WordPress Vulnerability Report

WordPress Vulnerability Report – January 11, 2023

Vulnerable plugins and themes are the #1 reason WordPress websites get hacked. The weekly WordPress Vulnerability Report powered by WPScan covers recent WordPress plugin, theme, and core vulnerabilities and what to do if you run one of the vulnerable plugins or themes on your website. Each vulnerability will have a severity rating of low, medium, high, or critical.

Avatar photo
SolidWP Editorial Team

Vulnerable plugins and themes are the #1 reason WordPress websites get hacked. The weekly WordPress Vulnerability Report powered by WPScan covers recent WordPress plugin, theme, and core vulnerabilities and what to do if you run one of the vulnerable plugins or themes on your website.

Each vulnerability will have a severity rating of low, medium, high, or critical. Responsible disclosure and reporting of vulnerabilities is an integral part of keeping the WordPress community safe. Please share this post with your friends to help get the word out and make WordPress safer for everyone!

WordPress Core News

WordPress 6.1.1 was released on November 15, 2022, as a short-cycle maintenance release with 29 bug fixes in Core and 21 bug fixes for the block editor. Because this is a core update, be sure to update to WordPress 6.1.1 as soon as possible! As always, with a major release like this, it makes sense to ensure your site is backed up with BackupBuddy before updating.

No new WordPress core vulnerabilities were disclosed this week.

There is a known unpatched vulnerability in WordPress core affecting all versions of WordPress. If you’re using iThemes Security, you’ve probably been alerted to this. As we are unsure when this very low-severity vulnerability will be patched, emails from iThemes Security will no longer alert for this specific vulnerability. Read our blog post about this vulnerability.

Get SolidWP tips direct in your inbox

Sign up

This field is for validation purposes and should be left unchanged.
Placeholder text
Placeholder text
Thanks

Oops something went wrong, please try submitting again

Get started with confidence — risk free, guaranteed

WordPress Plugin Vulnerabilities

In this section, the latest WordPress plugin vulnerabilities have been disclosed. Each plugin listing includes the type of vulnerability, the active installations, the version number if patched, the severity rating, and the CVE.

Widgets for Google Reviews

Plugin Slug:
wp-reviews-plugin-for-google
Installations:
100,000+
Vulnerability:
Contributor+ Stored XSS
Patched in Version:
9.8
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 9.8.

Strong Testimonials

Plugin Slug:
strong-testimonials
Installations:
100,000+
Vulnerability:
Contributor+ Stored XSS via Shortcode
Patched in Version:
3.0.3
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.0.3.

Royal Elementor Addons

Plugin Slug:
royal-elementor-addons
Installations:
100,000+
Vulnerability:
Menu Template Creation via CSRF; Subscriber+ Arbitrary Template Import; Subscriber+ Template Kit Import; Reflected XSS; Subscriber+ Arbitrary Plugin Deactivation; Subscriber+ Mega Menu Settings Update; Subscriber+ Arbitrary Import Deletion; Subscriber+ Arbitrary Plugin Activation; Subscriber+ Template Condition Update; Subscriber+ Arbitrary Template Activation; Subscriber+ Arbitrary Theme Activation
Patched in Version:
1.3.60
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.3.60.

Insert Pages

Plugin Slug:
insert-pages
Installations:
40,000+
Vulnerability:
Contributor+ Stored XSS
Patched in Version:
3.7.5
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.7.5.
Plugin Slug:
wp-extended-search
Installations:
20,000+
Vulnerability:
Contributor+ Stored XSS via Shortcode
Patched in Version:
2.1.2
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.1.2.

Pricing Tables WordPress Plugin – Easy Pricing Tables

Plugin Slug:
easy-pricing-tables
Installations:
20,000+
Vulnerability:
Contributor+ Stored XSS via Shortcode
Patched in Version:
3.2.3
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.2.3.

PDF.js Viewer

Plugin Slug:
pdfjs-viewer-shortcode
Installations:
20,000+
Vulnerability:
Contributor+ Stored XSS via Shortcode
Patched in Version:
2.1.8
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.1.8.

PPWP – WordPress Password Protect Page

Plugin Slug:
password-protect-page
Installations:
20,000+
Vulnerability:
Contributor+ Stored XSS in Shortcode
Patched in Version:
1.8.6
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.8.6.

Easy Testimonials

Plugin Slug:
easy-testimonials
Installations:
20,000+
Vulnerability:
Contributor+ Stored XSS
Patched in Version:
3.9.3
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.9.3.

Page View Count

Plugin Slug:
page-views-count
Installations:
20,000+
Vulnerability:
Contributor+ Stored XSS
Patched in Version:
2.6.1
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.6.1.

PDF Viewer

Plugin:
PDF Viewer
Plugin Slug:
pdf-viewer
Installations:
10,000+
Vulnerability:
Contributor+ Stored XSS via Shortcode
Patched in Version:
1.0.0
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.0.0.

PixCodes

Plugin:
PixCodes
Plugin Slug:
pixcodes
Installations:
10,000+
Vulnerability:
Contributor+ Stored XSS in Shortcode
Patched in Version:
2.3.7
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.3.7.

WP-ShowHide

Plugin Slug:
wp-showhide
Installations:
10,000+
Vulnerability:
Contributor+ Stored XSS via Shortcode
Patched in Version:
1.05
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.05.

miniOrange WordPress SAML SSO Premium

Plugin Slug:
miniorange-saml-20-single-sign-on
Installations:
10,000+
Vulnerability:
Open Redirect in SSO login
Patched in Version:
12.1.0
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 12.1.0.

miniOrange WordPress SAML SSO Standard

Plugin Slug:
miniorange-saml-20-single-sign-on
Installations:
10,000+
Vulnerability:
Open Redirect in SSO login
Patched in Version:
16.0.8
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 16.0.8.

miniOrange WordPress SAML SSO Premium Multisite

Plugin Slug:
miniorange-saml-20-single-sign-on
Installations:
10,000+
Vulnerability:
Open Redirect in SSO login
Patched in Version:
20.0.7
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 20.0.7.

CC Child Pages

Plugin Slug:
cc-child-pages
Installations:
10,000+
Vulnerability:
Contributor+ Stored XSS via Shortcode
Patched in Version:
1.43
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.43.

YourChannel: Everything you want in a YouTube plugin

Plugin Slug:
yourchannel
Installations:
10,000+
Vulnerability:
Contributor+ Stored XSS via Shortcode
Patched in Version:
1.2.3
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.2.3.

Bold Timeline Lite

Plugin Slug:
bold-timeline-lite
Installations:
10,000+
Vulnerability:
Contributor+ Stored XSS via Shortcode
Patched in Version:
1.1.5
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.1.5.

Clean Login

Plugin Slug:
clean-login
Installations:
10,000+
Vulnerability:
Contributor+ Stored XSS via Shortcode
Patched in Version:
1.13.7
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.13.7.

CPO Companion

Plugin Slug:
cpo-companion
Installations:
10,000+
Vulnerability:
Admin+ Stored XSS; Contributor+ Stored XSS via Shortcode
Patched in Version:
1.1.0
Severity Score:
Low
The vulnerability has been patched, so you should update to version 1.1.0.

Portfolio for Elementor, Image Gallery & Post Grid | PowerFolio

Plugin Slug:
portfolio-elementor
Installations:
10,000+
Vulnerability:
Contributor+ Stored XSS via Shortcode
Patched in Version:
2.3.1
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.3.1.

Themify Shortcodes

Plugin Slug:
themify-shortcodes
Installations:
10,000+
Vulnerability:
Contributor+ Stored XSS via Shortcode
Patched in Version:
2.0.8
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.0.8.

Event Manager and Tickets Selling Plugin for WooCommerce

Plugin Slug:
mage-eventpress
Installations:
9,000+
Vulnerability:
Contributor+ Stored XSS
Patched in Version:
3.8.0
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.8.0.

WP Social Widget

Plugin Slug:
wp-social-widget
Installations:
9,000+
Vulnerability:
Contributor+ Stored XSS
Patched in Version:
2.2.4
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.2.4.

Icon Widget

Plugin Slug:
icon-widget
Installations:
9,000+
Vulnerability:
Contributor+ Stored XSS via Shortcode
Patched in Version:
1.3.0
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.3.0.

Blog Designer – Post and Widget

Plugin Slug:
blog-designer-for-post-and-widget
Installations:
9,000+
Vulnerability:
Contributor+ Stored XSS via Shortcode
Patched in Version:
2.4.1
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.4.1.

Post Category Image With Grid and Slider

Plugin Slug:
post-category-image-with-grid-and-slider
Installations:
3,000+
Vulnerability:
Contributor+ Stored XSS via Shortcode
Patched in Version:
1.4.8
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.4.8.

Survey Maker

Plugin Slug:
survey-maker
Installations:
3,000+
Vulnerability:
Unauthenticated Stored XSS
Patched in Version:
3.1.4
Severity Score:
High
The vulnerability has been patched, so you should update to version 3.1.4.

WooCommerce Chained Products

Plugin Slug:
woocommerce-chained-products
Vulnerability:
Unauthenticated Arbitrary Options Update to 'no'
Patched in Version:
2.12.0
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.12.0.
Plugin Slug:
justified-gallery
Vulnerability:
Contributor+ Stored XSS via Shortcode
Patched in Version:
1.7.1
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.7.1.

AAWP

Plugin Slug:
aawp
Vulnerability:
Unsafe URL Handling
Patched in Version:
3.12.3
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.12.3.

WordPress Plugin Vulnerabilities – No Known Fix

This section contains plugin vulnerabilities with no known fix. Until a patch is available, immediately uninstall and delete the plugin.

Members Import

Plugin Slug:
members-import
Vulnerability:
XSS via Imported CSV
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched and the plugin is closed. You should uninstall and delete the plugin.
Plugin Slug:
cpt-bootstrap-carousel
Vulnerability:
Contributor+ Stored XSS via Shortcode
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched and the plugin is closed. You should uninstall and delete the plugin.

JetWidgets for Elementor

Plugin Slug:
jetwidgets-for-elementor
Vulnerability:
Settings Update via CSRF
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched and the plugin is closed. You should uninstall and delete the plugin.

MediaElement.js – HTML5 Video & Audio Player

Plugin Slug:
media-element-html5-video-and-audio-player
Vulnerability:
Contributor+ Stored XSS via Shortcode
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched and the plugin is closed. You should uninstall and delete the plugin.

Social Sharing Toolkit

Plugin Slug:
social-sharing-toolkit
Vulnerability:
Contributor+ Stored XSS via Shortcode
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched and the plugin is closed. You should uninstall and delete the plugin.

Accordion Shortcodes

Plugin Slug:
accordion-shortcodes
Vulnerability:
Contributor+ Stored XSS via Shortcode
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched and the plugin is closed. You should uninstall and delete the plugin.

FL3R FeelBox

Plugin Slug:
fl3r-feelbox
Vulnerability:
Settings Update via CSRF to Stored XSS; Moods Reset via CSRF
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched and the plugin is closed. You should uninstall and delete the plugin.

WordPress Theme Vulnerabilities

In this section, the latest WordPress theme vulnerabilities have been disclosed. Each theme listing includes the type of vulnerability, the active installations, the version number if patched, the severity rating, and the CVE.

No new WordPress theme vulnerabilities were disclosed this week.

Solid Security is part of Solid Suite — The best foundation for WordPress websites.

Every WordPress site needs security, backups, and management tools. That’s Solid Suite — an integrated bundle of three plugins: Solid Security, Solid Backups, and Solid Central. You also get access to Solid Academy’s learning resources for WordPress professionals. Build your next WordPress website on a solid foundation with Solid Suite!

Get Solid Security

Did you like this article? Spread the word: