Menu
iThemes
WordPress Security, Backups & Maintenance
  • Products
    • iThemes Security Pro
    • BackupBuddy
    • iThemes Sync
    • Why buy from iThemes?
  • Bundles
    • Essentials Bundle
    • Plugin Suite
    • WordPress Web Designer’s Toolkit
    • Customer Spotlights
  • Resources
    • Blog
    • WordPress 101 Tutorials
    • WordPress Ebooks
    • Weekly WordPress Vulnerability Report
    • The Ultimate Guide to Starting a Web Design Business
  • Training
    • Upcoming Webinars
    • Free Webinar Library
    • Premium Courses
    • Become a Member
    • Member Login
  • Support
    • Documentation
    • Get Help
    • Product Updates
    • Upgrade Policy
    • Contact
    • Our Mission: Make People’s Lives Awesome
  • Log In
WordPress News and Updates from iThemes
Categories
  • Product Updates
  • WordPress Backup
  • WordPress Block Editor
  • WordPress Ecommerce
  • WordPress for Freelancers
  • WordPress Security
  • WordPress Tutorials
  • WPprosper

WordPress Vulnerability Report – February 8, 2023

Written by iThemes Editorial Team on February 8, 2023

Last Updated on February 8, 2023

Vulnerable plugins and themes are the #1 reason WordPress websites get hacked. The weekly WordPress Vulnerability Report powered by WPScan covers recent WordPress plugin, theme, and core vulnerabilities and what to do if you run one of the vulnerable plugins or themes on your website.

In the past, we’ve listed vulnerabilities on a per-plugin or per-theme basis. To better describe the vulnerabilities listed, we’re now adding additional listings when a plugin has patched multiple vulnerabilities. While this makes the report somewhat longer, we feel that more information will help you understand the full scope of the vulnerabilities that have been patched so that you can more effectively make good decisions about your site’s security. We welcome your feedback!

Each vulnerability will have a severity rating of low, medium, high, or critical. Responsible disclosure and reporting of vulnerabilities is an integral part of keeping the WordPress community safe. Please share this post with your friends to help get the word out and make WordPress safer for everyone!

Contents of the February 8, 2023 Report
  • WordPress Core News
    • WordPress 6.2 Beta 1
  • WordPress Plugin Vulnerabilities
    • Ocean Extra
    • VK All in One Expansion Unit
    • Metform Elementor Contact Form Builder
    • My Sticky Elements
    • Print Invoice & Delivery Notes for WooCommerce
    • Wufoo Shortcode
    • ShortPixel Adaptive Images
    • GeoDirectory
    • Pie Register
    • Arigato Autoresponder and Newsletter
    • Donation Block For PayPal
    • Namaste! LMS
    • GS Insever Portfolio
  • WordPress Plugin Vulnerabilities – No Known Fix
    • User Activity
    • GigPress
    • Embed PDF
    • Custom Add User
    • Show-Hide / Collapse-Expand
    • List Pages Shortcode
    • Galleries by Angie Makes
    • Correos Oficial
    • Olevmedia Shortcodes
    • 0mk Shortener
  • WordPress Theme Vulnerabilities
  • The Best WordPress Security Plugin to Secure & Protect WordPress Sites

Download the Infographic

WordPress Core News

WordPress 6.1.1 was released on November 15, 2022, as a short-cycle maintenance release with 29 bug fixes in Core and 21 bug fixes for the block editor. Because this is a core update, be sure to update to WordPress 6.1.1 as soon as possible! As always, with a major release like this, it makes sense to ensure your site is backed up with BackupBuddy before updating.

WordPress 6.2 Beta 1

WordPress 6.2 Beta 1 is ready for download and testing! The current target for the final release is March 28, 2023.

  • No new WordPress core vulnerabilities were disclosed this week.

Get the weekly WordPress Vulnerability Report delivered to your inbox each Wednesday.
Subscribe now

WordPress Plugin Vulnerabilities

In this section, the latest WordPress plugin vulnerabilities have been disclosed. Each plugin listing includes the type of vulnerability, the active installations, the version number if patched, the severity rating, and the CVE.

Ocean Extra

Product image for Ocean Extra.
Plugin
Ocean Extra
Plugin Slug
ocean-extra
Installations
700,000+
Vulnerability
Contributor+ Stored XSS
Patched in Version
2.1.2
Severity Score
Medium
CVE
2023-23891
The vulnerability has been patched, so you should update to version 2.1.2.

VK All in One Expansion Unit

Product image for VK All in One Expansion Unit.
Plugin
VK All in One Expansion Unit
Plugin Slug
vk-all-in-one-expansion-unit
Installations
100,000+
Vulnerability
Contributor+ Stored XSS
Patched in Version
9.86.0.0
Severity Score
Medium
CVE
2023-0230
The vulnerability has been patched, so you should update to version 9.86.0.0.

Metform Elementor Contact Form Builder

Product image for Metform Elementor Contact Form Builder – Flexible and Design-Friendly Contact Form builder plugin for WordPress.
Plugin
Metform Elementor Contact Form Builder – Flexible and Design-Friendly Contact Form builder plugin for WordPress
Plugin Slug
metform
Installations
100,000+
Vulnerability
Unauthenticated Stored XSS
Patched in Version
3.2.0
Severity Score
High
CVE
2023-0084
The vulnerability has been patched, so you should update to version 3.2.0.

My Sticky Elements

Product image for All-in-one Floating Contact Form, Call, Chat, and 50+ Social Icon Tabs  – My Sticky Elements.
Plugin
All-in-one Floating Contact Form, Call, Chat, and 50+ Social Icon Tabs – My Sticky Elements
Plugin Slug
mystickyelements
Installations
40,000+
Vulnerability
Admin+ SQLi
Patched in Version
2.0.9
Severity Score
Medium
CVE
2023-0487
The vulnerability has been patched, so you should update to version 2.0.9.

Print Invoice & Delivery Notes for WooCommerce

Product image for Print Invoice & Delivery Notes for WooCommerce.
Plugin
Print Invoice & Delivery Notes for WooCommerce
Plugin Slug
woocommerce-delivery-notes
Installations
40,000+
Vulnerability
Reflected XSS
Patched in Version
4.7.2
Severity Score
High
CVE
2023-0479
The vulnerability has been patched, so you should update to version 4.7.2.

Wufoo Shortcode

Plugin
Wufoo Shortcode
Plugin Slug
wufoo-shortcode
Installations
20,000+
Vulnerability
Contributor+ Stored XSS via Shortcode
Patched in Version
1.52
Severity Score
Medium
CVE
2022-4679
The vulnerability has been patched, so you should update to version 1.52.

ShortPixel Adaptive Images

Product image for ShortPixel Adaptive Images – WebP, AVIF, CDN, Image Optimization.
Plugin
ShortPixel Adaptive Images – WebP, AVIF, CDN, Image Optimization
Plugin Slug
shortpixel-adaptive-images
Installations
20,000+
Vulnerability
Reflected XSS
Patched in Version
3.6.3
Severity Score
High
CVE
2023-0334
The vulnerability has been patched, so you should update to version 3.6.3.

GeoDirectory

Product image for GeoDirectory –  WordPress Business Directory Plugin and Classified Ads Listings.
Plugin
GeoDirectory – WordPress Business Directory Plugin and Classified Ads Listings
Plugin Slug
geodirectory
Installations
10,000+
Vulnerability
Admin+ SQLi
Patched in Version
2.2.24
Severity Score
Medium
CVE
2023-0278
The vulnerability has been patched, so you should update to version 2.2.24.

Pie Register

Product image for Registration Forms – User Registration Forms, Invitation-Based Registrations, Front-end User Profile, Login Form & Content Restriction.
Plugin
Registration Forms – User Registration Forms, Invitation-Based Registrations, Front-end User Profile, Login Form & Content Restriction
Plugin Slug
pie-register
Installations
4,000+
Vulnerability
Open Redirect
Patched in Version
3.8.2.3
Severity Score
Medium
CVE
2023-0552
The vulnerability has been patched, so you should update to version 3.8.2.3.

Arigato Autoresponder and Newsletter

Product image for Arigato Autoresponder and Newsletter.
Plugin
Arigato Autoresponder and Newsletter
Plugin Slug
bft-autoresponder
Installations
1,000+
Vulnerability
Admin+ Stored XSS
Patched in Version
2.1.7.2
Severity Score
Low
CVE
2023-0543
The vulnerability has been patched, so you should update to version 2.1.7.2.

Donation Block For PayPal

Product image for Donation Block For PayPal.
Plugin
Donation Block For PayPal
Plugin Slug
donations-block
Installations
800+
Vulnerability
Contributor+ Stored XSS
Patched in Version
2.1.0
Severity Score
Medium
CVE
2023-0535
The vulnerability has been patched, so you should update to version 2.1.0.

Namaste! LMS

Product image for Namaste! LMS.
Plugin
Namaste! LMS
Plugin Slug
namaste-lms
Installations
700+
Vulnerability
Admin+ Stored XSS
Patched in Version
2.5.9.4
Severity Score
Low
CVE
2023-0548
The vulnerability has been patched, so you should update to version 2.5.9.4.

GS Insever Portfolio

Product image for GS Insever Portfolio.
Plugin
GS Insever Portfolio
Plugin Slug
gs-instagram-portfolio
Installations
100+
Vulnerability
Contributor+ Stored XSS
Patched in Version
1.4.5
Severity Score
Medium
CVE
2023-0539
The vulnerability has been patched, so you should update to version 1.4.5.

WordPress Plugin Vulnerabilities – No Known Fix

This section contains plugin vulnerabilities with no known fix. Until a patch is available, immediately uninstall and delete the plugin.

User Activity

Product image for User Activity.
Plugin
User Activity
Plugin Slug
user-activity
Installations
300+
Vulnerability
IP Spoofing
Patched in Version
No Fix
Severity Score
Medium
CVE
2022-4550
The vulnerability has not been patched. You should deactivate the plugin.

GigPress

Plugin
GigPress
Plugin Slug
gigpress
Vulnerability
Subscriber+ SQLi
Patched in Version
No Fix
Severity Score
High
CVE
2023-0381
The vulnerability has not been patched and the plugin is closed. You should uninstall and delete the plugin.

Embed PDF

Plugin
Embed PDF
Plugin Slug
dirtysuds-embed-pdf
Vulnerability
Contributor+ Stored XSS via Shortcode
Patched in Version
No Fix
Severity Score
Medium
CVE
2022-4788
The vulnerability has not been patched and the plugin is closed. You should uninstall and delete the plugin.

Custom Add User

Plugin
Custom Add User
Plugin Slug
custom-add-user
Vulnerability
Reflected Cross-Site Scripting
Patched in Version
No Fix
Severity Score
High
CVE
2023-0043
The vulnerability has not been patched and the plugin is closed. You should uninstall and delete the plugin.

Show-Hide / Collapse-Expand

Plugin
Show-Hide / Collapse-Expand
Plugin Slug
show-hidecollapse-expand
Vulnerability
Contributor+ Stored XSS via Shortcode
Patched in Version
No Fix
Severity Score
Medium
CVE
2022-4829
The vulnerability has not been patched and the plugin is closed. You should uninstall and delete the plugin.

List Pages Shortcode

Plugin
List Pages Shortcode
Plugin Slug
list-pages-shortcode
Vulnerability
Contributor+ Stored XSS via Shortcode
Patched in Version
No Fix
Severity Score
Medium
CVE
2022-4757
The vulnerability has not been patched and the plugin is closed. You should uninstall and delete the plugin.

Galleries by Angie Makes

Plugin
Galleries by Angie Makes
Plugin Slug
wc-gallery
Vulnerability
Contributor+ Stored XSS via Shortcode
Patched in Version
No Fix
Severity Score
Medium
CVE
2022-4795
The vulnerability has not been patched and the plugin is closed. You should uninstall and delete the plugin.

Correos Oficial

Plugin
Correos Oficial
Plugin Slug
correosoficial
Vulnerability
Unauthenticated Arbitrary File Download
Patched in Version
No Fix
Severity Score
High
CVE
2023-0331
The vulnerability has not been patched. You should deactivate the plugin.

Olevmedia Shortcodes

Plugin
Olevmedia Shortcodes
Plugin Slug
olevmedia-shortcodes
Vulnerability
Contributor+ Stored XSS
Patched in Version
No Fix
Severity Score
Medium
CVE
2023-0168
The vulnerability has not been patched and the plugin is closed. You should uninstall and delete the plugin.

0mk Shortener

Plugin
0mk Shortener
Plugin Slug
0mk-shortener
Vulnerability
Stored XSS via CSRF
Patched in Version
No Fix
Severity Score
High
CVE
2022-2933
The vulnerability has not been patched. You should deactivate the plugin.

WordPress Theme Vulnerabilities

In this section, the latest WordPress theme vulnerabilities have been disclosed. Each theme listing includes the type of vulnerability, the active installations, the version number if patched, the severity rating, and the CVE.

  • Good news! No new WordPress theme vulnerabilities were disclosed this week.

Never worry about running a vulnerable plugin or theme again.

As you can see from this report, lots of new WordPress plugin and theme vulnerabilities are disclosed each week. We know it can be difficult to stay on top of every reported vulnerability disclosure, so the iThemes Security Pro plugin makes it easy to make sure your site isn’t running a theme, plugin, or WordPress core version with a known vulnerability.

Scans Your Website Twice a Day for Vulnerabilities

Your website’s plugins, themes, and WordPress core versions are checked against the WPScan Vulnerability Database for the latest vulnerability disclosures.

Automatically Updates if a Security Fix is Available

Paired with Version Management, iThemes Security will automatically update a plugin, theme, or WordPress core version if it has a vulnerability.

Emails You if Site Scan Detects a Vulnerability

You can receive an email report if your site is running vulnerable versions of a plugin, theme, or WordPress core. Customize the email addresses that receive scan results.

The Best WordPress Security Plugin to Secure & Protect WordPress Sites

WordPress currently powers over 40% of all websites, so it has become an easy target for hackers with malicious intent. The iThemes Security Pro plugin takes the guesswork out of WordPress security to make it easy to secure & protect your WordPress website. It’s like having a full-time security expert on staff who constantly monitors and protects your WordPress site for you.

Buy iThemes Security Pro


iThemes Team
iThemes Editorial Team

Each week, the team at iThemes team publishes new WordPress tutorials and resources, including the Weekly WordPress Vulnerability Report. Since 2008, iThemes has been dedicated to helping you build, maintain, and secure WordPress sites for yourself or for clients. Our mission? Make People’s Lives Awesome.

Share via:

  • Facebook
  • Twitter
  • LinkedIn
  • More
Other related posts
A computer riddled with security issue alerts. There is a large, orange shield with a slash in the middle of the screen. Surrounding it are a red target, a green skull and crossbones, an orange “bug”, a triangle with an explanation point in the middle and a gray gear.
WordPress Vulnerability Report – February 22, 2023
botnets
Botnets: What are They and How do They Operate
wordpress vulnerability report - security
WordPress Vulnerability Report – February 15, 2023
WordPress Security Recommendations
Top 10 WordPress Security Recommendations

Get updates on new themes & plugins plus special discounts

About iThemes

  • Contact Us
  • Website Accessibility Statement
  • Sitemap

Resources

  • Blog
  • Documentation
  • WordPress Tutorials
  • Free WordPress Ebooks
  • Free Webinar Library
  • Free Upcoming Webinars
  • iThemes Training
  • Affiliates

Customers

  • Member Panel Login
  • Support
  • FAQs
  • Upgrade Policy
  • Licensing
  • Terms and Conditions
  • Refund Policy

Top Products

  • BackupBuddy
  • iThemes Security Pro
  • iThemes Sync
  • Restrict Content Pro
  • WPComplete
  • WordPress Plugins
  • Content Upgrades
  • WordPress Landing Page Plugin
  • BackupBuddy Stash

iThemes Media LLC Copyright © 2023 All rights reserved | Privacy Policy

A Liquid Web Brand © 2022 All Rights Reserved.

Share via
Facebook
Twitter
LinkedIn
Mix
Email
Print
Copy Link
Powered by Social Snap
Copy link
CopyCopied
Powered by Social Snap

Get the Weekly WordPress Vulnerability Report

Vulnerable WordPress plugins and themes are the #1 reason WordPress sites get hacked, but keeping track of every new plugin and theme vulnerability is hard work. Get the weekly WordPress Vulnerability Report delivered right to your inbox to help keep your website secure.
No spam. Unsubscribe anytime.