WordPress Security

WordPress Vulnerability Report – August 16, 2023

Since last week, 90 total vulnerabilities emerged in public disclosure. They may affect over one million WordPress sites. There are 49 plugin vulnerabilities and five theme vulnerabilities with security patches, so run those updates! Additionally, there are 35 plugin vulnerabilities and one theme vulnerability with no patch available yet.

Dan Knauss

Since last week, 90 total vulnerabilities emerged in public disclosure. They may affect over one million WordPress sites. There are 49 plugin vulnerabilities and five theme vulnerabilities with security patches, so run those updates!

Additionally, there are 35 plugin vulnerabilities and one theme vulnerability with no patch available yet. If you use an unpatched plugin or theme, check their vendors’ intentions and progress on a security release. Suppose no patch is forthcoming or the vulnerable software has been marked “closed” and dropped from the official WordPress theme and plugin repositories. In that case, you should consider deactivation and removal in favor of alternative solutions.

WordPress Core News

WordPress 6.3 “Lionel” is out! This new release of WordPress was built to help you “create beautiful and compelling websites more efficiently than ever.” See what’s new in WordPress 6.3.

Don’t forget to fully back up your website before installing WordPress 6.3. BackupBuddy, the industry-leading data protection and recovery solution for WordPress, will help you build a strong backup strategy to manage all updates. Embrace the enhanced content creation experience of WordPress 6.3 with confidence — and a backup copy of your website safely stored on a remote server.

WordPress Core Vulnerabilities — Patched

No new WordPress core vulnerabilities were disclosed this week.

WordPress core is very secure when it’s properly configured and maintained. Vulnerable plugins not updated by site owners are the most common vector for attacks on WordPress websites. Our weekly WordPress Vulnerability Report, powered by Patchstack, covers new vulnerabilities that have emerged in plugins, themes, and/or WordPress core since last week’s report. Our goal is to spread awareness of emerging security threats and help you decide what to do if you find vulnerable software on your website. For a deeper analysis of recent trends in WordPress vulnerabilities and threat vectors, see our 2022 Annual Vulnerability Report.

These reports are published every Wednesday and include all active vulnerabilities tracked by Patchstack as of Monday since the previous report. This leaves a 48-hour window for the newest emerging vulnerabilities to be patched before full public disclosure. iThemes Security Pro users have access to vulnerability alerts emerging within this window.

WordPress Plugin Vulnerabilities — Patched

In this section, you’ll find the most recently disclosed WordPress plugin vulnerabilities fixed with a new release from their authors and maintainers. Please apply the updates if you are affected!

These vulnerabilities have been disclosed and scored for their severity, thanks to our friends at Patchstack. Each plugin listing includes the type of vulnerability with its CVE number and CVSS severity rating with links to more technical details. You’ll also see the number of active sites using the plugin and the plugin version release that patches the vulnerability. We start with the most popular plugins, representing the largest target for attackers.

Plugin Slug:
header-footer-code-manager
Installations:
400,000+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
1.1.35
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.1.35.

Gutenberg Blocks by Kadence Blocks – Page Builder

Plugin Slug:
kadence-blocks
Installations:
300,000+
Vulnerability:
Arbitrary File Upload
Patched in Version:
3.1.11
Severity Score:
Critical
The vulnerability has been patched, so you should update to version 3.1.11.

Post Grid Combo

Plugin Slug:
post-grid
Installations:
50,000+
Vulnerability:
Sensitive Data Exposure
Patched in Version:
2.2.51
Severity Score:
High
The vulnerability has been patched, so you should update to version 2.2.51.

Popup by Supsystic

Plugin Slug:
popup-by-supsystic
Installations:
20,000+
Vulnerability:
Broken Access Control
Patched in Version:
1.10.20
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.10.20.

Themesflat Addons For Elementor

Plugin Slug:
themesflat-addons-for-elementor
Installations:
20,000+
Vulnerability:
PHP Object Injection
Patched in Version:
2.0.1
Severity Score:
High
The vulnerability has been patched, so you should update to version 2.0.1.

Booking Package

Plugin Slug:
booking-package
Installations:
10,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.6.02
Severity Score:
High
The vulnerability has been patched, so you should update to version 1.6.02.
Plugin Slug:
justified-gallery
Installations:
10,000+
Vulnerability:
Broken Access Control
Patched in Version:
1.8.0
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.8.0.

Qubely

Plugin Slug:
qubely
Installations:
10,000+
Vulnerability:
Broken Access Control
Patched in Version:
1.8.6
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.8.6.

User Activity Log

Plugin Slug:
user-activity-log
Installations:
10,000+
Vulnerability:
Broken Access Control
Patched in Version:
1.6.6
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.6.6.

Stock Ticker

Plugin Slug:
stock-ticker
Installations:
4,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
3.23.4
Severity Score:
High
The vulnerability has been patched, so you should update to version 3.23.4.

Stock Ticker

Plugin Slug:
stock-ticker
Installations:
4,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
3.23.3
Severity Score:
High
The vulnerability has been patched, so you should update to version 3.23.3.

Accordion and Accordion Slider

Plugin Slug:
accordion-and-accordion-slider
Installations:
3,000+
Vulnerability:
Broken Access Control
Patched in Version:
1.2.5
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.2.5.

Online Booking & Scheduling Calendar for WordPress by vcita

Plugin Slug:
meeting-scheduler-by-vcita
Installations:
3,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
4.3.3
Severity Score:
High
The vulnerability has been patched, so you should update to version 4.3.3.

User Activity Tracking and Log

Plugin Slug:
user-activity-tracking-and-log
Installations:
3,000+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
4.0.9
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 4.0.9.

ImageRecycle pdf & image compression

Plugin Slug:
imagerecycle-pdf-image-compression
Installations:
2,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
3.1.12
Severity Score:
High
The vulnerability has been patched, so you should update to version 3.1.12.

ImageRecycle pdf & image compression

Plugin Slug:
imagerecycle-pdf-image-compression
Installations:
2,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
3.1.11
Severity Score:
High
The vulnerability has been patched, so you should update to version 3.1.11.

Leyka

Plugin:
Leyka
Plugin Slug:
leyka
Installations:
2,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
3.30.3
Severity Score:
High
The vulnerability has been patched, so you should update to version 3.30.3.

Portfolio and Projects

Plugin Slug:
portfolio-and-projects
Installations:
2,000+
Vulnerability:
Broken Access Control
Patched in Version:
1.3.8
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.3.8.

WP Testimonials

Plugin Slug:
testimonial-widgets
Installations:
2,000+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
1.4.3
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.4.3.

Bubble Menu

Plugin Slug:
bubble-menu
Installations:
1,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
3.0.5
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.0.5.
Plugin Slug:
gallery-photo-gallery
Installations:
1,000+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
5.2.7
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 5.2.7.

POEditor

Plugin:
POEditor
Plugin Slug:
poeditor
Installations:
1,000+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
0.9.8
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 0.9.8.

Sign-up Sheets

Plugin Slug:
sign-up-sheets
Installations:
1,000+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
2.2.9
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.2.9.

Post Timeline

Plugin Slug:
post-timeline
Installations:
800+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.2.6
Severity Score:
High
The vulnerability has been patched, so you should update to version 2.2.6.

wpShopGermany – Protected Shops

Plugin Slug:
wpshopgermany-protectedshops
Installations:
40+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.1
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.1.

Advanced Custom Fields Pro premium

Plugin Slug:
advanced-custom-fields-pro
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
6.1.8
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 6.1.8.

ARMember Premium

Plugin Slug:
armember
Vulnerability:
Broken Access Control
Patched in Version:
5.9.3
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 5.9.3.

Biometric Login for WooCommerce

Plugin Slug:
biometric-login-for-woocommerce
Vulnerability:
Privilege Escalation
Patched in Version:
1.0.4
Severity Score:
Critical
The vulnerability has been patched, so you should update to version 1.0.4.

Avada Builder

Plugin Slug:
fusion-builder
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
3.11.2
Severity Score:
High
The vulnerability has been patched, so you should update to version 3.11.2.

Avada Builder

Plugin Slug:
fusion-builder
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
3.11.2
Severity Score:
High
The vulnerability has been patched, so you should update to version 3.11.2.

Avada Builder

Plugin Slug:
fusion-builder
Vulnerability:
Broken Access Control
Patched in Version:
3.11.2
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.11.2.

Avada Builder

Plugin Slug:
fusion-builder
Vulnerability:
SQL Injection
Patched in Version:
3.11.2
Severity Score:
High
The vulnerability has been patched, so you should update to version 3.11.2.

Jupiter X Core

Plugin Slug:
jupiterx-core
Vulnerability:
Broken Access Control
Patched in Version:
3.3.5
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.3.5.

Jupiter X Core

Plugin Slug:
jupiterx-core
Vulnerability:
Broken Access Control
Patched in Version:
3.3.5
Severity Score:
High
The vulnerability has been patched, so you should update to version 3.3.5.

WooCommerce One Page Checkout

Plugin Slug:
woocommerce-one-page-checkout
Vulnerability:
Local File Inclusion
Patched in Version:
2.4.0
Severity Score:
High
The vulnerability has been patched, so you should update to version 2.4.0.

WordPress Plugin Vulnerabilities — Unpatched

This section contains plugin vulnerabilities with no known fix. Until a patch is available, you are advised to deactivate the plugin, at minimum, immediately. If there is a high risk of active exploits or the plugin remains unpatched for weeks, you are advised to delete the plugin. You should also delete persistently unpatched plugins the WordPress.org repository has locked and marked “Closed” so they can no longer be downloaded and installed.

Printful Integration for WooCommerce

Plugin Slug:
printful-shipping-for-woocommerce
Installations:
60,000+
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

WP 404 Auto Redirect to Similar Post

Plugin Slug:
wp-404-auto-redirect-to-similar-post
Installations:
50,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

MailChimp Forms by MailMunch

Plugin Slug:
mailchimp-forms-by-mailmunch
Installations:
30,000+
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

flowpaper

Plugin:
flowpaper
Plugin Slug:
flowpaper-lite-pdf-flipbook
Installations:
20,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Futurio Extra

Plugin Slug:
futurio-extra
Installations:
20,000+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Email Template Designer – WP HTML Mail

Plugin Slug:
wp-html-mail
Installations:
20,000+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

PixTypes

Plugin:
PixTypes
Plugin Slug:
pixtypes
Installations:
10,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Theme Demo Import

Plugin Slug:
theme-demo-import
Installations:
10,000+
Vulnerability:
Arbitrary File Upload
Patched in Version:
No Fix
Severity Score:
Critical
The vulnerability has not been patched. You should deactivate the plugin.

WP Categories Widget

Plugin Slug:
wp-categories-widget
Installations:
8,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Product Attachment for WooCommerce

Plugin Slug:
woo-product-attachment
Installations:
6,000+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

SendPress Newsletters

Plugin Slug:
sendpress
Installations:
5,000+
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

YITH WooCommerce Waitlist

Plugin Slug:
yith-woocommerce-waiting-list
Installations:
5,000+
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

BigBlueButton

Plugin Slug:
bigbluebutton
Installations:
4,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.
Plugin Slug:
easy-cookie-law
Installations:
4,000+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Make Paths Relative

Plugin Slug:
make-paths-relative
Installations:
4,000+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

WP Like Button

Plugin Slug:
wp-like-button
Installations:
4,000+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

LINE Notify

Plugin Slug:
wp-line-notify
Installations:
2,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Password Reset with Code for WordPress REST API

Plugin Slug:
bdvs-password-reset
Installations:
1,000+
Vulnerability:
Broken Authentication
Patched in Version:
No Fix
Severity Score:
Critical
The vulnerability has not been patched. You should deactivate the plugin.

Highcompress Image Compressor

Plugin Slug:
high-compress
Installations:
1,000+
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Kangu para WooCommerce

Plugin Slug:
kangu
Installations:
1,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

SB Child List

Plugin Slug:
sb-child-list
Installations:
1,000+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

WxSync

Plugin Slug:
wxsync
Installations:
1,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

wSecure Lite

Plugin Slug:
wsecure
Installations:
900+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Easy!Appointments

Plugin Slug:
easyappointments
Installations:
800+
Vulnerability:
Arbitrary File Deletion
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

WebLibrarian

Plugin Slug:
weblibrarian
Installations:
500+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

demon image annotation

Plugin Slug:
demon-image-annotation
Installations:
10+
Vulnerability:
SQL Injection
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Absolute Privacy

Plugin Slug:
absolute-privacy
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched and the plugin is closed. You should uninstall and delete the plugin.

All Users Messenger

Plugin Slug:
all-users-messenger
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched and the plugin is closed. You should uninstall and delete the plugin.

Canto

Plugin:
Canto
Plugin Slug:
canto
Vulnerability:
Remote File Inclusion
Patched in Version:
No Fix
Severity Score:
Critical
The vulnerability has not been patched and the plugin is closed. You should uninstall and delete the plugin.

FULL Customer

Plugin Slug:
full-customer
Vulnerability:
Sensitive Data Exposure
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched and the plugin is closed. You should uninstall and delete the plugin.

FULL Customer

Plugin Slug:
full-customer
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched and the plugin is closed. You should uninstall and delete the plugin.

Real Estate Manager

Plugin Slug:
real-estate-manager
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched and the plugin is closed. You should uninstall and delete the plugin.

Realia

Plugin:
Realia
Plugin Slug:
realia
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched and the plugin is closed. You should uninstall and delete the plugin.

Donations Made Easy – Smart Donations

Plugin Slug:
smart-donations
Vulnerability:
SQL Injection
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched and the plugin is closed. You should uninstall and delete the plugin.

WordPress Theme Vulnerabilities

In this section, you’ll find the latest WordPress theme vulnerabilities to be disclosed. You’ll see the same information we provided above for vulnerable plugins, and the same advice applies. If a security update exists, install it immediately. If a vulnerability remains unpatched in a theme you are actively using, you must find an alternative theme. Deactivate and delete persistently unpatched themes and those marked “Closed” in the WordPress.org theme repository. If you have a vulnerable theme installed that you are not actively using, delete it.

Avada

Theme:
Avada
Theme Slug:
avada
Vulnerability:
Broken Access Control
Patched in Version:
7.11.2
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 7.11.2.

Avada

Theme:
Avada
Theme Slug:
avada
Vulnerability:
Arbitrary File Upload
Patched in Version:
7.11.2
Severity Score:
High
The vulnerability has been patched, so you should update to version 7.11.2.

Avada

Theme:
Avada
Theme Slug:
avada
Vulnerability:
Server Side Request Forgery (SSRF)
Patched in Version:
7.11.2
Severity Score:
High
The vulnerability has been patched, so you should update to version 7.11.2.

Avada

Theme:
Avada
Theme Slug:
avada
Vulnerability:
Arbitrary File Upload
Patched in Version:
7.11.2
Severity Score:
Critical
The vulnerability has been patched, so you should update to version 7.11.2.

BeTheme

Theme:
Betheme
Theme Slug:
betheme
Vulnerability:
Broken Access Control
Patched in Version:
27.1.2
Severity Score:
High
The vulnerability has been patched, so you should update to version 27.1.2.

Business Pro

Theme Slug:
business-pro
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should switch themes.

Solid Security is part of Solid Suite — The best foundation for WordPress websites.

Every WordPress site needs security, backups, and management tools. That’s Solid Suite — an integrated bundle of three plugins: Solid Security, Solid Backups, and Solid Central. You also get access to Solid Academy’s learning resources for WordPress professionals. Build your next WordPress website on a solid foundation with Solid Suite!

Get Solid Security

Did you like this article? Spread the word: