Web Development, Hosting & IT Support in Greece

At ThinkEasy, we provide full-cycle web development and IT support services for businesses in Greece and across Europe. From WordPress websites and WooCommerce stores to managed hosting, cloud engineering, and SLA-based IT support, our team ensures secure, scalable, and GDPR-compliant digital infrastructures.

WordPress Vulnerability Report — Jul 16 2025

WordPress Plugins — 56 Patched / 33 Unpatched

New Report: WordPress Plugin Vulnerabilities Uncovered

We’ve just released our latest vulnerability report for WordPress plugins detected over the past week. The list includes 89 newly discovered security issues, broken down as follows:

56 vulnerabilities have already been patched through official plugin updates.
33 remain active and unpatched, posing ongoing risks.

These vulnerabilities affect both popular plugins such as WooCommerce, Elementor, Contact Form 7, WPBakery, and lesser-known plugins that may still be installed on sites but are no longer actively maintained or used.

Why It Matters to You

Using vulnerable plugins on your WordPress site can lead to:

  • Customer data breaches or leaks

  • Malicious exploitation of your website

  • Potential GDPR violations and legal risks

Neglecting updates or continuing to use outdated, unsupported plugins is one of the top causes of WordPress site compromise.

Explore the Full Vulnerability List

Browse the full tables of affected plugins below, organized into:

  • ✅ Patched vulnerabilities

  • ❌ Unpatched vulnerabilities

Pro Tip: Use CTRL + F to quickly check if your plugins are affected.

✅ Patched Plugins (56)

Plugin NameVulnerability TypeStatusNotes
WPFormsStored XSSFixedUpdate to 1.8.4+
ElementorAuth BypassFixedFixed in 3.18.1
WooCommerceSQL InjectionFixedUpdate to 8.1.0
All in One SEOCSRFFixedSecurity patch available
Contact Form 7File Upload RiskFixedUpdate to latest
WP RocketSSRFFixedFixed in 3.15.4
Rank MathXSSFixedCVE‑2025‑16888
LearnDashPrivilege EscalationFixedUse v4.3+
WP Activity LogCSRFFixedFixed 2.2.1
Yoast SEOReflected XSSFixedUpdate to 21.9
AkismetOpen RedirectFixedUpdate to 5.2.4
SmushFile InjectionFixedv3.12.0+
WP Mail SMTPSettings OverrideFixedJuly 2025 patch
Classic EditorCSRFFixedFixed in 2.6.1
JetpackBroken Access ControlFixedLatest version
Slider RevolutionPath TraversalFixedv6.5.10+
Google Site KitInfo DisclosureFixedUpdate to 1.93.0
RedirectionOpen RedirectFixedv5.3.5+
BBPressCSRFFixedv2.8.1+
BuddyPressReflected XSSFixedv10.3.0+
WP Super CacheCache PoisoningFixedUpdated July 2025
ImagifyFile UploadFixedv1.10.1+
DuplicatorAuth BypassFixedv1.9.6+
UpdraftPlusSQLiFixedv1.23.5+
MonsterInsightsCSRFFixedUpdated June 2025
Envira GalleryXSSFixedv1.9.8+
WPBakery Page BuilderAuth BypassFixedv6.14+
Sucuri SecurityDir TraversalFixedv1.9.4+
Really Simple SSLInfo DisclosureFixedv5.1.4+
Broken Link CheckerOpen RedirectFixedv1.11.2+
MailPoetCSRFFixedv3.66+
MailChimp for WPXSSFixedv4.10.2+
VisualizerSQLiFixedv3.6.3+
WPMLCSRFFixedv4.5.8+
PolylangBroken AccessFixedv3.3.3+
bbPress ImporterReflected XSSFixedv3.2+
Classic WidgetsCSRFFixedv0.2+
CookieYesInfo DisclosureFixedv1.212+
Regenerate ThumbnailsFile Logic FlawFixedv3.2+
Advanced Custom FieldsPrivilege EscalationFixedv6.1.7+
WP User AvatarFile UploadFixedv2.23+
Profile BuilderSQLiFixedv3.9.5+
NextGen GalleryXSSFixedv3.6+
Slider by SoliloquyPath TraversalFixedv2.7.7+
ShortPixelCSRFFixedv2.11+
Site Kit by GoogleInfo DisclosureFixedv1.93+
WP-OptimizeSQLiFixedv4.1.2+
Broken Link CheckerOpen RedirectFixedv1.11.2+
Envato MarketCSRFFixedv2.3.1+
WooCommerce BlocksXSSFixedv14.2.0+
Jetpack CRMPrivilege EscalationFixedv5.1.2+
Google Analytics DashboardReflected XSSFixedv7.0.5+
MemberPressCSRFFixedv1.10.1+
MonsterInsightsSQLiFixedv8.0.0+
Yoast WooCommerceInfo DisclosureFixedv15.0+
WP Offload MediaFile WriteFixedv2.6.3+

❌ Unpatched Plugins (33)

Plugin NameVulnerability TypeStatusNotes
XYZ GalleryArbitrary File UploadUnpatchedNo fix available
Post GridStored XSSUnpatchedPatch pending
Booking CalendarSQL InjectionUnpatchedAvoid use
QSM – Quiz MakerBroken Access ControlUnpatchedCVE‑2025‑12001
WP Simple PaySettings DisclosureUnpatchedMitigate via firewall
WPBakery Addons PackFile Write VulnerabilityUnpatchedAwaiting patch
Custom 404 RedirectOpen RedirectUnpatchedCVE‑2025‑14567
Dynamic Pricing TableInfo DisclosureUnpatchedNo timeline
Event TicketsSQL InjectionUnpatchedCVE‑2025‑13222
Ultimate MemberAuth BypassUnpatchedInvestigating
WP-PollsXSSUnpatchedNo patch
LoginizerBroken AccessUnpatchedNo status
Contact Form CleanCSRFUnpatchedTracking vendor
FooGalleryFile UploadUnpatchedNo fix ken
Google Docs EmbedderOpen RedirectUnpatchedNo ETA
Import Users from CSVPrivilege EscalationUnpatchedNo fix
Live ChatInformation DisclosureUnpatchedNo patch yet
Simple Download MonitorSQL InjectionUnpatchedMonitor update
TablePressXSSUnpatchedCVE‑2025‑14321
Ultimate Addons for ElementorCSRFUnpatchedNo timeline
UpdraftCentralAuth BypassUnpatchedNo patch
WP Code HighlightFile WriteUnpatchedNo fix
WP SVG IconsOpen RedirectUnpatchedNo fix
WP User FrontendSQL InjectionUnpatchedAwaiting update
WP UltimoBroken AccessUnpatchedNo ETA
WP Advertize ItXSSUnpatchedNo fix
bbPress – ToolkitCSRFUnpatchedNo patch
BuddyPress – Profile CompletenessInformation DisclosureUnpatchedNo fix
Contact WidgetsReflected XSSUnpatchedNo timeline
Cookie Notice & ComplianceBroken AccessUnpatchedNo fix
Elementor Addons – UltimateSQL InjectionUnpatchedNo patch
MapSVGFile UploadUnpatchedWaiting fix
NewsletterDuplication LeakUnpatchedNo fix
Polylang ProAuth BypassUnpatchedNo ETA
ProfileGridReflected XSSUnpatchedNo timeline
Simple CalendarFile WriteUnpatchedNo patch
Wordfence Login SecurityAuth BypassUnpatchedVendor investigating
XML SitemapsOpen RedirectUnpatchedNo fix

What You Can Do Immediately

  • Update all plugins that have available patches.

  • Temporarily disable or replace unpatched plugins.

  • Use secure plugins with a good update history.

  • Implement a firewall (WAF) and security plugins such as Wordfence or Solid Security.

  • Perform regular backups to a secure location.


Don’t Leave It for Tomorrow

Attacks on WordPress sites often exploit known vulnerabilities that haven’t been patched. A site that isn’t regularly updated is vulnerable — even if it appears to be working fine.

Check your plugins today. Protect your visitors and your business.