not been patched. You should deactivate the plugin.

Kanpress

Plugin:

Kanpress

Plugin Slug:
kanpress

Installations
20+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Goal Tracker for Patreon

Plugin Slug:
goal-tracker-for-patreon

Installations
10+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Support Ticket

Plugin Slug:
support-ticket

Installations
10+

Vulnerability:
Privilege Escalation

Patched in Version:
No Fix

Severity Score:
Critical


The vulnerability has not been patched. You should deactivate the plugin.

tli.tl auto Twitter poster

Plugin Slug:
tlitl-auto-twitter-poster

Installations
10+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

WP Funnel Manager

Plugin Slug:
wp-funnel-manager

Installations
10+

Vulnerability:
PHP Object Injection

Patched in Version:
No Fix

Severity Score:
Critical


The vulnerability has not been patched. You should deactivate the plugin.

Advance Food Menu

Plugin Slug:
advance-food-menu

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Premium Age Verification / Restriction for WordPress

Plugin:

Premium Age Verification / Restriction for WordPress

Plugin Slug:
age-restriction

Vulnerability:
Arbitrary File Upload

Patched in Version:
No Fix

Severity Score:
Critical


The vulnerability has not been patched. You should deactivate the plugin.

Bravis User

Plugin:

Bravis User

Plugin Slug:
bravis-user

Vulnerability:
Broken Authentication

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Exertio Framework

Plugin:

Exertio Framework

Plugin Slug:
exertio-framework

Vulnerability:
SQL Injection

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Silencesoft RSS Reader

Plugin:

Silencesoft RSS Reader

Plugin Slug:
external-rss-reader

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Listeo-Core

Plugin:

Listeo-Core

Plugin Slug:
listeo-core

Vulnerability:
SQL Injection

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Mesa Mesa Reservation Widget

Plugin Slug:
mesa-mesa-reservation-widget

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Ni WooCommerce Customer Product Report

Plugin:

Ni WooCommerce Customer Product Report

Plugin Slug:
ni-woocommerce-customer-product-report

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Ogulo – 360° Tour

Plugin:

Ogulo – 360° Tour

Plugin Slug:
ogulo-360-tour

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Portfolio Manager Pro

Plugin:

Portfolio Manager Pro

Plugin Slug:
otw-portfolio-manager

Vulnerability:
PHP Object Injection

Patched in Version:
No Fix

Severity Score:
Critical


The vulnerability has not been patched. You should deactivate the plugin.

Portfolio Manager Pro

Plugin:

Portfolio Manager Pro

Plugin Slug:
otw-portfolio-manager

Vulnerability:
Arbitrary File Upload

Patched in Version:
No Fix

Severity Score:
Critical


The vulnerability has not been patched. You should deactivate the plugin.

PressApps Knowledge Base Contextual Sidebar Addon

Plugin:

PressApps Knowledge Base Contextual Sidebar Addon

Plugin Slug:
pressapps-knowledge-base

Vulnerability:
PHP Object Injection

Patched in Version:
No Fix

Severity Score:
Critical


The vulnerability has not been patched. You should deactivate the plugin.

ProveSource Social Proof

Plugin:

ProveSource Social Proof

Plugin Slug:
provesource

Vulnerability:
Sensitive Data Exposure

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Restore Permanently delete Post or Page Data

Plugin:

Restore Permanently delete Post or Page Data

Plugin Slug:
restore-permanently-delete-post-or-page-data

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

ShortcodeHub – MultiPurpose Shortcode Builder

Plugin:

ShortcodeHub – MultiPurpose Shortcode Builder

Plugin Slug:
shortcodehub

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Super Store Finder

Plugin:

Super Store Finder

Plugin Slug:
superstorefinder-wp

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

ThemeMakers Visual Content Composer

Plugin:

ThemeMakers Visual Content Composer

Plugin Slug:
tmm_content_composer

Vulnerability:
PHP Object Injection

Patched in Version:
No Fix

Severity Score:
Critical


The vulnerability has not been patched. You should deactivate the plugin.

WC Plus

Plugin:

WC Plus

Plugin Slug:
wc-plus

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

WP Filter & Combine RSS Feeds

Plugin:

WP Filter & Combine RSS Feeds

Plugin Slug:
wp-filter-combine-rss-feeds

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

WP Talroo

Plugin:

WP Talroo

Plugin Slug:
wp-jobs2careers

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Wptobe-memberships

Plugin:

Wptobe-memberships

Plugin Slug:
wptobe-memberships

Vulnerability:
Arbitrary File Deletion

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

WS Theme Addons

Plugin:

WS Theme Addons

Plugin Slug:
ws-theme-addons

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

WP Crontrol

Plugin Slug:
wp-crontrol

Installations
300,000+

Vulnerability:
Server Side Request Forgery (SSRF)

Patched in Version:
1.19.2

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.19.2.

Redirection for Contact Form 7

Plugin Slug:
wpcf7-redirect

Installations
300,000+

Vulnerability:
Arbitrary File Deletion

Patched in Version:
3.2.5

Severity Score:
High


The vulnerability has been patched, so you should update to version 3.2.5.

Redirection for Contact Form 7

Plugin Slug:
wpcf7-redirect

Installations
300,000+

Vulnerability:
PHP Object Injection

Patched in Version:
3.2.5

Severity Score:
High


The vulnerability has been patched, so you should update to version 3.2.5.

Redirection for Contact Form 7

Plugin Slug:
wpcf7-redirect

Installations
300,000+

Vulnerability:
PHP Object Injection

Patched in Version:
3.2.5

Severity Score:
High


The vulnerability has been patched, so you should update to version 3.2.5.

GiveWP – Donation Plugin and Fundraising Platform

Plugin Slug:
give

Installations
100,000+

Vulnerability:
Broken Access Control

Patched in Version:
4.6.1

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 4.6.1.

WPC Smart Quick View for WooCommerce

Plugin Slug:
woo-smart-quick-view

Installations
100,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
4.2.2

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 4.2.2.

WPC Smart Compare for WooCommerce

Plugin Slug:
woo-smart-compare

Installations
80,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
6.4.8

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 6.4.8.

Media Library Assistant

Plugin Slug:
media-library-assistant

Installations
70,000+

Vulnerability:
Arbitrary File Deletion

Patched in Version:
3.28

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 3.28.

Greenshift – animation and page builder blocks

Plugin Slug:
greenshift-animation-and-page-builder-blocks

Installations
50,000+

Vulnerability:
Broken Access Control

Patched in Version:
12.1.2

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 12.1.2.

FunnelKit – Funnel Builder for WooCommerce Checkout

Plugin Slug:
funnel-builder

Installations
30,000+

Vulnerability:
Local File Inclusion

Patched in Version:
3.12.0

Severity Score:
High


The vulnerability has been patched, so you should update to version 3.12.0.

FunnelKit – Funnel Builder for WooCommerce Checkout

Plugin Slug:
funnel-builder

Installations
30,000+

Vulnerability:
Privilege Escalation

Patched in Version:
3.11.1

Severity Score:
High


The vulnerability has been patched, so you should update to version 3.11.1.

WP Visitor Statistics (Real Time Traffic)

Plugin Slug:
wp-stats-manager

Installations
30,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
8.3

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 8.3.

Fluent Support – Helpdesk & Customer Support Ticket System

Plugin Slug:
fluent-support

Installations
10,000+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
1.9.2

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.9.2.

NEX-Forms – Ultimate Forms Plugin for WordPress

Plugin Slug:
nex-forms-express-wp-form-builder

Installations
9,000+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
9.1.4

Severity Score:
High


The vulnerability has been patched, so you should update to version 9.1.4.

Flexible Map

Plugin Slug:
wp-flexible-map

Installations
8,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.19.0

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.19.0.

WP Colorbox

Plugin Slug:
wp-colorbox

Installations
7,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.1.6

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.1.6.

Raptive Ads

Plugin Slug:
adthrive-ads

Installations
6,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
3.9.0

Severity Score:
High


The vulnerability has been patched, so you should update to version 3.9.0.

Themify Builder

Plugin Slug:
themify-builder

Installations
6,000+

Vulnerability:
Broken Access Control

Patched in Version:
7.6.8

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 7.6.8.

CubeWP – All-in-One Dynamic Content Framework

Plugin Slug:
cubewp-framework

Installations
5,000+

Vulnerability:
Privilege Escalation

Patched in Version:
1.1.25

Severity Score:
High


The vulnerability has been patched, so you should update to version 1.1.25.

Themify Icons

Plugin Slug:
themify-icons

Installations
4,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.0.4

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.0.4.

E-cab Taxi Booking Manager for Woocommerce

Plugin Slug:
ecab-taxi-booking-manager

Installations
1,000+

Vulnerability:
Broken Authentication

Patched in Version:
1.3.1

Severity Score:
Critical


The vulnerability has been patched, so you should update to version 1.3.1.

WP Fast Total Search – The Power of Indexed Search

Plugin Slug:
fulltext-search

Installations
1,000+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
1.79.274

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.79.274.

Markup Markdown

Plugin Slug:
markup-markdown

Installations
1,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
3.20.7

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 3.20.7.

Recurring PayPal Donations

Plugin Slug:
recurring-donation

Installations
1,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.9

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.9.

Sign-up Sheets

Plugin Slug:
sign-up-sheets

Installations
1,000+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
2.3.3.1

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.3.3.1.

Simple Statistics for Feeds

Plugin Slug:
simple-feed-stats

Installations
1,000+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
20250820

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 20250820.

Themify Audio Dock

Plugin Slug:
themify-audio-dock

Installations
1,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.0.6

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.0.6.

MDTF – Meta Data and Taxonomies Filter

Plugin Slug:
wp-meta-data-filter-and-taxonomy-filter

Installations
1,000+

Vulnerability:
SQL Injection

Patched in Version:
1.3.3.8

Severity Score:
Critical


The vulnerability has been patched, so you should update to version 1.3.3.8.

WPPizza – A Restaurant Plugin

Plugin Slug:
wppizza

Installations
1,000+

Vulnerability:
Broken Access Control

Patched in Version:
3.19.8.1

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 3.19.8.1.

Sessions

Plugin:

Sessions

Plugin Slug:
sessions

Installations
900+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
3.2.1

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 3.2.1.

Notice Bar

Plugin:

Notice Bar

Plugin Slug:
notice-bar

Installations
800+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
3.1.4

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 3.1.4.

Church Admin

Plugin Slug:
church-admin

Installations
700+

Vulnerability:
Broken Access Control

Patched in Version:
5.0.27

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 5.0.27.

UPC/EAN/GTIN Code Generator

Plugin Slug:
upc-ean-barcode-generator

Installations
500+

Vulnerability:
Arbitrary File Deletion

Patched in Version:
2.0.3

Severity Score:
High


The vulnerability has been patched, so you should update to version 2.0.3.

Bible SuperSearch

Plugin Slug:
biblesupersearch

Installations
300+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
6.1.0

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 6.1.0.

Contact Manager

Plugin Slug:
contact-manager

Installations
100+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
8.6.6

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 8.6.6.

Vibes

Plugin:

Vibes

Plugin Slug:
vibes

Installations
100+

Vulnerability:
SQL Injection

Patched in Version:
2.2.1

Severity Score:
Critical


The vulnerability has been patched, so you should update to version 2.2.1.

ads.txt Guru Connect

Plugin Slug:
adstxt-guru-connect

Installations
90+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
1.1.2

Severity Score:
Critical


The vulnerability has been patched, so you should update to version 1.1.2.

Custom Query Shortcode

Plugin Slug:
custom-query-shortcode

Installations
30+

Vulnerability:
Directory Traversal

Patched in Version:
0.5.0

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 0.5.0.

Case Theme User

Plugin:

Case Theme User

Plugin Slug:
case-theme-user

Vulnerability:
Broken Authentication

Patched in Version:
1.0.4

Severity Score:
Critical


The vulnerability has been patched, so you should update to version 1.0.4.

eventlist

Plugin:

eventlist

Plugin Slug:
eventlist

Vulnerability:
Privilege Escalation

Patched in Version:
2.0.5

Severity Score:
High


The vulnerability has been patched, so you should update to version 2.0.5.

Global DNS

Plugin:

Global DNS

Plugin Slug:
global-dns

Vulnerability:
Remote Code Execution (RCE)

Patched in Version:
3.1.1

Severity Score:
Critical


The vulnerability has been patched, so you should update to version 3.1.1.

Miraculous Core Plugin

Plugin:

Miraculous Core Plugin

Plugin Slug:
miraculouscore

Vulnerability:
Privilege Escalation

Patched in Version:
2.0.8

Severity Score:
Critical


The vulnerability has been patched, so you should update to version 2.0.8.

Ovatheme Events

Plugin:

Ovatheme Events

Plugin Slug:
ova-events

Vulnerability:
Local File Inclusion

Patched in Version:
1.2.7

Severity Score:
High


The vulnerability has been patched, so you should update to version 1.2.7.

Simple Business Directory Pro

Plugin:

Simple Business Directory Pro

Plugin Slug:
simple-business-directory-pro

Vulnerability:
Privilege Escalation

Patched in Version:
15.6.9

Severity Score:
Critical


The vulnerability has been patched, so you should update to version 15.6.9.

Tourfic

Plugin:

Tourfic

Plugin Slug:
tourfic

Vulnerability:
Broken Access Control

Patched in Version:
2.15.0

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.15.0.

Automatic

Plugin:

Automatic

Plugin Slug:
wp-automatic

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
3.119.0

Severity Score:
High


The vulnerability has been patched, so you should update to version 3.119.0.

WordPress Themes — 13 Patched / 11 Unpatched

BlogMarks

Theme Slug:
blogmarks

Downloads
2,998

Vulnerability:
Local File Inclusion

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should switch themes.

Eximious Magazine

Theme Slug:
eximious-magazine

Downloads
89,583

Vulnerability:
Local File Inclusion

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should switch themes.

Glamer

Theme:

Glamer

Theme Slug:
glamer

Downloads
1,229

Vulnerability:
Local File Inclusion

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should switch themes.

Magazine Elite

Theme Slug:
magazine-elite

Downloads
23,250

Vulnerability:
Local File Inclusion

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should switch themes.

Magazine Saga

Theme Slug:
magazine-saga

Downloads
39,647

Vulnerability:
Local File Inclusion

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should switch themes.

Jannah

Theme:

Jannah

Theme Slug:
jannah

Vulnerability:
Local File Inclusion

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should switch themes.

Kalium

Theme:

Kalium

Theme Slug:
kalium

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should switch themes.

Kitring

Theme:

Kitring

Theme Slug:
kitring

Vulnerability:
Local File Inclusion

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should switch themes.

Nuss

Theme:

Nuss

Theme Slug:
nuss

Vulnerability:
Local File Inclusion

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should switch themes.

Organic Beauty

Theme:

Organic Beauty

Theme Slug:
organic-beauty

Vulnerability:
PHP Object Injection

Patched in Version:
No Fix

Severity Score:
Critical


The vulnerability has not been patched. You should switch themes.

Pro Bulk Watermark Plugin for WordPress

Theme:

Pro Bulk Watermark Plugin for WordPress

Theme Slug:
pro-watermark

Vulnerability:
Path Traversal

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should switch themes.

ColorMag

Theme:

ColorMag

Theme Slug:
colormag

Downloads
4,262,710

Vulnerability:
Broken Access Control

Patched in Version:
4.0.20

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 4.0.20.

Inspiro

Theme:

Inspiro

Theme Slug:
inspiro

Downloads
1,177,489

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
2.1.3

Severity Score:
High


The vulnerability has been patched, so you should update to version 2.1.3.

Spacious

Theme:

Spacious

Theme Slug:
spacious

Downloads
2,634,166

Vulnerability:
Broken Access Control

Patched in Version:
1.9.12

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.9.12.

Golo

Theme:

Golo

Theme Slug:
golo

Vulnerability:
Broken Authentication

Patched in Version:
1.7.1

Severity Score:
Critical


The vulnerability has been patched, so you should update to version 1.7.1.

Houzez

Theme:

Houzez

Theme Slug:
houzez

Vulnerability:
Broken Access Control

Patched in Version:
4.1.4

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 4.1.4.

JobZilla – Job Board WordPress Theme

Theme:

JobZilla – Job Board WordPress Theme

Theme Slug:
jobzilla

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
2.0.1

Severity Score:
High


The vulnerability has been patched, so you should update to version 2.0.1.

Kipso

Theme:

Kipso

Theme Slug:
kipso

Vulnerability:
Local File Inclusion

Patched in Version:
1.3.5

Severity Score:
High


The vulnerability has been patched, so you should update to version 1.3.5.

Jobmonster

Theme:

Jobmonster

Theme Slug:
noo-jobmonster

Vulnerability:
Sensitive Data Exposure

Patched in Version:
4.8.1

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 4.8.1.

Jobmonster

Theme:

Jobmonster

Theme Slug:
noo-jobmonster

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
4.8.1

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 4.8.1.

Jobmonster

Theme:

Jobmonster

Theme Slug:
noo-jobmonster

Vulnerability:
Broken Authentication

Patched in Version:
4.8.0

Severity Score:
Critical


The vulnerability has been patched, so you should update to version 4.8.0.

Real Spaces

Theme:

Real Spaces

Theme Slug:
real-spaces

Vulnerability:
Privilege Escalation

Patched in Version:
3.6.1

Severity Score:
Critical


The vulnerability has been patched, so you should update to version 3.6.1.

Real Spaces

Theme:

Real Spaces

Theme Slug:
real-spaces

Vulnerability:
Privilege Escalation

Patched in Version:
3.6

Severity Score:
High


The vulnerability has been patched, so you should update to version 3.6.

Sala

Theme:

Sala

Theme Slug:
sala

Vulnerability:
Local File Inclusion

Patched in Version:
1.1.7

Severity Score:
High


The vulnerability has been patched, so you should update to version 1.1.7.

Solid Security is part of Solid Suite — The best foundation for WordPress websites.

Every WordPress site needs security, backups, and management tools. That’s Solid Suite — an integrated bundle of three plugins: Solid Security, Solid Backups, and Solid Central. You also get access to Solid Academy’s learning resources for WordPress professionals. Build your next WordPress website on a solid foundation with Solid Suite!

Get Solid Security


The post WordPress Vulnerability Report — August 27, 2025 appeared first on SolidWP.

Click here to continue reading this article.