Pricing
Solutions
WordPress security
Instantly fix and mitigate vulnerabilities
Plugin auditing
Paid auditing for WordPress vendors
Managed VDP
Start a security program for your plugins
Bug Bounty
Join the community and earn bounties
Enterprise API
At scale monitoring and vPatching for hosts
Vulnerability database
The latest WordPress security intelligence
Login
Start trial
Quiz And Survey Master
ExpressTech Systems
Developer
10.3.1
Latest version
40,000
Installations
7 days ago
Last updated
WordPress Plugin
Active VDP
Report vulnerability
Vulnerabilities
Security Policy
Security Contributors
Vulnerability history
0 present
41 fixed
12 Mitigation rules
PHP Object Injection Vulnerability
<= 10.2.5
Sep 3, 2025
Template Creation via CSRF vulnerability
< 10.2.3
Aug 14, 2025
SQL Injection Vulnerability
<= 10.2.4
Aug 14, 2025
Author+ Stored XSS vulnerability
< 9.2.1
Mar 25, 2025
Author+ Stored XSS vulnerability
< 9.1.3
Sep 23, 2024
Contributor+ Stored XSS vulnerability
< 9.1.1
Aug 26, 2024
Contributor+ Stored XSS vulnerability
< 9.1.0
Aug 5, 2024
Contributor+ Stored XSS vulnerability
< 9.0.5
Jul 11, 2024
Contributor+ Stored XSS vulnerability
< 9.0.2
Jul 1, 2024
Authenticated (Contributor+) SQL Injection vulnerability
<= 9.0.1
Jun 7, 2024
Cross Site Scripting (XSS) vulnerability
<= 8.2.2
Mar 13, 2024
Cross Site Request Forgery (CSRF) vulnerability
<= 8.1.18
Dec 27, 2023
Broken Access Control vulnerability
<= 8.1.16
Dec 27, 2023
Cross Site Scripting (XSS) vulnerability
<= 8.1.13
Nov 16, 2023
Cross-Site Request Forgery via 'display_results' vulnerability
<= 8.1.15
Sep 13, 2023
Contributor+ Stored XSS vulnerability
< 8.1.11
Jul 27, 2023
Broken Access Control vulnerability
<= 8.1.10
Jul 17, 2023
Unauthenticated SQL Injection vulnerability
<= 8.1.4
Apr 16, 2023
Cross Site Request Forgery (CSRF) vulnerability
<= 8.0.10
Feb 28, 2023
Unauthenticated Arbitrary Media Deletion vulnerability
<= 8.0.8
Feb 17, 2023
Cross Site Request Forgery (CSRF)
<= 8.0.7
Feb 12, 2023
Unauth. iFrame Injection vulnerability via Paragraph and Short Answer
<= 8.0.4
Nov 29, 2022
Improper Input Validation vulnerability
<= 8.0.4
Nov 29, 2022
Bypass vulnerability
<= 7.3.10
Oct 21, 2022
Sensitive Information Disclosure vulnerability
<= 7.3.10
Oct 21, 2022
Cross-Site Scripting (XSS) vulnerability
<= 7.3.10
Oct 21, 2022
Multiple Insecure direct object references (IDOR) vulnerabilities
<= 7.3.6
Oct 21, 2022
Multiple Auth. Stored Cross-Site Scripting (XSS) vulnerabilities
<= 7.3.4
Oct 21, 2022
Auth. SQL Injection (SQLi) vulnerability
<= 7.3.4
Oct 21, 2022
Auth. Reflected Cross-Site Scripting (XSS) vulnerability
<= 7.3.4
Oct 21, 2022
Auth. Stored Cross-Site Scripting (XSS) vulnerability
<= 7.3.4
Oct 21, 2022
Insecure direct object references (IDOR) vulnerability
<= 7.3.4
Sep 29, 2022
Stored Cross-Site Scripting (XSS) vulnerability
<= 7.3.1
Sep 13, 2021
Unauthenticated Stored Cross-Site Scripting (XSS) vulnerability
<= 7.1.18
Jun 3, 2021
Reflected Cross-Site Scripting (XSS) vulnerability
<= 7.1.17
May 31, 2021
Authenticated SQL injection (SQLi) vulnerability
<= 7.1.13
Mar 26, 2021
Unauthenticated Arbitrary File Upload vulnerability
<= 7.0.1
Aug 29, 2020
Authenticated Reflected Cross-Site Scripting (XSS) vulnerability
<= 6.3.4
Dec 15, 2019
Authenticated Cross-Site Scripting (XSS) vulnerability
<= 6.2.1
Mar 12, 2019
Multiple Vulnerabilities
<= 4.7.8
Dec 15, 2016
Blind SQL Injection
<= 4.4.2
Jul 16, 2015