Pricing
Solutions
WordPress security
Instantly fix and mitigate vulnerabilities
Plugin auditing
Paid auditing for WordPress vendors
Managed VDP
Start a security program for your plugins
Bug Bounty
Join the community and earn bounties
Enterprise API
At scale monitoring and vPatching for hosts
Vulnerability database
The latest WordPress security intelligence
Login
Start trial
Ultimate Member
Ultimate Member
Developer
2.10.6
Latest version
200,000
Installations
Oct 2, 2025
Last updated
WordPress Plugin
Active VDP
Report vulnerability
Vulnerabilities
Security Policy
Security Contributors
Vulnerability history
0 present
36 fixed
12 Mitigation rules
Arbitrary Function Call vulnerability
<= 2.10.3
May 7, 2025
Unauthenticated Blind SQL Injection vulnerability
<= 2.10.1
Apr 17, 2025
Unauthenticated SQL Injection via search Parameter vulnerability
<= 2.10.0
Mar 4, 2025
Authenticated SQL Injection vulnerability
<= 2.9.2
Feb 20, 2025
Information Exposure vulnerability
<= 2.9.1
Jan 17, 2025
Unauthenticated SQL Injection vulnerability
<= 2.9.1
Jan 17, 2025
Missing Authorization to Authenticated (Subscriber+) Arbitrary User Profile Picture Update vulnerability
<= 2.8.9
Nov 21, 2024
Cross-Site Request Forgery to Membership Status Change vulnerability
<= 2.8.6
Oct 4, 2024
Authenticated (Contributor+) Stored Cross-Site Scripting vulnerability
<= 2.8.6
Oct 4, 2024
Authenticated (Subscriber+) Stored Cross-Site Scripting vulnerability
<= 2.8.4
Apr 15, 2024
Unauthenticated Stored Cross-Site Scripting vulnerability
<= 2.8.3
Mar 8, 2024
Unauthenticated SQL Injection vulnerability
2.1.3-2.8.2
Feb 23, 2024
Cross-Site Request Forgery vulnerability
<= 2.6.8
Aug 9, 2023
Unauthenticated Privilege Escalation
<= 2.6.6
Jun 29, 2023
Cross Site Request Forgery (CSRF) vulnerability
<= 2.6.0
Jun 22, 2023
Auth. Directory Traversal vulnerability
<= 2.5.0
Oct 28, 2022
Auth. Directory Traversal vulnerability
<= 2.5.0
Oct 28, 2022
Auth. Remote Code Execution vulnerability
<= 2.5.0
Oct 28, 2022
Auth. Limited Remote Code Execution vulnerability
<= 2.5.0
Oct 28, 2022
Authenticated Stored Cross-Site Scripting (XSS) vulnerability
<= 2.3.2
Jun 2, 2022
Open Redirect vulnerability
<= 2.3.1
May 1, 2022
Authenticated Reflected Cross-Site Scripting (XSS) vulnerability
<= 2.1.19
May 7, 2021
Unauthenticated/Authenticated Privilege Escalation
<= 2.1.11
Nov 9, 2020
Insecure Direct Object Reference (IDOR) vulnerability
<= 2.1.2
Jan 22, 2020
Cross-Site Scripting (XSS) vulnerability
<= 2.0.53
Aug 14, 2019
Cross-Site Request Forgery (CSRF) and Stored Cross-Site Scripting (XSS) vulnerabilities
<= 2.0.51
Jul 13, 2019
Multiple vulnerabilities
<= 2.0.45
May 16, 2019
Cross-Site Request Forgery (CSRF) vulnerability
<= 2.0.39
Apr 4, 2019
Cross-Site Request Forgery (CSRF) vulnerability
<= 2.0.32
Nov 27, 2018
Authenticated Cross-Site Scripting (XSS) vulnerability
<= 2.0.21
Aug 28, 2018
Unauthenticated Arbitrary File Upload vulnerability
<= 2.0.21
Aug 9, 2018
Unauthenticated Change Passwords
<= 1.3.75
Dec 6, 2016
Local File Inclusion
<= 1.3.64
Jul 10, 2016
Reflected Cross Site Scripting
<= 1.3.28
Dec 2, 2015
Cross Site Scripting
<= 1.2.994
Jun 18, 2015
Multiple Vulnerabilities
<= 1.0.78
Mar 16, 2015