Menu
iThemes
WordPress Security, Backups & Maintenance
  • Products
    • iThemes Security Pro
    • BackupBuddy
    • iThemes Sync
    • Why buy from iThemes?
  • Bundles
    • Essentials Bundle
    • Plugin Suite
    • WordPress Web Designer’s Toolkit
    • Customer Spotlights
  • Resources
    • Blog
    • WordPress 101 Tutorials
    • WordPress Ebooks
    • Weekly WordPress Vulnerability Report
    • The Ultimate Guide to Starting a Web Design Business
  • Training
    • Upcoming Webinars
    • Free Webinar Library
    • Premium Courses
    • Become a Member
    • Member Login
  • Support
    • Documentation
    • Get Help
    • Product Updates
    • Upgrade Policy
    • Contact
    • Our Mission: Make People’s Lives Awesome
  • Log In
WordPress News and Updates from iThemes
Categories
  • Product Updates
  • WordPress Backup
  • WordPress Block Editor
  • WordPress Ecommerce
  • WordPress for Freelancers
  • WordPress Security
  • WordPress Tutorials
  • WPprosper

WordPress Vulnerability Report – January 11, 2023

Written by iThemes Editorial Team on January 11, 2023

Last Updated on January 11, 2023

Vulnerable plugins and themes are the #1 reason WordPress websites get hacked. The weekly WordPress Vulnerability Report powered by WPScan covers recent WordPress plugin, theme, and core vulnerabilities and what to do if you run one of the vulnerable plugins or themes on your website.

Each vulnerability will have a severity rating of low, medium, high, or critical. Responsible disclosure and reporting of vulnerabilities is an integral part of keeping the WordPress community safe. Please share this post with your friends to help get the word out and make WordPress safer for everyone!

Contents of the January 11, 2023 Report
  • The Future of Authentication is Passkeys! Login to your WordPress site with Biometrics only available in iThemes Security Pro
  • WordPress Core News
  • WordPress Plugin Vulnerabilities
    • Widgets for Google Reviews
    • Strong Testimonials
    • Royal Elementor Addons
    • Simple Sitemap
    • RSS Aggregator by Feedzy
    • Insert Pages
    • News & Blog Designer Pack
    • Revive Old Posts – Social Media Auto Post and Scheduling Plugin
    • WP Extended Search
    • Pricing Tables WordPress Plugin – Easy Pricing Tables
    • PDF.js Viewer
    • PPWP – WordPress Password Protect Page
    • Easy Testimonials
    • Page View Count
    • Post Grid, Post Carousel, & List Category Posts
    • PDF Viewer
    • PixCodes
    • WP-ShowHide
    • miniOrange WordPress SAML SSO Premium
    • miniOrange WordPress SAML SSO Standard
    • miniOrange WordPress SAML SSO Premium Multisite
    • CC Child Pages
    • YourChannel: Everything you want in a YouTube plugin
    • Bold Timeline Lite
    • Clean Login
    • Custom User Profile Fields for User Registration & Member Frontend Profiles with Paid Memberships Pro
    • CPO Companion
    • Portfolio for Elementor, Image Gallery & Post Grid | PowerFolio
    • Themify Shortcodes
    • Event Manager and Tickets Selling Plugin for WooCommerce
    • WP Social Widget
    • Icon Widget
    • WP Tabs
    • Blog Designer – Post and Widget
    • Post Category Image With Grid and Slider
    • Survey Maker
    • Posts List Designer by Category
    • Membership For WooCommerce
    • WooCommerce Chained Products
    • Justified Gallery
    • AAWP
  • WordPress Plugin Vulnerabilities – No Known Fix
    • Members Import
    • CPT Bootstrap Carousel
    • JetWidgets for Elementor
    • MediaElement.js – HTML5 Video & Audio Player
    • Social Sharing Toolkit
    • Accordion Shortcodes
    • FL3R FeelBox
  • WordPress Theme Vulnerabilities
  • The Best WordPress Security Plugin to Secure & Protect WordPress Sites

The Future of Authentication is Passkeys! Login to your WordPress site with Biometrics only available in iThemes Security Pro

The problems of brute force attacks through credential stuffing, phishing attacks, and reused passwords have made our digital lives less secure. We’ve all tried to encourage 2-factor authentication as a protection, but less than 30% of users actually use 2FA. Password-based logins are a problem.

The future of authentication is passkeys, and iThemes Security Pro is the first to bring this breakthrough technology to WordPress sites. Using breakthrough WebAuthn technology based on public/private cryptography, passkeys make passwords obsolete. Now, website admins and end users can have secure logins without the inconvenience of additional two-factor apps, password managers, or complex password requirements.

Learn More About Passkeys

WordPress Core News

WordPress 6.1.1 was released on November 15, 2022, as a short-cycle maintenance release with 29 bug fixes in Core and 21 bug fixes for the block editor. Because this is a core update, be sure to update to WordPress 6.1.1 as soon as possible! As always, with a major release like this, it makes sense to ensure your site is backed up with BackupBuddy before updating.

  • No new WordPress core vulnerabilities were disclosed this week.

There is a known unpatched vulnerability in WordPress core affecting all versions of WordPress. If you’re using iThemes Security, you’ve probably been alerted to this. As we are unsure when this very low-severity vulnerability will be patched, emails from iThemes Security will no longer alert for this specific vulnerability. Read our blog post about this vulnerability.

Get the weekly WordPress Vulnerability Report delivered to your inbox each Wednesday.
Subscribe now

WordPress Plugin Vulnerabilities

In this section, the latest WordPress plugin vulnerabilities have been disclosed. Each plugin listing includes the type of vulnerability, the active installations, the version number if patched, the severity rating, and the CVE.

Widgets for Google Reviews

Product image for Widgets for Google Reviews.
Plugin
Widgets for Google Reviews
Plugin Slug
wp-reviews-plugin-for-google
Installations
100,000+
Vulnerability
Contributor+ Stored XSS
Patched in Version
9.8
Severity Score
Medium
CVE
2022-4470
The vulnerability has been patched, so you should update to version 9.8.

Strong Testimonials

Product image for Strong Testimonials.
Plugin
Strong Testimonials
Plugin Slug
strong-testimonials
Installations
100,000+
Vulnerability
Contributor+ Stored XSS via Shortcode
Patched in Version
3.0.3
Severity Score
Medium
CVE
2022-4717
The vulnerability has been patched, so you should update to version 3.0.3.

Royal Elementor Addons

Product image for Royal Elementor Addons (Elementor Templates, Post Grid, Mega Menu & Header Footer Builder, WooCommerce Builder, Product Grid, Slider, Parallax Image & other Free Elementor Widgets).
Plugin
Royal Elementor Addons (Elementor Templates, Post Grid, Mega Menu & Header Footer Builder, WooCommerce Builder, Product Grid, Slider, Parallax Image & other Free Elementor Widgets)
Plugin Slug
royal-elementor-addons
Installations
100,000+
Vulnerability
Menu Template Creation via CSRF; Subscriber+ Arbitrary Template Import; Subscriber+ Template Kit Import; Reflected XSS; Subscriber+ Arbitrary Plugin Deactivation; Subscriber+ Mega Menu Settings Update; Subscriber+ Arbitrary Import Deletion; Subscriber+ Arbitrary Plugin Activation; Subscriber+ Template Condition Update; Subscriber+ Arbitrary Template Activation; Subscriber+ Arbitrary Theme Activation
Patched in Version
1.3.60
Severity Score
Medium
CVE
2022-4707
The vulnerability has been patched, so you should update to version 1.3.60.

Simple Sitemap

Product image for Simple Sitemap – Create a Responsive HTML Sitemap.
Plugin
Simple Sitemap – Create a Responsive HTML Sitemap
Plugin Slug
simple-sitemap
Installations
90,000+
Vulnerability
Contributor+ Stored XSS
Patched in Version
3.5.8
Severity Score
Medium
CVE
2022-4472
The vulnerability has been patched, so you should update to version 3.5.8.

RSS Aggregator by Feedzy

Product image for RSS Aggregator by Feedzy – Powerful WP Autoblogging and News Aggregator.
Plugin
RSS Aggregator by Feedzy – Powerful WP Autoblogging and News Aggregator
Plugin Slug
feedzy-rss-feeds
Installations
50,000+
Vulnerability
Contributor+ Stored XSS
Patched in Version
4.1.1
Severity Score
Medium
CVE
2022-4667
The vulnerability has been patched, so you should update to version 4.1.1.

Insert Pages

Plugin
Insert Pages
Plugin Slug
insert-pages
Installations
40,000+
Vulnerability
Contributor+ Stored XSS
Patched in Version
3.7.5
Severity Score
Medium
CVE
2022-4483
The vulnerability has been patched, so you should update to version 3.7.5.

News & Blog Designer Pack

Product image for News & Blog Designer Pack – WordPress Blog Plugin — (Blog Post Grid, Blog Post Slider, Blog Post Carousel, Blog Post Ticker, Blog Post Masonry).
Plugin
News & Blog Designer Pack – WordPress Blog Plugin — (Blog Post Grid, Blog Post Slider, Blog Post Carousel, Blog Post Ticker, Blog Post Masonry)
Plugin Slug
blog-designer-pack
Installations
30,000+
Vulnerability
Contributor+ Stored XSS via Shortcode
Patched in Version
3.3
Severity Score
Medium
CVE
2022-4792
The vulnerability has been patched, so you should update to version 3.3.

Revive Old Posts – Social Media Auto Post and Scheduling Plugin

Product image for Revive Old Posts – Social Media Auto Post and Scheduling Plugin.
Plugin
Revive Old Posts – Social Media Auto Post and Scheduling Plugin
Plugin Slug
tweet-old-post
Installations
30,000+
Vulnerability
PHP Object Injection
Patched in Version
9.0.11
Severity Score
Low
CVE
2022-4680
The vulnerability has been patched, so you should update to version 9.0.11.

WP Extended Search

Product image for WP Extended Search.
Plugin
WP Extended Search
Plugin Slug
wp-extended-search
Installations
20,000+
Vulnerability
Contributor+ Stored XSS via Shortcode
Patched in Version
2.1.2
Severity Score
Medium
CVE
2022-4649
The vulnerability has been patched, so you should update to version 2.1.2.

Pricing Tables WordPress Plugin – Easy Pricing Tables

Product image for Pricing Tables WordPress Plugin – Easy Pricing Tables.
Plugin
Pricing Tables WordPress Plugin – Easy Pricing Tables
Plugin Slug
easy-pricing-tables
Installations
20,000+
Vulnerability
Contributor+ Stored XSS via Shortcode
Patched in Version
3.2.3
Severity Score
Medium
CVE
2022-4654
The vulnerability has been patched, so you should update to version 3.2.3.

PDF.js Viewer

Product image for PDF.js Viewer.
Plugin
PDF.js Viewer
Plugin Slug
pdfjs-viewer-shortcode
Installations
20,000+
Vulnerability
Contributor+ Stored XSS via Shortcode
Patched in Version
2.1.8
Severity Score
Medium
CVE
2022-4670
The vulnerability has been patched, so you should update to version 2.1.8.

PPWP – WordPress Password Protect Page

Product image for PPWP – Password Protect Pages.
Plugin
PPWP – Password Protect Pages
Plugin Slug
password-protect-page
Installations
20,000+
Vulnerability
Contributor+ Stored XSS in Shortcode
Patched in Version
1.8.6
Severity Score
Medium
CVE
2022-4626
The vulnerability has been patched, so you should update to version 1.8.6.

Easy Testimonials

Product image for Easy Testimonials.
Plugin
Easy Testimonials
Plugin Slug
easy-testimonials
Installations
20,000+
Vulnerability
Contributor+ Stored XSS
Patched in Version
3.9.3
Severity Score
Medium
CVE
2022-4577
The vulnerability has been patched, so you should update to version 3.9.3.

Page View Count

Product image for Page View Count.
Plugin
Page View Count
Plugin Slug
page-views-count
Installations
20,000+
Vulnerability
Contributor+ Stored XSS
Patched in Version
2.6.1
Severity Score
Medium
CVE
2023-0095
The vulnerability has been patched, so you should update to version 2.6.1.

Post Grid, Post Carousel, & List Category Posts

Product image for Post Grid, Post Carousel, & List Category Posts – by Smart Post Show.
Plugin
Post Grid, Post Carousel, & List Category Posts – by Smart Post Show
Plugin Slug
post-carousel
Installations
20,000+
Vulnerability
Contributor+ Stored XSS
Patched in Version
2.4.19
Severity Score
Medium
CVE
2023-0097
The vulnerability has been patched, so you should update to version 2.4.19.

PDF Viewer

Product image for PDF Viewer.
Plugin
PDF Viewer
Plugin Slug
pdf-viewer
Installations
10,000+
Vulnerability
Contributor+ Stored XSS via Shortcode
Patched in Version
1.0.0
Severity Score
Medium
CVE
2023-0033
The vulnerability has been patched, so you should update to version 1.0.0.

PixCodes

Plugin
PixCodes
Plugin Slug
pixcodes
Installations
10,000+
Vulnerability
Contributor+ Stored XSS in Shortcode
Patched in Version
2.3.7
Severity Score
Medium
CVE
2022-4671
The vulnerability has been patched, so you should update to version 2.3.7.

WP-ShowHide

Product image for WP-ShowHide.
Plugin
WP-ShowHide
Plugin Slug
wp-showhide
Installations
10,000+
Vulnerability
Contributor+ Stored XSS via Shortcode
Patched in Version
1.05
Severity Score
Medium
CVE
2022-4825
The vulnerability has been patched, so you should update to version 1.05.

miniOrange WordPress SAML SSO Premium

Product image for SAML Single Sign On – SSO Login.
Plugin
SAML Single Sign On – SSO Login
Plugin Slug
miniorange-saml-20-single-sign-on
Installations
10,000+
Vulnerability
Open Redirect in SSO login
Patched in Version
12.1.0
Severity Score
Medium
CVE
2022-4496
The vulnerability has been patched, so you should update to version 12.1.0.

miniOrange WordPress SAML SSO Standard

Product image for SAML Single Sign On – SSO Login.
Plugin
SAML Single Sign On – SSO Login
Plugin Slug
miniorange-saml-20-single-sign-on
Installations
10,000+
Vulnerability
Open Redirect in SSO login
Patched in Version
16.0.8
Severity Score
Medium
CVE
2022-4496
The vulnerability has been patched, so you should update to version 16.0.8.

miniOrange WordPress SAML SSO Premium Multisite

Product image for SAML Single Sign On – SSO Login.
Plugin
SAML Single Sign On – SSO Login
Plugin Slug
miniorange-saml-20-single-sign-on
Installations
10,000+
Vulnerability
Open Redirect in SSO login
Patched in Version
20.0.7
Severity Score
Medium
CVE
2022-4496
The vulnerability has been patched, so you should update to version 20.0.7.

CC Child Pages

Product image for CC Child Pages.
Plugin
CC Child Pages
Plugin Slug
cc-child-pages
Installations
10,000+
Vulnerability
Contributor+ Stored XSS via Shortcode
Patched in Version
1.43
Severity Score
Medium
CVE
2022-4776
The vulnerability has been patched, so you should update to version 1.43.

YourChannel: Everything you want in a YouTube plugin

Product image for YourChannel: Everything you want in a YouTube plugin..
Plugin
YourChannel: Everything you want in a YouTube plugin.
Plugin Slug
yourchannel
Installations
10,000+
Vulnerability
Contributor+ Stored XSS via Shortcode
Patched in Version
1.2.3
Severity Score
Medium
CVE
2022-4833
The vulnerability has been patched, so you should update to version 1.2.3.

Bold Timeline Lite

Product image for Bold Timeline Lite.
Plugin
Bold Timeline Lite
Plugin Slug
bold-timeline-lite
Installations
10,000+
Vulnerability
Contributor+ Stored XSS via Shortcode
Patched in Version
1.1.5
Severity Score
Medium
CVE
2022-4828
The vulnerability has been patched, so you should update to version 1.1.5.

Clean Login

Product image for Clean Login.
Plugin
Clean Login
Plugin Slug
clean-login
Installations
10,000+
Vulnerability
Contributor+ Stored XSS via Shortcode
Patched in Version
1.13.7
Severity Score
Medium
CVE
2022-4838
The vulnerability has been patched, so you should update to version 1.13.7.

Custom User Profile Fields for User Registration & Member Frontend Profiles with Paid Memberships Pro

Product image for Custom User Profile Fields for User Registration & Member Frontend Profiles with Paid Memberships Pro.
Plugin
Custom User Profile Fields for User Registration & Member Frontend Profiles with Paid Memberships Pro
Plugin Slug
pmpro-register-helper
Installations
10,000+
Vulnerability
Contributor+ Stored XSS via Shortcode
Patched in Version
1.8.1
Severity Score
Medium
CVE
2022-4831
The vulnerability has been patched, so you should update to version 1.8.1.

CPO Companion

Plugin
CPO Companion
Plugin Slug
cpo-companion
Installations
10,000+
Vulnerability
Admin+ Stored XSS; Contributor+ Stored XSS via Shortcode
Patched in Version
1.1.0
Severity Score
Low
CVE
2023-0162
The vulnerability has been patched, so you should update to version 1.1.0.

Portfolio for Elementor, Image Gallery & Post Grid | PowerFolio

Product image for Portfolio for Elementor, Image Gallery & Post Grid  | PowerFolio.
Plugin
Portfolio for Elementor, Image Gallery & Post Grid | PowerFolio
Plugin Slug
portfolio-elementor
Installations
10,000+
Vulnerability
Contributor+ Stored XSS via Shortcode
Patched in Version
2.3.1
Severity Score
Medium
CVE
2022-4765
The vulnerability has been patched, so you should update to version 2.3.1.

Themify Shortcodes

Plugin
Themify Shortcodes
Plugin Slug
themify-shortcodes
Installations
10,000+
Vulnerability
Contributor+ Stored XSS via Shortcode
Patched in Version
2.0.8
Severity Score
Medium
CVE
2022-4787
The vulnerability has been patched, so you should update to version 2.0.8.

Event Manager and Tickets Selling Plugin for WooCommerce

Product image for Event Manager and Tickets Selling Plugin for WooCommerce.
Plugin
Event Manager and Tickets Selling Plugin for WooCommerce
Plugin Slug
mage-eventpress
Installations
9,000+
Vulnerability
Contributor+ Stored XSS
Patched in Version
3.8.0
Severity Score
Medium
CVE
2023-0144
The vulnerability has been patched, so you should update to version 3.8.0.

WP Social Widget

Product image for WP Social Widget.
Plugin
WP Social Widget
Plugin Slug
wp-social-widget
Installations
9,000+
Vulnerability
Contributor+ Stored XSS
Patched in Version
2.2.4
Severity Score
Medium
CVE
2023-0074
The vulnerability has been patched, so you should update to version 2.2.4.

Icon Widget

Product image for Icon Widget.
Plugin
Icon Widget
Plugin Slug
icon-widget
Installations
9,000+
Vulnerability
Contributor+ Stored XSS via Shortcode
Patched in Version
1.3.0
Severity Score
Medium
CVE
2022-4763
The vulnerability has been patched, so you should update to version 1.3.0.

WP Tabs

Product image for WP Tabs – Responsive Tabs Plugin for WordPress.
Plugin
WP Tabs – Responsive Tabs Plugin for WordPress
Plugin Slug
wp-expand-tabs-free
Installations
9,000+
Vulnerability
Contributor+ Stored XSS
Patched in Version
2.1.17
Severity Score
Medium
CVE
2023-0071
The vulnerability has been patched, so you should update to version 2.1.17.

Blog Designer – Post and Widget

Product image for Blog Designer – Post and Widget.
Plugin
Blog Designer – Post and Widget
Plugin Slug
blog-designer-for-post-and-widget
Installations
9,000+
Vulnerability
Contributor+ Stored XSS via Shortcode
Patched in Version
2.4.1
Severity Score
Medium
CVE
2022-4793
The vulnerability has been patched, so you should update to version 2.4.1.

Post Category Image With Grid and Slider

Product image for Post Category Image With Grid and Slider.
Plugin
Post Category Image With Grid and Slider
Plugin Slug
post-category-image-with-grid-and-slider
Installations
3,000+
Vulnerability
Contributor+ Stored XSS via Shortcode
Patched in Version
1.4.8
Severity Score
Medium
CVE
2022-4747
The vulnerability has been patched, so you should update to version 1.4.8.

Survey Maker

Product image for Survey Maker – Best WordPress Survey Plugin.
Plugin
Survey Maker – Best WordPress Survey Plugin
Plugin Slug
survey-maker
Installations
3,000+
Vulnerability
Unauthenticated Stored XSS
Patched in Version
3.1.4
Severity Score
High
CVE
2023-0038
The vulnerability has been patched, so you should update to version 3.1.4.

Posts List Designer by Category

Product image for Posts List Designer by Category – List Category Posts Or Recent Posts.
Plugin
Posts List Designer by Category – List Category Posts Or Recent Posts
Plugin Slug
post-list-designer
Installations
1,000+
Vulnerability
Contributor+ Stored XSS via Shortcode
Patched in Version
3.2
Severity Score
Medium
CVE
2022-4749
The vulnerability has been patched, so you should update to version 3.2.

Membership For WooCommerce

Product image for Membership For WooCommerce – Add Simple Membership Plans, Recurring Revenue, Product Tags & Send Emails To Members with WooCommerce Membership.
Plugin
Membership For WooCommerce – Add Simple Membership Plans, Recurring Revenue, Product Tags & Send Emails To Members with WooCommerce Membership
Plugin Slug
membership-for-woocommerce
Installations
400+
Vulnerability
Unauthenticated Arbitrary File Upload
Patched in Version
2.1.7
Severity Score
Critical
CVE
2022-4395
The vulnerability has been patched, so you should update to version 2.1.7.

WooCommerce Chained Products

Plugin
Chained Products
Plugin Slug
woocommerce-chained-products
Vulnerability
Unauthenticated Arbitrary Options Update to ‘no’
Patched in Version
2.12.0
Severity Score
Medium
CVE
2022-4872
The vulnerability has been patched, so you should update to version 2.12.0.

Justified Gallery

Plugin
Justified Gallery
Plugin Slug
justified-gallery
Vulnerability
Contributor+ Stored XSS via Shortcode
Patched in Version
1.7.1
Severity Score
Medium
CVE
2022-4651
The vulnerability has been patched, so you should update to version 1.7.1.

AAWP

Plugin Slug
aawp
Vulnerability
Unsafe URL Handling
Patched in Version
3.12.3
Severity Score
Medium
CVE
2022-4794
The vulnerability has been patched, so you should update to version 3.12.3.

WordPress Plugin Vulnerabilities – No Known Fix

This section contains plugin vulnerabilities with no known fix. Until a patch is available, immediately uninstall and delete the plugin.

Members Import

Plugin
Members Import
Plugin Slug
members-import
Vulnerability
XSS via Imported CSV
Patched in Version
No Fix
Severity Score
Medium
CVE
2022-4663
The vulnerability has not been patched and the plugin is closed. You should uninstall and delete the plugin.

CPT Bootstrap Carousel

Plugin
CPT Bootstrap Carousel
Plugin Slug
cpt-bootstrap-carousel
Vulnerability
Contributor+ Stored XSS via Shortcode
Patched in Version
No Fix
Severity Score
Medium
CVE
2022-4834
The vulnerability has not been patched and the plugin is closed. You should uninstall and delete the plugin.

JetWidgets for Elementor

Plugin
JetWidgets For Elementor
Plugin Slug
jetwidgets-for-elementor
Vulnerability
Settings Update via CSRF
Patched in Version
No Fix
Severity Score
Medium
CVE
2023-0086
The vulnerability has not been patched and the plugin is closed. You should uninstall and delete the plugin.

MediaElement.js – HTML5 Video & Audio Player

Plugin
MediaElement.js – HTML5 Video & Audio Player
Plugin Slug
media-element-html5-video-and-audio-player
Vulnerability
Contributor+ Stored XSS via Shortcode
Patched in Version
No Fix
Severity Score
Medium
CVE
2022-4699
The vulnerability has not been patched and the plugin is closed. You should uninstall and delete the plugin.

Social Sharing Toolkit

Plugin
Social Sharing Toolkit
Plugin Slug
social-sharing-toolkit
Vulnerability
Contributor+ Stored XSS via Shortcode
Patched in Version
No Fix
Severity Score
Medium
CVE
2022-4835
The vulnerability has not been patched and the plugin is closed. You should uninstall and delete the plugin.

Accordion Shortcodes

Plugin
Accordion Shortcodes
Plugin Slug
accordion-shortcodes
Vulnerability
Contributor+ Stored XSS via Shortcode
Patched in Version
No Fix
Severity Score
Medium
CVE
2022-4781
The vulnerability has not been patched and the plugin is closed. You should uninstall and delete the plugin.

FL3R FeelBox

Plugin
FL3R FeelBox
Plugin Slug
fl3r-feelbox
Vulnerability
Settings Update via CSRF to Stored XSS; Moods Reset via CSRF
Patched in Version
No Fix
Severity Score
High
CVE
2022-4552
The vulnerability has not been patched and the plugin is closed. You should uninstall and delete the plugin.

WordPress Theme Vulnerabilities

In this section, the latest WordPress theme vulnerabilities have been disclosed. Each theme listing includes the type of vulnerability, the active installations, the version number if patched, the severity rating, and the CVE.

  • Good news! No new WordPress theme vulnerabilities were disclosed this week.

Never worry about running a vulnerable plugin or theme again.

As you can see from this report, lots of new WordPress plugin and theme vulnerabilities are disclosed each week. We know it can be difficult to stay on top of every reported vulnerability disclosure, so the iThemes Security Pro plugin makes it easy to make sure your site isn’t running a theme, plugin, or WordPress core version with a known vulnerability.

Scans Your Website Twice a Day for Vulnerabilities

Your website’s plugins, themes, and WordPress core versions are checked against the WPScan Vulnerability Database for the latest vulnerability disclosures.

Automatically Updates if a Security Fix is Available

Paired with Version Management, iThemes Security will automatically update a plugin, theme, or WordPress core version if it has a vulnerability.

Emails You if Site Scan Detects a Vulnerability

You can receive an email report if your site is running vulnerable versions of a plugin, theme, or WordPress core. Customize the email addresses that receive scan results.

The Best WordPress Security Plugin to Secure & Protect WordPress Sites

WordPress currently powers over 40% of all websites, so it has become an easy target for hackers with malicious intent. The iThemes Security Pro plugin takes the guesswork out of WordPress security to make it easy to secure & protect your WordPress website. It’s like having a full-time security expert on staff who constantly monitors and protects your WordPress site for you.

Buy iThemes Security Pro


iThemes Team
iThemes Editorial Team

Each week, the team at iThemes team publishes new WordPress tutorials and resources, including the Weekly WordPress Vulnerability Report. Since 2008, iThemes has been dedicated to helping you build, maintain, and secure WordPress sites for yourself or for clients. Our mission? Make People’s Lives Awesome.

Share via:

  • Facebook
  • Twitter
  • LinkedIn
  • More
Other related posts
A security-riddled computer monitor. There is a large, orange shield with a slash in the middle of the screen. Surrounding it are a red target, a green skull and crossbones, an orange “bug”, a triangle with an explanation point in the middle and a gray gear.
WordPress Vulnerability Report – January 25, 2023
Turnstile and hCaptcha
New Turnstile and hCaptcha Support in Security Pro 7.3
WordPress vulnerability report
WordPress Vulnerability Report – January 18, 2023
clickjacking
What is Clickjacking and How to Prevent it

Get updates on new themes & plugins plus special discounts

About iThemes

  • The Team
  • Contact Us
  • Website Accessibility Statement
  • Sitemap

Resources

  • Blog
  • Documentation
  • WordPress Tutorials
  • Free WordPress Ebooks
  • Free Webinar Library
  • Free Upcoming Webinars
  • iThemes Training
  • Affiliates

Customers

  • Member Panel Login
  • Support
  • FAQs
  • Upgrade Policy
  • Licensing
  • Terms and Conditions
  • Refund Policy

Top Products

  • BackupBuddy
  • iThemes Security Pro
  • iThemes Sync
  • Restrict Content Pro
  • WPComplete
  • WordPress Plugins
  • Content Upgrades
  • WordPress Landing Page Plugin
  • BackupBuddy Stash

iThemes Media LLC Copyright © 2023 All rights reserved | Privacy Policy

© 2022 All Rights Reserved.

Visit StellarWP Visit Nexcess
Share via
Facebook
Twitter
LinkedIn
Mix
Email
Print
Copy Link
Powered by Social Snap
Copy link
CopyCopied
Powered by Social Snap

Get the Weekly WordPress Vulnerability Report

Vulnerable WordPress plugins and themes are the #1 reason WordPress sites get hacked, but keeping track of every new plugin and theme vulnerability is hard work. Get the weekly WordPress Vulnerability Report delivered right to your inbox to help keep your website secure.
No spam. Unsubscribe anytime.