Menu
iThemes
WordPress Security, Backups & Maintenance
  • Products
    • iThemes Security Pro
    • BackupBuddy
    • iThemes Sync
    • Why buy from iThemes?
  • Bundles
    • Essentials Bundle
    • Plugin Suite
    • WordPress Web Designer’s Toolkit
    • Customer Spotlights
  • Resources
    • Blog
    • WordPress 101 Tutorials
    • WordPress Ebooks
    • Weekly WordPress Vulnerability Report
    • The Ultimate Guide to Starting a Web Design Business
  • Training
    • Upcoming Webinars
    • Free Webinar Library
    • Premium Courses
    • Become a Member
    • Member Login
  • Support
    • Documentation
    • Get Help
    • Product Updates
    • Upgrade Policy
    • Contact
    • Our Mission: Make People’s Lives Awesome
  • Log In
WordPress News and Updates from iThemes
Categories
  • Product Updates
  • WordPress Backup
  • WordPress Block Editor
  • WordPress Ecommerce
  • WordPress for Freelancers
  • WordPress Security
  • WordPress Tutorials
  • WPprosper

WordPress Vulnerability Report – February 2, 2022

Written by iThemes Editorial Team on February 2, 2022

Last Updated on February 2, 2022

Vulnerable plugins and themes are the #1 reason WordPress websites get hacked. The weekly WordPress Vulnerability Report powered by WPScan covers recent WordPress plugin, theme, and core vulnerabilities, and what to do if you run one of the vulnerable plugins or themes on your website.

Each vulnerability will have a severity rating of Low, Medium, High, or Critical. Responsible disclosure and reporting of vulnerabilities is an integral part of keeping the WordPress community safe. New in this report: vulnerabilities are now listed in order by the number of active installs, rather than the date of the disclosure.

Please share this post with your friends to help get the word out and make WordPress safer for everyone!

Contents of the February 2, 2022 Report
  • WordPress 5.9: Core Major Version Update Now Available
  • WordPress Plugin Vulnerabilities
    • Essential Addons for Elementor
    • Use Any Font
    • TI WooCommerce Wishlist
    • StatCounter
    • WPvivid Backup and Migration Plugin
    • LearnPress
    • WP RSS Aggregator
    • Simple Membership
    • Better Notifications for WP
    • Post Snippets
    • Blackhole for Bad Bots
    • WP Visitor Statistics (Real Time Traffic)
    • WP Accessibility Helper (WAH)
    • Asgaros Forum
    • WP Google Map
    • WHMCS Bridge
    • WP Review Slider
    • WP Ultimate CSV Importer
    • AP Custom Testimonial
    • Logo Showcase with Slick Slider
    • WP User
    • WS Form
  • Premium Plugin Vulnerabilities
    • Super Forms
    • WordPress GDPR & CCPA
    • Ti WooCommerce Wishlist Pro
    • AdSanity
  • WordPress Plugin Vulnerabilities – No Known Fix
    • Embed Swagger
    • Crazy Bone
    • WP Responsive Menu
  • WordPress Theme Vulnerabilities
  • How to Protect Your WordPress Website From Vulnerable Plugins and Themes
  • Get iThemes Security Pro with 24/7 Website Security Monitoring
Read the 2021 Annual Report
Download the Infographic

WordPress 5.9: Core Major Version Update Now Available

WordPress 5.9 “Joséphine” was released on January 25, 2022, as the first major WordPress core release of the year. The biggest thing to know about WordPress 5.9 is simply this: Full Site Editing (FSE) using the WordPress block editor is here (well, if you want to use it or your theme supports it).

WordPress 5.9 represents the largest release of Gutenberg features since the initial Gutenberg launch in WordPress 5.0. In addition, WordPress 5.9 includes 99 enhancements and 100 bug fixes.

In this post, we unpack what’s new and noteworthy in WordPress 5.9 so you can get the most out of the latest version of WordPress.

You can update to WordPress 5.9 by downloading from WordPress.org or visiting your WordPress admin dashboard > Updates and clicking Update Now.

If you have sites that have enabled automatic background updates, they should have already updated successfully. Just be sure to verify that all your WordPress sites are on WordPress 5.9.

See what’s new in WordPress 5.9

WordPress Plugin Vulnerabilities

In this section, the latest WordPress plugin vulnerabilities have been disclosed. Each plugin listing includes the type of vulnerability, the active installations, the version number if patched, and the severity rating.

Essential Addons for Elementor

Product image for Essential Addons for Elementor.
Plugin
Essential Addons for Elementor
Installations
1,000,000+
Vulnerability
Unauthenticated LFI
Patched in Version
5.0.5
Severity Score
Critical
The vulnerability has been patched, so you should update to version 5.0.5.

Use Any Font

Product image for Use Any Font | Custom Font Uploader.
Plugin
Use Any Font | Custom Font Uploader
Installations
200,000+
Vulnerability
Unauthenticated Arbitrary CSS Appending
Patched in Version
6.2.1
Severity Score
High
The vulnerability has been patched, so you should update to version 6.2.1.

TI WooCommerce Wishlist

Product image for TI WooCommerce Wishlist.
Plugin
TI WooCommerce Wishlist
Installations
100,000+
Vulnerability
Unauthenticated Blind SQL Injection
Patched in Version
1.40.1
Severity Score
High
The vulnerability has been patched, so you should update to version 1.40.1.

StatCounter

Plugin
StatCounter – Free Real Time Visitor Stats
Installations
100,000+
Vulnerability
Admin+ Stored Cross-Site Scripting
Patched in Version
2.0.7
Severity Score
Low
The vulnerability has been patched, so you should update to version 2.0.7.

WPvivid Backup and Migration Plugin

Product image for Migration, Backup, Staging – WPvivid Backup and Migration Plugin.
Plugin
Migration, Backup, Staging – WPvivid Backup and Migration Plugin
Installations
100,000+
Vulnerability
Unauthenticated Stored Cross-Site Scripting
Patched in Version
0.9.69
Severity Score
Critical
The vulnerability has been patched, so you should update to version 0.9.69.

LearnPress

Product image for LearnPress – WordPress LMS Plugin.
Plugin
LearnPress – WordPress LMS Plugin
Installations
100,000+
Vulnerability
Arbitrary Image Renaming
Patched in Version
4.1.5
Severity Score
Medium
The vulnerability has been patched, so you should update to version 4.1.5.

WP RSS Aggregator

Product image for WP RSS Aggregator – News Feeds, Autoblogging, Youtube Video Feeds and More.
Plugin
WP RSS Aggregator – News Feeds, Autoblogging, Youtube Video Feeds and More
Installations
60,000+
Vulnerability
Reflected Cross-Site Scripting (XSS)
Patched in Version
4.20
Severity Score
Medium
The vulnerability has been patched, so you should update to version 4.20.

Simple Membership

Product image for Simple Membership.
Plugin
Simple Membership
Installations
50,000+
Vulnerability
Arbitrary Member Deletion via CSRF
Patched in Version
4.0.9
Severity Score
Medium
The vulnerability has been patched, so you should update to version 4.0.9.

Better Notifications for WP

Product image for Customize WordPress Emails and Alerts – Better Notifications for WP.
Plugin
Customize WordPress Emails and Alerts – Better Notifications for WP
Installations
40,000+
Vulnerability
Email Address Disclosure
Patched in Version
1.8.7
Severity Score
Medium
The vulnerability has been patched, so you should update to version 1.8.7.

Post Snippets

Product image for Post Snippets.
Plugin
Post Snippets
Installations
30,000+
Vulnerability
CSRF to Stored Cross-Site Scripting
Patched in Version
3.1.4
Severity Score
High
The vulnerability has been patched, so you should update to version 3.1.4.

Blackhole for Bad Bots

Product image for Blackhole for Bad Bots.
Plugin
Blackhole for Bad Bots
Installations
30,000+
Vulnerability
Arbitrary IP Address Blocking via IP Spoofing
Patched in Version
3.3.2
Severity Score
High
The vulnerability has been patched, so you should update to version 3.3.2.

WP Visitor Statistics (Real Time Traffic)

Product image for WP Visitor Statistics (Real Time Traffic).
Plugin
WP Visitor Statistics (Real Time Traffic)
Installations
20,000+
Vulnerability
Arbitrary IP Address Exclusion to Stored XSS
Patched in Version
5.5
Severity Score
High
The vulnerability has been patched, so you should update to version 5.5.

WP Accessibility Helper (WAH)

Product image for WP Accessibility Helper (WAH).
Plugin
WP Accessibility Helper (WAH)
Installations
20,000+
Vulnerability
Reflected Cross-Site Scripting (XSS)
Patched in Version
0.6.0.7
Severity Score
Medium
The vulnerability has been patched, so you should update to version 0.6.0.7.

Asgaros Forum

Product image for Asgaros Forum.
Plugin
Asgaros Forum
Installations
20,000+
Vulnerability
Subscriber+ Blind SQL Injection
Patched in Version
2.0.0
Severity Score
High
The vulnerability has been patched, so you should update to version 2.0.0.

WP Google Map

Product image for Maps Plugin using Google Maps for WordPress – WP Google Map.
Plugin
Maps Plugin using Google Maps for WordPress – WP Google Map
Installations
20,000+
Vulnerability
Arbitrary Post Deletion and Plugin’s Settings Update via CSRF
Patched in Version
1.8.4
Severity Score
Medium
The vulnerability has been patched, so you should update to version 1.8.4.

WHMCS Bridge

Product image for WHMCS Bridge.
Plugin
WHMCS Bridge
Installations
10,000+
Vulnerability
Reflected Cross-Site Scripting (XSS)
Patched in Version
6.4b
Severity Score
Medium
The vulnerability has been patched, so you should update to version 6.4b.

WP Review Slider

Product image for WP Review Slider.
Plugin
WP Review Slider
Installations
10,000+
Vulnerability
Admin+ SQL Injection
Patched in Version
11.0
Severity Score
Medium
The vulnerability has been patched, so you should update to version 11.0.

WP Ultimate CSV Importer

Product image for Easy Drag And drop All Import : WP Ultimate CSV Importer.
Plugin
Easy Drag And drop All Import : WP Ultimate CSV Importer
Installations
10,000+
Vulnerability
Admin+ Stored Cross-Site Scripting
Patched in Version
6.4.3
Severity Score
Low
The vulnerability has been patched, so you should update to version 6.4.3.

AP Custom Testimonial

Product image for Testimonial WordPress Plugin – AP Custom Testimonial.
Plugin
Testimonial WordPress Plugin – AP Custom Testimonial
Installations
4,000+
Vulnerability
Reflected Cross-Site Scripting; Admin+ SQL Injection
Patched in Version
1.4.8
Severity Score
Medium
The vulnerability has been patched, so you should update to version 1.4.8.

Logo Showcase with Slick Slider

Product image for Logo Showcase with Slick Slider – Logo Carousel, Logo Slider & Logo Grid.
Plugin
Logo Showcase with Slick Slider – Logo Carousel, Logo Slider & Logo Grid
Installations
3,000+
Vulnerability
Arbitrary Media Title/Description/Alt Text/URL Update via CSRF
Patched in Version
2.0.1
Severity Score
Medium
The vulnerability has been patched, so you should update to version 2.0.1.

WP User

Product image for WP User – Custom Registration Forms, Login and User Profile.
Plugin
WP User – Custom Registration Forms, Login and User Profile
Installations
2,000+
Vulnerability
Reflected Cross-Site Scripting
Patched in Version
7.0
Severity Score
Medium
The vulnerability has been patched, so you should update to version 7.0.

WS Form

Product image for WS Form LITE – Drag & Drop Contact Form Builder for WordPress.
Plugin
WS Form LITE – Drag & Drop Contact Form Builder for WordPress
Installations
1,000+
Vulnerability
Admin+ Stored Cross-Site Scripting; Unauthenticated Stored Cross-Site Scripting
Patched in Version
1.8.176
Severity Score
High
The vulnerability has been patched, so you should update to version 1.8.176.

Premium Plugin Vulnerabilities

In this section, the latest WordPress plugin vulnerabilities have been disclosed in closed plugins. Each plugin listing includes the type of vulnerability, the severity rating, and the date of closure

Super Forms

Plugin
Super Forms – Drag & Drop Form Builder
Installations
Unknown (Premium Plugin)
Vulnerability
Reflected Cross-Site Scripting
Patched in Version
6.0.4
Severity Score
Medium
The vulnerability has been patched, so you should update to version 6.0.4.

WordPress GDPR & CCPA

Plugin
WordPress GDPR
Installations
Unknown (Premium Plugin)
Vulnerability
Authenticated Reflected Cross-Site Scripting; Unauthenticated Reflected Cross-Site Scripting
Patched in Version
1.9.27
Severity Score
Medium
The vulnerability has been patched, so you should update to version 1.9.27.

Ti WooCommerce Wishlist Pro

Plugin
TI WooCommerce Wishlist Pro
Installations
Unknown (Premium Plugin)
Vulnerability
Unauthenticated Blind SQL Injection
Patched in Version
1.40.1
Severity Score
High
The vulnerability has been patched, so you should update to version 1.40.1.

AdSanity

Plugin
AdSanity
Installations
Unknown (Premium Plugin)
Vulnerability
Contributor Arbitrary File Upload
Patched in Version
1.8.2
Severity Score
Critical
The vulnerability has been patched, so you should update to version 1.8.2.

WordPress Plugin Vulnerabilities – No Known Fix

In this section, the latest WordPress plugin vulnerabilities have been disclosed in closed plugins. Each plugin listing includes the type of vulnerability, the severity rating, and the date of closure

Embed Swagger

Plugin
Embed Swagger
Vulnerability
Reflected Cross-Site Scripting
Patched in Version
No Fix
Severity Score
Medium
The vulnerability has not been patched and the plugin is closed. You should uninstall and delete the plugin.

Crazy Bone

Plugin
Crazy Bone
Vulnerability
Unauthenticated Stored XSS
Patched in Version
No Fix
Severity Score
High
The vulnerability has not been patched and the plugin is closed. You should uninstall and delete the plugin.

WP Responsive Menu

Plugin
WP Responsive Menu
Vulnerability
Subscriber Settings Update to Stored XSS
Patched in Version
No Fix
Severity Score
High
The vulnerability has not been patched and the plugin is closed. You should uninstall and delete the plugin.

WordPress Theme Vulnerabilities

No new theme vulnerabilities were disclosed this week.

How to Protect Your WordPress Website From Vulnerable Plugins and Themes

As you can see from this report, lots of new WordPress plugin and theme vulnerabilities are disclosed each week. We know it can be difficult to stay on top of every reported vulnerability disclosure, so the iThemes Security Pro plugin makes it easy to make sure your site isn’t running a theme, plugin, or WordPress core version with a known vulnerability.

1. Install the iThemes Security Pro Plugin

The iThemes Security Pro plugin hardens your WordPress site against the most common ways that websites get hacked. With 30+ ways to secure your site in one easy to use plugin.

2. Enable the Site Scan to Check for Known Vulnerabilities

The Version Management feature in iThemes Security Pro integrates with the Site Scan to protect your site. Vulnerable themes, plugins and WordPress core versions will be automatically updated for you.

3. Activate File Change Detection

The key to quickly spotting a security breach is monitoring file changes on your website. The File Change Detection feature in iThemes Security Pro will scan your website’s files and alert you when changes occur on your website.

Get iThemes Security Pro with 24/7 Website Security Monitoring

iThemes Security Pro, our WordPress security plugin, offers 50+ ways to secure and protect your website from common WordPress security vulnerabilities. With WordPress, two-factor authentication, brute force protection, strong password enforcement, and more, you can add extra layers of security to your website.

  • Site scanner for plugin and theme vulnerabilities
  • File change detection
  • Real-time website security dashboard
  • WordPress security logs
  • Trusted devices to protect from session hijacking
  • reCAPTCHA
  • Brute force protection
  • Privilege escalation
  • Compromised passwords check & refusal

Get iThemes Security Pro

iThemes Team
iThemes Editorial Team

Each week, the team at iThemes team publishes new WordPress tutorials and resources, including the Weekly WordPress Vulnerability Report. Since 2008, iThemes has been dedicated to helping you build, maintain, and secure WordPress sites for yourself or for clients. Our mission? Make People’s Lives Awesome.

Share via:

  • Facebook
  • Twitter
  • LinkedIn
  • More
Other related posts
A security-riddled computer monitor. There is a large, orange shield with a slash in the middle of the screen. Surrounding it are a red target, a green skull and crossbones, an orange “bug”, a triangle with an explanation point in the middle and a gray gear.
WordPress Vulnerability Report – March 15, 2023
ip hack
What is an IP Hack?
Patchstack 2022 WordPress Security Review
The State of WordPress Security: Community and Collaboration Help Us All Win
wordpress-vulnerability-report
WordPress Vulnerability Report – March 8, 2023

Get updates on new themes & plugins plus special discounts

About iThemes

  • Contact Us
  • Website Accessibility Statement
  • Sitemap

Resources

  • Blog
  • Documentation
  • WordPress Tutorials
  • Free WordPress Ebooks
  • Free Webinar Library
  • Free Upcoming Webinars
  • iThemes Training
  • Affiliates

Customers

  • Member Panel Login
  • Support
  • FAQs
  • Upgrade Policy
  • Licensing
  • Terms and Conditions
  • Refund Policy

Top Products

  • BackupBuddy
  • iThemes Security Pro
  • iThemes Sync
  • Restrict Content Pro
  • WPComplete
  • WordPress Plugins
  • Content Upgrades
  • WordPress Landing Page Plugin
  • BackupBuddy Stash

iThemes Media LLC Copyright © 2023 All rights reserved | Privacy Policy

A Liquid Web Brand © 2022 All Rights Reserved.

Get the Weekly WordPress Vulnerability Report

Vulnerable WordPress plugins and themes are the #1 reason WordPress sites get hacked, but keeping track of every new plugin and theme vulnerability is hard work. Get the weekly WordPress Vulnerability Report delivered right to your inbox to help keep your website secure.

Get the Report
Share via
Facebook
Twitter
LinkedIn
Mix
Email
Print
Copy Link
Powered by Social Snap
Copy link
CopyCopied
Powered by Social Snap