Skip to content
Founder-led WordPress incident response and care Request an assessment
3zerodigital Request a Website Assessment

WordPress security records

WordPress Vulnerability Listing

Filter Production Feed records and inspect affected software, version ranges, severity, patch information and source attribution without opening separate UUID pages.

Dataset last synchronized: 2026-08-03 00:31:25 UTC

Clear filters

2 vulnerability records

MediumCVE-2025-49299

WebHotelier <= 1.9.2 - Authenticated (Contributor+) Stored Cross-Site Scripting

WebHotelier for WordPress: Currently marked unpatched

Affected versions: *-1.9.2

Vulnerability type: CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Affected software, patched versions and attribution

The WebHotelier plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.9.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

WebHotelier for WordPress

Affected versions: *-1.9.2

Patched versions: 1.10.0

Researcher credit: Peter Thaleikis

Applicable copyright and licence notices

This record contains material that is subject to copyright

Copyright 2012-2026 Defiant Inc.

Defiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.

Licence reference

This record contains material that is subject to copyright

Copyright 1999-2026 The MITRE Corporation

CVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.

Licence reference

Original Wordfence record
Published
June 5, 2025
CVSS
6.4
MediumCVE-2021-24435

Titan Framework <= (Various Versions) - Reflected Cross-Site Scripting

AMP extensions: Currently marked unpatchedVenture Event Manager: Currently marked unpatchedFlight Search Widget and Blocks: Currently marked unpatchedStars Menu: Currently marked unpatchedКнопка ЮMoney: Currently marked unpatchedDisable Image Right Click: Currently marked unpatchedSEO-Dashboard by gutewebsites.de: Currently marked unpatchedIcons with Links Widget: Currently marked unpatchedRequest Quote via Whatsapp for Woocommerce: Currently marked unpatchedWoosaleskit Bar: Currently marked unpatchedTR Easy Google Analytics: Currently marked unpatchedMedia Mirror: Currently marked unpatchedCustom Scrollbar Designer: Currently marked unpatchedPopup Modal For Youtube: Currently marked unpatchedFacebook Page Feed Timeline: Currently marked unpatchedWordPress Form Customizer | CF7 Customizer: Currently marked unpatchedExit Popup Show: Currently marked unpatchedBorder Loading Bar: Currently marked unpatchedCustom Text Selection Colors: Currently marked unpatchedEasy Google Map: Currently marked unpatchedSeatgeek Affiliate Tickets: Currently marked unpatchedTitan Framework: Currently marked unpatchedAd Blocker Notify Lite: Currently marked unpatchedAwesome Support – WordPress HelpDesk & Support Plugin: Currently marked unpatchedLive Chat for Fanpage: Currently marked unpatchedProduct Limited Time Availability Date for woocommerce: Currently marked unpatchedShare Posts To Email: Currently marked unpatchedEasy Gallery Slideshow: Currently marked unpatchedWP Mobile Menu – The Mobile-Friendly Responsive Menu: Currently marked unpatchedSticky Related Posts: Currently marked unpatchedICustomizer: Currently marked unpatchedCatchers Helpdesk and Ticket system for Support: Currently marked unpatchedWoocommerce Categories in gallery format: Currently marked unpatchedBootstrap Categories Gallery: Currently marked unpatchedTotal Sales For Woocommerce: Currently marked unpatchedShare Woocommerce to Email: Currently marked unpatchedEvents Shortcodes For The Events Calendar: Currently marked unpatchedSimple Behance Portfolio: Currently marked unpatchedbetteroptin: Currently marked unpatchedProject2App – Turn Your WordPress Site into an Android App: Currently marked unpatchedAoi Tori: Currently marked unpatchedStation Pro – Advanced Audio Streaming & Player for WordPress: Currently marked unpatchedEasy Justified Gallery: Currently marked unpatchedClinicalWP Core: Currently marked unpatchedWebHotelier for WordPress: Currently marked unpatched4k-icon-fonts-for-visual-composer: Currently marked unpatchedtcS3: Currently marked unpatchedW3SCloud Contact Form 7 to Zoho CRM: Currently marked unpatchedaffiliate-pro: Currently marked unpatched

Affected versions: *; [*, 3.2.5); *; *; [*, 2.4.0); *; *; *

Vulnerability type: CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Affected software, patched versions and attribution

The iframe-font-preview.php file of the titan-framework does not properly escape the font-weight and font-family GET parameters before outputting them back in an href attribute, leading to Reflected Cross-Site Scripting issues.

AMP extensions

Affected versions: *

Patched versions: Not supplied

Venture Event Manager

Affected versions: [*, 3.2.5)

Patched versions: 3.2.5

Flight Search Widget and Blocks

Affected versions: *

Patched versions: Not supplied

Stars Menu

Affected versions: *

Patched versions: Not supplied

Кнопка ЮMoney

Affected versions: [*, 2.4.0)

Patched versions: 2.4.0

Disable Image Right Click

Affected versions: *

Patched versions: Not supplied

SEO-Dashboard by gutewebsites.de

Affected versions: *

Patched versions: Not supplied

Icons with Links Widget

Affected versions: *

Patched versions: Not supplied

Request Quote via Whatsapp for Woocommerce

Affected versions: *

Patched versions: Not supplied

Woosaleskit Bar

Affected versions: *

Patched versions: Not supplied

TR Easy Google Analytics

Affected versions: *

Patched versions: Not supplied

Media Mirror

Affected versions: *

Patched versions: Not supplied

Custom Scrollbar Designer

Affected versions: *

Patched versions: Not supplied

Popup Modal For Youtube

Affected versions: *

Patched versions: Not supplied

Facebook Page Feed Timeline

Affected versions: *

Patched versions: Not supplied

WordPress Form Customizer | CF7 Customizer

Affected versions: *

Patched versions: Not supplied

Exit Popup Show

Affected versions: *

Patched versions: Not supplied

Border Loading Bar

Affected versions: *

Patched versions: Not supplied

Custom Text Selection Colors

Affected versions: *

Patched versions: Not supplied

Easy Google Map

Affected versions: *

Patched versions: Not supplied

Seatgeek Affiliate Tickets

Affected versions: *

Patched versions: Not supplied

Titan Framework

Affected versions: *

Patched versions: Not supplied

Ad Blocker Notify Lite

Affected versions: *

Patched versions: Not supplied

Awesome Support – WordPress HelpDesk & Support Plugin

Affected versions: *-6.0.10

Patched versions: 6.0.11

Live Chat for Fanpage

Affected versions: *-3.1.0

Patched versions: 3.1.1

Product Limited Time Availability Date for woocommerce

Affected versions: *

Patched versions: Not supplied

Share Posts To Email

Affected versions: *

Patched versions: Not supplied

Easy Gallery Slideshow

Affected versions: *

Patched versions: Not supplied

WP Mobile Menu – The Mobile-Friendly Responsive Menu

Affected versions: *-2.8.2.2

Patched versions: 2.8.2.3

Sticky Related Posts

Affected versions: *

Patched versions: Not supplied

ICustomizer

Affected versions: *-1.4.13

Patched versions: 1.5.0

Catchers Helpdesk and Ticket system for Support

Affected versions: *

Patched versions: Not supplied

Woocommerce Categories in gallery format

Affected versions: *

Patched versions: Not supplied

Bootstrap Categories Gallery

Affected versions: *

Patched versions: Not supplied

Total Sales For Woocommerce

Affected versions: *

Patched versions: Not supplied

Share Woocommerce to Email

Affected versions: *

Patched versions: Not supplied

Events Shortcodes For The Events Calendar

Affected versions: [*, 1.7.2)

Patched versions: 1.7.2

Simple Behance Portfolio

Affected versions: *

Patched versions: Not supplied

betteroptin

Affected versions: *

Patched versions: Not supplied

Project2App – Turn Your WordPress Site into an Android App

Affected versions: *

Patched versions: Not supplied

Aoi Tori

Affected versions: *

Patched versions: Not supplied

Station Pro – Advanced Audio Streaming & Player for WordPress

Affected versions: 2.2.1

Patched versions: 2.2.2

Easy Justified Gallery

Affected versions: *-1.1

Patched versions: 1.1.1

ClinicalWP Core

Affected versions: *

Patched versions: Not supplied

WebHotelier for WordPress

Affected versions: [*, 1.6.1)

Patched versions: 1.6.1

4k-icon-fonts-for-visual-composer

Affected versions: *

Patched versions: Not supplied

tcS3

Affected versions: *

Patched versions: Not supplied

W3SCloud Contact Form 7 to Zoho CRM

Affected versions: [*, 2.1.0)

Patched versions: 2.1.0

affiliate-pro

Affected versions: *

Patched versions: Not supplied

Researcher credit: iohex

Applicable copyright and licence notices

This record contains material that is subject to copyright

Copyright 2012-2026 Defiant Inc.

Defiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.

Licence reference

This record contains material that is subject to copyright

Copyright 1999-2026 The MITRE Corporation

CVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.

Licence reference

Original Wordfence record
Published
August 9, 2021
CVSS
6.1

Vulnerability data: Wordfence Intelligence. Analysis and practical guidance: 3Zero Digital.

Data Source, Attribution and Methodology

Production Feed records are aggregated without claiming discovery, exploitation or infection. Applicable source notices remain attached to individual records. Read the methodology.