Pricing
Solutions
WordPress security
Instantly fix and mitigate vulnerabilities
Plugin auditing
Paid auditing for WordPress vendors
Managed VDP
Start a security program for your plugins
Bug Bounty
Join the community and earn bounties
Enterprise API
At scale monitoring and vPatching for hosts
Vulnerability database
The latest WordPress security intelligence
Login
Start trial
Awesome Support
awesomesupport
Developer
6.3.6
Latest version
8,000
Installations
6 days ago
Last updated
WordPress Plugin
No VDP
See changelog
Claim ownership
Report vulnerability
Vulnerabilities
Vulnerability history
1 present
23 fixed
11 Mitigation rules
Deserialization of untrusted data vulnerability
<= 6.3.5
Sep 22, 2025
Sensitive Data Exposure vulnerability
<= 6.3.6
Aug 14, 2025
Unauthenticated Sensitive Information Exposure Through Unprotected Directory vulnerability
<= 6.3.1
Mar 31, 2025
Broken Access Control vulnerability
<= 6.3.1
Dec 11, 2024
Broken Access Control vulnerability
<= 6.1.7
Jun 6, 2024
Broken Access Control vulnerability
<= 6.1.7
Mar 29, 2024
Authenticated (Subscriber+) SQL Injection vulnerability
<= 6.1.7
Feb 12, 2024
Broken Access Control vulnerability
<= 6.1.6
Jan 31, 2024
Cross Site Request Forgery (CSRF) vulnerability
<= 6.1.5
Dec 27, 2023
Broken Access Control vulnerability
<= 6.1.5
Dec 27, 2023
Broken Access Control vulnerability
<= 6.1.7
Dec 7, 2023
Broken Access Control + CSRF vulnerability
<= 6.1.10
Dec 4, 2023
Broken Access control vulnerability
<= 6.1.4
Nov 23, 2023
Cross Site Request Forgery (CSRF) vulnerability
<= 6.1.4
Nov 23, 2023
Submitter+ Arbitrary File Deletion vulnerability
< 6.1.5
Nov 7, 2023
Reflected Cross-Site Scripting vulnerability
< 6.1.5
Nov 7, 2023
Insufficient permission check in wpas_edit_reply vulnerability
< 6.1.5
Nov 7, 2023
Auth. Arbitrary Exported Tickets Download vulnerability
<= 6.1.1
Nov 7, 2022
Multiple Authenticated Stored Cross-Site Scripting (XSS) vulnerabilities
<= 6.0.7
Sep 14, 2022
Multiple Authenticated Reflected Cross-Site Scripting (XSS) vulnerabilities
<= 6.0.6
Nov 26, 2021
Reflected Cross-Site Scripting (XSS) vulnerability
<= 6.0.8
Aug 9, 2021
Stored Cross-Site Scripting (XSS) vulnerability
<= 5.8.2
Jan 6, 2020
Authenticated Arbitrary File Deletion Vulnerability
<= 4.3.1
Oct 23, 2017
Authenticated Arbitrary File Viewing Vulnerability
<= 4.3.1
Oct 23, 2017