Menu
iThemes
WordPress Security, Backups & Maintenance
  • Products
    • iThemes Security Pro
    • BackupBuddy
    • iThemes Sync
    • Why buy from iThemes?
  • Bundles
    • Essentials Bundle
    • Solid Foundations
    • Customer Spotlights
  • Resources
    • Blog
    • WordPress 101 Tutorials
    • WordPress Ebooks
    • Weekly WordPress Vulnerability Report
    • The Ultimate Guide to Starting a Web Design Business
  • Training
    • Upcoming Webinars
    • Free Webinar Library
    • Premium Courses
    • Become a Member
    • Member Login
  • Support
    • Documentation
    • Get Help
    • Product Updates
    • Upgrade Policy
    • Contact
    • Our Mission: Make People’s Lives Awesome
  • Log In
WordPress News and Updates from iThemes
Categories
  • Product Updates
  • WordPress Backup
  • WordPress Block Editor
  • WordPress Ecommerce
  • WordPress for Freelancers
  • WordPress Security
  • WordPress Tutorials
  • WPprosper

WordPress Vulnerability Report – August 30, 2023

Written by Dan Knauss on August 30, 2023

Last Updated on August 30, 2023

Since last week, 56 total vulnerabilities emerged in public disclosure. They may affect over two million WordPress sites. There are 28 plugin vulnerabilities with security patches, so run those updates!

Additionally, there are 28 plugin vulnerabilities with no patch available yet. If you use an unpatched plugin or theme, check their vendors’ intentions and progress on a security release. Suppose no patch is forthcoming or the vulnerable software has been marked “closed” and dropped from the official WordPress theme and plugin repositories. In that case, you should consider deactivation and removal in favor of alternative solutions.

WordPress Core News

“Lionel” was released on August 8, 2023. This release of WordPress was built to help you “create beautiful and compelling websites more efficiently than ever.” See what’s new in WordPress 6.3.

Don’t forget to fully back up your website before installing WordPress 6.3. BackupBuddy, the industry-leading data protection and recovery solution for WordPress, will help you build a strong backup strategy to manage all updates. Embrace the enhanced content creation experience of WordPress 6.3 with confidence — and a backup copy of your website safely stored on a remote server.


WordPress Core Vulnerabilities — Patched

  • No new WordPress core vulnerabilities were disclosed this week.

WordPress core is very secure when it’s properly configured and maintained. Vulnerable plugins not updated by site owners are the most common vector for attacks on WordPress websites. Our weekly WordPress Vulnerability Report, powered by Patchstack, covers new vulnerabilities that have emerged in plugins, themes, and/or WordPress core since last week’s report. Our goal is to spread awareness of emerging security threats and help you decide what to do if you find vulnerable software on your website. For a deeper analysis of recent trends in WordPress vulnerabilities and threat vectors, see our 2022 Annual Vulnerability Report.

Contents of the August 30, 2023 Report
  1. WordPress Core News
  2. WordPress Core Vulnerabilities – Patched
  3. WordPress Plugin Vulnerabilities – Patched
    1. ElementsKit Lite
    2. Hide My WP Ghost – Security Plugin
    3. Slimstat Analytics
    4. Slimstat Analytics
    5. Folders
    6. iThemes Sync
    7. FV Flowplayer Video Player
    8. Donation Forms by Charitable
    9. ReviewX
    10. URL Shortify
    11. Min Max Control
    12. Category Slider for WooCommerce
    13. Herd Effects
    14. Order Tracking Pro
    15. Order Tracking Pro
    16. DoLogin Security
    17. WooCommerce PDF Invoice Builder
    18. WooCommerce PDF Invoice Builder
    19. WP Adminify
    20. Premmerce User Roles
    21. Save as PDF plugin by Pdfcrowd
    22. Event Tickets with Ticket Scanner
    23. Push Notification for Post and BuddyPress
    24. WP VK-??????
    25. Save as Image plugin by Pdfcrowd
    26. Appointment booking addon for Gravity Forms
    27. Jupiter X Core
    28. Jupiter X Core
  4. WordPress Plugin Vulnerabilities – Unpatched
    1. Royal Elementor Addons
    2. Post and Page Builder by BoldGrid
    3. Collapse-O-Matic
    4. Master Elementor Addons
    5. Ultimate Addons for Contact Form 7
    6. URL Shortener by MyThemeShop
    7. Landing Page Builder
    8. WP Super Minify
    9. Easy Coming Soon
    10. LuckyWP Scripts Control
    11. Social Share Boost
    12. MakeStories (for Google Web Stories)
    13. Simple URLs
    14. Simple URLs
    15. Simple URLs
    16. Vertical Marquee Plugin
    17. WP users media
    18. WP Search Analytics
    19. Sitekit
    20. Olive One Click Demo Import
    21. Secure Admin IP
    22. Cartpauj Register Captcha
    23. DX-auto-save-images
    24. FTP Access
    25. GuruWalk Affiliates
    26. Lock User Account
    27. Maintenance Switch
    28. Sticky Social Media Icons
  5. WordPress Theme Vulnerabilities
  6. The Best WordPress Security Plugin to Secure & Protect WordPress Sites

These reports are published every Wednesday and include all active vulnerabilities tracked by Patchstack as of Monday since the previous report. This leaves a 48-hour window for the newest emerging vulnerabilities to be patched before full public disclosure. iThemes Security Pro users have access to vulnerability alerts emerging within this window.

Get the weekly WordPress Vulnerability Report delivered to your inbox each Wednesday.
Subscribe now

WordPress Plugin Vulnerabilities — Patched

In this section, you’ll find the most recently disclosed WordPress plugin vulnerabilities fixed with a new release from their authors and maintainers. Please apply the updates if you are affected!

These vulnerabilities have been disclosed and scored for their severity, thanks to our friends at Patchstack. Each plugin listing includes the type of vulnerability with its CVE number and CVSS severity rating with links to more technical details. You’ll also see the number of active sites using the plugin and the plugin version release that patches the vulnerability. We start with the most popular plugins, representing the largest target for attackers.

ElementsKit Lite

Product image for ElementsKit Elementor addons.
Plugin
ElementsKit Elementor addons
Plugin Slug
elementskit-lite
Installations
1,000,000+
Vulnerability
Broken Access Control
Patched in Version
2.9.1
Severity Score
Medium
CVE
2023-39993
The vulnerability has been patched, so you should update to version 2.9.1.

Hide My WP Ghost – Security Plugin

Product image for Hide My WP Ghost – Security Plugin.
Plugin
Hide My WP Ghost – Security Plugin
Plugin Slug
hide-my-wp
Installations
200,000+
Vulnerability
Bypass Vulnerability
Patched in Version
5.0.26
Severity Score
Medium
CVE
2023-34001
The vulnerability has been patched, so you should update to version 5.0.26.

Slimstat Analytics

Product image for Slimstat Analytics.
Plugin
Slimstat Analytics
Plugin Slug
wp-slimstat
Installations
100,000+
Vulnerability
Broken Access Control
Patched in Version
5.0.6
Severity Score
Medium
CVE
2023-33994
The vulnerability has been patched, so you should update to version 5.0.6.

Slimstat Analytics

Product image for Slimstat Analytics.
Plugin
Slimstat Analytics
Plugin Slug
wp-slimstat
Installations
100,000+
Vulnerability
Cross Site Scripting (XSS)
Patched in Version
5.0.9
Severity Score
Medium
CVE
2023-40676
The vulnerability has been patched, so you should update to version 5.0.9.

Folders

Product image for Folders – Unlimited Folders to Organize Media Library Folder, Pages, Posts, File Manager.
Plugin
Folders – Unlimited Folders to Organize Media Library Folder, Pages, Posts, File Manager
Plugin Slug
folders
Installations
60,000+
Vulnerability
Arbitrary File Upload
Patched in Version
2.9.3
Severity Score
Critical
CVE
2023-40204
The vulnerability has been patched, so you should update to version 2.9.3.

iThemes Sync

Product image for iThemes Sync.
Plugin
iThemes Sync
Plugin Slug
ithemes-sync
Installations
50,000+
Vulnerability
Broken Access Control
Patched in Version
2.1.14
Severity Score
Medium
CVE
2023-40001
The vulnerability has been patched, so you should update to version 2.1.14.

FV Flowplayer Video Player

Product image for FV Flowplayer Video Player.
Plugin
FV Flowplayer Video Player
Plugin Slug
fv-wordpress-flowplayer
Installations
30,000+
Vulnerability
Cross Site Scripting (XSS)
Patched in Version
7.5.39.7212
Severity Score
High
CVE
2023-4520
The vulnerability has been patched, so you should update to version 7.5.39.7212.

Donation Forms by Charitable

Product image for Donation Forms by Charitable – Donations Plugin & Fundraising Platform for WordPress.
Plugin
Donation Forms by Charitable – Donations Plugin & Fundraising Platform for WordPress
Plugin Slug
charitable
Installations
10,000+
Vulnerability
Privilege Escalation
Patched in Version
1.7.0.13
Severity Score
Critical
CVE
2023-4404
The vulnerability has been patched, so you should update to version 1.7.0.13.

ReviewX

Product image for ReviewX – Multi-criteria Rating & Reviews for WooCommerce.
Plugin
ReviewX – Multi-criteria Rating & Reviews for WooCommerce
Plugin Slug
reviewx
Installations
10,000+
Vulnerability
Broken Access Control
Patched in Version
1.6.18
Severity Score
Medium
CVE
2023-40670
The vulnerability has been patched, so you should update to version 1.6.18.

URL Shortify

Product image for URL Shortify – Simple, Powerful and Easy URL Shortener Plugin For WordPress.
Plugin
URL Shortify – Simple, Powerful and Easy URL Shortener Plugin For WordPress
Plugin Slug
url-shortify
Installations
10,000+
Vulnerability
Cross Site Scripting (XSS)
Patched in Version
1.7.6
Severity Score
High
CVE
2023-4294
The vulnerability has been patched, so you should update to version 1.7.6.

Min Max Control

Product image for Min Max Control – Min Max Quantity & Step Control for WooCommerce.
Plugin
Min Max Control – Min Max Quantity & Step Control for WooCommerce
Plugin Slug
woo-min-max-quantity-step-control-single
Installations
10,000+
Vulnerability
Cross Site Scripting (XSS)
Patched in Version
4.6
Severity Score
High
CVE
2023-4270
The vulnerability has been patched, so you should update to version 4.6.

Category Slider for WooCommerce

Product image for Category Slider for WooCommerce.
Plugin
Category Slider for WooCommerce
Plugin Slug
woo-category-slider-grid
Installations
9,000+
Vulnerability
Broken Access Control
Patched in Version
1.4.16
Severity Score
Medium
CVE
2023-41132
The vulnerability has been patched, so you should update to version 1.4.16.

Herd Effects

Product image for Herd Effects – fake notifications and social proof plugin.
Plugin
Herd Effects – fake notifications and social proof plugin
Plugin Slug
mwp-herd-effect
Installations
5,000+
Vulnerability
Cross Site Request Forgery (CSRF)
Patched in Version
5.2.4
Severity Score
Medium
CVE
2023-4318
The vulnerability has been patched, so you should update to version 5.2.4.

Order Tracking Pro

Product image for Order Tracking – WordPress Status Tracking Plugin.
Plugin
Order Tracking – WordPress Status Tracking Plugin
Plugin Slug
order-tracking
Installations
4,000+
Vulnerability
Cross Site Scripting (XSS)
Patched in Version
3.3.7
Severity Score
Medium
CVE
2023-4500
The vulnerability has been patched, so you should update to version 3.3.7.

Order Tracking Pro

Product image for Order Tracking – WordPress Status Tracking Plugin.
Plugin
Order Tracking – WordPress Status Tracking Plugin
Plugin Slug
order-tracking
Installations
4,000+
Vulnerability
Cross Site Scripting (XSS)
Patched in Version
3.3.7
Severity Score
High
CVE
2023-4471
The vulnerability has been patched, so you should update to version 3.3.7.

DoLogin Security

Plugin
DoLogin Security
Plugin Slug
dologin
Installations
3,000+
Vulnerability
Bypass Vulnerability
Patched in Version
3.7
Severity Score
Medium
The vulnerability has been patched, so you should update to version 3.7.

WooCommerce PDF Invoice Builder

Product image for WooCommerce PDF Invoice Builder, Create invoices, packing slips and more.
Plugin
WooCommerce PDF Invoice Builder, Create invoices, packing slips and more
Plugin Slug
woo-pdf-invoice-builder
Installations
3,000+
Vulnerability
Broken Access Control
Patched in Version
1.2.92
Severity Score
Medium
CVE
2023-4245
The vulnerability has been patched, so you should update to version 1.2.92.

WooCommerce PDF Invoice Builder

Product image for WooCommerce PDF Invoice Builder, Create invoices, packing slips and more.
Plugin
WooCommerce PDF Invoice Builder, Create invoices, packing slips and more
Plugin Slug
woo-pdf-invoice-builder
Installations
3,000+
Vulnerability
Cross Site Scripting (XSS)
Patched in Version
1.2.91
Severity Score
Medium
CVE
2023-4160
The vulnerability has been patched, so you should update to version 1.2.91.

WP Adminify

Product image for WP Adminify – WordPress Dashboard Customization | Custom Login | Admin Columns | Dashboard Widget | Media Library Folders.
Plugin
WP Adminify – WordPress Dashboard Customization | Custom Login | Admin Columns | Dashboard Widget | Media Library Folders
Plugin Slug
adminify
Installations
1,000+
Vulnerability
Cross Site Scripting (XSS)
Patched in Version
3.1.6
Severity Score
Medium
CVE
2023-4060
The vulnerability has been patched, so you should update to version 3.1.6.

Premmerce User Roles

Product image for Premmerce User Roles.
Plugin
Premmerce User Roles
Plugin Slug
premmerce-user-roles
Installations
1,000+
Vulnerability
Broken Access Control
Patched in Version
1.0.13
Severity Score
High
CVE
2023-41130
The vulnerability has been patched, so you should update to version 1.0.13.

Save as PDF plugin by Pdfcrowd

Plugin
Save as PDF plugin by Pdfcrowd
Plugin Slug
save-as-pdf-by-pdfcrowd
Installations
1,000+
Vulnerability
Cross Site Scripting (XSS)
Patched in Version
2.16.1
Severity Score
Medium
CVE
2023-40668
The vulnerability has been patched, so you should update to version 2.16.1.

Event Tickets with Ticket Scanner

Product image for Event Tickets with Ticket Scanner.
Plugin
Event Tickets with Ticket Scanner
Plugin Slug
event-tickets-with-ticket-scanner
Installations
600+
Vulnerability
Cross Site Scripting (XSS)
Patched in Version
1.5.5
Severity Score
Medium
The vulnerability has been patched, so you should update to version 1.5.5.

Push Notification for Post and BuddyPress

Plugin
Push Notification for Post and BuddyPress
Plugin Slug
push-notification-for-post-and-buddypress
Installations
200+
Vulnerability
Broken Access Control
Patched in Version
1.64
Severity Score
Medium
The vulnerability has been patched, so you should update to version 1.64.

WP VK-??????

Product image for WP VK-???????????/??/?????????.
Plugin
WP VK-???????????/??/?????????
Plugin Slug
wp-vk
Installations
100+
Vulnerability
Cross Site Request Forgery (CSRF)
Patched in Version
1.3.4
Severity Score
Medium
The vulnerability has been patched, so you should update to version 1.3.4.

Save as Image plugin by Pdfcrowd

Plugin
Save as Image plugin by Pdfcrowd
Plugin Slug
save-as-image-by-pdfcrowd
Installations
30+
Vulnerability
Cross Site Scripting (XSS)
Patched in Version
2.16.1
Severity Score
Medium
CVE
2023-40665
The vulnerability has been patched, so you should update to version 2.16.1.

Appointment booking addon for Gravity Forms

Plugin
gAppointments
Plugin Slug
gAppointments
Vulnerability
Cross Site Scripting (XSS)
Patched in Version
1.10.0
Severity Score
High
CVE
2023-2705
The vulnerability has been patched, so you should update to version 1.10.0.

Jupiter X Core

Plugin
JupiterX Core
Plugin Slug
jupiterx-core
Vulnerability
Arbitrary File Upload
Patched in Version
3.3.8
Severity Score
Critical
CVE
2023-38388
The vulnerability has been patched, so you should update to version 3.3.8.

Jupiter X Core

Plugin
JupiterX Core
Plugin Slug
jupiterx-core
Vulnerability
Privilege Escalation
Patched in Version
3.4.3
Severity Score
Critical
CVE
2023-38389
The vulnerability has been patched, so you should update to version 3.4.3.

WordPress Plugin Vulnerabilities — Unpatched

This section contains plugin vulnerabilities with no known fix. Until a patch is available, you are advised to deactivate the plugin, at minimum, immediately. If there is a high risk of active exploits or the plugin remains unpatched for weeks, you are advised to delete the plugin. You should also delete persistently unpatched plugins the WordPress.org repository has locked and marked “Closed” so they can no longer be downloaded and installed.

Royal Elementor Addons

Product image for Royal Elementor Addons and Templates.
Plugin
Royal Elementor Addons and Templates
Plugin Slug
royal-elementor-addons
Installations
200,000+
Vulnerability
Cross Site Request Forgery (CSRF)
Patched in Version
No Fix
Severity Score
Medium
CVE
2022-47175
The vulnerability has not been patched. You should deactivate the plugin.

Post and Page Builder by BoldGrid

Product image for Post and Page Builder by BoldGrid – Visual Drag and Drop Editor.
Plugin
Post and Page Builder by BoldGrid – Visual Drag and Drop Editor
Plugin Slug
post-and-page-builder
Installations
100,000+
Vulnerability
Cross Site Request Forgery (CSRF)
Patched in Version
No Fix
Severity Score
Medium
CVE
2023-25480
The vulnerability has not been patched. You should deactivate the plugin.

Collapse-O-Matic

Product image for Collapse-O-Matic.
Plugin
Collapse-O-Matic
Plugin Slug
jquery-collapse-o-matic
Installations
60,000+
Vulnerability
Cross Site Scripting (XSS)
Patched in Version
No Fix
Severity Score
Medium
CVE
2023-40669
The vulnerability has not been patched. You should deactivate the plugin.

Master Elementor Addons

Product image for Master Addons for Elementor.
Plugin
Master Addons for Elementor
Plugin Slug
master-addons
Installations
40,000+
Vulnerability
Broken Access Control
Patched in Version
No Fix
Severity Score
Medium
CVE
2023-40679
The vulnerability has not been patched. You should deactivate the plugin.

Ultimate Addons for Contact Form 7

Product image for Ultimate Addons for Contact Form 7.
Plugin
Ultimate Addons for Contact Form 7
Plugin Slug
ultimate-addons-for-contact-form-7
Installations
20,000+
Vulnerability
Cross Site Scripting (XSS)
Patched in Version
No Fix
Severity Score
High
CVE
2023-30493
The vulnerability has not been patched. You should deactivate the plugin.

URL Shortener by MyThemeShop

Product image for URL Shortener by MyThemeShop.
Plugin
URL Shortener by MyThemeShop
Plugin Slug
mts-url-shortener
Installations
10,000+
Vulnerability
Cross Site Scripting (XSS)
Patched in Version
No Fix
Severity Score
High
CVE
2023-30472
The vulnerability has not been patched. You should deactivate the plugin.

Landing Page Builder

Product image for Landing Page Builder – Lead Page – Optin Page – Squeeze Page – WordPress Landing Pages.
Plugin
Landing Page Builder – Lead Page – Optin Page – Squeeze Page – WordPress Landing Pages
Plugin Slug
page-builder-add
Installations
10,000+
Vulnerability
Cross Site Scripting (XSS)
Patched in Version
No Fix
Severity Score
Medium
CVE
2023-40675
The vulnerability has not been patched. You should deactivate the plugin.

WP Super Minify

Product image for WP Super Minify.
Plugin
WP Super Minify
Plugin Slug
wp-super-minify
Installations
10,000+
Vulnerability
Cross Site Request Forgery (CSRF)
Patched in Version
No Fix
Severity Score
Medium
CVE
2023-27615
The vulnerability has not been patched. You should deactivate the plugin.

Easy Coming Soon

Product image for Easy Coming Soon.
Plugin
Easy Coming Soon
Plugin Slug
easy-coming-soon
Installations
7,000+
Vulnerability
Cross Site Scripting (XSS)
Patched in Version
No Fix
Severity Score
Medium
CVE
2023-25483
The vulnerability has not been patched. You should deactivate the plugin.

LuckyWP Scripts Control

Product image for LuckyWP Scripts Control.
Plugin
LuckyWP Scripts Control
Plugin Slug
luckywp-scripts-control
Installations
6,000+
Vulnerability
Broken Access Control
Patched in Version
No Fix
Severity Score
Medium
CVE
2023-29239
The vulnerability has not been patched. You should deactivate the plugin.

Social Share Boost

Plugin
Social Share Boost
Plugin Slug
social-share-boost
Installations
6,000+
Vulnerability
Cross Site Request Forgery (CSRF)
Patched in Version
No Fix
Severity Score
Medium
CVE
2023-25033
The vulnerability has not been patched. You should deactivate the plugin.

MakeStories (for Google Web Stories)

Product image for MakeStories (for Google Web Stories).
Plugin
MakeStories (for Google Web Stories)
Plugin Slug
makestories-helper
Installations
5,000+
Vulnerability
Cross Site Request Forgery (CSRF)
Patched in Version
No Fix
Severity Score
Medium
CVE
2023-27448
The vulnerability has not been patched. You should deactivate the plugin.

Simple URLs

Product image for Simple URLs – Link Cloaking, Product Displays, and Affiliate Link Management.
Plugin
Simple URLs – Link Cloaking, Product Displays, and Affiliate Link Management
Plugin Slug
simple-urls
Installations
5,000+
Vulnerability
Broken Access Control
Patched in Version
No Fix
Severity Score
Medium
CVE
2023-40678
The vulnerability has not been patched. You should deactivate the plugin.

Simple URLs

Product image for Simple URLs – Link Cloaking, Product Displays, and Affiliate Link Management.
Plugin
Simple URLs – Link Cloaking, Product Displays, and Affiliate Link Management
Plugin Slug
simple-urls
Installations
5,000+
Vulnerability
Cross Site Scripting (XSS)
Patched in Version
No Fix
Severity Score
Medium
CVE
2023-40674
The vulnerability has not been patched. You should deactivate the plugin.

Simple URLs

Product image for Simple URLs – Link Cloaking, Product Displays, and Affiliate Link Management.
Plugin
Simple URLs – Link Cloaking, Product Displays, and Affiliate Link Management
Plugin Slug
simple-urls
Installations
5,000+
Vulnerability
Cross Site Scripting (XSS)
Patched in Version
No Fix
Severity Score
High
CVE
2023-40667
The vulnerability has not been patched. You should deactivate the plugin.

Vertical Marquee Plugin

Product image for Vertical marquee plugin.
Plugin
Vertical marquee plugin
Plugin Slug
vertical-marquee-plugin
Installations
4,000+
Vulnerability
Cross Site Scripting (XSS)
Patched in Version
No Fix
Severity Score
Medium
CVE
2023-40677
The vulnerability has not been patched. You should deactivate the plugin.

WP users media

Plugin
WP Users Media
Plugin Slug
wp-users-media
Installations
4,000+
Vulnerability
Broken Access Control
Patched in Version
No Fix
Severity Score
Medium
CVE
2023-27428
The vulnerability has not been patched. You should deactivate the plugin.

WP Search Analytics

Product image for WP Search Analytics.
Plugin
WP Search Analytics
Plugin Slug
search-analytics
Installations
2,000+
Vulnerability
Cross Site Scripting (XSS)
Patched in Version
No Fix
Severity Score
High
CVE
2023-30471
The vulnerability has not been patched. You should deactivate the plugin.

Sitekit

Product image for Sitekit.
Plugin
Sitekit
Plugin Slug
sitekit
Installations
2,000+
Vulnerability
Cross Site Scripting (XSS)
Patched in Version
No Fix
Severity Score
Medium
CVE
2023-27628
The vulnerability has not been patched. You should deactivate the plugin.

Olive One Click Demo Import

Product image for Olive One Click Demo Import.
Plugin
Olive One Click Demo Import
Plugin Slug
olive-one-click-demo-import
Installations
1,000+
Vulnerability
Arbitrary File Upload
Patched in Version
No Fix
Severity Score
Critical
CVE
2023-29102
The vulnerability has not been patched. You should deactivate the plugin.

Secure Admin IP

Product image for Secure Admin IP.
Plugin
Secure Admin IP
Plugin Slug
secure-admin-ip
Installations
1,000+
Vulnerability
Broken Access Control
Patched in Version
No Fix
Severity Score
Medium
CVE
2023-41133
The vulnerability has not been patched. You should deactivate the plugin.

Cartpauj Register Captcha

Plugin
Cartpauj Register Captcha
Plugin Slug
cartpauj-register-captcha
Vulnerability
Bypass Vulnerability
Patched in Version
No Fix
Severity Score
Medium
CVE
2023-40673
The vulnerability has not been patched and the plugin is closed. You should uninstall and delete the plugin.

DX-auto-save-images

Plugin
DX-auto-save-images
Plugin Slug
dx-auto-save-images
Vulnerability
Cross Site Request Forgery (CSRF)
Patched in Version
No Fix
Severity Score
Medium
CVE
2023-40671
The vulnerability has not been patched and the plugin is closed. You should uninstall and delete the plugin.

FTP Access

Plugin
FTP Access
Plugin Slug
ftp-access
Vulnerability
Cross Site Scripting (XSS)
Patched in Version
No Fix
Severity Score
Medium
CVE
2023-3510
The vulnerability has not been patched and the plugin is closed. You should uninstall and delete the plugin.

GuruWalk Affiliates

Plugin
GuruWalk Affiliates
Plugin Slug
guruwalk-affiliates
Vulnerability
Cross Site Scripting (XSS)
Patched in Version
No Fix
Severity Score
Medium
CVE
2023-27622
The vulnerability has not been patched. You should deactivate the plugin.

Lock User Account

Plugin
Lock User Account
Plugin Slug
lock-user-account
Vulnerability
Cross Site Request Forgery (CSRF)
Patched in Version
No Fix
Severity Score
Medium
CVE
2023-4307
The vulnerability has not been patched and the plugin is closed. You should uninstall and delete the plugin.

Maintenance Switch

Plugin
Maintenance Switch
Plugin Slug
maintenance-switch
Vulnerability
Cross Site Request Forgery (CSRF)
Patched in Version
No Fix
Severity Score
Medium
CVE
2023-29235
The vulnerability has not been patched and the plugin is closed. You should uninstall and delete the plugin.

Sticky Social Media Icons

Plugin
Sticky Social Media Icons
Plugin Slug
sticky-social-media-icons
Vulnerability
Broken Access Control
Patched in Version
No Fix
Severity Score
Medium
CVE
2023-40672
The vulnerability has not been patched and the plugin is closed. You should uninstall and delete the plugin.

WordPress Theme Vulnerabilities

In this section, you’ll find the latest WordPress theme vulnerabilities to be disclosed. You’ll see the same information we provided above for vulnerable plugins, and the same advice applies. If a security update exists, install it immediately. If a vulnerability remains unpatched in a theme you are actively using, you must find an alternative theme. Deactivate and delete persistently unpatched themes and those marked “Closed” in the WordPress.org theme repository. If you have a vulnerable theme installed that you are not actively using, delete it.

  • No new WordPress theme vulnerabilities were disclosed this week.


Never worry about running a vulnerable plugin or theme again.

As you can see from this report, new WordPress plugin and theme vulnerabilities are disclosed every week. We know it can be difficult to stay on top of every reported vulnerability disclosure that matters to you, so the Themes Security Pro plugin makes it easy to ensure your site isn’t running a vulnerable theme, plugin, or version of WordPress core.

Scans Your Website Twice a Day for Vulnerabilities

Your website’s plugins, themes, and WordPress core versions are checked against the Patchstack Vulnerability Database for the latest vulnerability disclosures.

Automatically Updates if a Security Fix is Available

Paired with Version Management, iThemes Security will automatically update a plugin, theme, or WordPress core version if it has a vulnerability.

Emails You a Warning if Site Scan Detects a Vulnerability

You can receive an email report if your site is running vulnerable versions of a plugin, theme, or WordPress core. Customize the email addresses that receive scan results.

iThemes Security Pro

The Best WordPress Security Plugin to Secure & Protect WordPress Sites

WordPress currently powers over 40% of all websites, so it has become a popular target for hackers with malicious intent. The iThemes Security Pro plugin takes the guesswork out of WordPress security to make it easy to secure & protect your WordPress website. It’s like having a full-time security expert on staff who constantly monitors and protects your WordPress site for you.

Buy iThemes Security Pro


Dan Knauss
Dan Knauss

Dan Knauss is StellarWP’s Technical Content Generalist. He’s been a writer, teacher, and freelancer working in open source since the late 1990s and with WordPress since 2004.

Share via:

  • Facebook
  • Twitter
  • LinkedIn
  • More
Other related posts
WordPress Vulnerability Report
WordPress Vulnerability Report – September 6, 2023
WordPress Vulnerability Report
WordPress Vulnerability Report – August 23, 2023
A computer riddled with security issue alerts. There is a large, orange shield with a slash in the middle of the screen. Surrounding it are a red target, a green skull and crossbones, an orange “bug”, a triangle with an explanation point in the middle and a gray gear.
WordPress Vulnerability Report – August 16, 2023
WordPress vulnerability report
WordPress Vulnerability Report – August 9, 2023

Get updates on new themes & plugins plus special discounts

About iThemes

  • Contact Us
  • Website Accessibility Statement
  • Sitemap

Resources

  • Blog
  • Documentation
  • WordPress Tutorials
  • Free WordPress Ebooks
  • Free Webinar Library
  • Free Upcoming Webinars
  • iThemes Training
  • Affiliates

Customers

  • Member Panel Login
  • Support
  • FAQs
  • Upgrade Policy
  • Licensing
  • Terms and Conditions
  • Refund Policy

Top Products

  • BackupBuddy
  • iThemes Security Pro
  • iThemes Sync
  • Restrict Content Pro
  • WPComplete
  • WordPress Plugins
  • Content Upgrades
  • WordPress Landing Page Plugin
  • BackupBuddy Stash

iThemes Media LLC Copyright © 2023 All rights reserved | Privacy Policy

A Liquid Web Brand © 2022 All Rights Reserved.

Get the Weekly WordPress Vulnerability Report

Vulnerable WordPress plugins and themes are the #1 reason WordPress sites get hacked, but keeping track of every new plugin and theme vulnerability is hard work. Get the weekly WordPress Vulnerability Report delivered right to your inbox to help keep your website secure.

Get the Report
Share via
Facebook
Twitter
LinkedIn
Mix
Email
Print
Copy Link
Powered by Social Snap
Copy link
CopyCopied
Powered by Social Snap

Get the Weekly WordPress Vulnerability Report

Vulnerable WordPress plugins and themes are the #1 reason WordPress sites get hacked, but keeping track of every new plugin and theme vulnerability is hard work. Get the weekly WordPress Vulnerability Report delivered right to your inbox to help keep your website secure.
No spam. Unsubscribe anytime.