Falling Things

Falling Things has one disclosed vulnerability in the WordSec catalog, all reported in 2025; it is fixed as of September 2026. Their average CVSS score is 4.9, and the most serious one scores 4.9 out of 10.

The most common weakness is SQL Injection, behind 1 of the records (100%).

The one issue recorded for Falling Things has a vendor fix available, so running the current release closes it.

All of these findings were reported by astra.r3verii. Falling Things is installed on roughly 200 WordPress sites, so each unpatched flaw has a wide blast radius. The current release is tested up to WordPress 7.1.

Strategic Overview

Avg CVSSMedium
4.9/ 10
Patch Coverage100%
Open

0

Fixed

1

Get automatic notifications for all Falling Things vulnerabilities before they are exploited.

Highest severity on recordCVSS 4.9CVE-2025-32203

Falling things <= 1.08 - Authenticated (Editor+) SQL Injection

Read the full analysis

Vulnerability Records

1 records
Plugin Profile
Latestv1.10

Falling Things

manu225

Author

manu225

4.0(3)
80/100
Last Updated
2026-08-15 (29d ago)
Active Installs
200+
Downloads
18,980
Requires WP
3.5+
Requires PHP
5.6+
Tested up to
WP 7.1
Created
2016-03-25 (11y ago)

Falling leafs, snowflakes, flowers or wathever you want 🙂 Compatible with multisite. Demo video And there is a Pro version of this plugin, with many additional features: – choose which object fall (custom and multiple icons allowed) – quantity of objet falling – speed of the object (can be random speed) – 3 possible trajectories – define on wich pages or custom urls the falling things appear – define on wich period the falling things appear – multiple profils (ie: one for summer and one for winter) More informations and demos here

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C