Menu
iThemes
WordPress Security, Backups & Maintenance
  • Products
    • iThemes Security Pro
    • BackupBuddy
    • iThemes Sync
    • Why buy from iThemes?
  • Bundles
    • Essentials Bundle
    • Solid Foundations
    • Customer Spotlights
  • Resources
    • Blog
    • WordPress 101 Tutorials
    • WordPress Ebooks
    • Weekly WordPress Vulnerability Report
    • The Ultimate Guide to Starting a Web Design Business
  • Training
    • Upcoming Webinars
    • Free Webinar Library
    • Premium Courses
    • Become a Member
    • Member Login
  • Support
    • Documentation
    • Get Help
    • Product Updates
    • Upgrade Policy
    • Contact
    • Our Mission: Make People’s Lives Awesome
  • Log In
WordPress News and Updates from iThemes
Categories
  • Product Updates
  • WordPress Backup
  • WordPress Block Editor
  • WordPress Ecommerce
  • WordPress for Freelancers
  • WordPress Security
  • WordPress Tutorials
  • WPprosper

WordPress Vulnerability Report – August 23, 2023

Written by Dan Knauss on August 23, 2023

Last Updated on August 23, 2023

Since last week, 89 total vulnerabilities emerged in public disclosure. They may affect over one million WordPress sites. There are 43 plugin vulnerabilities and five theme vulnerabilities with security patches, so run those updates!

Additionally, there are 37 plugin vulnerabilities and four theme vulnerabilities with no patch available yet. If you use an unpatched plugin or theme, check their vendors’ intentions and progress on a security release. Suppose no patch is forthcoming or the vulnerable software has been marked “closed” and dropped from the official WordPress theme and plugin repositories. In that case, you should consider deactivation and removal in favor of alternative solutions.

WordPress Core News

“Lionel” was released on August 8, 2023. This release of WordPress was built to help you “create beautiful and compelling websites more efficiently than ever.” See what’s new in WordPress 6.3.

Don’t forget to fully back up your website before installing WordPress 6.3. BackupBuddy, the industry-leading data protection and recovery solution for WordPress, will help you build a strong backup strategy to manage all updates. Embrace the enhanced content creation experience of WordPress 6.3 with confidence — and a backup copy of your website safely stored on a remote server.


WordPress Core Vulnerabilities — Patched

  • No new WordPress core vulnerabilities were disclosed this week.

WordPress core is very secure when it’s properly configured and maintained. Vulnerable plugins not updated by site owners are the most common vector for attacks on WordPress websites. Our weekly WordPress Vulnerability Report, powered by Patchstack, covers new vulnerabilities that have emerged in plugins, themes, and/or WordPress core since last week’s report. Our goal is to spread awareness of emerging security threats and help you decide what to do if you find vulnerable software on your website. For a deeper analysis of recent trends in WordPress vulnerabilities and threat vectors, see our 2022 Annual Vulnerability Report.

Contents of the August 23, 2023 Report
  1. WordPress Core News
  2. WordPress Core Vulnerabilities – Patched
  3. WordPress Plugin Vulnerabilities – Patched
    1. InfiniteWP Client
    2. Advanced File Manager
    3. Blog2Social
    4. wpDataTables
    5. WP-PostRatings
    6. Cost Calculator Builder
    7. Countdown Timer Ultimate
    8. Media from FTP
    9. User Submitted Posts
    10. Album and Image Gallery plus Lightbox
    11. Cookies and Content Security Policy
    12. Stripe Payment Plugin for WooCommerce
    13. Smart SEO Tool
    14. Orders Tracking for WooCommerce
    15. Testimonial Grid and Testimonial Slider plus Carousel with Rotator Widget
    16. WP VR
    17. Blog Designer – Post and Widget
    18. WP Remote Users Sync
    19. WP Remote Users Sync
    20. Meta Slider and Carousel with Lightbox
    21. Plausible Analytics
    22. Post grid and filter ultimate
    23. Timeline and History slider
    24. JS Help Desk – Best Help Desk & Support Plugin
    25. Team Slider and Team Grid Showcase plus Team Carousel
    26. Trending/Popular Post Slider and Widget
    27. Video Gallery & Management
    28. Accordion and Accordion Slider
    29. DoLogin Security
    30. Video gallery and Player
    31. WooCommerce PDF Invoice Builder
    32. WooCommerce PDF Invoice Builder
    33. WooCommerce PDF Invoice Builder
    34. Accordion Slider
    35. Doofinder for WooCommerce
    36. Portfolio and Projects
    37. Post Ticker Ultimate
    38. CLUEVO LMS
    39. Serial Codes Generator and Validator with WooCommerce Support
    40. Event Tickets with Ticket Scanner
    41. Products Quick View for WooCommerce
    42. 123.chat
    43. Paid Memberships Pro CCBill Gateway
  4. WordPress Plugin Vulnerabilities – Unpatched
    1. Simple URLs
    2. Simple URLs
    3. Simple URLs
    4. Enhanced Ecommerce Google Analytics for WooCommerce
    5. GD Security Headers
    6. LINE Notify
    7. fitness calculators plugin
    8. Kanban Boards for WordPress
    9. Save as PDF plugin by Pdfcrowd
    10. Schedule Posts Calendar
    11. Schedule Posts Calendar
    12. Tabs & Accordion
    13. Dynamic Pricing and Discount Rules for WooCommerce
    14. rsvpmaker
    15. rsvpmaker
    16. Save as Image plugin by Pdfcrowd
    17. Typing Effect
    18. Password Reset with Code for WordPress REST API
    19. BigBlueButton
    20. Carrot
    21. Cartpauj Register Captcha
    22. Contact form 7 Custom validation
    23. Cleverwise Daily Quotes
    24. Cookies by JM
    25. CT Commerce
    26. Custom Admin Login Page | WPZest
    27. DX-auto-save-images
    28. Mortgage Calculator Estatik
    29. Make Paths Relative
    30. Simple Org Chart
    31. Simple Org Chart
    32. Simple Staff List
    33. Donations Made Easy – Smart Donations
    34. Sticky Social Media Icons
    35. WebLibrarian
    36. Putler Connector for WooCommerce
    37. Putler Connector for WooCommerce
  5. WordPress Theme Vulnerabilities
    1. Bazaar Lite
    2. Aapna
    3. College
    4. BunnyPressLite
    5. Anfaust
    6. Brain Power
    7. Cafe Bistro
    8. Anand
    9. Arendelle
  6. The Best WordPress Security Plugin to Secure & Protect WordPress Sites

These reports are published every Wednesday and include all active vulnerabilities tracked by Patchstack as of Monday since the previous report. This leaves a 48-hour window for the newest emerging vulnerabilities to be patched before full public disclosure. iThemes Security Pro users have access to vulnerability alerts emerging within this window.

Get the weekly WordPress Vulnerability Report delivered to your inbox each Wednesday.
Subscribe now

WordPress Plugin Vulnerabilities — Patched

In this section, you’ll find the most recently disclosed WordPress plugin vulnerabilities fixed with a new release from their authors and maintainers. Please apply the updates if you are affected!

These vulnerabilities have been disclosed and scored for their severity, thanks to our friends at Patchstack. Each plugin listing includes the type of vulnerability with its CVE number and CVSS severity rating with links to more technical details. You’ll also see the number of active sites using the plugin and the plugin version release that patches the vulnerability. We start with the most popular plugins, representing the largest target for attackers.

InfiniteWP Client

Product image for InfiniteWP Client.
Plugin
InfiniteWP Client
Plugin Slug
iwp-client
Installations
300,000+
Vulnerability
Sensitive Data Exposure
Patched in Version
1.12.1
Severity Score
High
CVE
2023-2916
The vulnerability has been patched, so you should update to version 1.12.1.

Advanced File Manager

Product image for Advanced File Manager.
Plugin
Advanced File Manager
Plugin Slug
file-manager-advanced
Installations
100,000+
Vulnerability
Sensitive Data Exposure
Patched in Version
5.1.1
Severity Score
Medium
CVE
2023-3814
The vulnerability has been patched, so you should update to version 5.1.1.

Blog2Social

Product image for Blog2Social: Social Media Auto Post & Scheduler.
Plugin
Blog2Social: Social Media Auto Post & Scheduler
Plugin Slug
blog2social
Installations
70,000+
Vulnerability
Cross Site Scripting (XSS)
Patched in Version
7.2.1
Severity Score
High
CVE
2023-40554
The vulnerability has been patched, so you should update to version 7.2.1.

wpDataTables

Product image for wpDataTables – WordPress Data Table, Dynamic Tables & Table Charts Plugin.
Plugin
wpDataTables – WordPress Data Table, Dynamic Tables & Table Charts Plugin
Plugin Slug
wpdatatables
Installations
70,000+
Vulnerability
PHP Object Injection
Patched in Version
2.1.66
Severity Score
Medium
The vulnerability has been patched, so you should update to version 2.1.66.

WP-PostRatings

Product image for WP-PostRatings.
Plugin
WP-PostRatings
Plugin Slug
wp-postratings
Installations
50,000+
Vulnerability
Bypass Vulnerability
Patched in Version
1.91.1
Severity Score
Medium
CVE
2023-40332
The vulnerability has been patched, so you should update to version 1.91.1.

Cost Calculator Builder

Product image for Cost Calculator Builder.
Plugin
Cost Calculator Builder
Plugin Slug
cost-calculator-builder
Installations
30,000+
Vulnerability
Broken Access Control
Patched in Version
3.1.43
Severity Score
Medium
CVE
2023-40011
The vulnerability has been patched, so you should update to version 3.1.43.

Countdown Timer Ultimate

Product image for Countdown Timer Ultimate.
Plugin
Countdown Timer Ultimate
Plugin Slug
countdown-timer-ultimate
Installations
20,000+
Vulnerability
Broken Access Control
Patched in Version
2.4.1
Severity Score
Medium
CVE
2023-40200
The vulnerability has been patched, so you should update to version 2.4.1.

Media from FTP

Product image for Media from FTP.
Plugin
Media from FTP
Plugin Slug
media-from-ftp
Installations
20,000+
Vulnerability
Settings Change
Patched in Version
11.17
Severity Score
Low
CVE
2023-4019
The vulnerability has been patched, so you should update to version 11.17.

User Submitted Posts

Product image for User Submitted Posts – Enable Users to Submit Posts from the Front End.
Plugin
User Submitted Posts – Enable Users to Submit Posts from the Front End
Plugin Slug
user-submitted-posts
Installations
20,000+
Vulnerability
Cross Site Scripting (XSS)
Patched in Version
20230811
Severity Score
High
CVE
2023-4308
The vulnerability has been patched, so you should update to version 20230811.

Album and Image Gallery plus Lightbox

Product image for Album and Image Gallery plus Lightbox.
Plugin
Album and Image Gallery plus Lightbox
Plugin Slug
album-and-image-gallery-plus-lightbox
Installations
10,000+
Vulnerability
Broken Access Control
Patched in Version
1.7.1
Severity Score
Medium
CVE
2023-40200
The vulnerability has been patched, so you should update to version 1.7.1.

Cookies and Content Security Policy

Product image for Cookies and Content Security Policy.
Plugin
Cookies and Content Security Policy
Plugin Slug
cookies-and-content-security-policy
Installations
10,000+
Vulnerability
Sensitive Data Exposure
Patched in Version
2.16
Severity Score
Medium
CVE
2023-40662
The vulnerability has been patched, so you should update to version 2.16.

Stripe Payment Plugin for WooCommerce

Product image for Stripe Payment Plugin for WooCommerce.
Plugin
Stripe Payment Plugin for WooCommerce
Plugin Slug
payment-gateway-stripe-and-woocommerce-integration
Installations
10,000+
Vulnerability
Broken Access Control
Patched in Version
3.8.0
Severity Score
Medium
CVE
2023-4040
The vulnerability has been patched, so you should update to version 3.8.0.

Smart SEO Tool

Product image for Smart SEO Tool – SEO.
Plugin
Smart SEO Tool – SEO
Plugin Slug
smart-seo-tool
Installations
10,000+
Vulnerability
Cross Site Request Forgery (CSRF)
Patched in Version
4.0.2
Severity Score
Medium
The vulnerability has been patched, so you should update to version 4.0.2.

Orders Tracking for WooCommerce

Product image for Orders Tracking for WooCommerce.
Plugin
Orders Tracking for WooCommerce
Plugin Slug
woo-orders-tracking
Installations
10,000+
Vulnerability
Directory Traversal
Patched in Version
1.2.6
Severity Score
Low
CVE
2023-4216
The vulnerability has been patched, so you should update to version 1.2.6.

Testimonial Grid and Testimonial Slider plus Carousel with Rotator Widget

Product image for Testimonial Grid and Testimonial Slider plus Carousel with Rotator Widget.
Plugin
Testimonial Grid and Testimonial Slider plus Carousel with Rotator Widget
Plugin Slug
wp-testimonial-with-widget
Installations
10,000+
Vulnerability
Broken Access Control
Patched in Version
3.3.1
Severity Score
Medium
CVE
2023-40200
The vulnerability has been patched, so you should update to version 3.3.1.

WP VR

Product image for WP VR – 360 Panorama and Virtual Tour Builder For WordPress.
Plugin
WP VR – 360 Panorama and Virtual Tour Builder For WordPress
Plugin Slug
wpvr
Installations
10,000+
Vulnerability
Cross Site Scripting (XSS)
Patched in Version
8.3.5
Severity Score
High
CVE
2023-40663
The vulnerability has been patched, so you should update to version 8.3.5.

Blog Designer – Post and Widget

Product image for Blog Designer – Post and Widget.
Plugin
Blog Designer – Post and Widget
Plugin Slug
blog-designer-for-post-and-widget
Installations
8,000+
Vulnerability
Broken Access Control
Patched in Version
2.5.2
Severity Score
Medium
CVE
2023-40200
The vulnerability has been patched, so you should update to version 2.5.2.

WP Remote Users Sync

Product image for WP Remote Users Sync.
Plugin
WP Remote Users Sync
Plugin Slug
wp-remote-users-sync
Installations
8,000+
Vulnerability
Broken Access Control
Patched in Version
1.2.12
Severity Score
Medium
CVE
2023-4374
The vulnerability has been patched, so you should update to version 1.2.12.

WP Remote Users Sync

Product image for WP Remote Users Sync.
Plugin
WP Remote Users Sync
Plugin Slug
wp-remote-users-sync
Installations
8,000+
Vulnerability
Server Side Request Forgery (SSRF)
Patched in Version
1.2.13
Severity Score
High
CVE
2023-3958
The vulnerability has been patched, so you should update to version 1.2.13.

Meta Slider and Carousel with Lightbox

Product image for Meta Slider and Carousel with Lightbox.
Plugin
Meta Slider and Carousel with Lightbox
Plugin Slug
meta-slider-and-carousel-with-lightbox
Installations
7,000+
Vulnerability
Broken Access Control
Patched in Version
1.8.3
Severity Score
Medium
CVE
2023-40200
The vulnerability has been patched, so you should update to version 1.8.3.

Plausible Analytics

Product image for Plausible Analytics.
Plugin
Plausible Analytics
Plugin Slug
plausible-analytics
Installations
7,000+
Vulnerability
Cross Site Scripting (XSS)
Patched in Version
1.3.4
Severity Score
Medium
CVE
2023-40553
The vulnerability has been patched, so you should update to version 1.3.4.

Post grid and filter ultimate

Product image for Post grid and filter ultimate.
Plugin
Post grid and filter ultimate
Plugin Slug
post-grid-and-filter-ultimate
Installations
7,000+
Vulnerability
Broken Access Control
Patched in Version
1.5.3
Severity Score
Medium
CVE
2023-40200
The vulnerability has been patched, so you should update to version 1.5.3.

Timeline and History slider

Product image for Timeline and History slider.
Plugin
Timeline and History slider
Plugin Slug
timeline-and-history-slider
Installations
6,000+
Vulnerability
Broken Access Control
Patched in Version
2.1.1
Severity Score
Medium
CVE
2023-40200
The vulnerability has been patched, so you should update to version 2.1.1.

JS Help Desk – Best Help Desk & Support Plugin

Product image for JS Help Desk – Best Help Desk & Support Plugin.
Plugin
JS Help Desk – Best Help Desk & Support Plugin
Plugin Slug
js-support-ticket
Installations
5,000+
Vulnerability
Arbitrary File Upload
Patched in Version
2.7.8
Severity Score
Critical
CVE
2023-25444
The vulnerability has been patched, so you should update to version 2.7.8.

Team Slider and Team Grid Showcase plus Team Carousel

Product image for Team Slider and Team Grid Showcase plus Team Carousel.
Plugin
Team Slider and Team Grid Showcase plus Team Carousel
Plugin Slug
wp-team-showcase-and-slider
Installations
4,000+
Vulnerability
Broken Access Control
Patched in Version
2.6.1
Severity Score
Medium
CVE
2023-40200
The vulnerability has been patched, so you should update to version 2.6.1.

Trending/Popular Post Slider and Widget

Product image for Trending/Popular Post Slider and Widget.
Plugin
Trending/Popular Post Slider and Widget
Plugin Slug
wp-trending-post-slider-and-widget
Installations
4,000+
Vulnerability
Broken Access Control
Patched in Version
1.6.1
Severity Score
Medium
CVE
2023-40200
The vulnerability has been patched, so you should update to version 1.6.1.

Video Gallery & Management

Product image for Video Gallery for YouTube Videos and WordPress.
Plugin
Video Gallery for YouTube Videos and WordPress
Plugin Slug
youtube-showcase
Installations
4,000+
Vulnerability
Cross Site Request Forgery (CSRF)
Patched in Version
3.3.6
Severity Score
Medium
CVE
2023-40558
The vulnerability has been patched, so you should update to version 3.3.6.

Accordion and Accordion Slider

Product image for Accordion and Accordion Slider.
Plugin
Accordion and Accordion Slider
Plugin Slug
accordion-and-accordion-slider
Installations
3,000+
Vulnerability
Broken Access Control
Patched in Version
1.2.5
Severity Score
Medium
CVE
2023-40200
The vulnerability has been patched, so you should update to version 1.2.5.

DoLogin Security

Plugin
DoLogin Security
Plugin Slug
dologin
Installations
3,000+
Vulnerability
Bypass Vulnerability
Patched in Version
3.7
Severity Score
Medium
The vulnerability has been patched, so you should update to version 3.7.

Video gallery and Player

Product image for Video gallery and Player.
Plugin
Video gallery and Player
Plugin Slug
html5-videogallery-plus-player
Installations
3,000+
Vulnerability
Broken Access Control
Patched in Version
2.6.6
Severity Score
Medium
CVE
2023-40200
The vulnerability has been patched, so you should update to version 2.6.6.

WooCommerce PDF Invoice Builder

Product image for WooCommerce PDF Invoice Builder, Create invoices, packing slips and more.
Plugin
WooCommerce PDF Invoice Builder, Create invoices, packing slips and more
Plugin Slug
woo-pdf-invoice-builder
Installations
3,000+
Vulnerability
Broken Access Control
Patched in Version
1.2.92
Severity Score
Medium
CVE
2023-4245
The vulnerability has been patched, so you should update to version 1.2.92.

WooCommerce PDF Invoice Builder

Product image for WooCommerce PDF Invoice Builder, Create invoices, packing slips and more.
Plugin
WooCommerce PDF Invoice Builder, Create invoices, packing slips and more
Plugin Slug
woo-pdf-invoice-builder
Installations
3,000+
Vulnerability
Cross Site Scripting (XSS)
Patched in Version
1.2.91
Severity Score
Medium
CVE
2023-4160
The vulnerability has been patched, so you should update to version 1.2.91.

WooCommerce PDF Invoice Builder

Product image for WooCommerce PDF Invoice Builder, Create invoices, packing slips and more.
Plugin
WooCommerce PDF Invoice Builder, Create invoices, packing slips and more
Plugin Slug
woo-pdf-invoice-builder
Installations
3,000+
Vulnerability
Cross Site Request Forgery (CSRF)
Patched in Version
1.2.91
Severity Score
Medium
CVE
2023-4161
The vulnerability has been patched, so you should update to version 1.2.91.

Accordion Slider

Product image for Accordion Slider.
Plugin
Accordion Slider
Plugin Slug
accordion-slider
Installations
2,000+
Vulnerability
Broken Access Control
Patched in Version
1.9.7
Severity Score
Medium
CVE
2023-40331
The vulnerability has been patched, so you should update to version 1.9.7.

Doofinder for WooCommerce

Plugin
Doofinder WP & WooCommerce Search
Plugin Slug
doofinder-for-woocommerce
Installations
2,000+
Vulnerability
Open Redirection
Patched in Version
2.0.0
Severity Score
Medium
CVE
2023-40602
The vulnerability has been patched, so you should update to version 2.0.0.

Portfolio and Projects

Product image for Portfolio and Projects.
Plugin
Portfolio and Projects
Plugin Slug
portfolio-and-projects
Installations
2,000+
Vulnerability
Broken Access Control
Patched in Version
1.3.8
Severity Score
Medium
CVE
2023-40200
The vulnerability has been patched, so you should update to version 1.3.8.

Post Ticker Ultimate

Product image for Post Ticker Ultimate.
Plugin
Post Ticker Ultimate
Plugin Slug
ticker-ultimate
Installations
2,000+
Vulnerability
Broken Access Control
Patched in Version
1.5.6
Severity Score
Medium
CVE
2023-40200
The vulnerability has been patched, so you should update to version 1.5.6.

CLUEVO LMS

Product image for CLUEVO LMS, E-Learning Platform.
Plugin
CLUEVO LMS, E-Learning Platform
Plugin Slug
cluevo-lms
Installations
700+
Vulnerability
Cross Site Request Forgery (CSRF)
Patched in Version
1.11.0
Severity Score
Medium
CVE
2023-40607
The vulnerability has been patched, so you should update to version 1.11.0.

Serial Codes Generator and Validator with WooCommerce Support

Product image for Serial Codes Generator and Validator with WooCommerce Support.
Plugin
Serial Codes Generator and Validator with WooCommerce Support
Plugin Slug
serial-codes-generator-and-validator
Installations
600+
Vulnerability
Cross Site Scripting (XSS)
Patched in Version
2.4.15
Severity Score
Medium
The vulnerability has been patched, so you should update to version 2.4.15.

Event Tickets with Ticket Scanner

Product image for Event Tickets with Ticket Scanner.
Plugin
Event Tickets with Ticket Scanner
Plugin Slug
event-tickets-with-ticket-scanner
Installations
500+
Vulnerability
Cross Site Scripting (XSS)
Patched in Version
1.5.5
Severity Score
Medium
The vulnerability has been patched, so you should update to version 1.5.5.

Products Quick View for WooCommerce

Product image for Products Quick View for WooCommerce.
Plugin
Products Quick View for WooCommerce
Plugin Slug
woocommerce-products-quick-view
Installations
100+
Vulnerability
Broken Access Control
Patched in Version
2.3.0
Severity Score
Medium
The vulnerability has been patched, so you should update to version 2.3.0.

123.chat

Product image for 123.chat – 1:1 Live Video Chat Tool Plugin.
Plugin
123.chat – 1:1 Live Video Chat Tool Plugin
Plugin Slug
123-chat-videochat
Installations
40+
Vulnerability
Cross Site Scripting (XSS)
Patched in Version
1.3.1
Severity Score
Medium
CVE
2023-4298
The vulnerability has been patched, so you should update to version 1.3.1.

Paid Memberships Pro CCBill Gateway

Plugin
Paid Memberships Pro CCBill Gateway
Plugin Slug
pmpro-ccbill
Vulnerability
Broken Access Control
Patched in Version
0.4
Severity Score
High
CVE
2023-40608
The vulnerability has been patched, so you should update to version 0.4.

WordPress Plugin Vulnerabilities — Unpatched

This section contains plugin vulnerabilities with no known fix. Until a patch is available, you are advised to deactivate the plugin, at minimum, immediately. If there is a high risk of active exploits or the plugin remains unpatched for weeks, you are advised to delete the plugin. You should also delete persistently unpatched plugins the WordPress.org repository has locked and marked “Closed” so they can no longer be downloaded and installed.

Simple URLs

Product image for Simple URLs – Link Cloaking, Product Displays, and Affiliate Link Management.
Plugin
Simple URLs – Link Cloaking, Product Displays, and Affiliate Link Management
Plugin Slug
simple-urls
Installations
5,000+
Vulnerability
Broken Access Control
Patched in Version
No Fix
Severity Score
Medium
CVE
2023-40678
The vulnerability has not been patched. You should deactivate the plugin.

Simple URLs

Product image for Simple URLs – Link Cloaking, Product Displays, and Affiliate Link Management.
Plugin
Simple URLs – Link Cloaking, Product Displays, and Affiliate Link Management
Plugin Slug
simple-urls
Installations
5,000+
Vulnerability
Cross Site Scripting (XSS)
Patched in Version
No Fix
Severity Score
Medium
CVE
2023-40674
The vulnerability has not been patched. You should deactivate the plugin.

Simple URLs

Product image for Simple URLs – Link Cloaking, Product Displays, and Affiliate Link Management.
Plugin
Simple URLs – Link Cloaking, Product Displays, and Affiliate Link Management
Plugin Slug
simple-urls
Installations
5,000+
Vulnerability
Cross Site Scripting (XSS)
Patched in Version
No Fix
Severity Score
High
CVE
2023-40667
The vulnerability has not been patched. You should deactivate the plugin.

Enhanced Ecommerce Google Analytics for WooCommerce

Product image for Enhanced Ecommerce Google Analytics for WooCommerce.
Plugin
Enhanced Ecommerce Google Analytics for WooCommerce
Plugin Slug
woo-ecommerce-tracking-for-google-and-facebook
Installations
3,000+
Vulnerability
Cross Site Request Forgery (CSRF)
Patched in Version
No Fix
Severity Score
Medium
CVE
2023-40561
The vulnerability has not been patched. You should deactivate the plugin.

GD Security Headers

Product image for GD Security Headers.
Plugin
GD Security Headers
Plugin Slug
gd-security-headers
Installations
2,000+
Vulnerability
Cross Site Scripting (XSS)
Patched in Version
No Fix
Severity Score
High
CVE
2023-40330
The vulnerability has not been patched. You should deactivate the plugin.

LINE Notify

Plugin
WP LINE Notify
Plugin Slug
wp-line-notify
Installations
2,000+
Vulnerability
Cross Site Scripting (XSS)
Patched in Version
No Fix
Severity Score
High
CVE
2023-30497
The vulnerability has not been patched. You should deactivate the plugin.

fitness calculators plugin

Product image for fitness calculators plugin.
Plugin
fitness calculators plugin
Plugin Slug
fitness-calculators
Installations
1,000+
Vulnerability
Cross Site Scripting (XSS)
Patched in Version
No Fix
Severity Score
Medium
CVE
2023-40552
The vulnerability has not been patched. You should deactivate the plugin.

Kanban Boards for WordPress

Product image for Kanban Boards for WordPress.
Plugin
Kanban Boards for WordPress
Plugin Slug
kanban
Installations
1,000+
Vulnerability
Arbitrary Code Execution
Patched in Version
No Fix
Severity Score
Critical
CVE
2023-40606
The vulnerability has not been patched. You should deactivate the plugin.

Save as PDF plugin by Pdfcrowd

Plugin
Save as PDF plugin by Pdfcrowd
Plugin Slug
save-as-pdf-by-pdfcrowd
Installations
1,000+
Vulnerability
Cross Site Scripting (XSS)
Patched in Version
No Fix
Severity Score
Medium
CVE
2023-40668
The vulnerability has not been patched. You should deactivate the plugin.

Schedule Posts Calendar

Product image for Schedule Posts Calendar.
Plugin
Schedule Posts Calendar
Plugin Slug
schedule-posts-calendar
Installations
1,000+
Vulnerability
Cross Site Request Forgery (CSRF)
Patched in Version
No Fix
Severity Score
Medium
CVE
2023-40556
The vulnerability has not been patched. You should deactivate the plugin.

Schedule Posts Calendar

Product image for Schedule Posts Calendar.
Plugin
Schedule Posts Calendar
Plugin Slug
schedule-posts-calendar
Installations
1,000+
Vulnerability
Cross Site Scripting (XSS)
Patched in Version
No Fix
Severity Score
Medium
CVE
2023-40560
The vulnerability has not been patched. You should deactivate the plugin.

Tabs & Accordion

Product image for Tabs & Accordion.
Plugin
Tabs & Accordion
Plugin Slug
tabs
Installations
1,000+
Vulnerability
Content Injection
Patched in Version
No Fix
Severity Score
Medium
CVE
2023-40557
The vulnerability has not been patched. You should deactivate the plugin.

Dynamic Pricing and Discount Rules for WooCommerce

Product image for Dynamic Pricing and Discount Rules for WooCommerce.
Plugin
Dynamic Pricing and Discount Rules for WooCommerce
Plugin Slug
woo-conditional-discount-rules-for-checkout
Installations
1,000+
Vulnerability
Cross Site Request Forgery (CSRF)
Patched in Version
No Fix
Severity Score
Medium
CVE
2023-40559
The vulnerability has not been patched. You should deactivate the plugin.

rsvpmaker

Product image for RSVPMaker.
Plugin
RSVPMaker
Plugin Slug
rsvpmaker
Installations
400+
Vulnerability
Cross Site Scripting (XSS)
Patched in Version
No Fix
Severity Score
High
CVE
2023-27616
The vulnerability has not been patched. You should deactivate the plugin.

rsvpmaker

Product image for RSVPMaker.
Plugin
RSVPMaker
Plugin Slug
rsvpmaker
Installations
400+
Vulnerability
Cross Site Scripting (XSS)
Patched in Version
No Fix
Severity Score
Medium
CVE
2023-27617
The vulnerability has not been patched. You should deactivate the plugin.

Save as Image plugin by Pdfcrowd

Plugin
Save as Image plugin by Pdfcrowd
Plugin Slug
save-as-image-by-pdfcrowd
Installations
50+
Vulnerability
Cross Site Scripting (XSS)
Patched in Version
No Fix
Severity Score
Medium
CVE
2023-40665
The vulnerability has not been patched. You should deactivate the plugin.

Typing Effect

Plugin
Typing Effect
Plugin Slug
animated-typing-effect
Vulnerability
Cross Site Scripting (XSS)
Patched in Version
No Fix
Severity Score
Medium
CVE
2023-40605
The vulnerability has not been patched and the plugin is closed. You should uninstall and delete the plugin.

Password Reset with Code for WordPress REST API

Plugin
Password Reset with Code for WordPress REST API
Plugin Slug
bdvs-password-reset
Vulnerability
Broken Authentication
Patched in Version
No Fix
Severity Score
Critical
CVE
2023-35039
The vulnerability has not been patched and the plugin is closed. You should uninstall and delete the plugin.

BigBlueButton

Plugin
BigBlueButton
Plugin Slug
bigbluebutton
Vulnerability
Cross Site Scripting (XSS)
Patched in Version
No Fix
Severity Score
Medium
The vulnerability has not been patched and the plugin is closed. You should uninstall and delete the plugin.

Carrot

Plugin
Carrot
Plugin Slug
carrrot
Vulnerability
Cross Site Scripting (XSS)
Patched in Version
No Fix
Severity Score
Medium
CVE
2023-40328
The vulnerability has not been patched and the plugin is closed. You should uninstall and delete the plugin.

Cartpauj Register Captcha

Plugin
Cartpauj Register Captcha
Plugin Slug
cartpauj-register-captcha
Vulnerability
Bypass Vulnerability
Patched in Version
No Fix
Severity Score
Medium
CVE
2023-40673
The vulnerability has not been patched and the plugin is closed. You should uninstall and delete the plugin.

Contact form 7 Custom validation

Plugin
Contact form 7 Custom validation
Plugin Slug
cf7-field-validation
Vulnerability
SQL Injection
Patched in Version
No Fix
Severity Score
High
CVE
2023-40609
The vulnerability has not been patched and the plugin is closed. You should uninstall and delete the plugin.

Cleverwise Daily Quotes

Plugin
Cleverwise Daily Quotes
Plugin Slug
cleverwise-daily-quotes
Vulnerability
Cross Site Scripting (XSS)
Patched in Version
No Fix
Severity Score
High
CVE
2023-40335
The vulnerability has not been patched and the plugin is closed. You should uninstall and delete the plugin.

Cookies by JM

Plugin
Cookies by JM
Plugin Slug
cookies-by-jm
Vulnerability
Cross Site Scripting (XSS)
Patched in Version
No Fix
Severity Score
Medium
CVE
2023-40604
The vulnerability has not been patched and the plugin is closed. You should uninstall and delete the plugin.

CT Commerce

Plugin
CT Commerce
Plugin Slug
ct-commerce
Vulnerability
Cross Site Scripting (XSS)
Patched in Version
No Fix
Severity Score
Medium
CVE
2023-40007
The vulnerability has not been patched and the plugin is closed. You should uninstall and delete the plugin.

Custom Admin Login Page | WPZest

Plugin
Custom Admin Login Page | WPZest
Plugin Slug
custom-admin-login-styler-wpzest
Vulnerability
Cross Site Scripting (XSS)
Patched in Version
No Fix
Severity Score
Medium
CVE
2023-40329
The vulnerability has not been patched and the plugin is closed. You should uninstall and delete the plugin.

DX-auto-save-images

Plugin
DX-auto-save-images
Plugin Slug
dx-auto-save-images
Vulnerability
Cross Site Request Forgery (CSRF)
Patched in Version
No Fix
Severity Score
Medium
CVE
2023-40671
The vulnerability has not been patched and the plugin is closed. You should uninstall and delete the plugin.

Mortgage Calculator Estatik

Plugin
Mortgage Calculator Estatik
Plugin Slug
estatik-mortgage-calculator
Vulnerability
Cross Site Scripting (XSS)
Patched in Version
No Fix
Severity Score
High
CVE
2023-40601
The vulnerability has not been patched and the plugin is closed. You should uninstall and delete the plugin.

Make Paths Relative

Plugin
Make Paths Relative
Plugin Slug
make-paths-relative
Vulnerability
Cross Site Request Forgery (CSRF)
Patched in Version
No Fix
Severity Score
Medium
CVE
2023-27433
The vulnerability has not been patched and the plugin is closed. You should uninstall and delete the plugin.

Simple Org Chart

Plugin
Simple Org Chart
Plugin Slug
simple-org-chart
Vulnerability
Broken Access Control
Patched in Version
No Fix
Severity Score
Medium
CVE
2023-40603
The vulnerability has not been patched and the plugin is closed. You should uninstall and delete the plugin.

Simple Org Chart

Plugin
Simple Org Chart
Plugin Slug
simple-org-chart
Vulnerability
Cross Site Request Forgery (CSRF)
Patched in Version
No Fix
Severity Score
Medium
CVE
2023-28791
The vulnerability has not been patched and the plugin is closed. You should uninstall and delete the plugin.

Simple Staff List

Plugin
Simple Staff List
Plugin Slug
simple-staff-list
Vulnerability
Cross Site Scripting (XSS)
Patched in Version
No Fix
Severity Score
Medium
CVE
2023-28790
The vulnerability has not been patched and the plugin is closed. You should uninstall and delete the plugin.

Donations Made Easy – Smart Donations

Plugin
Donations Made Easy – Smart Donations
Plugin Slug
smart-donations
Vulnerability
Cross Site Scripting (XSS)
Patched in Version
No Fix
Severity Score
High
CVE
2023-40664
The vulnerability has not been patched and the plugin is closed. You should uninstall and delete the plugin.

Sticky Social Media Icons

Plugin
Sticky Social Media Icons
Plugin Slug
sticky-social-media-icons
Vulnerability
Broken Access Control
Patched in Version
No Fix
Severity Score
Medium
CVE
2023-40672
The vulnerability has not been patched and the plugin is closed. You should uninstall and delete the plugin.

WebLibrarian

Plugin
WebLibrarian
Plugin Slug
weblibrarian
Vulnerability
Cross Site Scripting (XSS)
Patched in Version
No Fix
Severity Score
High
CVE
2023-29441
The vulnerability has not been patched and the plugin is closed. You should uninstall and delete the plugin.

Putler Connector for WooCommerce

Plugin
Putler Connector for WooCommerce
Plugin Slug
woocommerce-putler-connector
Vulnerability
Broken Access Control
Patched in Version
No Fix
Severity Score
Medium
CVE
2023-40326
The vulnerability has not been patched and the plugin is closed. You should uninstall and delete the plugin.

Putler Connector for WooCommerce

Plugin
Putler Connector for WooCommerce
Plugin Slug
woocommerce-putler-connector
Vulnerability
Broken Access Control
Patched in Version
No Fix
Severity Score
Medium
CVE
2023-40327
The vulnerability has not been patched and the plugin is closed. You should uninstall and delete the plugin.

WordPress Theme Vulnerabilities

In this section, you’ll find the latest WordPress theme vulnerabilities to be disclosed. You’ll see the same information we provided above for vulnerable plugins, and the same advice applies. If a security update exists, install it immediately. If a vulnerability remains unpatched in a theme you are actively using, you must find an alternative theme. Deactivate and delete persistently unpatched themes and those marked “Closed” in the WordPress.org theme repository. If you have a vulnerable theme installed that you are not actively using, delete it.

Bazaar Lite

Product image for Bazaar Lite.
Theme
Bazaar Lite
Theme Slug
bazaar-lite
Downloads
70,170
Vulnerability
Cross Site Scripting (XSS)
Patched in Version
1.8.6
Severity Score
High
CVE
2023-2813
The vulnerability has been patched, so you should update to version 1.8.6.

Aapna

Product image for Aapna.
Theme
Aapna
Theme Slug
aapna
Downloads
34,228
Vulnerability
Cross Site Scripting (XSS)
Patched in Version
No Fix
Severity Score
High
CVE
2023-2813
The vulnerability has not been patched. You should switch themes.

College

Product image for College.
Theme
College
Theme Slug
college
Downloads
26,976
Vulnerability
Cross Site Scripting (XSS)
Patched in Version
1.5.1
Severity Score
High
CVE
2023-2813
The vulnerability has been patched, so you should update to version 1.5.1.

BunnyPressLite

Product image for BunnyPressLite.
Theme
BunnyPressLite
Theme Slug
bunnypresslite
Downloads
17,962
Vulnerability
Cross Site Scripting (XSS)
Patched in Version
2.1
Severity Score
High
CVE
2023-2813
The vulnerability has been patched, so you should update to version 2.1.

Anfaust

Product image for Anfaust.
Theme
Anfaust
Theme Slug
anfaust
Downloads
17,345
Vulnerability
Cross Site Scripting (XSS)
Patched in Version
No Fix
Severity Score
High
CVE
2023-2813
The vulnerability has not been patched. You should switch themes.

Brain Power

Product image for Brain Power.
Theme
Brain Power
Theme Slug
brain-power
Downloads
15,015
Vulnerability
Cross Site Scripting (XSS)
Patched in Version
No Fix
Severity Score
High
CVE
2023-2813
The vulnerability has not been patched. You should switch themes.

Cafe Bistro

Product image for Cafe Bistro.
Theme
Cafe Bistro
Theme Slug
cafe-bistro
Downloads
10,047
Vulnerability
Cross Site Scripting (XSS)
Patched in Version
1.1.4
Severity Score
High
CVE
2023-2813
The vulnerability has been patched, so you should update to version 1.1.4.

Anand

Product image for Anand.
Theme
Anand
Theme Slug
anand
Downloads
8,755
Vulnerability
Cross Site Scripting (XSS)
Patched in Version
No Fix
Severity Score
High
CVE
2023-2813
The vulnerability has not been patched. You should switch themes.

Arendelle

Product image for Arendelle.
Theme
Arendelle
Theme Slug
arendelle
Downloads
8,504
Vulnerability
Cross Site Scripting (XSS)
Patched in Version
1.1.3
Severity Score
High
CVE
2023-2813
The vulnerability has been patched, so you should update to version 1.1.3.


Never worry about running a vulnerable plugin or theme again.

As you can see from this report, new WordPress plugin and theme vulnerabilities are disclosed every week. We know it can be difficult to stay on top of every reported vulnerability disclosure that matters to you, so the Themes Security Pro plugin makes it easy to ensure your site isn’t running a vulnerable theme, plugin, or version of WordPress core.

Scans Your Website Twice a Day for Vulnerabilities

Your website’s plugins, themes, and WordPress core versions are checked against the Patchstack Vulnerability Database for the latest vulnerability disclosures.

Automatically Updates if a Security Fix is Available

Paired with Version Management, iThemes Security will automatically update a plugin, theme, or WordPress core version if it has a vulnerability.

Emails You a Warning if Site Scan Detects a Vulnerability

You can receive an email report if your site is running vulnerable versions of a plugin, theme, or WordPress core. Customize the email addresses that receive scan results.

iThemes Security Pro

The Best WordPress Security Plugin to Secure & Protect WordPress Sites

WordPress currently powers over 40% of all websites, so it has become a popular target for hackers with malicious intent. The iThemes Security Pro plugin takes the guesswork out of WordPress security to make it easy to secure & protect your WordPress website. It’s like having a full-time security expert on staff who constantly monitors and protects your WordPress site for you.

Buy iThemes Security Pro


Dan Knauss
Dan Knauss

Dan Knauss is StellarWP’s Technical Content Generalist. He’s been a writer, teacher, and freelancer working in open source since the late 1990s and with WordPress since 2004.

Share via:

  • Facebook
  • Twitter
  • LinkedIn
  • More
Other related posts
wordpress vulnerability report - security
WordPress Vulnerability Report – August 30, 2023
A computer riddled with security issue alerts. There is a large, orange shield with a slash in the middle of the screen. Surrounding it are a red target, a green skull and crossbones, an orange “bug”, a triangle with an explanation point in the middle and a gray gear.
WordPress Vulnerability Report – August 16, 2023
WordPress vulnerability report
WordPress Vulnerability Report – August 9, 2023
A computer riddled with security issue alerts. There is a large, orange shield with a slash in the middle of the screen. Surrounding it are a red target, a green skull and crossbones, an orange “bug”, a triangle with an explanation point in the middle and a gray gear.
WordPress Vulnerability Report – August 2, 2023

Get updates on new themes & plugins plus special discounts

About iThemes

  • Contact Us
  • Website Accessibility Statement
  • Sitemap

Resources

  • Blog
  • Documentation
  • WordPress Tutorials
  • Free WordPress Ebooks
  • Free Webinar Library
  • Free Upcoming Webinars
  • iThemes Training
  • Affiliates

Customers

  • Member Panel Login
  • Support
  • FAQs
  • Upgrade Policy
  • Licensing
  • Terms and Conditions
  • Refund Policy

Top Products

  • BackupBuddy
  • iThemes Security Pro
  • iThemes Sync
  • Restrict Content Pro
  • WPComplete
  • WordPress Plugins
  • Content Upgrades
  • WordPress Landing Page Plugin
  • BackupBuddy Stash

iThemes Media LLC Copyright © 2023 All rights reserved | Privacy Policy

A Liquid Web Brand © 2022 All Rights Reserved.

Get the Weekly WordPress Vulnerability Report

Vulnerable WordPress plugins and themes are the #1 reason WordPress sites get hacked, but keeping track of every new plugin and theme vulnerability is hard work. Get the weekly WordPress Vulnerability Report delivered right to your inbox to help keep your website secure.

Get the Report
Share via
Facebook
Twitter
LinkedIn
Mix
Email
Print
Copy Link
Powered by Social Snap
Copy link
CopyCopied
Powered by Social Snap

Get the Weekly WordPress Vulnerability Report

Vulnerable WordPress plugins and themes are the #1 reason WordPress sites get hacked, but keeping track of every new plugin and theme vulnerability is hard work. Get the weekly WordPress Vulnerability Report delivered right to your inbox to help keep your website secure.
No spam. Unsubscribe anytime.