Menu
iThemes
WordPress Security, Backups & Maintenance
  • Products
    • iThemes Security Pro
    • BackupBuddy
    • iThemes Sync
    • Why buy from iThemes?
  • Bundles
    • Essentials Bundle
    • Solid Foundations
    • Customer Spotlights
  • Resources
    • Blog
    • WordPress 101 Tutorials
    • WordPress Ebooks
    • Weekly WordPress Vulnerability Report
    • The Ultimate Guide to Starting a Web Design Business
  • Training
    • Upcoming Webinars
    • Free Webinar Library
    • Premium Courses
    • Become a Member
    • Member Login
  • Support
    • Documentation
    • Get Help
    • Product Updates
    • Upgrade Policy
    • Contact
    • Our Mission: Make People’s Lives Awesome
  • Log In
WordPress News and Updates from iThemes
Categories
  • Product Updates
  • WordPress Backup
  • WordPress Block Editor
  • WordPress Ecommerce
  • WordPress for Freelancers
  • WordPress Security
  • WordPress Tutorials
  • WPprosper

WordPress Vulnerability Report – August 9, 2023

Written by Dan Knauss on August 9, 2023

Last Updated on August 9, 2023

Since last week, only 30 total vulnerabilities emerged in public disclosure, but they include the popular Advanced Custom Fields (ACF) plugin. ACF is used on over two million active WordPress sites. Fortunately, a patch is available immediately for ACF and 27 other plugin vulnerabilities, so run those updates if you’re affected!

Additionally, there are two plugin vulnerabilities with no patch available yet. If you use an unpatched plugin or theme, check their vendors’ intentions and progress on a security release. Suppose no patch is forthcoming or the vulnerable software has been marked “closed” and dropped from the official WordPress theme and plugin repositories. In that case, you should consider deactivation and removal in favor of alternative solutions.

WEBINAR REPLAY NOW AVAILABLE

New research from Snicco, WeWatchYourWebsite, Automattic-backed GridPane, and PatchStack claims WordPress security plugins with malware scanners are fundamentally flawed. And they’re being actively defeated by malware in the wild right now!

In this webinar replay, StellarWP technical writer Dan Knauss explains the problem with malware scanners and the WordPress security best practices you need to implement to keep your sites truly safe.

Watch the replay

WordPress Core News

WordPress 6.3 “Lionel” is out! This new release of WordPress was built to help you “create beautiful and compelling websites more efficiently than ever.” See what’s new in WordPress 6.3.

Don’t forget to fully back up your website before installing WordPress 6.3. BackupBuddy, the industry-leading data protection and recovery solution for WordPress, will help you build a strong backup strategy to manage all updates. Embrace the enhanced content creation experience of WordPress 6.3 with confidence — and a backup copy of your website safely stored on a remote server.


WordPress Core Vulnerabilities — Patched

  • No new WordPress core vulnerabilities were disclosed this week.

WordPress core is very secure when it’s properly configured and maintained. Vulnerable plugins not updated by site owners are the most common vector for attacks on WordPress websites. Our weekly WordPress Vulnerability Report, powered by Patchstack, covers new vulnerabilities that have emerged in plugins, themes, and/or WordPress core since last week’s report. Our goal is to spread awareness of emerging security threats and help you decide what to do if you find vulnerable software on your website. For a deeper analysis of recent trends in WordPress vulnerabilities and threat vectors, see our 2022 Annual Vulnerability Report.

Contents of the August 9, 2023 Report
  1. WordPress Core News
  2. WordPress Core Vulnerabilities – Patched
  3. WordPress Plugin Vulnerabilities – Patched
  4. WordPress Plugin Vulnerabilities – Unpatched
  5. WordPress Theme Vulnerabilities
  6. The Best WordPress Security Plugin to Secure & Protect WordPress Sites

These reports are published every Wednesday and include all active vulnerabilities tracked by Patchstack as of Monday since the previous report. This leaves a 48-hour window for the newest emerging vulnerabilities to be patched before full public disclosure. iThemes Security Pro users have access to vulnerability alerts emerging within this window.

Get the weekly WordPress Vulnerability Report delivered to your inbox each Wednesday.
Subscribe now

WordPress Plugin Vulnerabilities — Patched

In this section, you’ll find the most recently disclosed WordPress plugin vulnerabilities fixed with a new release from their authors and maintainers. Please apply the updates if you are affected!

These vulnerabilities have been disclosed and scored for their severity, thanks to our friends at Patchstack. Each plugin listing includes the type of vulnerability with its CVE number and CVSS severity rating with links to more technical details. You’ll also see the number of active sites using the plugin and the plugin version release that patches the vulnerability. We start with the most popular plugins, representing the largest target for attackers.

Advanced Custom Fields

Product image for Advanced Custom Fields (ACF).
Plugin
Advanced Custom Fields (ACF)
Plugin Slug
advanced-custom-fields
Installations
2,000,000+
Vulnerability
Authenticated Cross Site Scripting (XSS)
Patched in Version
6.1.8
Severity Score
Medium
The vulnerability has been patched, so you should update to version 6.1.8.

Duplicate Post

Product image for Duplicate Post.
Plugin
Duplicate Post
Plugin Slug
copy-delete-posts
Installations
200,000+
Vulnerability
Cross Site Request Forgery (CSRF) via AJAX action
Patched in Version
1.4.2
Severity Score
Medium
The vulnerability has been patched, so you should update to version 1.4.2.

TI WooCommerce Wishlist

Product image for TI WooCommerce Wishlist.
Plugin
TI WooCommerce Wishlist
Plugin Slug
ti-woocommerce-wishlist
Installations
100,000+
Vulnerability
Unauthenticated Blind SQL Injection via Rest API
Patched in Version
2.7.4
Severity Score
Critical
The vulnerability has been patched, so you should update to version 2.7.4.

Change WP Admin

Product image for Change WP Admin Login.
Plugin
Change WP Admin Login
Plugin Slug
change-wp-admin-login
Installations
90,000+
Vulnerability
Secret Login Page Disclosure
Patched in Version
1.1.4
Severity Score
Medium
CVE
2023-3604
The vulnerability has been patched, so you should update to version 1.1.4.

The Post Grid

Product image for The Post Grid – Shortcode, Gutenberg Blocks and Elementor Addon for Post Grid.
Plugin
The Post Grid – Shortcode, Gutenberg Blocks and Elementor Addon for Post Grid
Plugin Slug
the-post-grid
Installations
60,000+
Vulnerability
Cross Site Request Forgery (CSRF) Leading To CSS Change
Patched in Version
7.2.8
Severity Score
Medium
CVE
2023-39923
The vulnerability has been patched, so you should update to version 7.2.8.

PostX – Gutenberg Post Grid Blocks

Product image for PostX – Gutenberg Post Grid Blocks.
Plugin
PostX – Gutenberg Post Grid Blocks
Plugin Slug
ultimate-post
Installations
30,000+
Vulnerability
Reflected Cross Site Scripting (XSS)
Patched in Version
3.0.6
Severity Score
High
CVE
2023-3992
The vulnerability has been patched, so you should update to version 3.0.6.

Media from FTP

Product image for Media from FTP.
Plugin
Media from FTP
Plugin Slug
media-from-ftp
Installations
20,000+
Vulnerability
Improper Privilege Management
Patched in Version
11.16
Severity Score
Medium
The vulnerability has been patched, so you should update to version 11.16.

Themesflat Addons For Elementor

Product image for Themesflat Addons For Elementor.
Plugin
Themesflat Addons For Elementor
Plugin Slug
themesflat-addons-for-elementor
Installations
20,000+
Vulnerability
Unauthenticated PHP Object Injection
Patched in Version
2.0.1
Severity Score
High
CVE
2023-37390
The vulnerability has been patched, so you should update to version 2.0.1.

WP Ultimate CSV Importer

Product image for Import All Pages, Post types, Products, Orders, and Users as XML & CSV.
Plugin
Import All Pages, Post types, Products, Orders, and Users as XML & CSV
Plugin Slug
wp-ultimate-csv-importer
Installations
20,000+
Vulnerability
Authenticated Arbitrary Usermeta Update to Privilege Escalation
Patched in Version
7.9.9
Severity Score
Medium
CVE
2023-4140
The vulnerability has been patched, so you should update to version 7.9.9.

WP Ultimate CSV Importer

Product image for Import All Pages, Post types, Products, Orders, and Users as XML & CSV.
Plugin
Import All Pages, Post types, Products, Orders, and Users as XML & CSV
Plugin Slug
wp-ultimate-csv-importer
Installations
20,000+
Vulnerability
Sensitive Information Exposure via Directory Listing
Patched in Version
7.9.9
Severity Score
High
CVE
2023-4139
The vulnerability has been patched, so you should update to version 7.9.9.

WP Ultimate CSV Importer

Product image for Import All Pages, Post types, Products, Orders, and Users as XML & CSV.
Plugin
Import All Pages, Post types, Products, Orders, and Users as XML & CSV
Plugin Slug
wp-ultimate-csv-importer
Installations
20,000+
Vulnerability
Authenticated PHP file upload to Remote Code Execution (RCE)
Patched in Version
7.9.9
Severity Score
High
CVE
2023-4141
The vulnerability has been patched, so you should update to version 7.9.9.

WP Ultimate CSV Importer

Product image for Import All Pages, Post types, Products, Orders, and Users as XML & CSV.
Plugin
Import All Pages, Post types, Products, Orders, and Users as XML & CSV
Plugin Slug
wp-ultimate-csv-importer
Installations
20,000+
Vulnerability
Authenticated Remote Code Execution (RCE)
Patched in Version
7.9.9
Severity Score
High
CVE
2023-4142
The vulnerability has been patched, so you should update to version 7.9.9.

Booking Package

Product image for Booking Package.
Plugin
Booking Package
Plugin Slug
booking-package
Installations
10,000+
Vulnerability
Reflected Cross Site Scripting (XSS)
Patched in Version
1.6.02
Severity Score
High
CVE
2023-39918
The vulnerability has been patched, so you should update to version 1.6.02.

Stripe Payment Plugin for WooCommerce

Product image for Stripe Payment Plugin for WooCommerce.
Plugin
Stripe Payment Plugin for WooCommerce
Plugin Slug
payment-gateway-stripe-and-woocommerce-integration
Installations
10,000+
Vulnerability
Authentication Bypass
Patched in Version
3.7.8
Severity Score
Critical
CVE
2023-3162
The vulnerability has been patched, so you should update to version 3.7.8.

Simple Blog Card

Plugin
Simple Blog Card
Plugin Slug
simple-blog-card
Installations
3,000+
Vulnerability
Sensitive Data Exposure
Patched in Version
1.32
Severity Score
Medium
The vulnerability has been patched, so you should update to version 1.32.

Simple Blog Card

Plugin
Simple Blog Card
Plugin Slug
simple-blog-card
Installations
3,000+
Vulnerability
Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode
Patched in Version
1.31
Severity Score
Medium
The vulnerability has been patched, so you should update to version 1.31.

Leyka

Product image for Leyka.
Plugin
Leyka
Plugin Slug
leyka
Installations
2,000+
Vulnerability
Reflected Cross Site Scripting (XSS)
Patched in Version
3.30.3
Severity Score
High
CVE
2023-39314
The vulnerability has been patched, so you should update to version 3.30.3.

Photo Gallery by Ays – Responsive Image Gallery

Product image for Photo Gallery by Ays – Responsive Image Gallery.
Plugin
Photo Gallery by Ays – Responsive Image Gallery
Plugin Slug
gallery-photo-gallery
Installations
1,000+
Vulnerability
Cross Site Request Forgery (CSRF)
Patched in Version
5.2.7
Severity Score
Medium
CVE
2023-39917
The vulnerability has been patched, so you should update to version 5.2.7.

Sign-up Sheets

Product image for Sign-up Sheets.
Plugin
Sign-up Sheets
Plugin Slug
sign-up-sheets
Installations
1,000+
Vulnerability
Cross Site Request Forgery (CSRF)
Patched in Version
2.2.9
Severity Score
Medium
CVE
2023-39165
The vulnerability has been patched, so you should update to version 2.2.9.

Upload Media By URL

Plugin
Upload Media By URL
Plugin Slug
upload-media-by-url
Installations
1,000+
Vulnerability
Cross Site Request Forgery (CSRF)
Patched in Version
1.0.8
Severity Score
Medium
CVE
2023-3720
The vulnerability has been patched, so you should update to version 1.0.8.

Bus Ticket Booking with Seat Reservation

Product image for Bus Ticket Booking with Seat Reservation.
Plugin
Bus Ticket Booking with Seat Reservation
Plugin Slug
bus-ticket-booking-with-seat-reservation
Installations
900+
Vulnerability
Reflected Cross Site Scripting (XSS)
Patched in Version
5.2.4
Severity Score
High
CVE
2023-4067
The vulnerability has been patched, so you should update to version 5.2.4.

Simple Ticker

Plugin
Simple Ticker
Plugin Slug
simple-ticker
Installations
400+
Vulnerability
Authenticated (Contributor+) Stored Cross Site Scripting (XSS)
Patched in Version
3.06
Severity Score
Medium
The vulnerability has been patched, so you should update to version 3.06.

Job Board and Recruitment Plugin – JobWP

Product image for WordPress Job Board and Recruitment Plugin – JobWP.
Plugin
WordPress Job Board and Recruitment Plugin – JobWP
Plugin Slug
jobwp
Installations
300+
Vulnerability
Arbitrary File Upload
Patched in Version
2.1
Severity Score
Critical
CVE
2023-29384
The vulnerability has been patched, so you should update to version 2.1.

wpShopGermany – Protected Shops

Plugin
wpShopGermany – Protected Shops
Plugin Slug
wpshopgermany-protectedshops
Installations
40+
Vulnerability
Cross Site Scripting (XSS)
Patched in Version
2.1
Severity Score
Medium
CVE
2023-39919
The vulnerability has been patched, so you should update to version 2.1.

JetElements For Elementor

Plugin
JetElements For Elementor
Plugin Slug
jet-elements
Vulnerability
Authenticated Remote Code Execution (RCE)
Patched in Version
2.6.11
Severity Score
Critical
CVE
2023-39157
The vulnerability has been patched, so you should update to version 2.6.11.

Shop as a Customer for WooCommerce

Plugin
Shop as a Customer for WooCommerce
Plugin Slug
shop-as-a-customer-for-woocommerce
Vulnerability
Shop Manager+ Privilege Escalation
Patched in Version
1.2.4
Severity Score
High
The vulnerability has been patched, so you should update to version 1.2.4.

Shop as a Customer for WooCommerce

Plugin
Shop as a Customer for WooCommerce
Plugin Slug
shop-as-a-customer-for-woocommerce
Vulnerability
Subscriber+ Privilege Escalation
Patched in Version
1.1.8
Severity Score
High
The vulnerability has been patched, so you should update to version 1.1.8.

Simple Share Follow Button

Plugin
Simple Share Follow Button
Plugin Slug
simple-share-follow-button
Vulnerability
Authenticated (Contributor+) Stored Cross Site Scripting (XSS) via Shortcode
Patched in Version
1.04
Severity Score
Medium
The vulnerability has been patched, so you should update to version 1.04.

WordPress Plugin Vulnerabilities — Unpatched

This section contains plugin vulnerabilities with no known fix. Until a patch is available, you are advised to deactivate the plugin, at minimum, immediately. If there is a high risk of active exploits or the plugin remains unpatched for weeks, you are advised to delete the plugin. You should also delete persistently unpatched plugins the WordPress.org repository has locked and marked “Closed” so they can no longer be downloaded and installed.

Booster for Woocommerce

Product image for Booster for WooCommerce.
Plugin
Booster for WooCommerce
Plugin Slug
woocommerce-jetpack
Installations
60,000+
Vulnerability
Shop Manager+ Arbitrary Option Update
Patched in Version
No Fix
Severity Score
High
The vulnerability has not been patched. You should deactivate the plugin.

Front Editor

Product image for Guest posting / Frontend Posting wordpress plugin – WP Front User Submit / Front Editor.
Plugin
Guest posting / Frontend Posting wordpress plugin – WP Front User Submit / Front Editor
Plugin Slug
front-editor
Installations
200+
Vulnerability
Authenticated Stored Cross Site Scripting (XSS)
Patched in Version
No Fix
Severity Score
Medium
CVE
2023-1982
The vulnerability has not been patched. You should deactivate the plugin.

WordPress Theme Vulnerabilities

In this section, you’ll find the latest WordPress theme vulnerabilities to be disclosed. You’ll see the same information we provided above for vulnerable plugins, and the same advice applies. If a security update exists, install it immediately. If a vulnerability remains unpatched in a theme you are actively using, you must find an alternative theme. Deactivate and delete persistently unpatched themes and those marked “Closed” in the WordPress.org theme repository. If you have a vulnerable theme installed that you are not actively using, delete it.

  • No new WordPress theme vulnerabilities were disclosed this week.


Never worry about running a vulnerable plugin or theme again.

As you can see from this report, new WordPress plugin and theme vulnerabilities are disclosed every week. We know it can be difficult to stay on top of every reported vulnerability disclosure that matters to you, so the Themes Security Pro plugin makes it easy to ensure your site isn’t running a vulnerable theme, plugin, or version of WordPress core.

Scans Your Website Twice a Day for Vulnerabilities

Your website’s plugins, themes, and WordPress core versions are checked against the Patchstack Vulnerability Database for the latest vulnerability disclosures.

Automatically Updates if a Security Fix is Available

Paired with Version Management, iThemes Security will automatically update a plugin, theme, or WordPress core version if it has a vulnerability.

Emails You a Warning if Site Scan Detects a Vulnerability

You can receive an email report if your site is running vulnerable versions of a plugin, theme, or WordPress core. Customize the email addresses that receive scan results.

iThemes Security Pro

The Best WordPress Security Plugin to Secure & Protect WordPress Sites

WordPress currently powers over 40% of all websites, so it has become a popular target for hackers with malicious intent. The iThemes Security Pro plugin takes the guesswork out of WordPress security to make it easy to secure & protect your WordPress website. It’s like having a full-time security expert on staff who constantly monitors and protects your WordPress site for you.

Buy iThemes Security Pro


Dan Knauss
Dan Knauss

Dan Knauss is StellarWP’s Technical Content Generalist. He’s been a writer, teacher, and freelancer working in open source since the late 1990s and with WordPress since 2004.

Share via:

  • Facebook
  • Twitter
  • LinkedIn
  • More
Other related posts
WordPress vulnerability report
WordPress Vulnerability Report – September 13, 2023
WordPress Vulnerability Report
WordPress Vulnerability Report – September 6, 2023
wordpress vulnerability report - security
WordPress Vulnerability Report – August 30, 2023
WordPress Vulnerability Report
WordPress Vulnerability Report – August 23, 2023

Get updates on new themes & plugins plus special discounts

About iThemes

  • Contact Us
  • Website Accessibility Statement
  • Sitemap

Resources

  • Blog
  • Documentation
  • WordPress Tutorials
  • Free WordPress Ebooks
  • Free Webinar Library
  • Free Upcoming Webinars
  • iThemes Training
  • Affiliates

Customers

  • Member Panel Login
  • Support
  • FAQs
  • Upgrade Policy
  • Licensing
  • Terms and Conditions
  • Refund Policy

Top Products

  • BackupBuddy
  • iThemes Security Pro
  • iThemes Sync
  • Restrict Content Pro
  • WPComplete
  • WordPress Plugins
  • Content Upgrades
  • WordPress Landing Page Plugin
  • BackupBuddy Stash

iThemes Media LLC Copyright © 2023 All rights reserved | Privacy Policy

A Liquid Web Brand © 2022 All Rights Reserved.

Get the Weekly WordPress Vulnerability Report

Vulnerable WordPress plugins and themes are the #1 reason WordPress sites get hacked, but keeping track of every new plugin and theme vulnerability is hard work. Get the weekly WordPress Vulnerability Report delivered right to your inbox to help keep your website secure.

Get the Report
Share via
Facebook
Twitter
LinkedIn
Mix
Email
Print
Copy Link
Powered by Social Snap
Copy link
CopyCopied
Powered by Social Snap

Get the Weekly WordPress Vulnerability Report

Vulnerable WordPress plugins and themes are the #1 reason WordPress sites get hacked, but keeping track of every new plugin and theme vulnerability is hard work. Get the weekly WordPress Vulnerability Report delivered right to your inbox to help keep your website secure.
No spam. Unsubscribe anytime.