In this report, 133 vulnerabilities have been publicly disclosed. Security patches for 98 of these plugins and themes are now available, so please run those updates as soon as possible. If you’re a Solid Security Pro user, the version management tool may have already warned you and updated these plugins, depending on your settings.
Additionally, there are 35 plugin and theme vulnerabilities, and no patch has been available yet. If you’re a Solid Security Pro user, those vulnerabilities are already protected by the Solid Security firewall. Virtual patches from Patchstack will be applied when a vulnerability is considered high or medium risk. If no patch is forthcoming from the vendor or the vulnerable software has been marked “closed” and dropped from the official WordPress repositories, you should deactivate it soon and look for alternative solutions.
WordPress Core
WordPress 6.8.2 was released on July 15, 2025. This maintenance release includes fixes for 20 Core tickets and 15 Block Editor issues. For a full list of bug fixes, please refer to the release candidate announcement.
WordPress Plugins — 86 Patched / 33 Unpatched
Eventer
- Plugin:
-
Eventer
- Plugin Slug:
- eventer
- Installations
- 1,000+
- Vulnerability:
- Content Injection
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
-
2025-39483
PressForward
- Plugin:
-
PressForward
- Plugin Slug:
- pressforward
- Installations
- 200+
- Vulnerability:
- Server Side Request Forgery (SSRF)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
-
2025-28987
360 Photo Spheres
- Plugin:
-
360 Photo Spheres
- Plugin Slug:
- 360-sphere-images
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
-
2025-4588
Advanced Google Universal Analytics
- Plugin:
-
Advanced Google Universal Analytics
- Plugin Slug:
- advanced-google-universal-analytics
- Vulnerability:
- Broken Access Control
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
-
2025-28962
Affiliate Plus
- Plugin:
-
Affiliate Plus
- Plugin Slug:
- affiliate-plus
- Vulnerability:
- Cross Site Request Forgery (CSRF)
- Patched in Version:
- No Fix
- Severity Score:
- High
- CVE:
-
2025-7690
April Framework
- Plugin:
-
April Framework
- Plugin Slug:
- april-framework
- Vulnerability:
- Arbitrary File Upload
- Patched in Version:
- No Fix
- Severity Score:
- High
- CVE:
-
2024-13418
April Framework
- Plugin:
-
April Framework
- Plugin Slug:
- april-framework
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
-
2024-13419
April Framework
- Plugin:
-
April Framework
- Plugin Slug:
- april-framework
- Vulnerability:
- Broken Access Control
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
-
2024-13420
Image Gallery
- Plugin:
-
Image Gallery
- Plugin Slug:
- bee-quick-gallery
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- High
- CVE:
-
2025-8400
BeeTeam368 Extensions
- Plugin:
-
BeeTeam368 Extensions
- Plugin Slug:
- beeteam368-extensions
- Vulnerability:
- Local File Inclusion
- Patched in Version:
- No Fix
- Severity Score:
- Critical
- CVE:
-
2025-25174
Benaa Framework
- Plugin:
-
Benaa Framework
- Plugin Slug:
- benaa-framework
- Vulnerability:
- Arbitrary File Upload
- Patched in Version:
- No Fix
- Severity Score:
- High
- CVE:
-
2024-13418
Benaa Framework
- Plugin:
-
Benaa Framework
- Plugin Slug:
- benaa-framework
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
-
2024-13419
Benaa Framework
- Plugin:
-
Benaa Framework
- Plugin Slug:
- benaa-framework
- Vulnerability:
- Broken Access Control
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
-
2024-13420
Beyot Framework
- Plugin:
-
Beyot Framework
- Plugin Slug:
- beyot-framework
- Vulnerability:
- Arbitrary File Upload
- Patched in Version:
- No Fix
- Severity Score:
- High
- CVE:
-
2024-13418
Beyot Framework
- Plugin:
-
Beyot Framework
- Plugin Slug:
- beyot-framework
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
-
2024-13419
Beyot Framework
- Plugin:
-
Beyot Framework
- Plugin Slug:
- beyot-framework
- Vulnerability:
- Broken Access Control
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
-
2024-13420
Bonanza – WooCommerce Free Gifts Lite
- Plugin:
-
Bonanza – WooCommerce Free Gifts Lite
- Plugin Slug:
- bonanza-woocommerce-free-gifts-lite
- Vulnerability:
- Broken Access Control
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
-
2025-6730
Cube Portfolio
- Plugin:
-
Cube Portfolio
- Plugin Slug:
- cubeportfolio
- Vulnerability:
- SQL Injection
- Patched in Version:
- No Fix
- Severity Score:
- High
- CVE:
-
2025-52823
Custom Word Cloud
- Plugin:
-
Custom Word Cloud
- Plugin Slug:
- custom-word-cloud
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
-
2025-8317
Fan Page
- Plugin:
-
Fan Page
- Plugin Slug:
- fan-page
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
-
2025-6681
Auteur Framework
- Plugin:
-
Auteur Framework
- Plugin Slug:
- g5plus-auteur
- Vulnerability:
- Arbitrary File Upload
- Patched in Version:
- No Fix
- Severity Score:
- High
- CVE:
-
2024-13418
Auteur Framework
- Plugin:
-
Auteur Framework
- Plugin Slug:
- g5plus-auteur
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
-
2024-13419
Auteur Framework
- Plugin:
-
Auteur Framework
- Plugin Slug:
- g5plus-auteur
- Vulnerability:
- Broken Access Control
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
-
2024-13420
WP LOL Rotation
- Plugin:
-
WP LOL Rotation
- Plugin Slug:
- league-of-legends-rotation
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
-
2025-49437
Magic Edge – Lite
- Plugin:
-
Magic Edge – Lite
- Plugin Slug:
- magic-edge-lite-image-background-remover
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
-
2025-8391
Medical Addon for Elementor
- Plugin:
-
Medical Addon for Elementor
- Plugin Slug:
- medical-addon-for-elementor
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
-
2025-8212
Mmm Unity Loader
- Plugin:
-
Mmm Unity Loader
- Plugin Slug:
- mmm-unity-loader
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
-
2025-8399
My Reservation System
- Plugin:
-
My Reservation System
- Plugin Slug:
- my-reservation-system
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- High
- CVE:
-
2025-7022
SEO Metrics
- Plugin:
-
SEO Metrics
- Plugin Slug:
- seo-metrics-helper
- Vulnerability:
- Privilege Escalation
- Patched in Version:
- No Fix
- Severity Score:
- High
- CVE:
-
2025-6754
Supermalink
- Plugin:
-
Supermalink
- Plugin Slug:
- supermalink
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
-
2025-49433
TheBooking
- Plugin:
-
TheBooking
- Plugin Slug:
- thebooking
- Vulnerability:
- Broken Access Control
- Patched in Version:
- No Fix
- Severity Score:
- High
- CVE:
-
2025-52801
Amazon Native Shopping Recommendations
- Plugin:
-
Amazon Native Shopping Recommendations
- Plugin Slug:
- woozone-contextual
- Vulnerability:
- SQL Injection
- Patched in Version:
- No Fix
- Severity Score:
- Critical
- CVE:
-
2025-30633
YouTube Embed – YouTube Gallery, Vimeo Gallery – WordPress Plugin
- Plugin:
-
YouTube Embed – YouTube Gallery, Vimeo Gallery – WordPress Plugin
- Plugin Slug:
- youram-youtube-embed
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
-
2025-6692
Elementor Website Builder – More Than Just a Page Builder
- Plugin Slug:
- elementor
- Installations
- 10,000,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 3.30.3
- Severity Score:
- Medium
- CVE:
-
2025-4566
Ultimate Addons for Elementor (Formerly Elementor Header & Footer Builder)
- Plugin Slug:
- header-footer-elementor
- Installations
- 2,000,000+
- Vulnerability:
- Broken Access Control
- Patched in Version:
- 2.4.7
- Severity Score:
- Medium
- CVE:
-
2025-8488
Smart Slider 3
- Plugin:
-
Smart Slider 3
- Plugin Slug:
- smart-slider-3
- Installations
- 900,000+
- Vulnerability:
- SQL Injection
- Patched in Version:
- 3.5.1.29
- Severity Score:
- High
- CVE:
-
2025-6348
MetForm – Contact Form, Survey, Quiz, & Custom Form Builder for Elementor
- Plugin Slug:
- metform
- Installations
- 500,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 4.0.2
- Severity Score:
- Medium
- CVE:
-
2025-5684
Qi Addons For Elementor
- Plugin:
-
Qi Addons For Elementor
- Plugin Slug:
- qi-addons-for-elementor
- Installations
- 200,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 1.9.3
- Severity Score:
- Medium
- CVE:
-
2025-8146
AI Engine
GiveWP – Donation Plugin and Fundraising Platform
- Plugin Slug:
- give
- Installations
- 100,000+
- Vulnerability:
- Sensitive Data Exposure
- Patched in Version:
- 4.6.1
- Severity Score:
- High
GiveWP – Donation Plugin and Fundraising Platform
- Plugin Slug:
- give
- Installations
- 100,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 4.6.0
- Severity Score:
- Medium
- CVE:
-
2025-7205
The Plus Addons for Elementor – Elementor Addons, Page Templates, Widgets, Mega Menu, WooCommerce
- Plugin:
-
The Plus Addons for Elementor – Elementor Addons, Page Templates, Widgets, Mega Menu, WooCommerce
- Plugin Slug:
- the-plus-addons-for-elementor-page-builder
- Installations
- 100,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 6.3.11
- Severity Score:
- Medium
- CVE:
-
2025-7646
Brizy – Page Builder
- Plugin:
-
Brizy – Page Builder
- Plugin Slug:
- brizy
- Installations
- 80,000+
- Vulnerability:
- Broken Access Control
- Patched in Version:
- 2.6.21
- Severity Score:
- Medium
- CVE:
-
2025-4370
Customer Reviews for WooCommerce
- Plugin:
-
Customer Reviews for WooCommerce
- Plugin Slug:
- customer-reviews-woocommerce
- Installations
- 80,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 5.81.0
- Severity Score:
- High
- CVE:
-
2025-5720
HT Mega – Absolute Addons For Elementor
- Plugin Slug:
- ht-mega-for-elementor
- Installations
- 80,000+
- Vulnerability:
- Path Traversal
- Patched in Version:
- 2.9.2
- Severity Score:
- Medium
- CVE:
-
2025-8151
HT Mega – Absolute Addons For Elementor
- Plugin Slug:
- ht-mega-for-elementor
- Installations
- 80,000+
- Vulnerability:
- Sensitive Data Exposure
- Patched in Version:
- 2.9.2
- Severity Score:
- Medium
- CVE:
-
2025-8401
HT Mega – Absolute Addons For Elementor
- Plugin Slug:
- ht-mega-for-elementor
- Installations
- 80,000+
- Vulnerability:
- Broken Access Control
- Patched in Version:
- 2.9.2
- Severity Score:
- Medium
- CVE:
-
2025-8068
HT Mega – Absolute Addons For Elementor
- Plugin Slug:
- ht-mega-for-elementor
- Installations
- 80,000+
- Vulnerability:
- Broken Access Control
- Patched in Version:
- 2.9.1
- Severity Score:
- Medium
- CVE:
-
2025-54695
Ocean Social Sharing
- Plugin:
-
Ocean Social Sharing
- Plugin Slug:
- ocean-social-sharing
- Installations
- 80,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 2.2.2
- Severity Score:
- Medium
- CVE:
-
2025-7500
Sina Extension for Elementor (Header Builder, Footer Builter, Theme Builder, Slider, Gallery, Form, Modal, Data Table Free Elementor Widgets & Elementor Templates)
- Plugin Slug:
- sina-extension-for-elementor
- Installations
- 50,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 3.7.1
- Severity Score:
- Medium
- CVE:
-
2025-6228
WP Import Export Lite
- Plugin:
-
WP Import Export Lite
- Plugin Slug:
- wp-import-export-lite
- Installations
- 50,000+
- Vulnerability:
- Arbitrary File Upload
- Patched in Version:
- 3.9.30
- Severity Score:
- Critical
- CVE:
-
2025-5061
WP Import Export Lite
- Plugin:
-
WP Import Export Lite
- Plugin Slug:
- wp-import-export-lite
- Installations
- 50,000+
- Vulnerability:
- Arbitrary File Upload
- Patched in Version:
- 3.9.29
- Severity Score:
- Critical
- CVE:
-
2025-6207
NinjaScanner – Virus & Malware scan
- Plugin Slug:
- ninjascanner
- Installations
- 30,000+
- Vulnerability:
- Arbitrary File Deletion
- Patched in Version:
- 3.2.6
- Severity Score:
- Medium
- CVE:
-
2025-8213
Gutenberg Blocks – PublishPress Blocks Controls, Visibility, Reusable Blocks
- Plugin Slug:
- advanced-gutenberg
- Installations
- 20,000+
- Vulnerability:
- Local File Inclusion
- Patched in Version:
- 3.3.2
- Severity Score:
- High
- CVE:
-
2025-48332
Content Egg
- Plugin:
-
Content Egg
- Plugin Slug:
- content-egg
- Installations
- 20,000+
- Vulnerability:
- PHP Object Injection
- Patched in Version:
- 8.0.0
- Severity Score:
- High
- CVE:
-
2025-47536
BlockSpare: Gutenberg Blocks & Patterns for Blogs, Magazines, Business Sites – Post Grids, Sliders, Carousels, Counters, Page Builder & Starter Site Imports, No Coding Needed
- Plugin Slug:
- blockspare
- Installations
- 10,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 3.2.13.2
- Severity Score:
- Medium
- CVE:
-
2025-4684
Classified Listing – Classified ads & Business Directory Plugin
- Plugin Slug:
- classified-listing
- Installations
- 10,000+
- Vulnerability:
- Content Injection
- Patched in Version:
- 5.0.1
- Severity Score:
- Medium
- CVE:
-
2025-54698
Graphina – Elementor Charts and Graphs
- Plugin Slug:
- graphina-elementor-charts-and-graphs
- Installations
- 10,000+
- Vulnerability:
- Local File Inclusion
- Patched in Version:
- 3.1.2
- Severity Score:
- High
- CVE:
-
2025-23968
myCred – Points Management System For Gamification, Ranks, Badges, and Loyalty Rewards Program.
- Plugin:
-
myCred – Points Management System For Gamification, Ranks, Badges, and Loyalty Rewards Program.
- Plugin Slug:
- mycred
- Installations
- 10,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 2.9.4.4
- Severity Score:
- Medium
- CVE:
-
2025-54668
myCred – Points Management System For Gamification, Ranks, Badges, and Loyalty Rewards Program.
- Plugin:
-
myCred – Points Management System For Gamification, Ranks, Badges, and Loyalty Rewards Program.
- Plugin Slug:
- mycred
- Installations
- 10,000+
- Vulnerability:
- Race Condition
- Patched in Version:
- 2.9.4.4
- Severity Score:
- Medium
- CVE:
-
2025-54667
Paid Membership Subscriptions – Effortless Memberships, Recurring Payments & Content Restriction
- Plugin:
-
Paid Membership Subscriptions – Effortless Memberships, Recurring Payments & Content Restriction
- Plugin Slug:
- paid-member-subscriptions
- Installations
- 10,000+
- Vulnerability:
- Local File Inclusion
- Patched in Version:
- 2.15.5
- Severity Score:
- High
- CVE:
-
2025-54017
ShortPixel Adaptive Images – WebP, AVIF, CDN, Image Optimization
- Plugin Slug:
- shortpixel-adaptive-images
- Installations
- 10,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 3.10.5
- Severity Score:
- Medium
- CVE:
-
2025-6626
WP REST Cache
- Plugin:
-
WP REST Cache
- Plugin Slug:
- wp-rest-cache
- Installations
- 10,000+
- Vulnerability:
- Local File Inclusion
- Patched in Version:
- 2025.1.1
- Severity Score:
- High
- CVE:
-
2025-52716
Motors – Car Dealership & Classified Listings Plugin
- Plugin Slug:
- motors-car-dealership-classified-listings
- Installations
- 9,000+
- Vulnerability:
- Insecure Direct Object References (IDOR)
- Patched in Version:
- 1.4.81
- Severity Score:
- Medium
- CVE:
-
2025-54691
File Manager for Google Drive – Integrate Google Drive with WordPress
- Plugin Slug:
- integrate-google-drive
- Installations
- 8,000+
- Vulnerability:
- Cross Site Request Forgery (CSRF)
- Patched in Version:
- 1.5.3
- Severity Score:
- Medium
- CVE:
-
2025-54703
Event Booking Manager for WooCommerce – WpEvently
- Plugin Slug:
- mage-eventpress
- Installations
- 8,000+
- Vulnerability:
- Broken Access Control
- Patched in Version:
- 4.4.7
- Severity Score:
- Medium
- CVE:
-
2025-54705
Easiest Funnel Builder For WordPress & WooCommerce, Specialized For Digital Creators – WPFunnels
- Plugin:
-
Easiest Funnel Builder For WordPress & WooCommerce, Specialized For Digital Creators – WPFunnels
- Plugin Slug:
- wpfunnels
- Installations
- 8,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 3.5.27
- Severity Score:
- Medium
- CVE:
-
2025-54696
Button Block – Get fully customizable & multi-functional buttons
- Plugin Slug:
- button-block
- Installations
- 5,000+
- Vulnerability:
- Cross Site Request Forgery (CSRF)
- Patched in Version:
- 1.2.1
- Severity Score:
- Medium
- CVE:
-
2025-54694
Magical Addons For Elementor ( Header Footer Builder, Free Elementor Widgets, Elementor Templates Library )
- Plugin Slug:
- magical-addons-for-elementor
- Installations
- 5,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 1.3.9
- Severity Score:
- Medium
- CVE:
-
2025-8196
Simple File List
- Plugin:
-
Simple File List
- Plugin Slug:
- simple-file-list
- Installations
- 5,000+
- Vulnerability:
- Arbitrary File Download
- Patched in Version:
- 6.1.15
- Severity Score:
- High
- CVE:
-
2025-54021
Memory Usage, Memory Limit, PHP and Server Memory Health Check and Provide Suggestions
- Plugin Slug:
- wp-memory
- Installations
- 5,000+
- Vulnerability:
- Cross Site Request Forgery (CSRF)
- Patched in Version:
- 3.99
- Severity Score:
- Medium
- CVE:
-
2025-8104
Hydra Booking – All in One Appointment Booking System | Appointment Scheduling, Booking Calendar & WooCommerce Bookings
- Plugin Slug:
- hydra-booking
- Installations
- 4,000+
- Vulnerability:
- Privilege Escalation
- Patched in Version:
- 1.1.19
- Severity Score:
- High
- CVE:
-
2025-7689
Magical Posts Display – Elementor Advanced Posts widgets
- Plugin Slug:
- magical-posts-display
- Installations
- 4,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 1.2.53
- Severity Score:
- Medium
- CVE:
-
2025-54706
Chartify – WordPress Chart Plugin
- Plugin Slug:
- chart-builder
- Installations
- 3,000+
- Vulnerability:
- Cross Site Request Forgery (CSRF)
- Patched in Version:
- 3.5.4
- Severity Score:
- Medium
- CVE:
-
2025-54673
Masteriyo LMS – Online Course Builder for eLearning, LMS & Education
- Plugin Slug:
- learning-management-system
- Installations
- 3,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 1.18.4
- Severity Score:
- Medium
- CVE:
-
2025-54699
Product Configurator for WooCommerce
- Plugin Slug:
- product-configurator-for-woocommerce
- Installations
- 3,000+
- Vulnerability:
- Cross Site Request Forgery (CSRF)
- Patched in Version:
- 1.5.0
- Severity Score:
- Medium
- CVE:
-
2025-54674
BerqWP – Automated All-In-One Page Speed Optimization for Core Web Vitals, Cache, CDN, Images, CSS, and JavaScript
- Plugin Slug:
- searchpro
- Installations
- 3,000+
- Vulnerability:
- Arbitrary File Upload
- Patched in Version:
- 2.2.44
- Severity Score:
- Critical
- CVE:
-
2025-7443
Connector for Gravity Forms and Google Sheets
- Plugin Slug:
- wp-gravity-forms-spreadsheets
- Installations
- 3,000+
- Vulnerability:
- Cross Site Request Forgery (CSRF)
- Patched in Version:
- 1.2.5
- Severity Score:
- Medium
- CVE:
-
2025-54682
Connector for Gravity Forms and Google Sheets
- Plugin Slug:
- wp-gravity-forms-spreadsheets
- Installations
- 3,000+
- Vulnerability:
- Open Redirection
- Patched in Version:
- 1.2.5
- Severity Score:
- Medium
- CVE:
-
2025-54681
WP CTA
Online Booking & Scheduling Calendar for WordPress by vcita
- Plugin Slug:
- meeting-scheduler-by-vcita
- Installations
- 2,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 4.5.5
- Severity Score:
- Medium
- CVE:
-
2025-54676
Newsletters
- Plugin:
-
Newsletters
- Plugin Slug:
- newsletters-lite
- Installations
- 2,000+
- Vulnerability:
- Local File Inclusion
- Patched in Version:
- 4.11
- Severity Score:
- High
- CVE:
-
2025-54034
oik
- Plugin:
-
oik
- Plugin Slug:
- oik
- Installations
- 2,000+
- Vulnerability:
- Cross Site Request Forgery (CSRF)
- Patched in Version:
- 4.15.3
- Severity Score:
- Medium
- CVE:
-
2025-54671
Realtyna Organic IDX plugin + WPL Real Estate
- Plugin Slug:
- real-estate-listing-realtyna-wpl
- Installations
- 2,000+
- Vulnerability:
- Local File Inclusion
- Patched in Version:
- 5.0.1
- Severity Score:
- High
- CVE:
-
2025-54052
Sky Addons – Elementor Addons with Widgets & Templates
- Plugin Slug:
- sky-elementor-addons
- Installations
- 2,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 3.2.0
- Severity Score:
- Medium
- CVE:
-
2025-8216
WP Modal Popup with Cookie Integration
- Plugin Slug:
- wp-modal-popup-with-cookie-integration
- Installations
- 2,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 2.5
- Severity Score:
- Medium
- CVE:
-
2025-54683
Photo Engine (Media Organizer & Lightroom)
- Plugin Slug:
- wplr-sync
- Installations
- 2,000+
- Vulnerability:
- Cross Site Request Forgery (CSRF)
- Patched in Version:
- 6.4.4
- Severity Score:
- Medium
- CVE:
-
2025-54672
YITH WooCommerce Popup
- Plugin:
-
YITH WooCommerce Popup
- Plugin Slug:
- yith-woocommerce-popup
- Installations
- 2,000+
- Vulnerability:
- Cross Site Request Forgery (CSRF)
- Patched in Version:
- 1.48.1
- Severity Score:
- Medium
- CVE:
-
2025-54675
Photos, Files, YouTube, Twitter, Instagram, TikTok, Ecommerce Contest Gallery – Upload, Vote, Sell via PayPal or Stripe, Social Share Buttons, OpenAI
- Plugin Slug:
- contest-gallery
- Installations
- 1,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 26.1.1
- Severity Score:
- High
- CVE:
-
2025-7725
Custom API for WP
- Plugin:
-
Custom API for WP
- Plugin Slug:
- custom-api-for-wp
- Installations
- 1,000+
- Vulnerability:
- Privilege Escalation
- Patched in Version:
- 4.2.3
- Severity Score:
- Critical
- CVE:
-
2025-54049
Easy Elementor Addons
- Plugin:
-
Easy Elementor Addons
- Plugin Slug:
- easy-elementor-addons
- Installations
- 1,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 2.2.7
- Severity Score:
- Medium
- CVE:
-
2025-54704
Ebook Store
- Plugin:
-
Ebook Store
- Plugin Slug:
- ebook-store
- Installations
- 1,000+
- Vulnerability:
- Cross Site Request Forgery (CSRF)
- Patched in Version:
- 5.8014
- Severity Score:
- Medium
- CVE:
-
2025-54702
Product XML Feed Manager for WooCommerce – Google Shopping, Social Sites, Skroutz & More
- Plugin Slug:
- product-xml-feeds-for-woocommerce
- Installations
- 1,000+
- Vulnerability:
- Remote Code Execution (RCE)
- Patched in Version:
- 2.9.4
- Severity Score:
- Critical
- CVE:
-
2025-49887
StreamWeasels Twitch Integration
- Plugin:
-
StreamWeasels Twitch Integration
- Plugin Slug:
- streamweasels-twitch-integration
- Installations
- 1,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 1.9.4
- Severity Score:
- Medium
- CVE:
-
2025-7809
StreamWeasels YouTube Integration
- Plugin Slug:
- streamweasels-youtube-integration
- Installations
- 1,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 1.4.1
- Severity Score:
- Medium
- CVE:
-
2025-7811
All in One Time Clock Lite – Tracking Employee Time Has Never Been Easier
- Plugin Slug:
- aio-time-clock-lite
- Installations
- 800+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 2.0.1
- Severity Score:
- High
- CVE:
-
2025-6832
Integration for Constant Contact and Contact Form 7, WPForms, Elementor, Ninja Forms
- Plugin Slug:
- cf7-constant-contact
- Installations
- 800+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 1.1.8
- Severity Score:
- Medium
- CVE:
-
2025-54684
SureDash
- Plugin:
-
SureDash
- Plugin Slug:
- suredash
- Installations
- 600+
- Vulnerability:
- Sensitive Data Exposure
- Patched in Version:
- 1.2.0
- Severity Score:
- Medium
- CVE:
-
2025-54685
SureDash
- Plugin:
-
SureDash
- Plugin Slug:
- suredash
- Installations
- 600+
- Vulnerability:
- Privilege Escalation
- Patched in Version:
- 1.1.0
- Severity Score:
- High
- CVE:
-
2025-48164
DELUCKS SEO
- Plugin:
-
DELUCKS SEO
- Plugin Slug:
- delucks-seo
- Installations
- 500+
- Vulnerability:
- Privilege Escalation
- Patched in Version:
- 2.6.1
- Severity Score:
- High
- CVE:
-
2025-48165
BitFire Security – Firewall, WAF, Bot/Spam Blocker, Login Security
- Plugin Slug:
- bitfire
- Installations
- 400+
- Vulnerability:
- Sensitive Data Exposure
- Patched in Version:
- 4.6
- Severity Score:
- Medium
- CVE:
-
2025-6722
BuddyPress XProfile Custom Image Field
- Plugin Slug:
- buddypress-xprofile-image-field
- Installations
- 300+
- Vulnerability:
- Arbitrary File Deletion
- Patched in Version:
- 3.1.0
- Severity Score:
- High
- CVE:
-
2025-48158
Employee Directory – Staff Listing & Team Directory Plugin for WordPress
- Plugin Slug:
- employee-directory
- Installations
- 100+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 4.5.2
- Severity Score:
- Medium
- CVE:
-
2025-8295
Google Map Targeting
- Plugin:
-
Google Map Targeting
- Plugin Slug:
- gmap-targeting
- Installations
- 100+
- Vulnerability:
- Local File Inclusion
- Patched in Version:
- 1.1.7
- Severity Score:
- High
- CVE:
-
2025-52732
Dataverse Integration
- Plugin:
-
Dataverse Integration
- Plugin Slug:
- integration-cds
- Installations
- 100+
- Vulnerability:
- Privilege Escalation
- Patched in Version:
- 2.81.1
- Severity Score:
- High
- CVE:
-
2025-7695
StreamWeasels Kick Integration
- Plugin:
-
StreamWeasels Kick Integration
- Plugin Slug:
- streamweasels-kick-integration
- Installations
- 100+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 1.1.5
- Severity Score:
- Medium
- CVE:
-
2025-7810
Campus Directory – Faculty, Staff & Student Directory Plugin for WordPress
- Plugin Slug:
- campus-directory
- Installations
- 80+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 1.9.2
- Severity Score:
- Medium
- CVE:
-
2025-8313
StoreKeeper for WooCommerce
- Plugin:
-
StoreKeeper for WooCommerce
- Plugin Slug:
- storekeeper-for-woocommerce
- Installations
- 50+
- Vulnerability:
- Arbitrary File Upload
- Patched in Version:
- 14.4.5
- Severity Score:
- Critical
- CVE:
-
2025-48148
Download Counter
- Plugin:
-
Download Counter
- Plugin Slug:
- download-counter
- Installations
- 40+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 1.4
- Severity Score:
- Medium
- CVE:
-
2025-8294
Simple Contact Form Plugin for WordPress – WP Easy Contact
- Plugin Slug:
- wp-easy-contact
- Installations
- 40+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 4.0.2
- Severity Score:
- Medium
- CVE:
-
2025-8315
Appointment Booking Plugin for WordPress | Efficient Booking, Calendar & Client Scheduling – Bookify
- Plugin:
-
Appointment Booking Plugin for WordPress | Efficient Booking, Calendar & Client Scheduling – Bookify
- Plugin Slug:
- bookify
- Installations
- 20+
- Vulnerability:
- Privilege Escalation
- Patched in Version:
- 1.0.10
- Severity Score:
- High
- CVE:
-
2025-48142
Service Finder SMS System
- Plugin:
-
Service Finder SMS System
- Plugin Slug:
- aone-sms
- Vulnerability:
- Privilege Escalation
- Patched in Version:
- 3.0.0
- Severity Score:
- Critical
- CVE:
-
2025-5954
Brave Conversion Engine (PRO)
- Plugin:
-
Brave Conversion Engine (PRO)
- Plugin Slug:
- bravepopup-pro
- Vulnerability:
- Broken Authentication
- Patched in Version:
- 0.8.0
- Severity Score:
- Critical
- CVE:
-
2025-7710
JetEngine
- Plugin:
-
JetEngine
- Plugin Slug:
- jet-engine
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 3.7.2
- Severity Score:
- Medium
- CVE:
-
2025-54688
JetTabs
- Plugin:
-
JetTabs
- Plugin Slug:
- jet-tabs
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 2.2.9.2
- Severity Score:
- Medium
- CVE:
-
2025-54687
RT-Theme 18 | Extensions
- Plugin:
-
RT-Theme 18 | Extensions
- Plugin Slug:
- rt18-extensions
- Vulnerability:
- Local File Inclusion
- Patched in Version:
- 2.5
- Severity Score:
- High
- CVE:
-
2025-32288
Super Store Finder
- Plugin:
-
Super Store Finder
- Plugin Slug:
- superstorefinder-wp
- Vulnerability:
- SQL Injection
- Patched in Version:
- 7.6
- Severity Score:
- Critical
- CVE:
-
2025-52720
Use-your-Drive
- Plugin:
-
Use-your-Drive
- Plugin Slug:
- use-your-drive
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 3.3.2
- Severity Score:
- High
- CVE:
-
2025-7050
Woffice Core
- Plugin:
-
Woffice Core
- Plugin Slug:
- woffice-core
- Vulnerability:
- Arbitrary File Deletion
- Patched in Version:
- 5.4.27
- Severity Score:
- Medium
- CVE:
-
2025-7694
WordPress Themes — 12 Patched / 2 Unpatched
News Magazine X
- Theme:
-
News Magazine X
- Theme Slug:
- news-magazine-x
- Downloads
- 28,695
- Vulnerability:
- Local File Inclusion
- Patched in Version:
- No Fix
- Severity Score:
- High
- CVE:
-
2025-24766
Shopo
- Theme:
-
Shopo
- Theme Slug:
- shopo
- Vulnerability:
- Arbitrary File Upload
- Patched in Version:
- No Fix
- Severity Score:
- Critical
- CVE:
-
2025-31048
Appzend
Blogger Buzz
- Theme:
-
Blogger Buzz
- Theme Slug:
- blogger-buzz
- Downloads
- 52,137
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 1.2.7
- Severity Score:
- Medium
- CVE:
-
2025-54680
Alone
- Theme:
-
Alone
- Theme Slug:
- alone
- Vulnerability:
- Arbitrary Code Execution
- Patched in Version:
- 7.8.5
- Severity Score:
- Medium
- CVE:
-
2025-54019
Bricks Builder
- Theme:
-
Bricks Builder
- Theme Slug:
- bricks
- Vulnerability:
- SQL Injection
- Patched in Version:
- 2.0
- Severity Score:
- Critical
- CVE:
-
2025-6495
Cook&Meal
- Theme:
-
Cook&Meal
- Theme Slug:
- cookandmeal
- Vulnerability:
- Local File Inclusion
- Patched in Version:
- 1.2.4
- Severity Score:
- High
- CVE:
-
2025-48149
Druco
- Theme:
-
Druco
- Theme Slug:
- druco
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 1.5.3
- Severity Score:
- High
- CVE:
-
2025-54055
Exertio
- Theme:
-
Exertio
- Theme Slug:
- exertio
- Vulnerability:
- PHP Object Injection
- Patched in Version:
- 1.3.3
- Severity Score:
- Critical
- CVE:
-
2025-54686
KALLYAS – Creative eCommerce Multi-Purpose WordPress Theme
- Theme:
-
KALLYAS – Creative eCommerce Multi-Purpose WordPress Theme
- Theme Slug:
- kallyas
- Vulnerability:
- Arbitrary File Deletion
- Patched in Version:
- 4.22.0
- Severity Score:
- High
- CVE:
-
2025-6989
MediCenter – Health Medical Clinic
- Theme:
-
MediCenter – Health Medical Clinic
- Theme Slug:
- medicenter
- Vulnerability:
- PHP Object Injection
- Patched in Version:
- 15.2
- Severity Score:
- Critical
- CVE:
-
2025-54014
MinimogWP
- Theme:
-
MinimogWP
- Theme Slug:
- minimog
- Vulnerability:
- Content Injection
- Patched in Version:
- 3.9.1
- Severity Score:
- High
- CVE:
-
2025-8198
Platform
- Theme:
-
Platform
- Theme Slug:
- platform
- Vulnerability:
- Broken Access Control
- Patched in Version:
- 1.4.4
- Severity Score:
- Critical
- CVE:
-
2015-10143
UpStore
- Theme:
-
UpStore
- Theme Slug:
- upstore
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 1.7.1
- Severity Score:
- High
- CVE:
-
2025-48296
Solid Security is part of Solid Suite — The best foundation for WordPress websites.
Every WordPress site needs security, backups, and management tools. That’s Solid Suite — an integrated bundle of three plugins: Solid Security, Solid Backups, and Solid Central. You also get access to Solid Academy’s learning resources for WordPress professionals. Build your next WordPress website on a solid foundation with Solid Suite!
The post WordPress Vulnerability Report — August 6, 2025 appeared first on SolidWP.
Click here to continue reading this article.