WordPress Vulnerability Report

WordPress Vulnerability Report – January 18, 2023

Vulnerable plugins and themes are the #1 reason WordPress websites get hacked. The weekly WordPress Vulnerability Report powered by WPScan covers recent WordPress plugin, theme, and core vulnerabilities and what to do if you run one of the vulnerable plugins or themes on your website. Each vulnerability will have a severity rating of low, medium, high, or critical.

Avatar photo
SolidWP Editorial Team

Vulnerable plugins and themes are the #1 reason WordPress websites get hacked. The weekly WordPress Vulnerability Report powered by WPScan covers recent WordPress plugin, theme, and core vulnerabilities and what to do if you run one of the vulnerable plugins or themes on your website.

Each vulnerability will have a severity rating of low, medium, high, or critical. Responsible disclosure and reporting of vulnerabilities is an integral part of keeping the WordPress community safe. Please share this post with your friends to help get the word out and make WordPress safer for everyone!

WordPress Core News

WordPress 6.1.1 was released on November 15, 2022, as a short-cycle maintenance release with 29 bug fixes in Core and 21 bug fixes for the block editor. Because this is a core update, be sure to update to WordPress 6.1.1 as soon as possible! As always, with a major release like this, it makes sense to ensure your site is backed up with BackupBuddy before updating.

No new WordPress core vulnerabilities were disclosed this week.

There is a known unpatched vulnerability in WordPress core affecting all versions of WordPress. If you’re using iThemes Security, you’ve probably been alerted to this. As we are unsure when this very low-severity vulnerability will be patched, emails from iThemes Security will no longer alert for this specific vulnerability. Read our blog post about this vulnerability.

Get SolidWP tips direct in your inbox

Sign up

This field is for validation purposes and should be left unchanged.
Placeholder text
Placeholder text
Thanks

Oops something went wrong, please try submitting again

Get started with confidence — risk free, guaranteed

WordPress Plugin Vulnerabilities

In this section, the latest WordPress plugin vulnerabilities have been disclosed. Each plugin listing includes the type of vulnerability, the active installations, the version number if patched, the severity rating, and the CVE.

SiteGround Security

Plugin Slug:
sg-security
Installations:
700,000+
Vulnerability:
Admin+ SQLi
Patched in Version:
1.3.1
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.3.1.

Enable Media Replace

Plugin Slug:
enable-media-replace
Installations:
600,000+
Vulnerability:
Author+ Arbitrary File Upload
Patched in Version:
4.0.2
Severity Score:
Critical
The vulnerability has been patched, so you should update to version 4.0.2.

Royal Elementor Addons

Plugin Slug:
royal-elementor-addons
Installations:
100,000+
Vulnerability:
Menu Template Creation via CSRF; ubscriber+ Arbitrary Template Import; Subscriber+ Template Kit Import; Reflected XSS; Subscriber+ Arbitrary Plugin Deactivation; Subscriber+ Mega Menu Settings Update; Subscriber+ Arbitrary Import Deletion; Subscriber+ Arbitrary Plugin Activation; Subscriber+ Template Condition Update; Subscriber+ Arbitrary Template Activation; Subscriber+ Arbitrary Theme Activation
Patched in Version:
1.3.60
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.3.60.

Strong Testimonials

Plugin Slug:
strong-testimonials
Installations:
100,000+
Vulnerability:
Contributor+ Stored XSS via Shortcode
Patched in Version:
3.0.3
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.0.3.

WP Show Posts

Plugin Slug:
wp-show-posts
Installations:
100,000+
Vulnerability:
Contributor+ Stored XSS
Patched in Version:
1.1.4
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.1.4.
Plugin Slug:
contextual-related-posts
Installations:
70,000+
Vulnerability:
Contributor+ Stored XSS
Patched in Version:
3.3.1
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.3.1.

Stream

Plugin:
Stream
Plugin Slug:
stream
Installations:
70,000+
Vulnerability:
Subscriber+ Alert Creation
Patched in Version:
3.9.2
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.9.2.

Meks Flexible Shortcodes

Plugin Slug:
meks-flexible-shortcodes
Installations:
30,000+
Vulnerability:
Contributor+ Stored XSS
Patched in Version:
1.3.5
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.3.5.

Easy Testimonials

Plugin Slug:
easy-testimonials
Installations:
20,000+
Vulnerability:
Contributor+ Stored XSS
Patched in Version:
3.9.3
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.9.3.

WP Visitor Statistics (Real Time Traffic)

Plugin Slug:
wp-stats-manager
Installations:
20,000+
Vulnerability:
Contributor+ Stored XSS via Shortcode
Patched in Version:
6.5
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 6.5.

Leaflet Maps Marker (Google Maps, OpenStreetMap, Bing Maps)

Plugin Slug:
leaflet-maps-marker
Installations:
20,000+
Vulnerability:
Contributor+ Stored XSS via Shortcode
Patched in Version:
3.12.7
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.12.7.

PPWP – WordPress Password Protect Page

Plugin Slug:
password-protect-page
Installations:
20,000+
Vulnerability:
Contributor+ Stored XSS in Shortcode
Patched in Version:
1.8.6
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.8.6.

Page View Count

Plugin Slug:
page-views-count
Installations:
20,000+
Vulnerability:
Contributor+ Stored XSS
Patched in Version:
2.6.1
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.6.1.

PDF.js Viewer

Plugin Slug:
pdfjs-viewer-shortcode
Installations:
20,000+
Vulnerability:
Contributor+ Stored XSS via Shortcode
Patched in Version:
2.1.8
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.1.8.

Annual Archive

Plugin Slug:
anual-archive
Installations:
10,000+
Vulnerability:
Contributor+ Stored XSS
Patched in Version:
1.6.0
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.6.0.

TemplatesNext ToolKit

Plugin Slug:
templatesnext-toolkit
Installations:
10,000+
Vulnerability:
Contributor+ Stored XSS via Shortcode
Patched in Version:
3.2.8
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.2.8.

WP Customer Area

Plugin Slug:
customer-area
Installations:
10,000+
Vulnerability:
RCE via CSRF
Patched in Version:
8.1.4
Severity Score:
High
The vulnerability has been patched, so you should update to version 8.1.4.

Clean Login

Plugin Slug:
clean-login
Installations:
10,000+
Vulnerability:
Contributor+ Stored XSS via Shortcode
Patched in Version:
1.13.7
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.13.7.

Materialis Companion

Plugin Slug:
materialis-companion
Installations:
10,000+
Vulnerability:
Contributor+ Stored XSS via Shortcode
Patched in Version:
1.3.40
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.3.40.

Send PDF for Contact Form 7

Plugin Slug:
send-pdf-for-contact-form-7
Installations:
10,000+
Vulnerability:
Contributor+ Stored XSS via Shortcode
Patched in Version:
0.9.9.2
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 0.9.9.2.

YaMaps for WordPress Plugin

Plugin Slug:
yamaps
Installations:
10,000+
Vulnerability:
Contributor+ Stored XSS
Patched in Version:
0.6.26
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 0.6.26.

Easy Accept Payments for PayPal

Plugin Slug:
wordpress-easy-paypal-payment-or-donation-accept-plugin
Installations:
10,000+
Vulnerability:
Contributor+ Stored XSS
Patched in Version:
4.9.10
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 4.9.10.

Breadcrumb

Plugin:
Breadcrumb
Plugin Slug:
breadcrumb
Installations:
10,000+
Vulnerability:
Contributor+ Stored XSS via Shortcode
Patched in Version:
1.5.33
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.5.33.

WP Blog and Widget

Plugin Slug:
wp-blog-and-widgets
Installations:
10,000+
Vulnerability:
Contributor+ Stored XSS via Shortcode
Patched in Version:
2.3.1
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.3.1.

YourChannel: Everything you want in a YouTube plugin

Plugin Slug:
yourchannel
Installations:
10,000+
Vulnerability:
Contributor+ Stored XSS via Shortcode; Subscriber+ Stored XSS
Patched in Version:
1.2.3
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.2.3.

WP-ShowHide

Plugin Slug:
wp-showhide
Installations:
10,000+
Vulnerability:
Contributor+ Stored XSS via Shortcode
Patched in Version:
1.05
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.05.

Simple Tooltips

Plugin Slug:
simple-tooltips
Installations:
10,000+
Vulnerability:
Contributor+ Stored XSS via Shortcode
Patched in Version:
2.1.4
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.1.4.

jQuery T(-) Countdown Widget

Plugin Slug:
jquery-t-countdown-widget
Installations:
10,000+
Vulnerability:
Contributor+ Stored XSS
Patched in Version:
2.3.24
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.3.24.

Event Manager and Tickets Selling Plugin for WooCommerce

Plugin Slug:
mage-eventpress
Installations:
9,000+
Vulnerability:
Contributor+ Stored XSS
Patched in Version:
3.8.0
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.8.0.

YouTube Channel

Plugin Slug:
youtube-channel
Installations:
9,000+
Vulnerability:
Contributor+ Stored XSS via Shortcode
Patched in Version:
3.23.0
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.23.0.

EAN for WooCommerce

Plugin Slug:
ean-for-woocommerce
Installations:
9,000+
Vulnerability:
Contributor+ Stored XSS
Patched in Version:
4.4.3
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 4.4.3.

Judge.me Product Reviews for WooCommerce

Plugin Slug:
judgeme-product-reviews-woocommerce
Installations:
8,000+
Vulnerability:
Contributor+ Stored XSS
Patched in Version:
1.3.21
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.3.21.
Plugin Slug:
responsive-gallery-grid
Installations:
7,000+
Vulnerability:
Contributor+ Stored XSS
Patched in Version:
2.3.9
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.3.9.

Simple Membership WP

Plugin Slug:
simple-membership-wp-user-import
Installations:
5,000+
Vulnerability:
Admin+ SQLi
Patched in Version:
1.8
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.8.

Post Category Image With Grid and Slider

Plugin Slug:
post-category-image-with-grid-and-slider
Installations:
3,000+
Vulnerability:
Contributor+ Stored XSS via Shortcode
Patched in Version:
1.4.8
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.4.8.
Plugin Slug:
utubevideo-gallery
Installations:
500+
Vulnerability:
Contributor+ Stored XSS
Patched in Version:
2.0.8
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.0.8.

GamiPress – Vimeo integration

Plugin Slug:
gamipress-vimeo-integration
Installations:
400+
Vulnerability:
Contributor+ Stored XSS
Patched in Version:
1.0.9
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.0.9.

WP FullCalendar

Plugin Slug:
wp-fullcalendar
Vulnerability:
Unauthenticated Arbitrary Post Access
Patched in Version:
1.5
Severity Score:
High
The vulnerability has been patched, so you should update to version 1.5.

Hide My WP

Plugin:
Hide My WP
Plugin Slug:
hide_my_wp
Vulnerability:
Unauthenticated SQLi
Patched in Version:
6.2.9
Severity Score:
High
The vulnerability has been patched, so you should update to version 6.2.9.

WordPress Plugin Vulnerabilities – No Known Fix

This section contains plugin vulnerabilities with no known fix. Until a patch is available, immediately uninstall and delete the plugin.

Widget Shortcode

Plugin Slug:
widget-shortcode
Installations:
80,000+
Vulnerability:
Contributor+ Stored XSS
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Widgets on Pages

Plugin Slug:
widgets-on-pages
Installations:
30,000+
Vulnerability:
Contributor+ Stored XSS
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Rich Table of Contents

Plugin Slug:
rich-table-of-content
Installations:
30,000+
Vulnerability:
Contributor+ Stored XSS
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

WordPrezi

Plugin:
WordPrezi
Plugin Slug:
wordprezi
Vulnerability:
Contributor+ Strored XSS
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched and the plugin is closed. You should uninstall and delete the plugin.

Naver Map

Plugin:
Naver Map
Plugin Slug:
naver-map
Vulnerability:
Contributor+ Stored XSS
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched and the plugin is closed. You should uninstall and delete the plugin.
Plugin Slug:
gallery-factory-lite
Vulnerability:
Contributor+ Stored XSS
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched and the plugin is closed. You should uninstall and delete the plugin.

ResponsiveVoice Text To Speech

Plugin Slug:
responsivevoice-text-to-speech
Vulnerability:
Contributor+ Stored XSS
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched and the plugin is closed. You should uninstall and delete the plugin.

Vimeo Video Autoplay Automute

Plugin Slug:
vimeo-video-autoplay-automute
Vulnerability:
Contributor+ Stored XSS
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched and the plugin is closed. You should uninstall and delete the plugin.

Flexible Captcha

Plugin Slug:
flexible-captcha
Vulnerability:
Contributor+ Stored XSS
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched and the plugin is closed. You should uninstall and delete the plugin.

Cloak Front End Email

Plugin Slug:
cloak-front-end-email
Vulnerability:
Contributor+ Stored XSS
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched and the plugin is closed. You should uninstall and delete the plugin.

WordPress Theme Vulnerabilities

In this section, the latest WordPress theme vulnerabilities have been disclosed. Each theme listing includes the type of vulnerability, the active installations, the version number if patched, the severity rating, and the CVE.

No new WordPress theme vulnerabilities were disclosed this week.

Solid Security is part of Solid Suite — The best foundation for WordPress websites.

Every WordPress site needs security, backups, and management tools. That’s Solid Suite — an integrated bundle of three plugins: Solid Security, Solid Backups, and Solid Central. You also get access to Solid Academy’s learning resources for WordPress professionals. Build your next WordPress website on a solid foundation with Solid Suite!

Get Solid Security

Did you like this article? Spread the word: