Pricing
Solutions
WordPress security
Instantly fix and mitigate vulnerabilities
Plugin auditing
Paid auditing for WordPress vendors
Managed VDP
Start a security program for your plugins
Bug Bounty
Join the community and earn bounties
Enterprise API
At scale monitoring and vPatching for hosts
Vulnerability database
The latest WordPress security intelligence
Login
Start trial
WP Statistics
VeronaLabs
Developer
14.15.6
Latest version
600,000
Installations
Nov 9, 2025
Last updated
WordPress Plugin
Active VDP
Report vulnerability
Vulnerabilities
Security Policy
Security Contributors
Vulnerability history
0 present
28 fixed
12 Mitigation rules
Unauthenticated Stored Cross-Site Scripting via User-Agent Header vulnerability
<= 14.15.4
Sep 27, 2025
Broken Access Control Vulnerability
<= 14.15
Aug 14, 2025
Missing Authorization to Authenticated (Subscriber+) Arbitrary Plugin Settings Update vulnerability
<= 14.13.3
Apr 29, 2025
Unauthenticated Stored Cross-Site Scripting vulnerability
<= 14.5
Mar 12, 2024
Admin+ SQL Injection vulnerability
< 14.0
Mar 28, 2023
Multiple Authenticated SQL Injection vulnerabilities
<= 13.2.10
Jan 31, 2023
Authenticated SQLi vulnerability
< 13.2.9
Dec 27, 2022
Authenticated Stored Cross-Site Scripting (XSS) vulnerability
<= 13.2.1
May 24, 2022
Reflected Cross-Site Scripting (XSS) vulnerability
<= 13.2.1
May 10, 2022
Unauthenticated Stored Cross-Site Scripting (XSS) vulnerability
<= 13.1.5
Feb 17, 2022
Unauthenticated Stored Cross-Site Scripting (XSS) vulnerability
<= 13.1.5
Feb 17, 2022
Unauthenticated Stored Cross-Site Scripting (XSS) vulnerability
<= 13.1.5
Feb 17, 2022
Unauthenticated Blind SQL Injection (SQLi) vulnerability
<= 13.1.5
Feb 16, 2022
Unauthenticated Blind SQL Injection (SQLi) vulnerability
<= 13.1.5
Feb 16, 2022
Unauthenticated Blind SQL Injection (SQLi) via IP vulnerability
<= 13.1.5
Feb 16, 2022
Unauthenticated SQL Injection vulnerability
<= 13.1.4
Feb 10, 2022
Unauthenticated Time-Based Blind SQL Injection (SQLi) vulnerability
<= 13.0.7
May 18, 2021
Unauthenticated Stored Cross-Site Scripting (XSS) vulnerability
<= 12.6.6.1
Jul 4, 2019
Authenticated Stored Cross-Site Scripting (XSS) vulnerability
<= 12.6.5
Jun 12, 2019
Cross-Site Scripting (XSS) vulnerability
<= 12.6.3
Apr 24, 2019
Authenticated SQL Injection vulnerability
<= 12.0.7
Jul 1, 2017
Reflected Cross-Site Scripting (XSS) vulnerability
<= 12.0.5
Apr 28, 2017
SQL Injection
<= 9.4
Nov 22, 2015
Cross Site Scripting
<= 9.5.1
Aug 10, 2015
Cross Site Scripting
<= 2.2.4
Jun 25, 2015
Stored & Reflected XSS
<= 8.3
May 15, 2015
Stored XSS
<= 8.4
May 15, 2015
Stored Cross Site Scripting
<= 9.1.2
May 15, 2015