Lock Your Updates Plugins/Themes Manager
Lock Your Updates Plugins/Themes Manager has one disclosed vulnerability in the WordSec catalog, all reported in 2025; it remains unpatched as of September 2026. Their average CVSS score is 6.1, and the most serious one scores 6.1 out of 10.
The most common weakness is Cross-Site Scripting, behind 1 of the records (100%).
The one issue recorded for Lock Your Updates Plugins/Themes Manager has no published fix yet, which makes virtual patching the only reliable mitigation. The oldest unresolved one dates back to 2025.
All of these findings were reported by João Pedro Soares de Alcântara. Lock Your Updates Plugins/Themes Manager is installed on roughly 300 WordPress sites, so each unpatched flaw has a wide blast radius. The current release is tested up to WordPress 4.1.42.
CVE-2025-32537Lock Your Updates <= 1.1 - Reflected Cross-Site Scripting
Read the full analysisVulnerability Records

Lock Your Updates Plugins/Themes Manager
Author
Rachel Cherry
It hopefully doesn’t happen alot, but sometimes you have to edit the core code of a plugin or theme. It’s not ideal, and it sucks, but, whatever the reason, you had to do it. Now you’re worried you’re going to forget about your edit, update your plugin or theme (as you usually should), and lose your edits! Well, instead of worrying, use the Lock Your Updates Plugins/Themes Manager to lock your plugins and themes from being updated and to store notes to help you remember what edits you made, all from the plugins or themes admin management page. The Lock Your Updates Plugins/Themes Manager is multisite compatible. Features Provides simple lock/unlock management on the plugins and themes admin management page. Provides method of storing notes so you can remember why you locked the plugin or theme. You will still be notified that a plugin or theme needs to be updated, even if it is locked. Lock Your Updates is multisite compatible. If running WordPress multisite, Lock Your Updates provides an admin column that shows you where your plugins and themes are active. If You’d Like To Contribute If you’d like to contribute to this plugin, feel free to do so on the “Lock Your Updates” GitHub repo. Credits A big shoutout to Aaron Robb @aaron_robb who helped make this plugin grow.
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C