In this report, 114 vulnerabilities have been publicly disclosed. Security patches for 75 of these plugins and themes are now available, so please run those updates as soon as possible. If you’re a Solid Security Pro user, the version management tool may have already warned you and updated these plugins, depending on your settings.
Additionally, there are 39 plugin and theme vulnerabilities, and no patch has been available yet. If you’re a Solid Security Pro user, those vulnerabilities are already protected by the Solid Security firewall. Virtual patches from Patchstack will be applied when a vulnerability is considered high or medium risk. If no patch is forthcoming from the vendor or the vulnerable software has been marked “closed” and dropped from the official WordPress repositories, you should deactivate it soon and look for alternative solutions.
WordPress Core
WordPress 6.8.2 was released on July 15, 2025. This maintenance release includes fixes for 20 Core tickets and 15 Block Editor issues. For a full list of bug fixes, please refer to the release candidate announcement.
WordPress Plugins — 68 Patched / 28 Unpatched
Poll, Survey & Quiz Maker Plugin by Opinion Stage
- Plugin Slug:
- social-polls-by-opinionstage
- Installations
- 8,000+
- Vulnerability:
- Local File Inclusion
- Patched in Version:
- No Fix
- Severity Score:
- High
- CVE:
-
2025-53328
Gutenify – Visual Site Builder Blocks & Site Templates.
- Plugin Slug:
- gutenify
- Installations
- 6,000+
- Vulnerability:
- Local File Inclusion
- Patched in Version:
- No Fix
- Severity Score:
- High
- CVE:
-
2025-53326
Chartbeat
- Plugin:
-
Chartbeat
- Plugin Slug:
- chartbeat
- Installations
- 1,000+
- Vulnerability:
- Server Side Request Forgery (SSRF)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
-
2025-53250
Post Type Converter
- Plugin:
-
Post Type Converter
- Plugin Slug:
- post-type-converter
- Installations
- 1,000+
- Vulnerability:
- Cross Site Request Forgery (CSRF)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
-
2025-48303
Link View
- Plugin:
-
Link View
- Plugin Slug:
- link-view
- Installations
- 900+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
-
2025-48110
Employee Directory – Staff Listing & Team Directory Plugin for WordPress
- Plugin Slug:
- employee-directory
- Installations
- 100+
- Vulnerability:
- PHP Object Injection
- Patched in Version:
- No Fix
- Severity Score:
- High
- CVE:
-
2025-53243
NextGEN Gallery Search
- Plugin:
-
NextGEN Gallery Search
- Plugin Slug:
- nextgen-gallery-search-galleries
- Installations
- 100+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- High
- CVE:
-
2025-53224
Page Manager for Elementor
- Plugin:
-
Page Manager for Elementor
- Plugin Slug:
- page-manager-for-elementor
- Installations
- 100+
- Vulnerability:
- Broken Access Control
- Patched in Version:
- No Fix
- Severity Score:
- High
- CVE:
-
2025-53230
Theme Switcher Reloaded
- Plugin:
-
Theme Switcher Reloaded
- Plugin Slug:
- theme-switcher-reloaded
- Installations
- 100+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- High
- CVE:
-
2025-53223
XmasB Quotes
- Plugin:
-
XmasB Quotes
- Plugin Slug:
- xmasb-quotes
- Installations
- 100+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- High
- CVE:
-
2025-53220
Google XML News Sitemap plugin
- Plugin:
-
Google XML News Sitemap plugin
- Plugin Slug:
- gn-xml-sitemap
- Installations
- 90+
- Vulnerability:
- Cross Site Request Forgery (CSRF)
- Patched in Version:
- No Fix
- Severity Score:
- High
- CVE:
-
2025-48304
SEO For Images
- Plugin:
-
SEO For Images
- Plugin Slug:
- seo-for-images
- Installations
- 90+
- Vulnerability:
- Cross Site Request Forgery (CSRF)
- Patched in Version:
- No Fix
- Severity Score:
- High
- CVE:
-
2025-48307
WooCommerce Payment Gateway for Saferpay
- Plugin Slug:
- woocommerce-payment-gateway-for-saferpay
- Installations
- 60+
- Vulnerability:
- Path Traversal
- Patched in Version:
- No Fix
- Severity Score:
- High
- CVE:
-
2025-48317
XM-Backup
- Plugin:
-
XM-Backup
- Plugin Slug:
- xm-backup
- Installations
- 60+
- Vulnerability:
- Cross Site Request Forgery (CSRF)
- Patched in Version:
- No Fix
- Severity Score:
- High
- CVE:
-
2025-48109
bidorbuy Store Integrator
- Plugin:
-
bidorbuy Store Integrator
- Plugin Slug:
- bidorbuystoreintegrator
- Installations
- 50+
- Vulnerability:
- Remote Code Execution (RCE)
- Patched in Version:
- No Fix
- Severity Score:
- Critical
- CVE:
-
2025-48100
Yahoo! WebPlayer
- Plugin:
-
Yahoo! WebPlayer
- Plugin Slug:
- yahoo-media-player
- Installations
- 50+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- High
- CVE:
-
2025-53215
Savyour Affiliate Partner
- Plugin:
-
Savyour Affiliate Partner
- Plugin Slug:
- savyour-affiliate-partner
- Installations
- 40+
- Vulnerability:
- Cross Site Request Forgery (CSRF)
- Patched in Version:
- No Fix
- Severity Score:
- High
- CVE:
-
2025-48306
Goal Tracker for Patreon
- Plugin:
-
Goal Tracker for Patreon
- Plugin Slug:
- goal-tracker-for-patreon
- Installations
- 10+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
-
2025-48305
Premium Age Verification / Restriction for WordPress
- Plugin:
-
Premium Age Verification / Restriction for WordPress
- Plugin Slug:
- age-restriction
- Vulnerability:
- Arbitrary File Download
- Patched in Version:
- No Fix
- Severity Score:
- High
- CVE:
-
2025-49403
Premium Age Verification / Restriction for WordPress
- Plugin:
-
Premium Age Verification / Restriction for WordPress
- Plugin Slug:
- age-restriction
- Vulnerability:
- Arbitrary File Upload
- Patched in Version:
- No Fix
- Severity Score:
- Critical
- CVE:
-
2025-49408
Exertio Framework
- Plugin:
-
Exertio Framework
- Plugin Slug:
- exertio-framework
- Vulnerability:
- SQL Injection
- Patched in Version:
- No Fix
- Severity Score:
- High
- CVE:
-
2025-49402
iATS Online Forms
- Plugin:
-
iATS Online Forms
- Plugin Slug:
- iats-online-forms
- Vulnerability:
- SQL Injection
- Patched in Version:
- No Fix
- Severity Score:
- High
- CVE:
-
2025-9441
Printeers Print & Ship
- Plugin:
-
Printeers Print & Ship
- Plugin Slug:
- invition-print-ship
- Vulnerability:
- Directory Traversal
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
-
2025-48081
List Subpages
- Plugin:
-
List Subpages
- Plugin Slug:
- list-sub-pages
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
-
2025-8290
OSM Map Widget for Elementor
- Plugin:
-
OSM Map Widget for Elementor
- Plugin Slug:
- osm-map-elementor
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
-
2025-8619
Related Posts Lite
- Plugin:
-
Related Posts Lite
- Plugin Slug:
- related-posts-lite
- Vulnerability:
- Cross Site Request Forgery (CSRF)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
-
2025-9618
Theme Blvd Widget Areas
- Plugin:
-
Theme Blvd Widget Areas
- Plugin Slug:
- theme-blvd-widget-areas
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- High
- CVE:
-
2025-53289
Ultimate Tag Warrior Importer
- Plugin:
-
Ultimate Tag Warrior Importer
- Plugin Slug:
- utw-importer
- Vulnerability:
- Cross Site Request Forgery (CSRF)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
-
2025-9374
All-in-One WP Migration and Backup
- Plugin Slug:
- all-in-one-wp-migration
- Installations
- 5,000,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 7.98
- Severity Score:
- Medium
- CVE:
-
2025-8490
TablePress – Tables in WordPress made easy
- Plugin Slug:
- tablepress
- Installations
- 700,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 3.2.1
- Severity Score:
- Medium
- CVE:
-
2025-9500
Ocean Extra
- Plugin:
-
Ocean Extra
- Plugin Slug:
- ocean-extra
- Installations
- 600,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 2.5.0
- Severity Score:
- Medium
- CVE:
-
2025-9499
SiteSEO – SEO Simplified
- Plugin:
-
SiteSEO – SEO Simplified
- Plugin Slug:
- siteseo
- Installations
- 400,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 1.2.8
- Severity Score:
- Medium
- CVE:
-
2025-9277
Otter Blocks – Gutenberg Blocks, Page Builder for Gutenberg Editor & FSE
- Plugin Slug:
- otter-blocks
- Installations
- 300,000+
- Vulnerability:
- Sensitive Data Exposure
- Patched in Version:
- 3.1.1
- Severity Score:
- High
- CVE:
-
2025-55715
Unlimited Elements For Elementor
- Plugin:
-
Unlimited Elements For Elementor
- Plugin Slug:
- unlimited-elements-for-elementor
- Installations
- 300,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 1.5.149
- Severity Score:
- Medium
- CVE:
-
2025-8603
Beaver Builder – WordPress Page Builder
- Plugin Slug:
- beaver-builder-lite-version
- Installations
- 100,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 2.9.3.1
- Severity Score:
- High
- CVE:
-
2025-8897
WP Bulk Delete
- Plugin:
-
WP Bulk Delete
- Plugin Slug:
- wp-bulk-delete
- Installations
- 90,000+
- Vulnerability:
- Broken Access Control
- Patched in Version:
- 1.3.7
- Severity Score:
- Medium
- CVE:
-
2025-58192
Ajax Search Lite – Live Search & Filter
- Plugin Slug:
- ajax-search-lite
- Installations
- 80,000+
- Vulnerability:
- Broken Access Control
- Patched in Version:
- 4.13.2
- Severity Score:
- Medium
- CVE:
-
2025-7956
Bold Page Builder
- Plugin:
-
Bold Page Builder
- Plugin Slug:
- bold-page-builder
- Installations
- 50,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 5.4.4
- Severity Score:
- Medium
- CVE:
-
2025-58194
Booking Calendar
- Plugin:
-
Booking Calendar
- Plugin Slug:
- booking
- Installations
- 50,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 10.14.2
- Severity Score:
- Medium
- CVE:
-
2025-9346
Uncanny Automator – Easy Automation, Integration, Webhooks & Workflow Builder Plugin
- Plugin Slug:
- uncanny-automator
- Installations
- 50,000+
- Vulnerability:
- Broken Access Control
- Patched in Version:
- 6.8.0
- Severity Score:
- Medium
- CVE:
-
2025-58193
UiCore Elements – Free Elementor widgets and templates
- Plugin Slug:
- uicore-elements
- Installations
- 40,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 1.3.5
- Severity Score:
- Medium
- CVE:
-
2025-58196
Booster for WooCommerce – PDF Invoices, Abandoned Cart, Variation Swatches & 100+ Tools
- Plugin Slug:
- woocommerce-jetpack
- Installations
- 40,000+
- Vulnerability:
- Arbitrary File Upload
- Patched in Version:
- 7.2.5
- Severity Score:
- High
- CVE:
-
2024-13342
140+ Widgets | Xpro Addons For Elementor – FREE
- Plugin Slug:
- xpro-elementor-addons
- Installations
- 30,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 1.4.18
- Severity Score:
- Medium
- CVE:
-
2025-58195
Simple Download Monitor
- Plugin:
-
Simple Download Monitor
- Plugin Slug:
- simple-download-monitor
- Installations
- 20,000+
- Vulnerability:
- SQL Injection
- Patched in Version:
- 3.9.34
- Severity Score:
- High
- CVE:
-
2025-8977
Simple Download Monitor
- Plugin:
-
Simple Download Monitor
- Plugin Slug:
- simple-download-monitor
- Installations
- 20,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 3.9.35
- Severity Score:
- Medium
- CVE:
-
2025-58197
UsersWP – Front-end login form, User Registration, User Profile & Members Directory plugin for WP
- Plugin:
-
UsersWP – Front-end login form, User Registration, User Profile & Members Directory plugin for WP
- Plugin Slug:
- userswp
- Installations
- 20,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 1.2.43
- Severity Score:
- Medium
- CVE:
-
2025-9344
Lazy Load for Videos
- Plugin:
-
Lazy Load for Videos
- Plugin Slug:
- lazy-load-for-videos
- Installations
- 10,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 2.18.8
- Severity Score:
- Medium
- CVE:
-
2025-7732
Xpro Theme Builder For Elementor – FREE
- Plugin Slug:
- xpro-theme-builder
- Installations
- 10,000+
- Vulnerability:
- Broken Access Control
- Patched in Version:
- 1.2.10
- Severity Score:
- Medium
- CVE:
-
2025-58198
AfterShip Tracking – All-In-One WooCommerce Order Tracking (Free plan available)
- Plugin Slug:
- aftership-woocommerce-tracking
- Installations
- 9,000+
- Vulnerability:
- Broken Access Control
- Patched in Version:
- 1.17.18
- Severity Score:
- Medium
- CVE:
-
2025-58201
Events Addon for Elementor
- Plugin:
-
Events Addon for Elementor
- Plugin Slug:
- events-addon-for-elementor
- Installations
- 8,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 2.3.0
- Severity Score:
- Medium
- CVE:
-
2025-8150
LWSCache
Event Booking Manager for WooCommerce – WpEvently
- Plugin Slug:
- mage-eventpress
- Installations
- 8,000+
- Vulnerability:
- PHP Object Injection
- Patched in Version:
- 4.4.9
- Severity Score:
- High
- CVE:
-
2025-54742
Xagio SEO – AI Powered SEO
- Plugin:
-
Xagio SEO – AI Powered SEO
- Plugin Slug:
- xagio-seo
- Installations
- 8,000+
- Vulnerability:
- Sensitive Data Exposure
- Patched in Version:
- 7.1.0.6
- Severity Score:
- High
- CVE:
-
2024-13807
Solace Extra
- Plugin:
-
Solace Extra
- Plugin Slug:
- solace-extra
- Installations
- 7,000+
- Vulnerability:
- Server Side Request Forgery (SSRF)
- Patched in Version:
- 1.3.3
- Severity Score:
- Medium
- CVE:
-
2025-58203
Simple Page Access Restriction
- Plugin:
-
Simple Page Access Restriction
- Plugin Slug:
- simple-page-access-restriction
- Installations
- 6,000+
- Vulnerability:
- Cross Site Request Forgery (CSRF)
- Patched in Version:
- 1.0.33
- Severity Score:
- Medium
- CVE:
-
2025-58202
B Slider – Responsive Image Slider
- Plugin Slug:
- b-slider
- Installations
- 5,000+
- Vulnerability:
- Broken Access Control
- Patched in Version:
- 2.0.0
- Severity Score:
- Medium
- CVE:
-
2025-54734
Block Bad Bots and Stop Bad Bots Crawlers and Spiders and Anti Spam Protection
- Plugin Slug:
- stopbadbots
- Installations
- 5,000+
- Vulnerability:
- Broken Authentication
- Patched in Version:
- 11.59
- Severity Score:
- Medium
- CVE:
-
2025-9376
Tourfic — Travel, Hotel & Car Rental Booking for WooCommerce
- Plugin Slug:
- tourfic
- Installations
- 5,000+
- Vulnerability:
- Broken Access Control
- Patched in Version:
- 2.15.0
- Severity Score:
- Medium
- CVE:
-
2024-8860
All Bootstrap Blocks
- Plugin:
-
All Bootstrap Blocks
- Plugin Slug:
- all-bootstrap-blocks
- Installations
- 4,000+
- Vulnerability:
- Broken Access Control
- Patched in Version:
- 1.3.29
- Severity Score:
- Medium
- CVE:
-
2025-54733
ElementInvader Addons for Elementor
- Plugin Slug:
- elementinvader-addons-for-elementor
- Installations
- 4,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 1.3.7
- Severity Score:
- Medium
- CVE:
-
2025-58205
Podlove Podcast Publisher
- Plugin:
-
Podlove Podcast Publisher
- Plugin Slug:
- podlove-podcasting-plugin-for-wordpress
- Installations
- 4,000+
- Vulnerability:
- Open Redirection
- Patched in Version:
- 4.2.6
- Severity Score:
- Medium
- CVE:
-
2025-58204
JS Archive List
- Plugin:
-
JS Archive List
- Plugin Slug:
- jquery-archive-list-widget
- Installations
- 3,000+
- Vulnerability:
- SQL Injection
- Patched in Version:
- 6.1.6
- Severity Score:
- Critical
- CVE:
-
2025-54726
Responsive YouTube Video Gallery Plugin for WordPress – YouTube Showcase
- Plugin Slug:
- youtube-showcase
- Installations
- 3,000+
- Vulnerability:
- PHP Object Injection
- Patched in Version:
- 3.5.2
- Severity Score:
- High
- CVE:
-
2025-54731
Pronamic Google Maps
- Plugin:
-
Pronamic Google Maps
- Plugin Slug:
- pronamic-google-maps
- Installations
- 2,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 2.4.2
- Severity Score:
- Medium
- CVE:
-
2025-9352
Feeds For TikTok – Show TikTok Videos in Grid or Feed Layout
- Plugin Slug:
- b-tiktok-feed
- Installations
- 1,000+
- Vulnerability:
- Broken Access Control
- Patched in Version:
- 1.0.22
- Severity Score:
- High
- CVE:
-
2025-54710
E-cab Taxi Booking Manager for Woocommerce
- Plugin Slug:
- ecab-taxi-booking-manager
- Installations
- 1,000+
- Vulnerability:
- Broken Authentication
- Patched in Version:
- 1.3.1
- Severity Score:
- Critical
- CVE:
-
2025-54713
PDF for Elementor Forms + Drag And Drop Template Builder
- Plugin Slug:
- pdf-for-elementor-forms
- Installations
- 1,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 6.3.0
- Severity Score:
- Medium
- CVE:
-
2025-58208
Skyword XMLRPC publishing
- Plugin:
-
Skyword XMLRPC publishing
- Plugin Slug:
- skyword-plugin
- Installations
- 1,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 2.5.3
- Severity Score:
- Medium
- CVE:
-
2024-11907
Zephyr Project Manager
- Plugin:
-
Zephyr Project Manager
- Plugin Slug:
- zephyr-project-manager
- Installations
- 1,000+
- Vulnerability:
- Broken Access Control
- Patched in Version:
- 3.3.202
- Severity Score:
- High
- CVE:
-
2025-54714
Drag and Drop File Upload for Elementor Forms
- Plugin Slug:
- drag-and-drop-file-upload-for-elementor-forms
- Installations
- 800+
- Vulnerability:
- Arbitrary File Upload
- Patched in Version:
- 1.5.4
- Severity Score:
- Critical
- CVE:
-
2025-49387
Transcoder
- Plugin:
-
Transcoder
- Plugin Slug:
- transcoder
- Installations
- 700+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 1.4.1
- Severity Score:
- Medium
- CVE:
-
2025-58209
Employee Spotlight – Team Member Showcase & Meet the Team Plugin
- Plugin Slug:
- employee-spotlight
- Installations
- 500+
- Vulnerability:
- PHP Object Injection
- Patched in Version:
- 5.1.2
- Severity Score:
- High
- CVE:
-
2025-53583
Epeken All Kurir Plugin for Woocommerce Full Version
- Plugin Slug:
- epeken-all-kurir
- Installations
- 500+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 2.0.2
- Severity Score:
- Medium
- CVE:
-
2025-58212
UPC/EAN/GTIN Code Generator
- Plugin:
-
UPC/EAN/GTIN Code Generator
- Plugin Slug:
- upc-ean-barcode-generator
- Installations
- 500+
- Vulnerability:
- Arbitrary File Deletion
- Patched in Version:
- 2.0.3
- Severity Score:
- High
- CVE:
-
2025-53588
Chatbox Manager
- Plugin:
-
Chatbox Manager
- Plugin Slug:
- wa-chatbox-manager
- Installations
- 500+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 1.2.7
- Severity Score:
- Medium
- CVE:
-
2025-58211
Customer Support Ticket System & Helpdesk Plugin for WordPress
- Plugin Slug:
- wp-ticket
- Installations
- 500+
- Vulnerability:
- PHP Object Injection
- Patched in Version:
- 6.0.3
- Severity Score:
- High
- CVE:
-
2025-53584
Booking System Trafft
- Plugin:
-
Booking System Trafft
- Plugin Slug:
- booking-system-trafft
- Installations
- 400+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 1.0.15
- Severity Score:
- Medium
- CVE:
-
2025-58213
Captcha.eu
- Plugin:
-
Captcha.eu
- Plugin Slug:
- captcha-eu
- Installations
- 200+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 1.0.61
- Severity Score:
- High
- CVE:
-
2025-53579
Dynamic AJAX Product Filters for WooCommerce
- Plugin Slug:
- dynamic-ajax-product-filters-for-woocommerce
- Installations
- 100+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 1.3.8
- Severity Score:
- Medium
- CVE:
-
2025-8073
File Manager, Code Editor, and Backup by Managefy
- Plugin Slug:
- softdiscover-db-file-manager
- Installations
- 100+
- Vulnerability:
- Path Traversal
- Patched in Version:
- 1.5.0
- Severity Score:
- Medium
- CVE:
-
2025-9345
Vibes
WP Thumbtack Review Slider
- Plugin:
-
WP Thumbtack Review Slider
- Plugin Slug:
- wp-thumbtack-review-slider
- Installations
- 100+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 2.7
- Severity Score:
- Medium
- CVE:
-
2025-58216
Video Share VOD – Turnkey Video Site Builder Script
- Plugin Slug:
- video-share-vod
- Installations
- 90+
- Vulnerability:
- Cross Site Request Forgery (CSRF)
- Patched in Version:
- 2.7.7
- Severity Score:
- High
- CVE:
-
2025-7812
Instant Breaking News
- Plugin:
-
Instant Breaking News
- Plugin Slug:
- instant-breaking-news
- Installations
- 60+
- Vulnerability:
- Cross Site Request Forgery (CSRF)
- Patched in Version:
- 1.0.1
- Severity Score:
- High
- CVE:
-
2025-58217
Custom Query Shortcode
- Plugin:
-
Custom Query Shortcode
- Plugin Slug:
- custom-query-shortcode
- Installations
- 40+
- Vulnerability:
- Directory Traversal
- Patched in Version:
- 0.5.0
- Severity Score:
- Medium
- CVE:
-
2025-8562
Simple Contact Form Plugin for WordPress – WP Easy Contact
- Plugin Slug:
- wp-easy-contact
- Installations
- 40+
- Vulnerability:
- PHP Object Injection
- Patched in Version:
- 4.0.2
- Severity Score:
- High
- CVE:
-
2025-53572
RingCentral Communications Plugin – FREE
- Plugin Slug:
- rccp-free
- Installations
- 30+
- Vulnerability:
- Broken Authentication
- Patched in Version:
- 1.7.0
- Severity Score:
- Critical
- CVE:
-
2025-7955
Small Package Quotes – USPS Edition
- Plugin Slug:
- small-package-quotes-usps-edition
- Installations
- 10+
- Vulnerability:
- PHP Object Injection
- Patched in Version:
- 1.3.10
- Severity Score:
- High
- CVE:
-
2025-58218
Dokan Pro
- Plugin:
-
Dokan Pro
- Plugin Slug:
- dokan-pro
- Vulnerability:
- Privilege Escalation
- Patched in Version:
- 4.0.6
- Severity Score:
- High
- CVE:
-
2025-5931
eventlist
- Plugin:
-
eventlist
- Plugin Slug:
- eventlist
- Vulnerability:
- Privilege Escalation
- Patched in Version:
- 2.0.5
- Severity Score:
- High
- CVE:
-
2025-6366
WooCommerce csv import export
- Plugin:
-
WooCommerce csv import export
- Plugin Slug:
- extendons-eo-wooimport-export
- Vulnerability:
- Arbitrary File Deletion
- Patched in Version:
- 2.0.7
- Severity Score:
- High
- CVE:
-
2025-54029
Houzez CRM
- Plugin:
-
Houzez CRM
- Plugin Slug:
- houzez-crm
- Vulnerability:
- Broken Access Control
- Patched in Version:
- 1.5.0
- Severity Score:
- Medium
- CVE:
-
2025-49402
Nest Addons
- Plugin:
-
Nest Addons
- Plugin Slug:
- nest-addons
- Vulnerability:
- SQL Injection
- Patched in Version:
- 1.6.4
- Severity Score:
- Critical
- CVE:
-
2025-54720
Slider Revolution
- Plugin:
-
Slider Revolution
- Plugin Slug:
- revslider
- Vulnerability:
- Arbitrary File Download
- Patched in Version:
- 6.7.37
- Severity Score:
- Medium
- CVE:
-
2025-9217
Automatic
- Plugin:
-
Automatic
- Plugin Slug:
- wp-automatic
- Vulnerability:
- Cross Site Request Forgery (CSRF)
- Patched in Version:
- 3.119.0
- Severity Score:
- High
- CVE:
-
2025-6247
WP ULike Pro
- Plugin:
-
WP ULike Pro
- Plugin Slug:
- wp-ulike-pro
- Vulnerability:
- Arbitrary File Upload
- Patched in Version:
- 1.9.4
- Severity Score:
- Medium
- CVE:
-
2024-9648
WordPress Themes — 7 Patched / 11 Unpatched
Magazine Saga
- Theme:
-
Magazine Saga
- Theme Slug:
- magazine-saga
- Downloads
- 39,662
- Vulnerability:
- Local File Inclusion
- Patched in Version:
- No Fix
- Severity Score:
- High
- CVE:
-
2025-53227
ArcHub
- Theme:
-
ArcHub
- Theme Slug:
- archub
- Vulnerability:
- Broken Access Control
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
-
2025-0951
Cars4Rent
- Theme:
-
Cars4Rent
- Theme Slug:
- cars4rent
- Vulnerability:
- PHP Object Injection
- Patched in Version:
- No Fix
- Severity Score:
- Critical
- CVE:
-
2025-49434
Hub
- Theme:
-
Hub
- Theme Slug:
- hub
- Vulnerability:
- Broken Access Control
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
-
2025-0951
Jannah
- Theme:
-
Jannah
- Theme Slug:
- jannah
- Vulnerability:
- Local File Inclusion
- Patched in Version:
- No Fix
- Severity Score:
- High
- CVE:
-
2025-53334
Jina – Celebration Agency Theme
- Theme:
-
Jina – Celebration Agency Theme
- Theme Slug:
- jina
- Vulnerability:
- Deserialization of untrusted data
- Patched in Version:
- No Fix
- Severity Score:
- Critical
- CVE:
-
2025-31927
The Restaurant
- Theme:
-
The Restaurant
- Theme Slug:
- nrgrestaurant
- Vulnerability:
- PHP Object Injection
- Patched in Version:
- No Fix
- Severity Score:
- Critical
- CVE:
-
2025-31927
Nuss
- Theme:
-
Nuss
- Theme Slug:
- nuss
- Vulnerability:
- Local File Inclusion
- Patched in Version:
- No Fix
- Severity Score:
- High
- CVE:
-
2025-49894
Pro Bulk Watermark Plugin for WordPress
- Theme:
-
Pro Bulk Watermark Plugin for WordPress
- Theme Slug:
- pro-watermark
- Vulnerability:
- Path Traversal
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
-
2025-4956
Rozario
- Theme:
-
Rozario
- Theme Slug:
- rozario
- Vulnerability:
- PHP Object Injection
- Patched in Version:
- No Fix
- Severity Score:
- Critical
- CVE:
-
2025-31927
Upking – Hiking Club WordPress Theme
- Theme:
-
Upking – Hiking Club WordPress Theme
- Theme Slug:
- upking
- Vulnerability:
- Deserialization of untrusted data
- Patched in Version:
- No Fix
- Severity Score:
- Critical
- CVE:
-
2025-31927
Golo
- Theme:
-
Golo
- Theme Slug:
- golo
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 1.7.2
- Severity Score:
- High
- CVE:
-
2025-54724
Houzez
- Theme:
-
Houzez
- Theme Slug:
- houzez
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 4.1.4
- Severity Score:
- High
- CVE:
-
2025-49407
Houzez
- Theme:
-
Houzez
- Theme Slug:
- houzez
- Vulnerability:
- Local File Inclusion
- Patched in Version:
- 4.1.4
- Severity Score:
- High
- CVE:
-
2025-49405
Ireca
- Theme:
-
Ireca
- Theme Slug:
- ireca
- Vulnerability:
- Local File Inclusion
- Patched in Version:
- 1.8.6
- Severity Score:
- High
- CVE:
-
2025-54716
Makeaholic
- Theme:
-
Makeaholic
- Theme Slug:
- makeaholic
- Vulnerability:
- Broken Access Control
- Patched in Version:
- 1.8.7
- Severity Score:
- Medium
- CVE:
-
2025-58210
Neresa
- Theme:
-
Neresa
- Theme Slug:
- neresa-wp
- Vulnerability:
- Local File Inclusion
- Patched in Version:
- 1.4
- Severity Score:
- High
- CVE:
-
2025-49383
Pin WP
- Theme:
-
Pin WP
- Theme Slug:
- pin-wp
- Vulnerability:
- Arbitrary File Upload
- Patched in Version:
- 7.2
- Severity Score:
- Critical
- CVE:
-
2025-53251
Solid Security is part of Solid Suite — The best foundation for WordPress websites.
Every WordPress site needs security, backups, and management tools. That’s Solid Suite — an integrated bundle of three plugins: Solid Security, Solid Backups, and Solid Central. You also get access to Solid Academy’s learning resources for WordPress professionals. Build your next WordPress website on a solid foundation with Solid Suite!
The post WordPress Vulnerability Report — September 3, 2025 appeared first on SolidWP.
Click here to continue reading this article.