WordPress Security

WordPress Vulnerability Report – August 23, 2023

Since last week, 89 total vulnerabilities emerged in public disclosure. They may affect over one million WordPress sites. There are 43 plugin vulnerabilities and five theme vulnerabilities with security patches, so run those updates! Additionally, there are 37 plugin vulnerabilities and four theme vulnerabilities with no patch available yet.

Dan Knauss

Since last week, 89 total vulnerabilities emerged in public disclosure. They may affect over one million WordPress sites. There are 43 plugin vulnerabilities and five theme vulnerabilities with security patches, so run those updates!

Additionally, there are 37 plugin vulnerabilities and four theme vulnerabilities with no patch available yet. If you use an unpatched plugin or theme, check their vendors’ intentions and progress on a security release. Suppose no patch is forthcoming or the vulnerable software has been marked “closed” and dropped from the official WordPress theme and plugin repositories. In that case, you should consider deactivation and removal in favor of alternative solutions.

WordPress Core News

“Lionel” was released on August 8, 2023. This release of WordPress was built to help you “create beautiful and compelling websites more efficiently than ever.” See what’s new in WordPress 6.3.

Don’t forget to fully back up your website before installing WordPress 6.3. BackupBuddy, the industry-leading data protection and recovery solution for WordPress, will help you build a strong backup strategy to manage all updates. Embrace the enhanced content creation experience of WordPress 6.3 with confidence — and a backup copy of your website safely stored on a remote server.

WordPress Core Vulnerabilities — Patched

No new WordPress core vulnerabilities were disclosed this week.

WordPress core is very secure when it’s properly configured and maintained. Vulnerable plugins not updated by site owners are the most common vector for attacks on WordPress websites. Our weekly WordPress Vulnerability Report, powered by Patchstack, covers new vulnerabilities that have emerged in plugins, themes, and/or WordPress core since last week’s report. Our goal is to spread awareness of emerging security threats and help you decide what to do if you find vulnerable software on your website. For a deeper analysis of recent trends in WordPress vulnerabilities and threat vectors, see our 2022 Annual Vulnerability Report.

These reports are published every Wednesday and include all active vulnerabilities tracked by Patchstack as of Monday since the previous report. This leaves a 48-hour window for the newest emerging vulnerabilities to be patched before full public disclosure. iThemes Security Pro users have access to vulnerability alerts emerging within this window.

WordPress Plugin Vulnerabilities — Patched

In this section, you’ll find the most recently disclosed WordPress plugin vulnerabilities fixed with a new release from their authors and maintainers. Please apply the updates if you are affected!

These vulnerabilities have been disclosed and scored for their severity, thanks to our friends at Patchstack. Each plugin listing includes the type of vulnerability with its CVE number and CVSS severity rating with links to more technical details. You’ll also see the number of active sites using the plugin and the plugin version release that patches the vulnerability. We start with the most popular plugins, representing the largest target for attackers.

InfiniteWP Client

Plugin Slug:
iwp-client
Installations:
300,000+
Vulnerability:
Sensitive Data Exposure
Patched in Version:
1.12.1
Severity Score:
High
The vulnerability has been patched, so you should update to version 1.12.1.

Advanced File Manager

Plugin Slug:
file-manager-advanced
Installations:
100,000+
Vulnerability:
Sensitive Data Exposure
Patched in Version:
5.1.1
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 5.1.1.

WP-PostRatings

Plugin Slug:
wp-postratings
Installations:
50,000+
Vulnerability:
Bypass Vulnerability
Patched in Version:
1.91.1
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.91.1.

Cost Calculator Builder

Plugin Slug:
cost-calculator-builder
Installations:
30,000+
Vulnerability:
Broken Access Control
Patched in Version:
3.1.43
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.1.43.

Countdown Timer Ultimate

Plugin Slug:
countdown-timer-ultimate
Installations:
20,000+
Vulnerability:
Broken Access Control
Patched in Version:
2.4.1
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.4.1.

Media from FTP

Plugin Slug:
media-from-ftp
Installations:
20,000+
Vulnerability:
Settings Change
Patched in Version:
11.17
Severity Score:
Low
The vulnerability has been patched, so you should update to version 11.17.
Plugin Slug:
album-and-image-gallery-plus-lightbox
Installations:
10,000+
Vulnerability:
Broken Access Control
Patched in Version:
1.7.1
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.7.1.

Cookies and Content Security Policy

Plugin Slug:
cookies-and-content-security-policy
Installations:
10,000+
Vulnerability:
Sensitive Data Exposure
Patched in Version:
2.16
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.16.

Stripe Payment Plugin for WooCommerce

Plugin Slug:
payment-gateway-stripe-and-woocommerce-integration
Installations:
10,000+
Vulnerability:
Broken Access Control
Patched in Version:
3.8.0
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.8.0.

Smart SEO Tool

Plugin Slug:
smart-seo-tool
Installations:
10,000+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
4.0.2
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 4.0.2.

Orders Tracking for WooCommerce

Plugin Slug:
woo-orders-tracking
Installations:
10,000+
Vulnerability:
Directory Traversal
Patched in Version:
1.2.6
Severity Score:
Low
The vulnerability has been patched, so you should update to version 1.2.6.

Blog Designer – Post and Widget

Plugin Slug:
blog-designer-for-post-and-widget
Installations:
8,000+
Vulnerability:
Broken Access Control
Patched in Version:
2.5.2
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.5.2.

WP Remote Users Sync

Plugin Slug:
wp-remote-users-sync
Installations:
8,000+
Vulnerability:
Broken Access Control
Patched in Version:
1.2.12
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.2.12.

WP Remote Users Sync

Plugin Slug:
wp-remote-users-sync
Installations:
8,000+
Vulnerability:
Server Side Request Forgery (SSRF)
Patched in Version:
1.2.13
Severity Score:
High
The vulnerability has been patched, so you should update to version 1.2.13.
Plugin Slug:
meta-slider-and-carousel-with-lightbox
Installations:
7,000+
Vulnerability:
Broken Access Control
Patched in Version:
1.8.3
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.8.3.

Plausible Analytics

Plugin Slug:
plausible-analytics
Installations:
7,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.3.4
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.3.4.

Post grid and filter ultimate

Plugin Slug:
post-grid-and-filter-ultimate
Installations:
7,000+
Vulnerability:
Broken Access Control
Patched in Version:
1.5.3
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.5.3.

Timeline and History slider

Plugin Slug:
timeline-and-history-slider
Installations:
6,000+
Vulnerability:
Broken Access Control
Patched in Version:
2.1.1
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.1.1.

JS Help Desk – Best Help Desk & Support Plugin

Plugin Slug:
js-support-ticket
Installations:
5,000+
Vulnerability:
Arbitrary File Upload
Patched in Version:
2.7.8
Severity Score:
Critical
The vulnerability has been patched, so you should update to version 2.7.8.
Plugin Slug:
wp-team-showcase-and-slider
Installations:
4,000+
Vulnerability:
Broken Access Control
Patched in Version:
2.6.1
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.6.1.

Trending/Popular Post Slider and Widget

Plugin Slug:
wp-trending-post-slider-and-widget
Installations:
4,000+
Vulnerability:
Broken Access Control
Patched in Version:
1.6.1
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.6.1.
Plugin Slug:
youtube-showcase
Installations:
4,000+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
3.3.6
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.3.6.

Accordion and Accordion Slider

Plugin Slug:
accordion-and-accordion-slider
Installations:
3,000+
Vulnerability:
Broken Access Control
Patched in Version:
1.2.5
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.2.5.

DoLogin Security

Plugin Slug:
dologin
Installations:
3,000+
Vulnerability:
Bypass Vulnerability
Patched in Version:
3.7
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.7.
Plugin Slug:
html5-videogallery-plus-player
Installations:
3,000+
Vulnerability:
Broken Access Control
Patched in Version:
2.6.6
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.6.6.

Accordion Slider

Plugin Slug:
accordion-slider
Installations:
2,000+
Vulnerability:
Broken Access Control
Patched in Version:
1.9.7
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.9.7.

Doofinder for WooCommerce

Plugin Slug:
doofinder-for-woocommerce
Installations:
2,000+
Vulnerability:
Open Redirection
Patched in Version:
2.0.0
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.0.0.

Portfolio and Projects

Plugin Slug:
portfolio-and-projects
Installations:
2,000+
Vulnerability:
Broken Access Control
Patched in Version:
1.3.8
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.3.8.

Post Ticker Ultimate

Plugin Slug:
ticker-ultimate
Installations:
2,000+
Vulnerability:
Broken Access Control
Patched in Version:
1.5.6
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.5.6.

CLUEVO LMS

Plugin Slug:
cluevo-lms
Installations:
700+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
1.11.0
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.11.0.

Serial Codes Generator and Validator with WooCommerce Support

Plugin Slug:
serial-codes-generator-and-validator
Installations:
600+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.4.15
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.4.15.

Event Tickets with Ticket Scanner

Plugin Slug:
event-tickets-with-ticket-scanner
Installations:
500+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.5.5
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.5.5.

Products Quick View for WooCommerce

Plugin Slug:
woocommerce-products-quick-view
Installations:
100+
Vulnerability:
Broken Access Control
Patched in Version:
2.3.0
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.3.0.

123.chat

Plugin Slug:
123-chat-videochat
Installations:
40+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.3.1
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.3.1.

Paid Memberships Pro CCBill Gateway

Plugin Slug:
pmpro-ccbill
Vulnerability:
Broken Access Control
Patched in Version:
0.4
Severity Score:
High
The vulnerability has been patched, so you should update to version 0.4.

WordPress Plugin Vulnerabilities — Unpatched

This section contains plugin vulnerabilities with no known fix. Until a patch is available, you are advised to deactivate the plugin, at minimum, immediately. If there is a high risk of active exploits or the plugin remains unpatched for weeks, you are advised to delete the plugin. You should also delete persistently unpatched plugins the WordPress.org repository has locked and marked “Closed” so they can no longer be downloaded and installed.

Enhanced Ecommerce Google Analytics for WooCommerce

Plugin Slug:
woo-ecommerce-tracking-for-google-and-facebook
Installations:
3,000+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

GD Security Headers

Plugin Slug:
gd-security-headers
Installations:
2,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

LINE Notify

Plugin Slug:
wp-line-notify
Installations:
2,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

fitness calculators plugin

Plugin Slug:
fitness-calculators
Installations:
1,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Kanban Boards for WordPress

Plugin Slug:
kanban
Installations:
1,000+
Vulnerability:
Arbitrary Code Execution
Patched in Version:
No Fix
Severity Score:
Critical
The vulnerability has not been patched. You should deactivate the plugin.

Save as PDF plugin by Pdfcrowd

Plugin Slug:
save-as-pdf-by-pdfcrowd
Installations:
1,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Schedule Posts Calendar

Plugin Slug:
schedule-posts-calendar
Installations:
1,000+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Schedule Posts Calendar

Plugin Slug:
schedule-posts-calendar
Installations:
1,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Tabs & Accordion

Plugin Slug:
tabs
Installations:
1,000+
Vulnerability:
Content Injection
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Dynamic Pricing and Discount Rules for WooCommerce

Plugin Slug:
woo-conditional-discount-rules-for-checkout
Installations:
1,000+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

rsvpmaker

Plugin:
RSVPMaker
Plugin Slug:
rsvpmaker
Installations:
400+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

rsvpmaker

Plugin:
RSVPMaker
Plugin Slug:
rsvpmaker
Installations:
400+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Save as Image plugin by Pdfcrowd

Plugin Slug:
save-as-image-by-pdfcrowd
Installations:
50+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Typing Effect

Plugin Slug:
animated-typing-effect
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched and the plugin is closed. You should uninstall and delete the plugin.

Password Reset with Code for WordPress REST API

Plugin Slug:
bdvs-password-reset
Vulnerability:
Broken Authentication
Patched in Version:
No Fix
Severity Score:
Critical
The vulnerability has not been patched and the plugin is closed. You should uninstall and delete the plugin.

BigBlueButton

Plugin Slug:
bigbluebutton
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched and the plugin is closed. You should uninstall and delete the plugin.

Carrot

Plugin:
Carrot
Plugin Slug:
carrrot
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched and the plugin is closed. You should uninstall and delete the plugin.

Cartpauj Register Captcha

Plugin Slug:
cartpauj-register-captcha
Vulnerability:
Bypass Vulnerability
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched and the plugin is closed. You should uninstall and delete the plugin.

Contact form 7 Custom validation

Plugin Slug:
cf7-field-validation
Vulnerability:
SQL Injection
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched and the plugin is closed. You should uninstall and delete the plugin.

Cleverwise Daily Quotes

Plugin Slug:
cleverwise-daily-quotes
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched and the plugin is closed. You should uninstall and delete the plugin.

Cookies by JM

Plugin Slug:
cookies-by-jm
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched and the plugin is closed. You should uninstall and delete the plugin.

CT Commerce

Plugin Slug:
ct-commerce
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched and the plugin is closed. You should uninstall and delete the plugin.

Custom Admin Login Page | WPZest

Plugin Slug:
custom-admin-login-styler-wpzest
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched and the plugin is closed. You should uninstall and delete the plugin.

DX-auto-save-images

Plugin Slug:
dx-auto-save-images
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched and the plugin is closed. You should uninstall and delete the plugin.

Mortgage Calculator Estatik

Plugin Slug:
estatik-mortgage-calculator
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched and the plugin is closed. You should uninstall and delete the plugin.

Make Paths Relative

Plugin Slug:
make-paths-relative
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched and the plugin is closed. You should uninstall and delete the plugin.

Simple Org Chart

Plugin Slug:
simple-org-chart
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched and the plugin is closed. You should uninstall and delete the plugin.

Simple Org Chart

Plugin Slug:
simple-org-chart
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched and the plugin is closed. You should uninstall and delete the plugin.

Simple Staff List

Plugin Slug:
simple-staff-list
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched and the plugin is closed. You should uninstall and delete the plugin.

Donations Made Easy – Smart Donations

Plugin Slug:
smart-donations
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched and the plugin is closed. You should uninstall and delete the plugin.

Sticky Social Media Icons

Plugin Slug:
sticky-social-media-icons
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched and the plugin is closed. You should uninstall and delete the plugin.

WebLibrarian

Plugin Slug:
weblibrarian
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched and the plugin is closed. You should uninstall and delete the plugin.

Putler Connector for WooCommerce

Plugin Slug:
woocommerce-putler-connector
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched and the plugin is closed. You should uninstall and delete the plugin.

Putler Connector for WooCommerce

Plugin Slug:
woocommerce-putler-connector
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched and the plugin is closed. You should uninstall and delete the plugin.

WordPress Theme Vulnerabilities

In this section, you’ll find the latest WordPress theme vulnerabilities to be disclosed. You’ll see the same information we provided above for vulnerable plugins, and the same advice applies. If a security update exists, install it immediately. If a vulnerability remains unpatched in a theme you are actively using, you must find an alternative theme. Deactivate and delete persistently unpatched themes and those marked “Closed” in the WordPress.org theme repository. If you have a vulnerable theme installed that you are not actively using, delete it.

Bazaar Lite

Theme Slug:
bazaar-lite
Downloads:
70,170
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.8.6
Severity Score:
High
The vulnerability has been patched, so you should update to version 1.8.6.

Aapna

Theme:
Aapna
Theme Slug:
aapna
Downloads:
34,228
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should switch themes.

College

Theme:
College
Theme Slug:
college
Downloads:
26,976
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.5.1
Severity Score:
High
The vulnerability has been patched, so you should update to version 1.5.1.

BunnyPressLite

Theme Slug:
bunnypresslite
Downloads:
17,962
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.1
Severity Score:
High
The vulnerability has been patched, so you should update to version 2.1.

Anfaust

Theme:
Anfaust
Theme Slug:
anfaust
Downloads:
17,345
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should switch themes.

Brain Power

Theme Slug:
brain-power
Downloads:
15,015
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should switch themes.

Cafe Bistro

Theme Slug:
cafe-bistro
Downloads:
10,047
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.1.4
Severity Score:
High
The vulnerability has been patched, so you should update to version 1.1.4.

Anand

Theme:
Anand
Theme Slug:
anand
Downloads:
8,755
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should switch themes.

Arendelle

Theme:
Arendelle
Theme Slug:
arendelle
Downloads:
8,504
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.1.3
Severity Score:
High
The vulnerability has been patched, so you should update to version 1.1.3.

Solid Security is part of Solid Suite — The best foundation for WordPress websites.

Every WordPress site needs security, backups, and management tools. That’s Solid Suite — an integrated bundle of three plugins: Solid Security, Solid Backups, and Solid Central. You also get access to Solid Academy’s learning resources for WordPress professionals. Build your next WordPress website on a solid foundation with Solid Suite!

Get Solid Security