In this report, 297 vulnerabilities have been publicly disclosed. Security patches for 93 of these plugins and themes are now available, so please run those updates as soon as possible. If you’re a Solid Security Pro user, the version management tool may have already warned you and updated these plugins, depending on your settings.

Additionally, there are 204 plugin and theme vulnerabilities, and no patch has been available yet. If you’re a Solid Security Pro user, those vulnerabilities are already protected by the Solid Security firewall. Virtual patches from Patchstack will be applied when a vulnerability is considered high or medium risk. If no patch is forthcoming from the vendor or the vulnerable software has been marked “closed” and dropped from the official WordPress repositories, you should deactivate it soon and look for alternative solutions.

Along with poor user account security, vulnerable plugins and themes are among the top reasons why WordPress websites get hacked. Unfortunately, cyberattacks are increasing in volume and sophistication. They’re also increasingly aimed at small to mid-sized businesses.

Our WordPress Vulnerability Report covers the latest emerging WordPress plugin, theme, and core vulnerabilities. Each vulnerability will have a severity rating of LowMediumHigh, or Critical. Responsible disclosure of vulnerabilities is essential to keeping the WordPress community safe. Please share this report to help spread the word and make WordPress — and the web — more secure.

WordPress Core

WordPress 6.8.2 was released on July 15, 2025. This maintenance release includes fixes for 20 Core tickets and 15 Block Editor issues. For a full list of bug fixes, please refer to the release candidate announcement.

No new core vulnerabilities were disclosed this week.

WordPress Plugins — 83 Patched / 112 Unpatched

ARI Fancy Lightbox – Popup for WordPress

Plugin Slug:
ari-fancy-lightbox

Installations
10,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium

The vulnerability has not been patched. You should deactivate the plugin.

Ray Enterprise Translation

Plugin Slug:
lingotek-translation

Installations
10,000+

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
Medium

The vulnerability has not been patched. You should deactivate the plugin.

Themify Popup

Plugin Slug:
themify-popup

Installations
9,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium

The vulnerability has not been patched. You should deactivate the plugin.

Ibtana – Ecommerce Product Addons

Plugin Slug:
ibtana-ecommerce-product-addons

Installations
8,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium

The vulnerability has not been patched. You should deactivate the plugin.

License Manager for WooCommerce

Plugin Slug:
license-manager-for-woocommerce

Installations
7,000+

Vulnerability:
SQL Injection

Patched in Version:
No Fix

Severity Score:
High

The vulnerability has not been patched. You should deactivate the plugin.

Authors List

Plugin Slug:
authors-list

Installations
5,000+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
Medium

The vulnerability has not been patched. You should deactivate the plugin.

Social Sharing Plugin – Kiwi

Plugin Slug:
kiwi-social-share

Installations
5,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium

The vulnerability has not been patched. You should deactivate the plugin.

Payoneer Checkout

Plugin Slug:
payoneer-checkout

Installations
5,000+

Vulnerability:
Content Spoofing

Patched in Version:
No Fix

Severity Score:
Medium

The vulnerability has not been patched. You should deactivate the plugin.

Assistant – Every Day Productivity Apps

Plugin Slug:
assistant

Installations
4,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High

The vulnerability has not been patched. You should deactivate the plugin.

BCM Duplicate Menu

Plugin Slug:
bcm-duplicate-menu

Installations
4,000+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
Medium

The vulnerability has not been patched. You should deactivate the plugin.

Elementor Element Condition

Plugin Slug:
ele-conditions

Installations
4,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium

The vulnerability has not been patched. You should deactivate the plugin.

Notification for Telegram

Plugin Slug:
notification-for-telegram

Installations
4,000+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
Medium

The vulnerability has not been patched. You should deactivate the plugin.

SEO Auto Linker

Plugin Slug:
wpa-seo-auto-linker

Installations
4,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium

The vulnerability has not been patched. You should deactivate the plugin.

WPB Elementor Addons

Plugin Slug:
wpb-elementor-addons

Installations
4,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium

The vulnerability has not been patched. You should deactivate the plugin.

Custom WooCommerce Checkout Fields Editor

Plugin Slug:
add-fields-to-checkout-page-woocommerce

Installations
3,000+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
Medium

The vulnerability has not been patched. You should deactivate the plugin.

Ninja Charts – WordPress Charts and Graphs Plugin

Plugin Slug:
ninja-charts

Installations
3,000+

Vulnerability:
Sensitive Data Exposure

Patched in Version:
No Fix

Severity Score:
Medium

The vulnerability has not been patched. You should deactivate the plugin.

Responder

Plugin:

Responder

Plugin Slug:
responder

Installations
3,000+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
Medium

The vulnerability has not been patched. You should deactivate the plugin.

TrustMate.io – WooCommerce integration

Plugin Slug:
trustmate-io-integration-for-woocommerce

Installations
3,000+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
Medium

The vulnerability has not been patched. You should deactivate the plugin.

Widgetize Pages Light

Plugin Slug:
widgetize-pages-light

Installations
3,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium

The vulnerability has not been patched. You should deactivate the plugin.

WP Email Template

Plugin Slug:
wp-email-template

Installations
3,000+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
Medium

The vulnerability has not been patched. You should deactivate the plugin.

WordPress Error Monitoring by Bugsnag

Plugin Slug:
bugsnag

Installations
2,000+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
High

The vulnerability has not been patched. You should deactivate the plugin.

WordPress prettyPhoto

Plugin Slug:
prettyphoto

Installations
2,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium

The vulnerability has not been patched. You should deactivate the plugin.

Purge Varnish Cache

Plugin Slug:
purge-varnish

Installations
2,000+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
High

The vulnerability has not been patched. You should deactivate the plugin.

Brilliant Web-to-Lead for Salesforce

Plugin Slug:
salesforce-wordpress-to-lead

Installations
2,000+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
High

The vulnerability has not been patched. You should deactivate the plugin.

Simple Link List Widget

Plugin Slug:
simple-link-list-widget

Installations
2,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium

The vulnerability has not been patched. You should deactivate the plugin.

Ultimate Client Dash

Plugin Slug:
ulimate-client-dash

Installations
2,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium

The vulnerability has not been patched. You should deactivate the plugin.

Aitasi Coming Soon

Plugin Slug:
aitasi-coming-soon

Installations
1,000+

Vulnerability:
Deserialization of untrusted data

Patched in Version:
No Fix

Severity Score:
High

The vulnerability has not been patched. You should deactivate the plugin.

Great Restaurant Menu WP

Plugin Slug:
best-restaurant-menu-by-pricelisto

Installations
1,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium

The vulnerability has not been patched. You should deactivate the plugin.

Easy Flash Embed

Plugin Slug:
easy-flash-embed

Installations
1,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium

The vulnerability has not been patched. You should deactivate the plugin.

Product Carousel Slider for Elementor

Plugin Slug:
ecommerce-product-carousel-slider-for-elementor

Installations
1,000+

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
Low

The vulnerability has not been patched. You should deactivate the plugin.

GoUrl Bitcoin Payment Gateway & Paid Downloads & Membership

Plugin Slug:
gourl-bitcoin-payment-gateway-paid-downloads-membership

Installations
1,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium

The vulnerability has not been patched. You should deactivate the plugin.

StagTools

Plugin:

StagTools

Plugin Slug:
stagtools

Installations
1,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium

The vulnerability has not been patched. You should deactivate the plugin.

Today’s Date Inserter

Plugin Slug:
todays-date-inserter

Installations
1,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium

The vulnerability has not been patched. You should deactivate the plugin.

Bulk Featured Image

Plugin Slug:
bulk-featured-image

Installations
900+

Vulnerability:
Arbitrary File Upload

Patched in Version:
No Fix

Severity Score:
Critical

The vulnerability has not been patched. You should deactivate the plugin.

WP Notification Bell

Plugin Slug:
wp-notification-bell

Installations
900+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium

The vulnerability has not been patched. You should deactivate the plugin.

Developer Tools Blocker

Plugin Slug:
swiftninjapro-inspect-element-console-blocker

Installations
800+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
Medium

The vulnerability has not been patched. You should deactivate the plugin.

Carousel Ultimate

Plugin Slug:
carousel

Installations
700+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium

The vulnerability has not been patched. You should deactivate the plugin.

WP Mail

Plugin:

WP Mail

Plugin Slug:
wp-mail

Installations
600+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium

The vulnerability has not been patched. You should deactivate the plugin.

Comment Form WP – Customize Default Comment Form

Plugin Slug:
comment-form-wp

Installations
500+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium

The vulnerability has not been patched. You should deactivate the plugin.

Get Cash

Plugin:

Get Cash

Plugin Slug:
get-cash

Installations
500+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium

The vulnerability has not been patched. You should deactivate the plugin.

???? ???

Plugin:

???? ???

Plugin Slug:
mshop-naver-talktalk

Installations
500+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium

The vulnerability has not been patched. You should deactivate the plugin.

WP Publication Archive

Plugin Slug:
wp-publication-archive

Installations
500+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium

The vulnerability has not been patched. You should deactivate the plugin.

Job Board Manager

Plugin Slug:
job-board-manager

Installations
400+

Vulnerability:
Content Injection

Patched in Version:
No Fix

Severity Score:
Low

The vulnerability has not been patched. You should deactivate the plugin.

Parallax Scrolling Enllax.js

Plugin Slug:
parallax-scrolling-enllax-js

Installations
300+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
Medium

The vulnerability has not been patched. You should deactivate the plugin.

Parallax Scrolling Enllax.js

Plugin Slug:
parallax-scrolling-enllax-js

Installations
300+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium

The vulnerability has not been patched. You should deactivate the plugin.

Bonus for Woo

Plugin Slug:
bonus-for-woo

Installations
200+

Vulnerability:
Other Vulnerability Type

Patched in Version:
No Fix

Severity Score:
Medium

The vulnerability has not been patched. You should deactivate the plugin.

Custom Team Manager

Plugin Slug:
custom-team-manager

Installations
200+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium

The vulnerability has not been patched. You should deactivate the plugin.

Donation Forms WP by Givecloud

Plugin Slug:
donation-forms-by-givecloud

Installations
200+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium

The vulnerability has not been patched. You should deactivate the plugin.

eDS Responsive Menu

Plugin Slug:
eds-responsive-menu

Installations
200+

Vulnerability:
PHP Object Injection

Patched in Version:
No Fix

Severity Score:
High

The vulnerability has not been patched. You should deactivate the plugin.

Invelity MyGLS connect

Plugin Slug:
invelity-mygls-connect

Installations
200+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
High

The vulnerability has not been patched. You should deactivate the plugin.

Media Author

Plugin Slug:
media-author

Installations
200+

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
Medium

The vulnerability has not been patched. You should deactivate the plugin.

Search by Google

Plugin Slug:
search-google

Installations
200+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium

The vulnerability has not been patched. You should deactivate the plugin.

Smooth Accordion

Plugin Slug:
smooth-accordion

Installations
200+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium

The vulnerability has not been patched. You should deactivate the plugin.

SS Font Awesome Icon

Plugin Slug:
ss-font-awesome-icon

Installations
200+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium

The vulnerability has not been patched. You should deactivate the plugin.

short.io

Plugin:

short.io

Plugin Slug:
wp-shortcm

Installations
200+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium

The vulnerability has not been patched. You should deactivate the plugin.

Add to Feedly

Plugin Slug:
add-to-feedly

Installations
100+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
High

The vulnerability has not been patched. You should deactivate the plugin.

AP HoneyPot WordPress Plugin

Plugin Slug:
ap-honeypot

Installations
100+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
High

The vulnerability has not been patched. You should deactivate the plugin.

Auto Last Youtube Video

Plugin Slug:
auto-last-youtube-video

Installations
100+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
High

The vulnerability has not been patched. You should deactivate the plugin.

Boxed Content

Plugin Slug:
boxed-content

Installations
100+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium

The vulnerability has not been patched. You should deactivate the plugin.

Bulk Watermark

Plugin Slug:
bulk-watermark

Installations
100+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
High

The vulnerability has not been patched. You should deactivate the plugin.

connectDaily Events Calendar Plugin

Plugin Slug:
connect-daily-web-calendar

Installations
100+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium

The vulnerability has not been patched. You should deactivate the plugin.

Table of content

Plugin Slug:
content-table

Installations
100+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
High

The vulnerability has not been patched. You should deactivate the plugin.

Database to Excel

Plugin Slug:
database-to-excel

Installations
100+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
High

The vulnerability has not been patched. You should deactivate the plugin.

FW Anker

Plugin:

FW Anker

Plugin Slug:
fw-anker

Installations
100+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium

The vulnerability has not been patched. You should deactivate the plugin.

Hide Real Download Path

Plugin Slug:
hide-real-download-path

Installations
100+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
High

The vulnerability has not been patched. You should deactivate the plugin.

MSTW League Manager

Plugin Slug:
mstw-league-manager

Installations
100+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
High

The vulnerability has not been patched. You should deactivate the plugin.

Popping Sidebars and Widgets Light

Plugin Slug:
popping-sidebars-and-widgets-light

Installations
100+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
High

The vulnerability has not been patched. You should deactivate the plugin.

Quick Event Calendar

Plugin Slug:
quick-event-calendar

Installations
100+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
High

The vulnerability has not been patched. You should deactivate the plugin.

Showpass WordPress Extension

Plugin Slug:
showpass

Installations
100+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium

The vulnerability has not been patched. You should deactivate the plugin.

Ultimate AJAX Login

Plugin Slug:
ultimate-ajax-login

Installations
100+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
High

The vulnerability has not been patched. You should deactivate the plugin.

WN Flipbox Pro

Plugin Slug:
wn-flipbox-pro

Installations
100+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
High

The vulnerability has not been patched. You should deactivate the plugin.

Woocommerce Notify Updated Product

Plugin Slug:
woocommerce-notify-updated-product

Installations
100+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
Medium

The vulnerability has not been patched. You should deactivate the plugin.

WP likes

Plugin:

WP likes

Plugin Slug:
wp-likes

Installations
100+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
High

The vulnerability has not been patched. You should deactivate the plugin.

WPB Image Widget

Plugin Slug:
wpb-image-widget

Installations
100+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium

The vulnerability has not been patched. You should deactivate the plugin.

Enable Latex

Plugin Slug:
enable-latex

Installations
90+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
High

The vulnerability has not been patched. You should deactivate the plugin.

Zoomify embed for WP

Plugin Slug:
zoom-image-shortcode

Installations
90+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium

The vulnerability has not been patched. You should deactivate the plugin.

???

Plugin:

???

Plugin Slug:
jinshuju

Installations
80+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium

The vulnerability has not been patched. You should deactivate the plugin.

Compact Admin

Plugin Slug:
compact-admin

Installations
70+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
Medium

The vulnerability has not been patched. You should deactivate the plugin.

Site Info

Plugin:

Site Info

Plugin Slug:
site-info-dashboard-widget

Installations
70+

Vulnerability:
Sensitive Data Exposure

Patched in Version:
No Fix

Severity Score:
Low

The vulnerability has not been patched. You should deactivate the plugin.

Aparat Video Shortcode

Plugin Slug:
aparat-shortcode

Installations
60+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium

The vulnerability has not been patched. You should deactivate the plugin.

Easy Download Media Counter

Plugin Slug:
easy-download-media-counter

Installations
60+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium

The vulnerability has not been patched. You should deactivate the plugin.

Floating Window Music Player

Plugin Slug:
floating-window-music-player

Installations
60+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
High

The vulnerability has not been patched. You should deactivate the plugin.

Master Paper Collapse Toggle

Plugin Slug:
master-paper-collapse-toggle

Installations
60+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium

The vulnerability has not been patched. You should deactivate the plugin.

SimaCookie

Plugin:

SimaCookie

Plugin Slug:
simasicher-dsgvo-cookie

Installations
60+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
Medium

The vulnerability has not been patched. You should deactivate the plugin.

SimaCookie

Plugin:

SimaCookie

Plugin Slug:
simasicher-dsgvo-cookie

Installations
60+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium

The vulnerability has not been patched. You should deactivate the plugin.

Pushe Web Push Notification

Plugin Slug:
pushe-webpush

Installations
50+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium

The vulnerability has not been patched. You should deactivate the plugin.

Simple Price Calculator

Plugin Slug:
simple-price-calculator-basic

Installations
50+

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
Medium

The vulnerability has not been patched. You should deactivate the plugin.

WP Github Gist

Plugin Slug:
wp-github-gist

Installations
50+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium

The vulnerability has not been patched. You should deactivate the plugin.

WP-GraphViz

Plugin Slug:
wp-graphviz

Installations
50+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium

The vulnerability has not been patched. You should deactivate the plugin.

WordPress StoryMap Plugin

Plugin Slug:
wp-storymap

Installations
50+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium

The vulnerability has not been patched. You should deactivate the plugin.

New Simple Gallery

Plugin Slug:
new-simple-gallery

Installations
30+

Vulnerability:
SQL Injection

Patched in Version:
No Fix

Severity Score:
High

The vulnerability has not been patched. You should deactivate the plugin.

Simple Text Slider

Plugin Slug:
simple-text-slider

Installations
30+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium

The vulnerability has not been patched. You should deactivate the plugin.

Course Booking Platform

Plugin Slug:
course-booking-platform

Installations
10+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium

The vulnerability has not been patched. You should deactivate the plugin.

Instant Locations

Plugin Slug:
instant-locations

Installations
10+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium

The vulnerability has not been patched. You should deactivate the plugin.

Constant Contact for WordPress

Plugin:

Constant Contact for WordPress

Plugin Slug:
constant-contact-api

Vulnerability:
PHP Object Injection

Patched in Version:
No Fix

Severity Score:
High

The vulnerability has not been patched. You should deactivate the plugin.

FAT Event – WordPress Event and Calendar Booking

Plugin:

FAT Event – WordPress Event and Calendar Booking

Plugin Slug:
fat-event

Vulnerability:
Local File Inclusion

Patched in Version:
No Fix

Severity Score:
High

The vulnerability has not been patched. You should deactivate the plugin.

Make, formerly Integromat Connector

Plugin:

Make, formerly Integromat Connector

Plugin Slug:
integromat-connector

Vulnerability:
Arbitrary File Upload

Patched in Version:
No Fix

Severity Score:
High

The vulnerability has not been patched. You should deactivate the plugin.

PopAd

Plugin:

PopAd

Plugin Slug:
popad

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
Medium

The vulnerability has not been patched. You should deactivate the plugin.

Recent Posts Widget Extended

Plugin:

Recent Posts Widget Extended

Plugin Slug:
recent-posts-widget-extended

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium

The vulnerability has not been patched. You should deactivate the plugin.

Search Cloud One

Plugin Slug:
search-cloud-one

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium

The vulnerability has not been patched. You should deactivate the plugin.

Spirit Framework

Plugin:

Spirit Framework

Plugin Slug:
spirit-framework

Vulnerability:
Local File Inclusion

Patched in Version:
No Fix

Severity Score:
High

The vulnerability has not been patched. You should deactivate the plugin.

Translate This gTranslate Shortcode

Plugin:

Translate This gTranslate Shortcode

Plugin Slug:
translate-this-google-translate-web-element-shortcode

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium

The vulnerability has not been patched. You should deactivate the plugin.

Uxper Booking

Plugin:

Uxper Booking

Plugin Slug:
uxper-booking

Vulnerability:
SQL Injection

Patched in Version:
No Fix

Severity Score:
High

The vulnerability has not been patched. You should deactivate the plugin.

vipdrv

Plugin:

vipdrv

Plugin Slug:
vipdrv-vip-test-drive

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium

The vulnerability has not been patched. You should deactivate the plugin.

Woocommerce Gifts Product

Plugin:

Woocommerce Gifts Product

Plugin Slug:
woo-gift-product

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
Medium

The vulnerability has not been patched. You should deactivate the plugin.

WooCommerce Single Page Checkout

Plugin:

WooCommerce Single Page Checkout

Plugin Slug:
woo-single-page-checkout

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
Medium

The vulnerability has not been patched. You should deactivate the plugin.

WordPress Helpdesk Integration

Plugin:

WordPress Helpdesk Integration

Plugin Slug:
wp-helpdesk-integration

Vulnerability:
Local File Inclusion

Patched in Version:
No Fix

Severity Score:
High

The vulnerability has not been patched. You should deactivate the plugin.

Admin Menu Editor

Plugin Slug:
admin-menu-editor

Installations
400,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.14.1

Severity Score:
Medium

The vulnerability has been patched, so you should update to version 1.14.1.

Post SMTP – WP SMTP Plugin with Email Logs and Mobile App for Failure Notifications – Gmail SMTP, Office 365, Brevo, Mailgun, Amazon SES and more

Plugin Slug:
post-smtp

Installations
400,000+

Vulnerability:
Broken Access Control

Patched in Version:
3.4.2

Severity Score:
Medium

The vulnerability has been patched, so you should update to version 3.4.2.

AI Engine

Plugin:

AI Engine

Plugin Slug:
ai-engine

Installations
100,000+

Vulnerability:
Broken Access Control

Patched in Version:
2.9.6

Severity Score:
Medium

The vulnerability has been patched, so you should update to version 2.9.6.

Brizy – Page Builder

Plugin Slug:
brizy

Installations
70,000+

Vulnerability:
Broken Access Control

Patched in Version:
2.7.13

Severity Score:
Medium

The vulnerability has been patched, so you should update to version 2.7.13.

User Registration & Membership – Custom Registration Form Builder, Custom Login Form, User Profile, Content Restriction & Membership Plugin

Plugin Slug:
user-registration

Installations
60,000+

Vulnerability:
SQL Injection

Patched in Version:
4.4.0

Severity Score:
High

The vulnerability has been patched, so you should update to version 4.4.0.

WP-Members Membership Plugin

Plugin Slug:
wp-members

Installations
60,000+

Vulnerability:
Content Injection

Patched in Version:
3.5.4.3

Severity Score:
Medium

The vulnerability has been patched, so you should update to version 3.5.4.3.

Ditty – Responsive News Tickers, Sliders, and Lists

Plugin Slug:
ditty-news-ticker

Installations
30,000+

Vulnerability:
Server Side Request Forgery (SSRF)

Patched in Version:
3.1.58

Severity Score:
High

The vulnerability has been patched, so you should update to version 3.1.58.

Klarna Order Management for WooCommerce

Plugin Slug:
klarna-order-management-for-woocommerce

Installations
20,000+

Vulnerability:
Sensitive Data Exposure

Patched in Version:
1.9.9

Severity Score:
Medium

The vulnerability has been patched, so you should update to version 1.9.9.

LA-Studio Element Kit for Elementor

Plugin Slug:
lastudio-element-kit

Installations
20,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.5.5.2

Severity Score:
Medium

The vulnerability has been patched, so you should update to version 1.5.5.2.

wpForo Forum

Plugin Slug:
wpforo

Installations
20,000+

Vulnerability:
Insecure Direct Object References (IDOR)

Patched in Version:
2.4.7

Severity Score:
Medium

The vulnerability has been patched, so you should update to version 2.4.7.

Multi Step Form

Plugin Slug:
multi-step-form

Installations
10,000+

Vulnerability:
Arbitrary File Upload

Patched in Version:
1.7.26

Severity Score:
High

The vulnerability has been patched, so you should update to version 1.7.26.

Order Delivery Date for WooCommerce

Plugin Slug:
order-delivery-date-for-woocommerce

Installations
10,000+

Vulnerability:
Broken Access Control

Patched in Version:
4.2.0

Severity Score:
Medium

The vulnerability has been patched, so you should update to version 4.2.0.

Sticky Side Buttons

Plugin Slug:
sticky-side-buttons

Installations
10,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.0.0

Severity Score:
Medium

The vulnerability has been patched, so you should update to version 2.0.0.

Malcure Malware Scanner — #1 Toolset for Malware Removal

Plugin Slug:
wp-malware-removal

Installations
10,000+

Vulnerability:
Broken Access Control

Patched in Version:
16.9

Severity Score:
Medium

The vulnerability has been patched, so you should update to version 16.9.

If-So Dynamic Content Personalization

Plugin Slug:
if-so

Installations
8,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.9.4.1

Severity Score:
Medium

The vulnerability has been patched, so you should update to version 1.9.4.1.

aThemes Addons for Elementor

Plugin Slug:
athemes-addons-for-elementor-lite

Installations
7,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.1.3

Severity Score:
Medium

The vulnerability has been patched, so you should update to version 1.1.3.

Surfer – WordPress Plugin

Plugin Slug:
surferseo

Installations
6,000+

Vulnerability:
Broken Access Control

Patched in Version:
1.6.5.584

Severity Score:
Medium

The vulnerability has been patched, so you should update to version 1.6.5.584.

Cookie Notice & Consent Banner for GDPR & CCPA Compliance

Plugin Slug:
cookie-notice-and-consent-banner

Installations
5,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.7.12

Severity Score:
Medium

The vulnerability has been patched, so you should update to version 1.7.12.

MediaPress

Plugin:

MediaPress

Plugin Slug:
mediapress

Installations
5,000+

Vulnerability:
Local File Inclusion

Patched in Version:
1.6.0

Severity Score:
High

The vulnerability has been patched, so you should update to version 1.6.0.

Latest Post Shortcode

Plugin Slug:
latest-post-shortcode

Installations
4,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
14.10

Severity Score:
Medium

The vulnerability has been patched, so you should update to version 14.10.

Gallery PhotoBlocks

Plugin Slug:
photoblocks-grid-gallery

Installations
4,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.3.2

Severity Score:
Medium

The vulnerability has been patched, so you should update to version 1.3.2.

Posts Table with Search & Sort

Plugin Slug:
posts-data-table

Installations
3,000+

Vulnerability:
Broken Access Control

Patched in Version:
1.4.11

Severity Score:
Medium

The vulnerability has been patched, so you should update to version 1.4.11.

Property Hive

Plugin Slug:
propertyhive

Installations
3,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.1.6

Severity Score:
Medium

The vulnerability has been patched, so you should update to version 2.1.6.

Tickera – WordPress Event Ticketing

Plugin Slug:
tickera-event-ticketing-system

Installations
3,000+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
3.5.5.8

Severity Score:
Medium

The vulnerability has been patched, so you should update to version 3.5.5.8.

Amministrazione Trasparente

Plugin Slug:
amministrazione-trasparente

Installations
1,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
9.1

Severity Score:
Medium

The vulnerability has been patched, so you should update to version 9.1.

Tooltipy (tooltips for WP)

Plugin Slug:
bluet-keywords-tooltip-generator

Installations
1,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
5.5.9

Severity Score:
Medium

The vulnerability has been patched, so you should update to version 5.5.9.

Easy Timer

Plugin:

Easy Timer

Plugin Slug:
easy-timer

Installations
1,000+

Vulnerability:
Remote Code Execution (RCE)

Patched in Version:
4.2.2

Severity Score:
High

The vulnerability has been patched, so you should update to version 4.2.2.

ELEX WooCommerce Google Shopping (Google Product Feed)

Plugin Slug:
elex-woocommerce-google-product-feed-plugin-basic

Installations
1,000+

Vulnerability:
SQL Injection

Patched in Version:
1.4.4

Severity Score:
High

The vulnerability has been patched, so you should update to version 1.4.4.

F4 Media Taxonomies

Plugin Slug:
f4-media-taxonomies

Installations
1,000+

Vulnerability:
Broken Access Control

Patched in Version:
1.1.5

Severity Score:
Medium

The vulnerability has been patched, so you should update to version 1.1.5.

InPost Gallery

Plugin Slug:
inpost-gallery

Installations
1,000+

Vulnerability:
Local File Inclusion

Patched in Version:
2.1.4.6

Severity Score:
High

The vulnerability has been patched, so you should update to version 2.1.4.6.

Mobile Contact Line

Plugin Slug:
mobile-contact-line

Installations
1,000+

Vulnerability:
Broken Access Control

Patched in Version:
2.4.1

Severity Score:
Medium

The vulnerability has been patched, so you should update to version 2.4.1.

PDF for WPForms + Drag and Drop Template Builder

Plugin Slug:
pdf-for-wpforms

Installations
1,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
6.3.0

Severity Score:
Medium

The vulnerability has been patched, so you should update to version 6.3.0.

WordPress Events Calendar Plugin – Pie Calendar

Plugin Slug:
pie-calendar

Installations
1,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.2.9

Severity Score:
Medium

The vulnerability has been patched, so you should update to version 1.2.9.

PuzzleMe for WordPress

Plugin Slug:
puzzleme

Installations
1,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.2.1

Severity Score:
Medium

The vulnerability has been patched, so you should update to version 1.2.1.

Quick Paypal Payments

Plugin Slug:
quick-paypal-payments

Installations
1,000+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
5.7.47

Severity Score:
Medium

The vulnerability has been patched, so you should update to version 5.7.47.

Frisbii Pay

Plugin Slug:
reepay-checkout-gateway

Installations
1,000+

Vulnerability:
Broken Access Control

Patched in Version:
1.8.3

Severity Score:
Medium

The vulnerability has been patched, so you should update to version 1.8.3.

SKT Addons for Elementor

Plugin Slug:
skt-addons-for-elementor

Installations
1,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
3.8

Severity Score:
Medium

The vulnerability has been patched, so you should update to version 3.8.

Vayu Blocks – Website Builder for the Block Editor

Plugin Slug:
vayu-blocks

Installations
1,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.3.10

Severity Score:
Medium

The vulnerability has been patched, so you should update to version 1.3.10.

WP Bannerize Pro

Plugin Slug:
wp-bannerize-pro

Installations
1,000+

Vulnerability:
Server Side Request Forgery (SSRF)

Patched in Version:
1.11.0

Severity Score:
Medium

The vulnerability has been patched, so you should update to version 1.11.0.

WP Flow Plus

Plugin Slug:
wp-imageflow2

Installations
1,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
5.2.6

Severity Score:
Medium

The vulnerability has been patched, so you should update to version 5.2.6.

Show Eventbrite Events – Event Feed for Eventbrite

Plugin Slug:
event-feed-for-eventbrite

Installations
900+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.4.0

Severity Score:
Medium

The vulnerability has been patched, so you should update to version 1.4.0.

Exchange Rates

Plugin Slug:
exchange-rates

Installations
900+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.3.0

Severity Score:
Medium

The vulnerability has been patched, so you should update to version 1.3.0.

RumbleTalk Live Group Chat – HTML5

Plugin Slug:
rumbletalk-chat-a-chat-with-themes

Installations
900+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
6.3.6

Severity Score:
Medium

The vulnerability has been patched, so you should update to version 6.3.6.

Simple Matomo Tracking Code

Plugin Slug:
simple-matomo-tracking-code

Installations
900+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.1.1

Severity Score:
Medium

The vulnerability has been patched, so you should update to version 1.1.1.

Dadevarzan WordPress Common

Plugin Slug:
dadevarzan-common

Installations
700+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.2.3

Severity Score:
Medium

The vulnerability has been patched, so you should update to version 2.2.3.

IssueM

Plugin:

IssueM

Plugin Slug:
issuem

Installations
700+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.9.1

Severity Score:
Medium

The vulnerability has been patched, so you should update to version 2.9.1.

Booking Ultra Pro Appointments Booking Calendar Plugin

Plugin Slug:
booking-ultra-pro

Installations
600+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.1.22

Severity Score:
Medium

The vulnerability has been patched, so you should update to version 1.1.22.

immonex Kickstart

Plugin Slug:
immonex-kickstart

Installations
300+

Vulnerability:
Local File Inclusion

Patched in Version:
1.11.13

Severity Score:
High

The vulnerability has been patched, so you should update to version 1.11.13.

Cloud SAML SSO – Single Sign On Login

Plugin Slug:
cloud-sso-single-sign-on

Installations
100+

Vulnerability:
Broken Access Control

Patched in Version:
1.0.20

Severity Score:
High

The vulnerability has been patched, so you should update to version 1.0.20.

Cloud SAML SSO – Single Sign On Login

Plugin Slug:
cloud-sso-single-sign-on

Installations
100+

Vulnerability:
Broken Access Control

Patched in Version:
1.0.20

Severity Score:
Medium

The vulnerability has been patched, so you should update to version 1.0.20.

Smart Table Builder

Plugin Slug:
smart-table-builder

Installations
100+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.0.2

Severity Score:
Medium

The vulnerability has been patched, so you should update to version 1.0.2.

StreamWeasels Kick Integration

Plugin Slug:
streamweasels-kick-integration

Installations
100+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.1.6

Severity Score:
Medium

The vulnerability has been patched, so you should update to version 1.1.6.

Html Social share buttons

Plugin Slug:
html-social-share-buttons

Installations
90+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.2.0

Severity Score:
Medium

The vulnerability has been patched, so you should update to version 2.2.0.

Optio Dentistry

Plugin Slug:
optio-dentistry

Installations
80+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.3

Severity Score:
Medium

The vulnerability has been patched, so you should update to version 2.3.

atec Debug

Plugin:

atec Debug

Plugin Slug:
atec-debug

Installations
40+

Vulnerability:
Arbitrary File Deletion

Patched in Version:
1.2.23

Severity Score:
High

The vulnerability has been patched, so you should update to version 1.2.23.

atec Debug

Plugin:

atec Debug

Plugin Slug:
atec-debug

Installations
40+

Vulnerability:
Remote Code Execution (RCE)

Patched in Version:
1.2.23

Severity Score:
High

The vulnerability has been patched, so you should update to version 1.2.23.

atec Debug

Plugin:

atec Debug

Plugin Slug:
atec-debug

Installations
40+

Vulnerability:
Arbitrary File Download

Patched in Version:
1.2.23

Severity Score:
Medium

The vulnerability has been patched, so you should update to version 1.2.23.

LTL Freight Quotes – Day & Ross Edition

Plugin Slug:
ltl-freight-quotes-day-ross-edition

Installations
10+

Vulnerability:
PHP Object Injection

Patched in Version:
2.1.12

Severity Score:
High

The vulnerability has been patched, so you should update to version 2.1.12.

ZIP Code Based Content Protection

Plugin Slug:
zip-code-based-content-protection

Installations
10+

Vulnerability:
SQL Injection

Patched in Version:
1.0.1

Severity Score:
High

The vulnerability has been patched, so you should update to version 1.0.1.

Biagiotti Core

Plugin:

Biagiotti Core

Plugin Slug:
biagiotti-core

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.1.4

Severity Score:
Medium

The vulnerability has been patched, so you should update to version 2.1.4.

Exit Intent Popup

Plugin:

Exit Intent Popup

Plugin Slug:
exitintentpopup

Vulnerability:
Server Side Request Forgery (SSRF)

Patched in Version:
1.0.3

Severity Score:
Medium

The vulnerability has been patched, so you should update to version 1.0.3.

LTL Freight Quotes – Daylight Edition

Plugin Slug:
ltl-freight-quotes-daylight-edition

Vulnerability:
PHP Object Injection

Patched in Version:
2.2.8

Severity Score:
High

The vulnerability has been patched, so you should update to version 2.2.8.

LTL Freight Quotes – TQL Edition

Plugin Slug:
ltl-freight-quotes-tql-edition

Vulnerability:
PHP Object Injection

Patched in Version:
1.2.7

Severity Score:
High

The vulnerability has been patched, so you should update to version 1.2.7.

Mikado Core

Plugin:

Mikado Core

Plugin Slug:
mikado-core

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.6

Severity Score:
Medium

The vulnerability has been patched, so you should update to version 1.6.

Wilmer Core

Plugin:

Wilmer Core

Plugin Slug:
wilmer-core

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.4.6

Severity Score:
Medium

The vulnerability has been patched, so you should update to version 2.4.6.

WordPress Themes — 10 Patched / 92 Unpatched

ConsultStreet

Theme Slug:
consultstreet

Downloads
581,213

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
Medium

The vulnerability has not been patched. You should switch themes.

Shk Corporate

Theme Slug:
shk-corporate

Downloads
105,547

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
Medium

The vulnerability has not been patched. You should switch themes.

SoftMe

Theme:

SoftMe

Theme Slug:
softme

Downloads
155,328

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
Medium

The vulnerability has not been patched. You should switch themes.

Abogado

Theme:

Abogado

Theme Slug:
abogado

Vulnerability:
Local File Inclusion

Patched in Version:
No Fix

Severity Score:
High

The vulnerability has not been patched. You should switch themes.

Accalia

Theme:

Accalia

Theme Slug:
accalia

Vulnerability:
Local File Inclusion

Patched in Version:
No Fix

Severity Score:
High

The vulnerability has not been patched. You should switch themes.

Adrena

Theme:

Adrena

Theme Slug:
adrena

Vulnerability:
Local File Inclusion

Patched in Version:
No Fix

Severity Score:
High

The vulnerability has not been patched. You should switch themes.

Advice

Theme:

Advice

Theme Slug:
advice

Vulnerability:
Local File Inclusion

Patched in Version:
No Fix

Severity Score:
High

The vulnerability has not been patched. You should switch themes.

Agora

Theme:

Agora

Theme Slug:
agora

Vulnerability:
Local File Inclusion

Patched in Version:
No Fix

Severity Score:
High

The vulnerability has not been patched. You should switch themes.

Alanzo

Theme:

Alanzo

Theme Slug:
alanzo

Vulnerability:
Local File Inclusion

Patched in Version:
No Fix

Severity Score:
High

The vulnerability has not been patched. You should switch themes.

Albertino

Theme:

Albertino

Theme Slug:
albertino

Vulnerability:
Local File Inclusion

Patched in Version:
No Fix

Severity Score:
High

The vulnerability has not been patched. You should switch themes.

Alhambra

Theme:

Alhambra

Theme Slug:
alhambra

Vulnerability:
Local File Inclusion

Patched in Version:
No Fix

Severity Score:
High

The vulnerability has not been patched. You should switch themes.

A.Williams

Theme:

A.Williams

Theme Slug:
alisha-williams

Vulnerability:
Local File Inclusion

Patched in Version:
No Fix

Severity Score:
High

The vulnerability has not been patched. You should switch themes.

AlphaColor

Theme:

AlphaColor

Theme Slug:
alpha-color

Vulnerability:
Local File Inclusion

Patched in Version:
No Fix

Severity Score:
High

The vulnerability has not been patched. You should switch themes.

Anesta

Theme:

Anesta

Theme Slug:
anesta

Vulnerability:
Local File Inclusion

Patched in Version:
No Fix

Severity Score:
High

The vulnerability has not been patched. You should switch themes.

Angela

Theme:

Angela

Theme Slug:
angela

Vulnerability:
Local File Inclusion

Patched in Version:
No Fix

Severity Score:
High

The vulnerability has not been patched. You should switch themes.

AI ANN

Theme:

AI ANN

Theme Slug:
ann

Vulnerability:
Local File Inclusion

Patched in Version:
No Fix

Severity Score:
High

The vulnerability has not been patched. You should switch themes.

Anubia

Theme:

Anubia

Theme Slug:
anubia

Vulnerability:
Local File Inclusion

Patched in Version:
No Fix

Severity Score:
High

The vulnerability has not been patched. You should switch themes.

Artesia

Theme:

Artesia

Theme Slug:
artesia

Vulnerability:
Local File Inclusion

Patched in Version:
No Fix

Severity Score:
High

The vulnerability has not been patched. You should switch themes.

Asclepius

Theme:

Asclepius

Theme Slug:
asclepius

Vulnerability:
Local File Inclusion

Patched in Version:
No Fix

Severity Score:
High

The vulnerability has not been patched. You should switch themes.

Belicia

Theme:

Belicia

Theme Slug:
belicia

Vulnerability:
Local File Inclusion

Patched in Version:
No Fix

Severity Score:
High

The vulnerability has not been patched. You should switch themes.

BeYoga

Theme:

BeYoga

Theme Slug:
beyoga

Vulnerability:
Local File Inclusion

Patched in Version:
No Fix

Severity Score:
High

The vulnerability has not been patched. You should switch themes.

Birdily | Travel Agency & Tour Booking WordPress Theme

Theme:

Birdily | Travel Agency & Tour Booking WordPress Theme

Theme Slug:
birdily

Vulnerability:
Local File Inclusion

Patched in Version:
No Fix

Severity Score:
High

The vulnerability has not been patched. You should switch themes.

Bonko

Theme:

Bonko

Theme Slug:
bonko

Vulnerability:
Local File Inclusion

Patched in Version:
No Fix

Severity Score:
High

The vulnerability has not been patched. You should switch themes.

Booklovers

Theme:

Booklovers

Theme Slug:
booklovers

Vulnerability:
Local File Inclusion

Patched in Version:
No Fix

Severity Score:
High

The vulnerability has not been patched. You should switch themes.

Callie Britt

Theme:

Callie Britt

Theme Slug:
callie-britt

Vulnerability:
Local File Inclusion

Patched in Version:
No Fix

Severity Score:
High

The vulnerability has not been patched. You should switch themes.

Camelia

Theme:

Camelia

Theme Slug:
camelia

Vulnerability:
Local File Inclusion

Patched in Version:
No Fix

Severity Score:
High

The vulnerability has not been patched. You should switch themes.

Carlax

Theme:

Carlax

Theme Slug:
carlax

Vulnerability:
Local File Inclusion

Patched in Version:
No Fix

Severity Score:
High

The vulnerability has not been patched. You should switch themes.

Carz

Theme:

Carz

Theme Slug:
carz

Vulnerability:
Local File Inclusion

Patched in Version:
No Fix

Severity Score:
High

The vulnerability has not been patched. You should switch themes.

ChainPress

Theme:

ChainPress

Theme Slug:
chainpress

Vulnerability:
Local File Inclusion

Patched in Version:
No Fix

Severity Score:
High

The vulnerability has not been patched. You should switch themes.

Chakra

Theme:

Chakra

Theme Slug:
chakra

Vulnerability:
Local File Inclusion

Patched in Version:
No Fix

Severity Score:
High

The vulnerability has not been patched. You should switch themes.

Chardonnay

Theme:

Chardonnay

Theme Slug:
chardonnay

Vulnerability:
Local File Inclusion

Patched in Version:
No Fix

Severity Score:
High

The vulnerability has not been patched. You should switch themes.

Childy

Theme:

Childy

Theme Slug:
childly

Vulnerability:
Local File Inclusion

Patched in Version:
No Fix

Severity Score:
High

The vulnerability has not been patched. You should switch themes.

Chrimson

Theme:

Chrimson

Theme Slug:
chrimson

Vulnerability:
Local File Inclusion

Patched in Version:
No Fix

Severity Score:
High

The vulnerability has not been patched. You should switch themes.

City Hostel

Theme:

City Hostel

Theme Slug:
cityhostel

Vulnerability:
Local File Inclusion

Patched in Version:
No Fix

Severity Score:
High

The vulnerability has not been patched. You should switch themes.

69 Clothing

Theme:

69 Clothing

Theme Slug:
clothing69

Vulnerability:
Local File Inclusion

Patched in Version:
No Fix

Severity Score:
High

The vulnerability has not been patched. You should switch themes.

Corredo

Theme:

Corredo

Theme Slug:
corredo

Vulnerability:
Local File Inclusion

Patched in Version:
No Fix

Severity Score:
High

The vulnerability has not been patched. You should switch themes.

Credit Card Experience

Theme:

Credit Card Experience

Theme Slug:
creditcard

Vulnerability:
Local File Inclusion

Patched in Version:
No Fix

Severity Score:
High

The vulnerability has not been patched. You should switch themes.

Crework

Theme:

Crework

Theme Slug:
crework

Vulnerability:
Local File Inclusion

Patched in Version:
No Fix

Severity Score:
High

The vulnerability has not been patched. You should switch themes.

Custom Made

Theme:

Custom Made

Theme Slug:
custom-made

Vulnerability:
Local File Inclusion

Patched in Version:
No Fix

Severity Score:
High

The vulnerability has not been patched. You should switch themes.

Def

Theme:

Def

Theme Slug:
def

Vulnerability:
Local File Inclusion

Patched in Version:
No Fix

Severity Score:
High

The vulnerability has not been patched. You should switch themes.

Doccure

Theme:

Doccure

Theme Slug:
doccure

Vulnerability:
Arbitrary File Upload

Patched in Version:
No Fix

Severity Score:
Critical

The vulnerability has not been patched. You should switch themes.

Doccure

Theme:

Doccure

Theme Slug:
doccure

Vulnerability:
Broken Authentication

Patched in Version:
No Fix

Severity Score:
Critical

The vulnerability has not been patched. You should switch themes.

Doccure

Theme:

Doccure

Theme Slug:
doccure

Vulnerability:
Arbitrary File Upload

Patched in Version:
No Fix

Severity Score:
Critical

The vulnerability has not been patched. You should switch themes.

Drone Media

Theme:

Drone Media

Theme Slug:
drone-media

Vulnerability:
Local File Inclusion

Patched in Version:
No Fix

Severity Score:
High

The vulnerability has not been patched. You should switch themes.

Edema

Theme:

Edema

Theme Slug:
edema

Vulnerability:
Local File Inclusion

Patched in Version:
No Fix

Severity Score:
High

The vulnerability has not been patched. You should switch themes.

Elementra

Theme:

Elementra

Theme Slug:
elementra

Vulnerability:
Local File Inclusion

Patched in Version:
No Fix

Severity Score:
High

The vulnerability has not been patched. You should switch themes.

Fortunio

Theme:

Fortunio

Theme Slug:
fortunio

Vulnerability:
Local File Inclusion

Patched in Version:
No Fix

Severity Score:
High

The vulnerability has not been patched. You should switch themes.

Good Wine

Theme:

Good Wine

Theme Slug:
good-wine-shop

Vulnerability:
Local File Inclusion

Patched in Version:
No Fix

Severity Score:
High

The vulnerability has not been patched. You should switch themes.

Gravity

Theme:

Gravity

Theme Slug:
gravity

Vulnerability:
Local File Inclusion

Patched in Version:
No Fix

Severity Score:
High

The vulnerability has not been patched. You should switch themes.

Gutentype

Theme:

Gutentype

Theme Slug:
gutentype

Vulnerability:
Local File Inclusion

Patched in Version:
No Fix

Severity Score:
High

The vulnerability has not been patched. You should switch themes.

Hampton

Theme:

Hampton

Theme Slug:
hampton

Vulnerability:
Local File Inclusion

Patched in Version:
No Fix

Severity Score:
High

The vulnerability has not been patched. You should switch themes.

Happy Rider

Theme:

Happy Rider

Theme Slug:
happy-rider

Vulnerability:
Local File Inclusion

Patched in Version:
No Fix

Severity Score:
High

The vulnerability has not been patched. You should switch themes.

Healthy Blog

Theme:

Healthy Blog

Theme Slug:
healthy-blog

Vulnerability:
Local File Inclusion

Patched in Version:
No Fix

Severity Score:
High

The vulnerability has not been patched. You should switch themes.

Heaven11

Theme:

Heaven11

Theme Slug:
heaven11

Vulnerability:
Local File Inclusion

Patched in Version:
No Fix

Severity Score:
High

The vulnerability has not been patched. You should switch themes.

Hello Summer

Theme:

Hello Summer

Theme Slug:
hello-summer

Vulnerability:
Local File Inclusion

Patched in Version:
No Fix

Severity Score:
High

The vulnerability has not been patched. You should switch themes.

Hogwords

Theme:

Hogwords

Theme Slug:
hogwords

Vulnerability:
Local File Inclusion

Patched in Version:
No Fix

Severity Score:
High

The vulnerability has not been patched. You should switch themes.

HotLock

Theme:

HotLock

Theme Slug:
hotlock

Vulnerability:
Local File Inclusion

Patched in Version:
No Fix

Severity Score:
High

The vulnerability has not been patched. You should switch themes.

Insurance Ancora

Theme:

Insurance Ancora

Theme Slug:
insurance-ancora

Vulnerability:
Local File Inclusion

Patched in Version:
No Fix

Severity Score:
High

The vulnerability has not been patched. You should switch themes.

Juno

Theme:

Juno

Theme Slug:
junotoys

Vulnerability:
Local File Inclusion

Patched in Version:
No Fix

Severity Score:
High

The vulnerability has not been patched. You should switch themes.

Kargo

Theme:

Kargo

Theme Slug:
kargo

Vulnerability:
Local File Inclusion

Patched in Version:
No Fix

Severity Score:
High

The vulnerability has not been patched. You should switch themes.

Lab

Theme:

Lab

Theme Slug:
lab

Vulnerability:
Local File Inclusion

Patched in Version:
No Fix

Severity Score:
High

The vulnerability has not been patched. You should switch themes.

Laundry City

Theme:

Laundry City

Theme Slug:
laundrycity

Vulnerability:
Local File Inclusion

Patched in Version:
No Fix

Severity Score:
High

The vulnerability has not been patched. You should switch themes.

MediaFlex

Theme:

MediaFlex

Theme Slug:
mediaflex

Vulnerability:
Local File Inclusion

Patched in Version:
No Fix

Severity Score:
High

The vulnerability has not been patched. You should switch themes.

Nazareth

Theme:

Nazareth

Theme Slug:
nazareth

Vulnerability:
Local File Inclusion

Patched in Version:
No Fix

Severity Score:
High

The vulnerability has not been patched. You should switch themes.

OldStory

Theme:

OldStory

Theme Slug:
oldstory

Vulnerability:
Local File Inclusion

Patched in Version:
No Fix

Severity Score:
High

The vulnerability has not been patched. You should switch themes.

Partiso

Theme:

Partiso

Theme Slug:
partiso

Vulnerability:
Local File Inclusion

Patched in Version:
No Fix

Severity Score:
High

The vulnerability has not been patched. You should switch themes.

PathWell

Theme:

PathWell

Theme Slug:
pathwell

Vulnerability:
Local File Inclusion

Patched in Version:
No Fix

Severity Score:
High

The vulnerability has not been patched. You should switch themes.

Planet Shakers

Theme:

Planet Shakers

Theme Slug:
planet-shakers

Vulnerability:
Local File Inclusion

Patched in Version:
No Fix

Severity Score:
High

The vulnerability has not been patched. You should switch themes.

Plastica

Theme:

Plastica

Theme Slug:
plastica

Vulnerability:
Local File Inclusion

Patched in Version:
No Fix

Severity Score:
High

The vulnerability has not been patched. You should switch themes.

Let’s Play

Theme:

Let’s Play

Theme Slug:
playhockey

Vulnerability:
Local File Inclusion

Patched in Version:
No Fix

Severity Score:
High

The vulnerability has not been patched. You should switch themes.

Podium

Theme:

Podium

Theme Slug:
podium

Vulnerability:
Local File Inclusion

Patched in Version:
No Fix

Severity Score:
High

The vulnerability has not been patched. You should switch themes.

Preston

Theme:

Preston

Theme Slug:
preston

Vulnerability:
Local File Inclusion

Patched in Version:
No Fix

Severity Score:
High

The vulnerability has not been patched. You should switch themes.

ProDent

Theme:

ProDent

Theme Slug:
prodent

Vulnerability:
Local File Inclusion

Patched in Version:
No Fix

Severity Score:
High

The vulnerability has not been patched. You should switch themes.

ProGuards

Theme:

ProGuards

Theme Slug:
proguards

Vulnerability:
Local File Inclusion

Patched in Version:
No Fix

Severity Score:
High

The vulnerability has not been patched. You should switch themes.

ProRange

Theme:

ProRange

Theme Slug:
prorange

Vulnerability:
Local File Inclusion

Patched in Version:
No Fix

Severity Score:
High

The vulnerability has not been patched. You should switch themes.

Qwery

Theme:

Qwery

Theme Slug:
qwery

Vulnerability:
Local File Inclusion

Patched in Version:
No Fix

Severity Score:
High

The vulnerability has not been patched. You should switch themes.

Samadhi

Theme:

Samadhi

Theme Slug:
samadhi

Vulnerability:
Local File Inclusion

Patched in Version:
No Fix

Severity Score:
High

The vulnerability has not been patched. You should switch themes.

Smart Casa

Theme:

Smart Casa

Theme Slug:
smart-casa

Vulnerability:
Local File Inclusion

Patched in Version:
No Fix

Severity Score:
High

The vulnerability has not been patched. You should switch themes.

SoccerClub

Theme:

SoccerClub

Theme Slug:
soccerclub

Vulnerability:
Local File Inclusion

Patched in Version:
No Fix

Severity Score:
High

The vulnerability has not been patched. You should switch themes.

Softic

Theme:

Softic

Theme Slug:
softic

Vulnerability:
Local File Inclusion

Patched in Version:
No Fix

Severity Score:
High

The vulnerability has not been patched. You should switch themes.

Solio

Theme:

Solio

Theme Slug:
solio

Vulnerability:
Local File Inclusion

Patched in Version:
No Fix

Severity Score:
High

The vulnerability has not been patched. You should switch themes.

StevenWatkins

Theme:

StevenWatkins

Theme Slug:
steven-watkins

Vulnerability:
Local File Inclusion

Patched in Version:
No Fix

Severity Score:
High

The vulnerability has not been patched. You should switch themes.

Stratego

Theme:

Stratego

Theme Slug:
stratego

Vulnerability:
Local File Inclusion

Patched in Version:
No Fix

Severity Score:
High

The vulnerability has not been patched. You should switch themes.

Studeon

Theme:

Studeon

Theme Slug:
studeon

Vulnerability:
Local File Inclusion

Patched in Version:
No Fix

Severity Score:
High

The vulnerability has not been patched. You should switch themes.

Tantra

Theme:

Tantra

Theme Slug:
tantra

Vulnerability:
Local File Inclusion

Patched in Version:
No Fix

Severity Score:
High

The vulnerability has not been patched. You should switch themes.

Tax Help

Theme:

Tax Help

Theme Slug:
tax-help

Vulnerability:
Local File Inclusion

Patched in Version:
No Fix

Severity Score:
High

The vulnerability has not been patched. You should switch themes.

Translang

Theme:

Translang

Theme Slug:
translang

Vulnerability:
Local File Inclusion

Patched in Version:
No Fix

Severity Score:
High

The vulnerability has not been patched. You should switch themes.

Travesia

Theme:

Travesia

Theme Slug:
travesia

Vulnerability:
Local File Inclusion

Patched in Version:
No Fix

Severity Score:
High

The vulnerability has not been patched. You should switch themes.

Vagabonds

Theme:

Vagabonds

Theme Slug:
vagabonds

Vulnerability:
Local File Inclusion

Patched in Version:
No Fix

Severity Score:
High

The vulnerability has not been patched. You should switch themes.

Wine House

Theme:

Wine House

Theme Slug:
wine-house

Vulnerability:
Local File Inclusion

Patched in Version:
No Fix

Severity Score:
High

The vulnerability has not been patched. You should switch themes.

Wise Move

Theme:

Wise Move

Theme Slug:
wisemove

Vulnerability:
Local File Inclusion

Patched in Version:
No Fix

Severity Score:
High

The vulnerability has not been patched. You should switch themes.

WotaHub

Theme:

WotaHub

Theme Slug:
wotahub

Vulnerability:
Local File Inclusion

Patched in Version:
No Fix

Severity Score:
High

The vulnerability has not been patched. You should switch themes.

OceanWP

Theme:

OceanWP

Theme Slug:
oceanwp

Downloads
8,786,658

Vulnerability:
Settings Change

Patched in Version:
4.1.2

Severity Score:
Medium

The vulnerability has been patched, so you should update to version 4.1.2.

SaasLauncher

Theme Slug:
saaslauncher

Downloads
67,440

Vulnerability:
Broken Access Control

Patched in Version:
1.3.1

Severity Score:
Medium

The vulnerability has been patched, so you should update to version 1.3.1.

AdForest

Theme:

AdForest

Theme Slug:
adforest

Vulnerability:
Broken Authentication

Patched in Version:
6.0.10

Severity Score:
Critical

The vulnerability has been patched, so you should update to version 6.0.10.

Flatsome

Theme:

Flatsome

Theme Slug:
flatsome

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
3.20.1

Severity Score:
Medium

The vulnerability has been patched, so you should update to version 3.20.1.

Goza

Theme:

Goza

Theme Slug:
goza-theme

Vulnerability:
Arbitrary File Deletion

Patched in Version:
3.2.3

Severity Score:
High

The vulnerability has been patched, so you should update to version 3.2.3.

Goza

Theme:

Goza

Theme Slug:
goza-theme

Vulnerability:
Arbitrary File Upload

Patched in Version:
3.2.3

Severity Score:
Critical

The vulnerability has been patched, so you should update to version 3.2.3.

Miraculous

Theme:

Miraculous

Theme Slug:
miraculous

Vulnerability:
SQL Injection

Patched in Version:
2.0.9

Severity Score:
Critical

The vulnerability has been patched, so you should update to version 2.0.9.

Oblo

Theme:

Oblo

Theme Slug:
oblo

Vulnerability:
Local File Inclusion

Patched in Version:
2.2.5

Severity Score:
High

The vulnerability has been patched, so you should update to version 2.2.5.

Rehub

Theme:

Rehub

Theme Slug:
rehub-theme

Vulnerability:
Content Injection

Patched in Version:
19.9.8

Severity Score:
High

The vulnerability has been patched, so you should update to version 19.9.8.

Rehub

Theme:

Rehub

Theme Slug:
rehub-theme

Vulnerability:
Sensitive Data Exposure

Patched in Version:
19.9.8

Severity Score:
Medium

The vulnerability has been patched, so you should update to version 19.9.8.

Solid Security is part of Solid Suite — The best foundation for WordPress websites.

Every WordPress site needs security, backups, and management tools. That’s Solid Suite — an integrated bundle of three plugins: Solid Security, Solid Backups, and Solid Central. You also get access to Solid Academy’s learning resources for WordPress professionals. Build your next WordPress website on a solid foundation with Solid Suite!

Get Solid Security


The post WordPress Vulnerability Report — September 10, 2025 appeared first on SolidWP.

Click here to continue reading this article.