If some of these WordPress plugins look familiar, you’re not imagining it. Repeat offenders and serious new risks fill the list, from privilege escalation to SQL injection. We also show how our rebuilt AI malware scanner uncovers hidden PHP threats others overlook.

This widely used plugin has a serious access control flaw, and it’s far from its first appearance in our reports. Updating it should be at the top of your list.

Unlimited Elements For Elementor (Free Widgets, Addons, Templates) Plugin
Broken Access Control; 9.3/10; Update to v2.0.23+; Recurring 18×

Editor Comment
It’s worth taking a few minutes each week to perform a sites review to catch issues early and wherever possible, use ShieldPRO’s auto-upgrade feature for vulnerable plugins.

These plugins are also worth a quick check, especially if you rely on any of them for SEO, image optimisation or login security. Most of the issues are XSS, and every one already has an update available.

WP 2FA Plugin
Broken Authentication; 7.5/10; Update to v4.1.0+

All In One SEO Pack Plugin
XSS; 7.1/10; Update to v5.0.2+; Recurring 5×

EWWW Image Optimizer Plugin
XSS; 7.1/10; Update to v8.8.0+; Recurring 6×

Smash Balloon Social Post Feed Plugin
XSS; 7.1/10; Update to v4.14.0+; Recurring 2×

Kubio AI Page Builder Plugin
XSS; 7.1/10; Update to v2.9.3+; Recurring 7×

WPC Smart Quick View for WooCommerce Plugin
XSS; 7.1/10; Update to v4.4.1+

Relevanssi Premium Plugin
XSS; 7.1/10; Update to v2.31.5+; Recurring 5×

Starter Templates Plugin
XSS; 6.5/10; Update to v4.7.8+; Recurring 6×

Presto Player Plugin
XSS; 6.5/10; Update to v4.5.3+; Recurring 4×

Premium Addons for Elementor Plugin
XSS; 6.5/10; Update to v4.11.110+; Recurring 7×

MetForm Plugin
Broken Access Control; 5.3/10; Update to v4.3.1+; Recurring 6×

Event Tickets Plugin
Broken Access Control; 4.3/10; Update to v5.30.0.1+; Recurring 12×

Editor Comment
It’s worth taking a few minutes each week to perform a sites review to catch issues early and wherever possible, use ShieldPRO’s auto-upgrade feature for vulnerable plugins.

These plugins have smaller user bases, but their flaws are among the most dangerous kind. If any of them run on your sites, don’t put off updating.

Ninja Forms File Uploads Extension Plugin
Arbitrary File Upload; 10/10; Update to v3.3.35+; Recurring 5×

Divi Membership Plugin
Privilege Escalation; 9.8/10; Update to v3.0.0+

DevKit Pro Plugin
Privilege Escalation; 9.8/10; Update to v2.3.1+

WPLMS Plugin
SQL Injection; 9.3/10; Update to v1.9.9.8.2+; Recurring 2×

OAuth Single Sign On – SSO (OAuth Client) Plugin
Bypass Vulnerability; 9.8/10; Update to v7.1.3+; Recurring 3×

WP Data Access Plugin
SQL Injection; 9.3/10; Update to v5.5.83+; Recurring 11×

Editor Comment
It’s worth taking a few minutes each week to perform a sites review to catch issues early and wherever possible, use ShieldPRO’s auto-upgrade feature for vulnerable plugins.

#4 – Our blog: Detect WordPress PHP Malware with 99% Accuracy

We’ve rebuilt AI-based malware scanner from the ground up. It catches PHP malware that signature scanners miss, and it stops flagging the clean files that waste your time. Fewer scares, fewer infections, and answers you can act on.

More Info →

Thanks for reading, and have a wonderful week!

Paul Goodchild
Shield Security for WordPress