SW Plus
SW Plus has one disclosed vulnerability in the WordSec catalog, all reported in 2025; it remains unpatched as of September 2026. Their average CVSS score is 6.1, and the most serious one scores 6.1 out of 10.
The most common weakness is Cross-Site Scripting, behind 1 of the records (100%).
The one issue recorded for SW Plus has no published fix yet, which makes virtual patching the only reliable mitigation. The oldest unresolved one dates back to 2025.
All of these findings were reported by 0xd4rk5id3. SW Plus is installed on roughly 40 WordPress sites, so each unpatched flaw has a wide blast radius. The current release is tested up to WordPress 6.8.8.
CVE-2025-25108SW Plus <= 2.1 - Reflected Cross-Site Scripting
Read the full analysisVulnerability Records
SW Plus
Author
shalomworld
SW Plus gives visitors to your website a unique eye on the Catholic world: Papal events LIVE from the Vatican and around the globe Daily Mass, Rosary, Divine Mercy Chaplet Uplifting personal testimonies, vocation stories, talk series, Biblical teachings, conferences from across the country and much more. All hosting is done by Shalom World. No extra storage, nor hidden costs or fees are required. Content is secure, with no private information collected from the visitors or by the website. Web Service Source: https://www.shalomworld.org/ About : https://www.shalomworld.org/swplus Terms & Conditions: https://www.shalomworld.org/about/terms Plugin Installation Instruction: https://www.shalomworld.org/swplus-wordpress.pdf We will be using SW Plus web service to validate the APP ID. Unless the APP ID is validated it won’t be saved and the SW Plus would not be visible in your website. Please make sure you register and create account first.
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C