| Plugin name | Vulnerability | Patch Priority score |
| EmbedPress | Broken Access Control | 2 |
| YITH WooCommerce Ajax Product Filter | Cross Site Scripting (XSS) | 2 |
| Brizy – Page Builder | Broken Access Control | 1 |
| Matomo Analytics | Cross Site Request Forgery (CSRF) | 1 |
| Event Tickets | Cross Site Request Forgery (CSRF) | 1 |
| OnePress | Cross Site Scripting (XSS) | 1 |
| Tutor LMS | Cross Site Scripting (XSS) | 1 |
| Auto Featured Image (Auto Post Thumbnail) | Broken Access Control | 1 |
| WP RSS Aggregator | Broken Access Control | 1 |
| Phlox Portfolio | Cross Site Scripting (XSS) | 1 |
| Image Hover Effects – Elementor Addon | Cross Site Scripting (XSS) | 1 |
| Ultimate Blocks – Gutenberg Blocks Plugin | Cross Site Scripting (XSS) | 1 |
| Internal Link Juicer: SEO Auto Linker for WordPress | Cross Site Request Forgery (CSRF) | 1 |
| Ditty | Cross Site Scripting (XSS) | 1 |
| PowerPress Podcasting | Cross Site Scripting (XSS) | 1 |
| Social Media Widget | Cross Site Scripting (XSS) | 1 |
| Qi Blocks | Cross Site Scripting (XSS) | 1 |
| Quiz And Survey Master | Cross Site Scripting (XSS) | 1 |
| Index WP MySQL For Speed | Cross Site Scripting (XSS) | 2 |
| FULL Customer | Cross Site Scripting (XSS) | 2 |
| Seriously Simple Podcasting | Cross Site Scripting (XSS) | 1 |
| WP Popups | Full Path Disclosure (FPD) | 1 |
| Master Addons for Elementor | Cross Site Scripting (XSS) | 1 |
| Team Members | Cross Site Scripting (XSS) | 1 |
| Backup and Staging by WP Time Capsule | Privilege Escalation | 4 |
| Form Vibes – Database Manager for Forms | SQL Injection | 3 |
| TeraWallet – For WooCommerce | SQL Injection | 3 |
| Login by Auth0 | Cross Site Scripting (XSS) | 2 |
| WP Event Manager | Cross Site Scripting (XSS) | 1 |
| WordPress File Upload | Directory Traversal | 1 |
| User Submitted Posts | Cross Site Scripting (XSS) | 1 |
| Giveaways and Contests by RafflePress | Cross Site Scripting (XSS) | 1 |
| Image Photo Gallery Final Tiles Grid | Cross Site Scripting (XSS) | 1 |
| Wholesale Suite | Broken Access Control | 1 |
| Secure Copy Content Protection and Content Locking | Cross Site Scripting (XSS) | 1 |
| Slider by 10Web | Cross Site Scripting (XSS) | 1 |
| Branda | Full Path Disclosure (FPD) | 1 |
| Meks Smart Author Widget | Cross Site Scripting (XSS) | 1 |
| SmartCrawl WordPress SEO checker, SEO analyzer, SEO optimizer | Full Path Disclosure (FPD) | 1 |
| MP3 Audio Player for Music, Radio & Podcast by Sonaar | Cross Site Scripting (XSS) | 1 |
| WP Accessibility Helper (WAH) | Broken Access Control | 1 |
| SmartMag | Multiple Vulnerabilities | 1 |
| WP Photo Album Plus | Cross Site Scripting (XSS) | 2 |
| Link Library | Cross Site Scripting (XSS) | 2 |
| Goftino | Cross Site Scripting (XSS) | 2 |
| XCloner Backup, Restore and Migrate | Sensitive Data Exposure | 1 |
| SchedulePress | Sensitive Data Exposure | 1 |
| Shortcodes Ultimate Pro | Cross Site Scripting (XSS) | 1 |
| Product Enquiry for WooCommerce | Cross Site Scripting (XSS) | 1 |
| Packlink PRO shipping module | Broken Access Control | 1 |
| Metorik – Reports & Email Automation for WooCommerce | Cross Site Request Forgery (CSRF) | 1 |
| ReCaptcha Integration for WordPress | Cross Site Scripting (XSS) | 1 |
| WP Travel Engine | Cross Site Scripting (XSS) | 1 |
| BuddyBoss Theme | Cross Site Request Forgery (CSRF) | 1 |
| Gum Elementor Addon | Cross Site Scripting (XSS) | 1 |
| Simple Post Notes | Cross Site Scripting (XSS) | 1 |
| If-So Dynamic Content Personalization | Cross Site Scripting (XSS) | 2 |
| If-So Dynamic Content Personalization | Cross Site Scripting (XSS) | 1 |
| JSON Content Importer | Server Side Request Forgery (SSRF) | 1 |
| WP ERP | SQL Injection | 1 |
| Plugin Notes Plus | Cross Site Scripting (XSS) | 1 |
| iPanorama 360 WordPress Virtual Tour Builder | Broken Access Control | 1 |
| ProfileGrid | Insecure Direct Object References (IDOR) | 1 |
| Jobmonster | Arbitrary File Deletion | 4 |
| Jobmonster | Privilege Escalation | 4 |
| Advanced post slider | Cross Site Scripting (XSS) | 1 |
| Post Layouts for Gutenberg | Cross Site Scripting (XSS) | 1 |
| InstaWP Connect | Privilege Escalation | 4 |
| Plum: Spin Wheel & Email Pop-up | Cross Site Scripting (XSS) | 3 |
| WP QuickLaTeX | Cross Site Scripting (XSS) | 1 |
| WP Links Page | Broken Access Control | 1 |
| Send Users Email | Sensitive Data Exposure | 1 |
| Plum: Spin Wheel & Email Pop-up | Broken Access Control | 1 |
| Magical Addons For Elementor | Server Side Request Forgery (SSRF) | 1 |
| Magical Addons For Elementor | Cross Site Scripting (XSS) | 1 |
| Fusion | Cross Site Scripting (XSS) | 1 |
| MStore API | Broken Authentication | 4 |
| Zoho Campaigns | Cross Site Scripting (XSS) | 2 |
| Zoho CRM Lead Magnet | Cross Site Scripting (XSS) | 2 |
| CM On Demand Search And Replace | Cross Site Request Forgery (CSRF) | 1 |
| Watu Quiz | Cross Site Scripting (XSS) | 1 |
| Google Adsense & Banner Ads by AdsforWP | Cross Site Request Forgery (CSRF) | 1 |
| ElementInvader Addons for Elementor | Cross Site Scripting (XSS) | 1 |
| VikRentCar | Cross Site Request Forgery (CSRF) | 1 |
| Arkhe Blocks | Cross Site Scripting (XSS) | 1 |
| Magical Posts Display – Elementor & Gutenberg Posts Blocks | Cross Site Scripting (XSS) | 1 |
| Point | Cross Site Request Forgery (CSRF) | 1 |
| WP2Speed Faster | Sensitive Data Exposure | 1 |
| Generate PDF using Contact Form 7 | Cross Site Request Forgery (CSRF) | 1 |
| Woocommerce OpenPos | Arbitrary File Deletion | 4 |
| MakeStories (for Google Web Stories) | Arbitrary File Download | 3 |
| Woocommerce OpenPos | Broken Access Control | 3 |
| Woocommerce OpenPos | SQL Injection | 3 |
| Insert or Embed Articulate Content into WordPress | Arbitrary File Upload | 2 |
| Simple Responsive Slider | Cross Site Scripting (XSS) | 2 |
| AForms | Sensitive Data Exposure | 1 |
| Typebot | Cross Site Scripting (XSS) | 1 |
| HitPay Payment Gateway for WooCommerce | Sensitive Data Exposure | 1 |
| Realtyna Organic IDX plugin | Arbitrary File Upload | 1 |
| Meks Video Importer | Broken Access Control | 1 |
| Events Calendar for Google | Local File Inclusion | 1 |
| Wallet System for WooCommerce | Sensitive Data Exposure | 1 |
| Spiffy Calendar | SQL Injection | 1 |
| Recipe Maker For Your Food Blog from Zip Recipes | Sensitive Data Exposure | 1 |
| Cliengo – Chatbot | Cross Site Request Forgery (CSRF) | 1 |
| Timeline Module for Beaver Builder | Cross Site Scripting (XSS) | 1 |
| ConeBlog – WordPress Blog Widgets | Cross Site Scripting (XSS) | 1 |
| JSON API User | Privilege Escalation | 4 |
| EazyDocs | Broken Access Control | 2 |
| Moloni | Cross Site Scripting (XSS) | 2 |
| AdPush | Cross Site Scripting (XSS) | 2 |
| ARForms Form Builder | Cross Site Scripting (XSS) | 2 |
| Web and WooCommerce Addons for WPBakery Builder | Broken Access Control | 1 |
| Glossary | Sensitive Data Exposure | 1 |
| SVG Block | Cross Site Scripting (XSS) | 1 |
| Popularis Verse | Cross Site Request Forgery (CSRF) | 1 |
| EleForms | Broken Access Control | 1 |
| Change From Email | Cross Site Scripting (XSS) | 1 |
| EazyDocs | Cross Site Scripting (XSS) | 1 |
| Download Button for Elementor | Cross Site Scripting (XSS) | 1 |
| ExS Widgets | Local File Inclusion | 1 |
| WP Event Aggregator | Cross Site Scripting (XSS) | 1 |
| Product Delivery Date for WooCommerce – Lite | Broken Access Control | 1 |
| SKT Skill Bar | Cross Site Scripting (XSS) | 1 |
| Simple Popup | Cross Site Scripting (XSS) | 1 |
| SlingBlocks – Gutenberg Blocks by FunnelKit (Formerly WooFunnels) | Cross Site Scripting (XSS) | 1 |
| Calendar.online / Kalender.digital | Cross Site Scripting (XSS) | 1 |
| codoc | Cross Site Scripting (XSS) | 1 |
| Caxton – Create Pro page layouts in Gutenberg | Cross Site Scripting (XSS) | 1 |
| Featured Image Generator | Broken Access Control | 1 |
| Chained Quiz | Broken Access Control | 1 |
| WP User Switch | Privilege Escalation | 4 |
| Event post | Local File Inclusion | 3 |
| Product Designer | Arbitrary Content Deletion | 3 |
| PayPlus Payment Gateway | SQL Injection | 3 |
| Import Spreadsheets from Microsoft Excel | Arbitrary File Upload | 2 |
| Seraphinite Post .DOCX Source | Server Side Request Forgery (SSRF) | 2 |
| Booking Ultra Pro | Local File Inclusion | 2 |
| WPCS | Content Injection | 2 |
| WooCommerce Report | Cross Site Scripting (XSS) | 2 |
| Appmaker – Convert WooCommerce to Android & iOS Native Mobile Apps | Cross Site Scripting (XSS) | 2 |
| Multisite Content Copier/Updater | Cross Site Scripting (XSS) | 2 |
| WP GoToWebinar | Cross Site Scripting (XSS) | 2 |
| WooCommerce Predictive Search | Cross Site Scripting (XSS) | 2 |
| MBE eShip | Cross Site Scripting (XSS) | 2 |
| TOCHAT.BE | Cross Site Scripting (XSS) | 2 |
| CM Email Registration Blacklist and Whitelist | Cross Site Request Forgery (CSRF) | 1 |
| Oceanic | Cross Site Request Forgery (CSRF) | 1 |
| i-transform | Cross Site Request Forgery (CSRF) | 1 |
| Zephyr Project Manager | Sensitive Data Exposure | 1 |
| Quotes And Tips | Arbitrary File Upload | 1 |
| WappPress | Server Side Request Forgery (SSRF) | 1 |
| Coming Soon | Sensitive Data Exposure | 1 |
| DirectoryPress | SQL Injection | 1 |
| Taggbox | Cross Site Request Forgery (CSRF) | 1 |
| Animated Rotating Words | Cross Site Request Forgery (CSRF) | 1 |
| Olive One Click Demo Import | Sensitive Data Exposure | 1 |
| MBE eShip | Sensitive Data Exposure | 1 |
| Amazing Hover Effects | Cross Site Scripting (XSS) | 1 |
| ReDi Restaurant Reservation | Broken Access Control | 1 |
| Patricia Blog | Cross Site Request Forgery (CSRF) | 1 |
| i-amaze | Cross Site Request Forgery (CSRF) | 1 |
| MBE eShip | Cross Site Request Forgery (CSRF) | 1 |
| Seraphinite Post .DOCX Source | Broken Access Control | 1 |
| WP Fast Total Search | Broken Access Control | 1 |
| GD Rating System | Local File Inclusion | 1 |
| WordPress Team Manager | Local File Inclusion | 1 |
| Academy LMS | Broken Access Control | 1 |
| Sirv | Broken Access Control | 1 |
| WP GoToWebinar | Broken Access Control | 1 |
| Sky Addons for Elementor | Cross Site Scripting (XSS) | 1 |
| FancyPost – Best Ultimate Post Block, Post Grid, Layouts, Carousel, Slider For Gutenberg & Elementor | Cross Site Scripting (XSS) | 1 |
| Animated Typed JS Shortcode | Cross Site Scripting (XSS) | 1 |
| REVIEWS.io | Cross Site Scripting (XSS) | 1 |
| Booking Ultra Pro | Cross Site Scripting (XSS) | 1 |
| SKT Addons for Elementor | Cross Site Scripting (XSS) | 1 |
| CodePen Embedded Pens Shortcode | Cross Site Scripting (XSS) | 1 |
| Power BI Embedded for WordPress | Cross Site Scripting (XSS) | 1 |
| Bradmax Player | Cross Site Scripting (XSS) | 1 |
| GutSlider – All in One Block Slider | Cross Site Scripting (XSS) | 1 |
| Responsive Mobile | Cross Site Scripting (XSS) | 1 |
| WPBITS Addons For Elementor Page Builder | Cross Site Scripting (XSS) | 1 |
| Gravity Forms: Multiple Form Instances | Full Path Disclosure (FPD) | 1 |
| Patricia Lite | Cross Site Request Forgery (CSRF) | 1 |
| Tabs For WPBakery Page Builder | Cross Site Scripting (XSS) | 1 |
| Barcode Scanner with Inventory & Order Manager | SQL Injection | 3 |
| BerqWP | Server Side Request Forgery (SSRF) | 2 |
| SociallyViral | Cross Site Request Forgery (CSRF) | 1 |
| User Activity Log Pro | Broken Access Control | 2 |
| Admin Dashboard RSS Feed | Cross Site Scripting (XSS) | 1 |
| Job Board Manager | Cross Site Scripting (XSS) | 2 |
| Contact Form 7 Summary and Print | Cross Site Request Forgery (CSRF) | 1 |
| Master Popups | Cross Site Scripting (XSS) | 1 |
| Tournamatch | Cross Site Scripting (XSS) | 2 |
| Tournamatch | Cross Site Scripting (XSS) | 1 |
| Smart Image Gallery | Cross Site Request Forgery (CSRF) | 1 |
| Bug Library | Remote Code Execution (RCE) | 4 |
| Uncanny Automator Pro | Cross Site Scripting (XSS) | 2 |
| Affiliate Manager | Cross Site Request Forgery (CSRF) | 1 |
| Embed Peertube Playlist | Cross Site Scripting (XSS) | 1 |
| Website Content in Page or Post | Cross Site Scripting (XSS) | 1 |
| Hostel | Cross Site Scripting (XSS) | 2 |
| OpenPGP Form Encryption | Cross Site Scripting (XSS) | 1 |
| WP Total Branding | Cross Site Scripting (XSS) | 1 |
| SULly | Cross Site Scripting (XSS) | 2 |
| counterpoint | Cross Site Scripting (XSS) | 2 |
| SULly | Cross Site Scripting (XSS) | 1 |
| SULly | Cross Site Request Forgery (CSRF) | 1 |
| SULly | Cross Site Request Forgery (CSRF) | 1 |
| Support SVG | Cross Site Scripting (XSS) | 1 |
| Simple Video Directory | Cross Site Scripting (XSS) | 1 |
| WP Announcement | Cross Site Scripting (XSS) | 1 |
| Seraphinite Accelerator (Full, premium) | Cross Site Request Forgery (CSRF) | 1 |
| WP eStore | Cross Site Scripting (XSS) | 2 |
| WP eMember | Cross Site Scripting (XSS) | 2 |
| Affiliate Manager | Cross Site Scripting (XSS) | 2 |
| WP eMember | Cross Site Scripting (XSS) | 2 |
| WP eMember | Cross Site Scripting (XSS) | 2 |
| Swift Framework Page Builder | Cross Site Scripting (XSS) | 2 |
| Light Poll | Cross Site Request Forgery (CSRF) | 1 |
| WP eStore | Cross Site Request Forgery (CSRF) | 1 |
| Affiliate Manager | Cross Site Request Forgery (CSRF) | 1 |
| WP eMember | Arbitrary File Upload | 1 |
| WP eMember | Cross Site Request Forgery (CSRF) | 1 |
| WP eMember | Cross Site Request Forgery (CSRF) | 1 |
| EventON | Cross Site Scripting (XSS) | 1 |
| Laposta | Sensitive Data Exposure | 1 |
| Swift Framework Page Builder | Cross Site Scripting (XSS) | 1 |
| Event post | Cross Site Request Forgery (CSRF) | 1 |
| FormFlow | Cross Site Scripting (XSS) | 1 |
| Payflex Payment Gateway | Broken Access Control | 1 |
| UltraAddons Elementor Lite | Cross Site Scripting (XSS) | 1 |