| #401 | Themify Event Post | 25 | 397 | 143 | 3k+ | | | Output is not escaped |
| #402 | TrackShip for WooCommerce | 25 | 421 | 957 | 6k+ | | | Non-prefixed global variable |
| #403 | TranslatePress – Translate Multilingual sites with AI Translation | 25 | 452 | 1,541 | 400k+ | | | Non-prefixed hook name |
| #404 | Broadcast Live Video – Live Streaming : WebRTC, HLS, RTSP, RTMP | 25 | 298 | 1,010 | 500 | | | Request data is not unslashed |
| #405 | Webcomic | 25 | 593 | 308 | 600 | | | Output is not escaped |
| #406 | weForms – Easy Drag & Drop Contact Form Builder For WordPress | 25 | 916 | 450 | 10k+ | | | Output is not escaped |
| #407 | Product Table for WooCommerce | 25 | 183 | 896 | 5k+ | | | Non-prefixed global variable |
| #408 | Pay with Vipps and MobilePay for WooCommerce | 25 | 846 | 514 | 5k+ | | | Output is not escaped |
| #409 | HUSKY – Products Filter Professional for WooCommerce | 25 | | 1,895 | 90k+ | | | Non-prefixed global variable |
| #410 | Wordfence Login Security | 25 | 248 | 418 | 70k+ | | | Output is not escaped |
| #411 | Nested Pages | 25 | 674 | 560 | 90k+ | | | Non-prefixed global variable |
| #412 | WP Spell Check | 25 | 6 | 4,390 | 2k+ | | | Direct Query |
| #413 | YeeMail — Email Template Builder & Customizer | 25 | 606 | 222 | 600 | | | wp function not compatible with requires wp |
| #414 | Video Gallery – YouTube Gallery, Playlist & Video Grid | 25 | 275 | 1,070 | 2k+ | | | Non-prefixed hook name |
| #415 | AfterShip Tracking – All-In-One WooCommerce Order Tracking (Free plan available) | 26 | 286 | 291 | 8k+ | | | Text Domain Mismatch |
| #416 | Blog Floating Button | 26 | 705 | 240 | 9k+ | | | Output is not escaped |
| #417 | Charitable – Donation Plugin for WordPress – Fundraising with Recurring Donations & More | 26 | 97 | 270 | 10k+ | | | error log error log |
| #418 | Database for Contact Form 7, WPforms, Elementor forms | 26 | 317 | 489 | 60k+ | | | Non-prefixed global variable |
| #419 | Ditty – Responsive News Tickers, Sliders, and Lists | 26 | 561 | 484 | 30k+ | | | Output is not escaped |
| #420 | FG Drupal to WordPress | 26 | 275 | 100 | 700 | | | Unsafe printing function |
| #421 | JustTables – WooCommerce Product Table | 26 | 534 | 652 | 600 | | | Non-prefixed global variable |
| #422 | Klarna for WooCommerce | 26 | 284 | 507 | 30k+ | | | Dynamic hook name |
| #423 | Media File Renamer: Rename for better SEO (AI-Powered) | 26 | 148 | 170 | 40k+ | | | Direct Query |
| #424 | Barion Payment Gateway for WooCommerce | 26 | 71 | 221 | 6k+ | | | Non-prefixed global variable |
| #425 | RestaurantPress | 26 | 265 | 518 | 600 | | | Output is not escaped |
| #426 | Send Users Email – Email Subscribers, Email Marketing Newsletter | 26 | 188 | 415 | 5k+ | | | Non-prefixed global variable |
| #427 | Sliced Invoices – WordPress Invoice Plugin | 26 | 684 | 455 | 5k+ | | | Output is not escaped |
| #428 | Ultimate Reviews | 26 | 515 | 345 | 500 | | | Output is not escaped |
| #429 | User Submitted Posts – Enable Users to Submit Posts from the Front End | 26 | 699 | 396 | 10k+ | | | Text Domain Mismatch |
| #430 | WDesignKit – Elementor & Gutenberg Starter Templates, Patterns, Cloud Workspace & Widget Builder | 26 | 265 | 793 | 30k+ | | | Missing nonce verification |
| #431 | WPCOM Member | 26 | 432 | 638 | 1k+ | | | Non Singular String Literal Domain |
| #432 | Addon Elements for Elementor (formerly Elementor Addon Elements) | 27 | 4,065 | 103 | 90k+ | | | Text Domain Mismatch |
| #433 | Animation Addons for Elementor – GSAP Motion Elementor Addons & Website Templates | 27 | 8 | 550 | 10k+ | | | Non-prefixed namespace |
| #434 | Apollo13 Framework Extensions | 27 | 171 | 273 | 20k+ | | | Non-prefixed global variable |
| #435 | Contact Form Generator : Creative form builder for WordPress | 27 | 1,076 | 1,510 | 800 | | | Output is not escaped |
| #436 | Echo Knowledge Base – Documentation, FAQs, Chat & Smart Search | 27 | 289 | 751 | 10k+ | | | Output is not escaped |
| #437 | FG Joomla to WordPress | 27 | 278 | 101 | 7k+ | | | Unsafe printing function |
| #438 | Ray Enterprise Translation | 27 | 87 | 606 | 8k+ | | | Non-prefixed global variable |
| #439 | Memberful – Membership Plugin | 27 | 351 | 336 | 1k+ | | | Text Domain Mismatch |
| #440 | MLSImport – Download and synchronize real estate data from various MLS (Multiple Listing Services) | 27 | 154 | 551 | 5k+ | | | Non-prefixed global variable |
| #441 | Online Lesson Booking | 27 | 978 | 281 | 500 | | | Non Singular String Literal Domain |
| #442 | Pie Register – User Registration, Profiles & Content Restriction | 27 | | 1,779 | 1k+ | | | Non-prefixed global variable |
| #443 | Sign-up Sheets | 27 | 325 | 363 | 1k+ | | | Output is not escaped |
| #444 | Simple Event Planner | 27 | 149 | 346 | 1k+ | | | Non-prefixed global variable |
| #445 | Social Web Suite – Social Media Auto Post, Social Media Auto Publish | 27 | 74 | 164 | 500 | | | Non-prefixed global variable |
| #446 | ST Elementor Addons | 27 | 225 | 374 | 400 | | | Non-prefixed global variable |
| #447 | Orbit Fox: Duplicate Page, Menu Icons, SVG Support, Cookie Notice, Custom Fonts & More | 27 | 165 | 430 | 100k+ | | | Non-prefixed global variable |
| #448 | Tutor LMS – Migration Tool | 27 | 139 | 341 | 1k+ | | | Direct Query |
| #449 | Ultimate Watermark – Image Watermark, Image Protection & Bulk Watermarking | 27 | 164 | 303 | 1k+ | | | Nonce verification recommended |
| #450 | Verge3D Publishing and E-Commerce | 27 | 245 | 298 | 400 | | | Nonce verification recommended |