Plugin name | Vulnerability | Patch Priority score |
EmbedPress | Broken Access Control | 2 |
YITH WooCommerce Ajax Product Filter | Cross Site Scripting (XSS) | 2 |
Brizy – Page Builder | Broken Access Control | 1 |
Matomo Analytics | Cross Site Request Forgery (CSRF) | 1 |
Event Tickets | Cross Site Request Forgery (CSRF) | 1 |
OnePress | Cross Site Scripting (XSS) | 1 |
Tutor LMS | Cross Site Scripting (XSS) | 1 |
Auto Featured Image (Auto Post Thumbnail) | Broken Access Control | 1 |
WP RSS Aggregator | Broken Access Control | 1 |
Phlox Portfolio | Cross Site Scripting (XSS) | 1 |
Image Hover Effects – Elementor Addon | Cross Site Scripting (XSS) | 1 |
Ultimate Blocks – Gutenberg Blocks Plugin | Cross Site Scripting (XSS) | 1 |
Internal Link Juicer: SEO Auto Linker for WordPress | Cross Site Request Forgery (CSRF) | 1 |
Ditty | Cross Site Scripting (XSS) | 1 |
PowerPress Podcasting | Cross Site Scripting (XSS) | 1 |
Social Media Widget | Cross Site Scripting (XSS) | 1 |
Qi Blocks | Cross Site Scripting (XSS) | 1 |
Quiz And Survey Master | Cross Site Scripting (XSS) | 1 |
Index WP MySQL For Speed | Cross Site Scripting (XSS) | 2 |
FULL Customer | Cross Site Scripting (XSS) | 2 |
Seriously Simple Podcasting | Cross Site Scripting (XSS) | 1 |
WP Popups | Full Path Disclosure (FPD) | 1 |
Master Addons for Elementor | Cross Site Scripting (XSS) | 1 |
Team Members | Cross Site Scripting (XSS) | 1 |
Backup and Staging by WP Time Capsule | Privilege Escalation | 4 |
Form Vibes – Database Manager for Forms | SQL Injection | 3 |
TeraWallet – For WooCommerce | SQL Injection | 3 |
Login by Auth0 | Cross Site Scripting (XSS) | 2 |
WP Event Manager | Cross Site Scripting (XSS) | 1 |
WordPress File Upload | Directory Traversal | 1 |
User Submitted Posts | Cross Site Scripting (XSS) | 1 |
Giveaways and Contests by RafflePress | Cross Site Scripting (XSS) | 1 |
Image Photo Gallery Final Tiles Grid | Cross Site Scripting (XSS) | 1 |
Wholesale Suite | Broken Access Control | 1 |
Secure Copy Content Protection and Content Locking | Cross Site Scripting (XSS) | 1 |
Slider by 10Web | Cross Site Scripting (XSS) | 1 |
Branda | Full Path Disclosure (FPD) | 1 |
Meks Smart Author Widget | Cross Site Scripting (XSS) | 1 |
SmartCrawl WordPress SEO checker, SEO analyzer, SEO optimizer | Full Path Disclosure (FPD) | 1 |
MP3 Audio Player for Music, Radio & Podcast by Sonaar | Cross Site Scripting (XSS) | 1 |
WP Accessibility Helper (WAH) | Broken Access Control | 1 |
SmartMag | Multiple Vulnerabilities | 1 |
WP Photo Album Plus | Cross Site Scripting (XSS) | 2 |
Link Library | Cross Site Scripting (XSS) | 2 |
Goftino | Cross Site Scripting (XSS) | 2 |
XCloner Backup, Restore and Migrate | Sensitive Data Exposure | 1 |
SchedulePress | Sensitive Data Exposure | 1 |
Shortcodes Ultimate Pro | Cross Site Scripting (XSS) | 1 |
Product Enquiry for WooCommerce | Cross Site Scripting (XSS) | 1 |
Packlink PRO shipping module | Broken Access Control | 1 |
Metorik – Reports & Email Automation for WooCommerce | Cross Site Request Forgery (CSRF) | 1 |
ReCaptcha Integration for WordPress | Cross Site Scripting (XSS) | 1 |
WP Travel Engine | Cross Site Scripting (XSS) | 1 |
BuddyBoss Theme | Cross Site Request Forgery (CSRF) | 1 |
Gum Elementor Addon | Cross Site Scripting (XSS) | 1 |
Simple Post Notes | Cross Site Scripting (XSS) | 1 |
If-So Dynamic Content Personalization | Cross Site Scripting (XSS) | 2 |
If-So Dynamic Content Personalization | Cross Site Scripting (XSS) | 1 |
JSON Content Importer | Server Side Request Forgery (SSRF) | 1 |
WP ERP | SQL Injection | 1 |
Plugin Notes Plus | Cross Site Scripting (XSS) | 1 |
iPanorama 360 WordPress Virtual Tour Builder | Broken Access Control | 1 |
ProfileGrid | Insecure Direct Object References (IDOR) | 1 |
Jobmonster | Arbitrary File Deletion | 4 |
Jobmonster | Privilege Escalation | 4 |
Advanced post slider | Cross Site Scripting (XSS) | 1 |
Post Layouts for Gutenberg | Cross Site Scripting (XSS) | 1 |
InstaWP Connect | Privilege Escalation | 4 |
Plum: Spin Wheel & Email Pop-up | Cross Site Scripting (XSS) | 3 |
WP QuickLaTeX | Cross Site Scripting (XSS) | 1 |
WP Links Page | Broken Access Control | 1 |
Send Users Email | Sensitive Data Exposure | 1 |
Plum: Spin Wheel & Email Pop-up | Broken Access Control | 1 |
Magical Addons For Elementor | Server Side Request Forgery (SSRF) | 1 |
Magical Addons For Elementor | Cross Site Scripting (XSS) | 1 |
Fusion | Cross Site Scripting (XSS) | 1 |
MStore API | Broken Authentication | 4 |
Zoho Campaigns | Cross Site Scripting (XSS) | 2 |
Zoho CRM Lead Magnet | Cross Site Scripting (XSS) | 2 |
CM On Demand Search And Replace | Cross Site Request Forgery (CSRF) | 1 |
Watu Quiz | Cross Site Scripting (XSS) | 1 |
Google Adsense & Banner Ads by AdsforWP | Cross Site Request Forgery (CSRF) | 1 |
ElementInvader Addons for Elementor | Cross Site Scripting (XSS) | 1 |
VikRentCar | Cross Site Request Forgery (CSRF) | 1 |
Arkhe Blocks | Cross Site Scripting (XSS) | 1 |
Magical Posts Display – Elementor & Gutenberg Posts Blocks | Cross Site Scripting (XSS) | 1 |
Point | Cross Site Request Forgery (CSRF) | 1 |
WP2Speed Faster | Sensitive Data Exposure | 1 |
Generate PDF using Contact Form 7 | Cross Site Request Forgery (CSRF) | 1 |
Woocommerce OpenPos | Arbitrary File Deletion | 4 |
MakeStories (for Google Web Stories) | Arbitrary File Download | 3 |
Woocommerce OpenPos | Broken Access Control | 3 |
Woocommerce OpenPos | SQL Injection | 3 |
Insert or Embed Articulate Content into WordPress | Arbitrary File Upload | 2 |
Simple Responsive Slider | Cross Site Scripting (XSS) | 2 |
AForms | Sensitive Data Exposure | 1 |
Typebot | Cross Site Scripting (XSS) | 1 |
HitPay Payment Gateway for WooCommerce | Sensitive Data Exposure | 1 |
Realtyna Organic IDX plugin | Arbitrary File Upload | 1 |
Meks Video Importer | Broken Access Control | 1 |
Events Calendar for Google | Local File Inclusion | 1 |
Wallet System for WooCommerce | Sensitive Data Exposure | 1 |
Spiffy Calendar | SQL Injection | 1 |
Recipe Maker For Your Food Blog from Zip Recipes | Sensitive Data Exposure | 1 |
Cliengo – Chatbot | Cross Site Request Forgery (CSRF) | 1 |
Timeline Module for Beaver Builder | Cross Site Scripting (XSS) | 1 |
ConeBlog – WordPress Blog Widgets | Cross Site Scripting (XSS) | 1 |
JSON API User | Privilege Escalation | 4 |
EazyDocs | Broken Access Control | 2 |
Moloni | Cross Site Scripting (XSS) | 2 |
AdPush | Cross Site Scripting (XSS) | 2 |
ARForms Form Builder | Cross Site Scripting (XSS) | 2 |
Web and WooCommerce Addons for WPBakery Builder | Broken Access Control | 1 |
Glossary | Sensitive Data Exposure | 1 |
SVG Block | Cross Site Scripting (XSS) | 1 |
Popularis Verse | Cross Site Request Forgery (CSRF) | 1 |
EleForms | Broken Access Control | 1 |
Change From Email | Cross Site Scripting (XSS) | 1 |
EazyDocs | Cross Site Scripting (XSS) | 1 |
Download Button for Elementor | Cross Site Scripting (XSS) | 1 |
ExS Widgets | Local File Inclusion | 1 |
WP Event Aggregator | Cross Site Scripting (XSS) | 1 |
Product Delivery Date for WooCommerce – Lite | Broken Access Control | 1 |
SKT Skill Bar | Cross Site Scripting (XSS) | 1 |
Simple Popup | Cross Site Scripting (XSS) | 1 |
SlingBlocks – Gutenberg Blocks by FunnelKit (Formerly WooFunnels) | Cross Site Scripting (XSS) | 1 |
Calendar.online / Kalender.digital | Cross Site Scripting (XSS) | 1 |
codoc | Cross Site Scripting (XSS) | 1 |
Caxton – Create Pro page layouts in Gutenberg | Cross Site Scripting (XSS) | 1 |
Featured Image Generator | Broken Access Control | 1 |
Chained Quiz | Broken Access Control | 1 |
WP User Switch | Privilege Escalation | 4 |
Event post | Local File Inclusion | 3 |
Product Designer | Arbitrary Content Deletion | 3 |
PayPlus Payment Gateway | SQL Injection | 3 |
Import Spreadsheets from Microsoft Excel | Arbitrary File Upload | 2 |
Seraphinite Post .DOCX Source | Server Side Request Forgery (SSRF) | 2 |
Booking Ultra Pro | Local File Inclusion | 2 |
WPCS | Content Injection | 2 |
WooCommerce Report | Cross Site Scripting (XSS) | 2 |
Appmaker – Convert WooCommerce to Android & iOS Native Mobile Apps | Cross Site Scripting (XSS) | 2 |
Multisite Content Copier/Updater | Cross Site Scripting (XSS) | 2 |
WP GoToWebinar | Cross Site Scripting (XSS) | 2 |
WooCommerce Predictive Search | Cross Site Scripting (XSS) | 2 |
MBE eShip | Cross Site Scripting (XSS) | 2 |
TOCHAT.BE | Cross Site Scripting (XSS) | 2 |
CM Email Registration Blacklist and Whitelist | Cross Site Request Forgery (CSRF) | 1 |
Oceanic | Cross Site Request Forgery (CSRF) | 1 |
i-transform | Cross Site Request Forgery (CSRF) | 1 |
Zephyr Project Manager | Sensitive Data Exposure | 1 |
Quotes And Tips | Arbitrary File Upload | 1 |
WappPress | Server Side Request Forgery (SSRF) | 1 |
Coming Soon | Sensitive Data Exposure | 1 |
DirectoryPress | SQL Injection | 1 |
Taggbox | Cross Site Request Forgery (CSRF) | 1 |
Animated Rotating Words | Cross Site Request Forgery (CSRF) | 1 |
Olive One Click Demo Import | Sensitive Data Exposure | 1 |
MBE eShip | Sensitive Data Exposure | 1 |
Amazing Hover Effects | Cross Site Scripting (XSS) | 1 |
ReDi Restaurant Reservation | Broken Access Control | 1 |
Patricia Blog | Cross Site Request Forgery (CSRF) | 1 |
i-amaze | Cross Site Request Forgery (CSRF) | 1 |
MBE eShip | Cross Site Request Forgery (CSRF) | 1 |
Seraphinite Post .DOCX Source | Broken Access Control | 1 |
WP Fast Total Search | Broken Access Control | 1 |
GD Rating System | Local File Inclusion | 1 |
WordPress Team Manager | Local File Inclusion | 1 |
Academy LMS | Broken Access Control | 1 |
Sirv | Broken Access Control | 1 |
WP GoToWebinar | Broken Access Control | 1 |
Sky Addons for Elementor | Cross Site Scripting (XSS) | 1 |
FancyPost – Best Ultimate Post Block, Post Grid, Layouts, Carousel, Slider For Gutenberg & Elementor | Cross Site Scripting (XSS) | 1 |
Animated Typed JS Shortcode | Cross Site Scripting (XSS) | 1 |
REVIEWS.io | Cross Site Scripting (XSS) | 1 |
Booking Ultra Pro | Cross Site Scripting (XSS) | 1 |
SKT Addons for Elementor | Cross Site Scripting (XSS) | 1 |
CodePen Embedded Pens Shortcode | Cross Site Scripting (XSS) | 1 |
Power BI Embedded for WordPress | Cross Site Scripting (XSS) | 1 |
Bradmax Player | Cross Site Scripting (XSS) | 1 |
GutSlider – All in One Block Slider | Cross Site Scripting (XSS) | 1 |
Responsive Mobile | Cross Site Scripting (XSS) | 1 |
WPBITS Addons For Elementor Page Builder | Cross Site Scripting (XSS) | 1 |
Gravity Forms: Multiple Form Instances | Full Path Disclosure (FPD) | 1 |
Patricia Lite | Cross Site Request Forgery (CSRF) | 1 |
Tabs For WPBakery Page Builder | Cross Site Scripting (XSS) | 1 |
Barcode Scanner with Inventory & Order Manager | SQL Injection | 3 |
BerqWP | Server Side Request Forgery (SSRF) | 2 |
SociallyViral | Cross Site Request Forgery (CSRF) | 1 |
User Activity Log Pro | Broken Access Control | 2 |
Admin Dashboard RSS Feed | Cross Site Scripting (XSS) | 1 |
Job Board Manager | Cross Site Scripting (XSS) | 2 |
Contact Form 7 Summary and Print | Cross Site Request Forgery (CSRF) | 1 |
Master Popups | Cross Site Scripting (XSS) | 1 |
Tournamatch | Cross Site Scripting (XSS) | 2 |
Tournamatch | Cross Site Scripting (XSS) | 1 |
Smart Image Gallery | Cross Site Request Forgery (CSRF) | 1 |
Bug Library | Remote Code Execution (RCE) | 4 |
Uncanny Automator Pro | Cross Site Scripting (XSS) | 2 |
Affiliate Manager | Cross Site Request Forgery (CSRF) | 1 |
Embed Peertube Playlist | Cross Site Scripting (XSS) | 1 |
Website Content in Page or Post | Cross Site Scripting (XSS) | 1 |
Hostel | Cross Site Scripting (XSS) | 2 |
OpenPGP Form Encryption | Cross Site Scripting (XSS) | 1 |
WP Total Branding | Cross Site Scripting (XSS) | 1 |
SULly | Cross Site Scripting (XSS) | 2 |
counterpoint | Cross Site Scripting (XSS) | 2 |
SULly | Cross Site Scripting (XSS) | 1 |
SULly | Cross Site Request Forgery (CSRF) | 1 |
SULly | Cross Site Request Forgery (CSRF) | 1 |
Support SVG | Cross Site Scripting (XSS) | 1 |
Simple Video Directory | Cross Site Scripting (XSS) | 1 |
WP Announcement | Cross Site Scripting (XSS) | 1 |
Seraphinite Accelerator (Full, premium) | Cross Site Request Forgery (CSRF) | 1 |
WP eStore | Cross Site Scripting (XSS) | 2 |
WP eMember | Cross Site Scripting (XSS) | 2 |
Affiliate Manager | Cross Site Scripting (XSS) | 2 |
WP eMember | Cross Site Scripting (XSS) | 2 |
WP eMember | Cross Site Scripting (XSS) | 2 |
Swift Framework Page Builder | Cross Site Scripting (XSS) | 2 |
Light Poll | Cross Site Request Forgery (CSRF) | 1 |
WP eStore | Cross Site Request Forgery (CSRF) | 1 |
Affiliate Manager | Cross Site Request Forgery (CSRF) | 1 |
WP eMember | Arbitrary File Upload | 1 |
WP eMember | Cross Site Request Forgery (CSRF) | 1 |
WP eMember | Cross Site Request Forgery (CSRF) | 1 |
EventON | Cross Site Scripting (XSS) | 1 |
Laposta | Sensitive Data Exposure | 1 |
Swift Framework Page Builder | Cross Site Scripting (XSS) | 1 |
Event post | Cross Site Request Forgery (CSRF) | 1 |
FormFlow | Cross Site Scripting (XSS) | 1 |
Payflex Payment Gateway | Broken Access Control | 1 |
UltraAddons Elementor Lite | Cross Site Scripting (XSS) | 1 |