Menu
iThemes
WordPress Security, Backups & Maintenance
  • Products
    • iThemes Security Pro
    • BackupBuddy
    • iThemes Sync
    • Why buy from iThemes?
  • Bundles
    • Essentials Bundle
    • Plugin Suite
    • WordPress Web Designer’s Toolkit
    • Customer Spotlights
  • Resources
    • Blog
    • WordPress 101 Tutorials
    • WordPress Ebooks
    • Weekly WordPress Vulnerability Report
    • The Ultimate Guide to Starting a Web Design Business
  • Training
    • Upcoming Webinars
    • Free Webinar Library
    • Premium Courses
    • Become a Member
    • Member Login
  • Support
    • Documentation
    • Get Help
    • Product Updates
    • Upgrade Policy
    • Contact
    • Our Mission: Make People’s Lives Awesome
  • Log In
WordPress News and Updates from iThemes
Categories
  • Product Updates
  • WordPress Backup
  • WordPress Block Editor
  • WordPress Ecommerce
  • WordPress for Freelancers
  • WordPress Security
  • WordPress Tutorials
  • WPprosper

WordPress Vulnerability Report – January 18, 2023

Written by iThemes Editorial Team on January 18, 2023

Last Updated on January 18, 2023

Vulnerable plugins and themes are the #1 reason WordPress websites get hacked. The weekly WordPress Vulnerability Report powered by WPScan covers recent WordPress plugin, theme, and core vulnerabilities and what to do if you run one of the vulnerable plugins or themes on your website.

Each vulnerability will have a severity rating of low, medium, high, or critical. Responsible disclosure and reporting of vulnerabilities is an integral part of keeping the WordPress community safe. Please share this post with your friends to help get the word out and make WordPress safer for everyone!

Contents of the January 18, 2023 Report
  • The Future of Authentication is Passkeys! Login to your WordPress site with Biometrics only available in iThemes Security Pro
  • WordPress Core News
  • WordPress Plugin Vulnerabilities
    • MonsterInsights
    • SiteGround Security
    • ExactMetrics
    • Enable Media Replace
    • Royal Elementor Addons
    • Strong Testimonials
    • WOOF – Products Filter for WooCommerce
    • WP Show Posts
    • Contextual Related Posts
    • Stream
    • Tutor LMS
    • Happyforms
    • Meks Flexible Shortcodes
    • Easy Testimonials
    • WP Visitor Statistics (Real Time Traffic)
    • Leaflet Maps Marker (Google Maps, OpenStreetMap, Bing Maps)
    • PPWP – WordPress Password Protect Page
    • Page View Count
    • PDF.js Viewer
    • Annual Archive
    • TemplatesNext ToolKit
    • Html5 Audio Player
    • WP Customer Area
    • Clean Login
    • Giveaways and Contests by RafflePress
    • Materialis Companion
    • Send PDF for Contact Form 7
    • Restaurant Menu
    • YaMaps for WordPress Plugin
    • Easy Accept Payments for PayPal
    • Breadcrumb
    • WP Blog and Widget
    • WP VR
    • YourChannel: Everything you want in a YouTube plugin
    • WP-ShowHide
    • Simple Tooltips
    • jQuery T(-) Countdown Widget
    • Event Manager and Tickets Selling Plugin for WooCommerce
    • YouTube Channel
    • EAN for WooCommerce
    • WC Vendors Marketplace
    • Judge.me Product Reviews for WooCommerce
    • Responsive Gallery Grid
    • Simple URLs
    • Simple Membership WP
    • WPFunnels
    • Post Category Image With Grid and Slider
    • PDF Generator for WordPress
    • uTubeVideo Gallery
    • GamiPress – Vimeo integration
    • WP FullCalendar
    • Hide My WP
  • WordPress Plugin Vulnerabilities – No Known Fix
    • Widget Shortcode
    • Widgets on Pages
    • Rich Table of Contents
    • WordPrezi
    • Naver Map
    • Gallery Factory Lite
    • ResponsiveVoice Text To Speech
    • Vimeo Video Autoplay Automute
    • Flexible Captcha
    • Cloak Front End Email
  • WordPress Theme Vulnerabilities
  • The Best WordPress Security Plugin to Secure & Protect WordPress Sites

The Future of Authentication is Passkeys! Login to your WordPress site with Biometrics only available in iThemes Security Pro

The problems of brute force attacks through credential stuffing, phishing attacks, and reused passwords have made our digital lives less secure. We’ve all tried to encourage 2-factor authentication as a protection, but less than 30% of users actually use 2FA. Password-based logins are a problem.

The future of authentication is passkeys, and iThemes Security Pro is the first to bring this breakthrough technology to WordPress sites. Using breakthrough WebAuthn technology based on public/private cryptography, passkeys make passwords obsolete. Now, website admins and end users can have secure logins without the inconvenience of additional two-factor apps, password managers, or complex password requirements.

Learn More About Passkeys

WordPress Core News

WordPress 6.1.1 was released on November 15, 2022, as a short-cycle maintenance release with 29 bug fixes in Core and 21 bug fixes for the block editor. Because this is a core update, be sure to update to WordPress 6.1.1 as soon as possible! As always, with a major release like this, it makes sense to ensure your site is backed up with BackupBuddy before updating.

  • No new WordPress core vulnerabilities were disclosed this week.

There is a known unpatched vulnerability in WordPress core affecting all versions of WordPress. If you’re using iThemes Security, you’ve probably been alerted to this. As we are unsure when this very low-severity vulnerability will be patched, emails from iThemes Security will no longer alert for this specific vulnerability. Read our blog post about this vulnerability.

Get the weekly WordPress Vulnerability Report delivered to your inbox each Wednesday.
Subscribe now

WordPress Plugin Vulnerabilities

In this section, the latest WordPress plugin vulnerabilities have been disclosed. Each plugin listing includes the type of vulnerability, the active installations, the version number if patched, the severity rating, and the CVE.

MonsterInsights

Product image for MonsterInsights – Google Analytics Dashboard for WordPress (Website Stats Made Easy).
Plugin
MonsterInsights – Google Analytics Dashboard for WordPress (Website Stats Made Easy)
Plugin Slug
google-analytics-for-wordpress
Installations
3,000,000+
Vulnerability
Contributor+ Stored XSS
Patched in Version
8.12.1
Severity Score
Medium
CVE
2023-0081
The vulnerability has been patched, so you should update to version 8.12.1.

SiteGround Security

Product image for SiteGround Security.
Plugin
SiteGround Security
Plugin Slug
sg-security
Installations
700,000+
Vulnerability
Admin+ SQLi
Patched in Version
1.3.1
Severity Score
Medium
CVE
2023-0234
The vulnerability has been patched, so you should update to version 1.3.1.

ExactMetrics

Product image for ExactMetrics – Google Analytics Dashboard for WordPress (Website Stats Plugin).
Plugin
ExactMetrics – Google Analytics Dashboard for WordPress (Website Stats Plugin)
Plugin Slug
google-analytics-dashboard-for-wp
Installations
700,000+
Vulnerability
Contributor+ Stored XSS
Patched in Version
7.12.1
Severity Score
Medium
CVE
2023-0082
The vulnerability has been patched, so you should update to version 7.12.1.

Enable Media Replace

Product image for Enable Media Replace.
Plugin
Enable Media Replace
Plugin Slug
enable-media-replace
Installations
600,000+
Vulnerability
Author+ Arbitrary File Upload
Patched in Version
4.0.2
Severity Score
Critical
CVE
2023-0255
The vulnerability has been patched, so you should update to version 4.0.2.

Royal Elementor Addons

Product image for Royal Elementor Addons and Templates.
Plugin
Royal Elementor Addons and Templates
Plugin Slug
royal-elementor-addons
Installations
100,000+
Vulnerability
Menu Template Creation via CSRF; ubscriber+ Arbitrary Template Import; Subscriber+ Template Kit Import; Reflected XSS; Subscriber+ Arbitrary Plugin Deactivation; Subscriber+ Mega Menu Settings Update; Subscriber+ Arbitrary Import Deletion; Subscriber+ Arbitrary Plugin Activation; Subscriber+ Template Condition Update; Subscriber+ Arbitrary Template Activation; Subscriber+ Arbitrary Theme Activation
Patched in Version
1.3.60
Severity Score
Medium
CVE
2022-4707
The vulnerability has been patched, so you should update to version 1.3.60.

Strong Testimonials

Product image for Strong Testimonials.
Plugin
Strong Testimonials
Plugin Slug
strong-testimonials
Installations
100,000+
Vulnerability
Contributor+ Stored XSS via Shortcode
Patched in Version
3.0.3
Severity Score
Medium
CVE
2022-4717
The vulnerability has been patched, so you should update to version 3.0.3.

WOOF – Products Filter for WooCommerce

Product image for HUSKY – Products Filter for WooCommerce Professional.
Plugin
HUSKY – Products Filter for WooCommerce Professional
Plugin Slug
woocommerce-products-filter
Installations
100,000+
Vulnerability
Admin+ PHP Object Injection
Patched in Version
1.3.2
Severity Score
Low
CVE
2022-4489
The vulnerability has been patched, so you should update to version 1.3.2.

WP Show Posts

Product image for WP Show Posts.
Plugin
WP Show Posts
Plugin Slug
wp-show-posts
Installations
100,000+
Vulnerability
Contributor+ Stored XSS
Patched in Version
1.1.4
Severity Score
Medium
CVE
2022-4459
The vulnerability has been patched, so you should update to version 1.1.4.

Contextual Related Posts

Product image for Contextual Related Posts.
Plugin
Contextual Related Posts
Plugin Slug
contextual-related-posts
Installations
70,000+
Vulnerability
Contributor+ Stored XSS
Patched in Version
3.3.1
Severity Score
Medium
CVE
2023-0252
The vulnerability has been patched, so you should update to version 3.3.1.

Stream

Product image for Stream.
Plugin
Stream
Plugin Slug
stream
Installations
70,000+
Vulnerability
Subscriber+ Alert Creation
Patched in Version
3.9.2
Severity Score
Medium
CVE
2022-4384
The vulnerability has been patched, so you should update to version 3.9.2.

Tutor LMS

Product image for Tutor LMS – eLearning and online course solution.
Plugin
Tutor LMS – eLearning and online course solution
Plugin Slug
tutor
Installations
60,000+
Vulnerability
Reflected Cross-Site Scripting
Patched in Version
2.0.10
Severity Score
High
CVE
2023-0236
The vulnerability has been patched, so you should update to version 2.0.10.

Happyforms

Product image for Form builder to get in touch with visitors, grow your email list and collect payments — Happyforms.
Plugin
Form builder to get in touch with visitors, grow your email list and collect payments — Happyforms
Plugin Slug
happyforms
Installations
40,000+
Vulnerability
Contributor+ Stored XSS
Patched in Version
1.22.0
Severity Score
Medium
CVE
2023-0096
The vulnerability has been patched, so you should update to version 1.22.0.

Meks Flexible Shortcodes

Product image for Meks Flexible Shortcodes.
Plugin
Meks Flexible Shortcodes
Plugin Slug
meks-flexible-shortcodes
Installations
30,000+
Vulnerability
Contributor+ Stored XSS
Patched in Version
1.3.5
Severity Score
Medium
CVE
2022-4562
The vulnerability has been patched, so you should update to version 1.3.5.

Easy Testimonials

Product image for Easy Testimonials.
Plugin
Easy Testimonials
Plugin Slug
easy-testimonials
Installations
20,000+
Vulnerability
Contributor+ Stored XSS
Patched in Version
3.9.3
Severity Score
Medium
CVE
2022-4577
The vulnerability has been patched, so you should update to version 3.9.3.

WP Visitor Statistics (Real Time Traffic)

Product image for WP Visitor Statistics (Real Time Traffic).
Plugin
WP Visitor Statistics (Real Time Traffic)
Plugin Slug
wp-stats-manager
Installations
20,000+
Vulnerability
Contributor+ Stored XSS via Shortcode
Patched in Version
6.5
Severity Score
Medium
CVE
2022-4656
The vulnerability has been patched, so you should update to version 6.5.

Leaflet Maps Marker (Google Maps, OpenStreetMap, Bing Maps)

Product image for Leaflet Maps Marker (Google Maps, OpenStreetMap, Bing Maps).
Plugin
Leaflet Maps Marker (Google Maps, OpenStreetMap, Bing Maps)
Plugin Slug
leaflet-maps-marker
Installations
20,000+
Vulnerability
Contributor+ Stored XSS via Shortcode
Patched in Version
3.12.7
Severity Score
Medium
CVE
2022-4677
The vulnerability has been patched, so you should update to version 3.12.7.

PPWP – WordPress Password Protect Page

Product image for PPWP – Password Protect Pages.
Plugin
PPWP – Password Protect Pages
Plugin Slug
password-protect-page
Installations
20,000+
Vulnerability
Contributor+ Stored XSS in Shortcode
Patched in Version
1.8.6
Severity Score
Medium
CVE
2022-4626
The vulnerability has been patched, so you should update to version 1.8.6.

Page View Count

Product image for Page View Count.
Plugin
Page View Count
Plugin Slug
page-views-count
Installations
20,000+
Vulnerability
Contributor+ Stored XSS
Patched in Version
2.6.1
Severity Score
Medium
CVE
2023-0095
The vulnerability has been patched, so you should update to version 2.6.1.

PDF.js Viewer

Product image for PDF.js Viewer.
Plugin
PDF.js Viewer
Plugin Slug
pdfjs-viewer-shortcode
Installations
20,000+
Vulnerability
Contributor+ Stored XSS via Shortcode
Patched in Version
2.1.8
Severity Score
Medium
CVE
2022-4670
The vulnerability has been patched, so you should update to version 2.1.8.

Annual Archive

Product image for Annual Archive.
Plugin
Annual Archive
Plugin Slug
anual-archive
Installations
10,000+
Vulnerability
Contributor+ Stored XSS
Patched in Version
1.6.0
Severity Score
Medium
CVE
2023-0178
The vulnerability has been patched, so you should update to version 1.6.0.

TemplatesNext ToolKit

Product image for TemplatesNext ToolKit.
Plugin
TemplatesNext ToolKit
Plugin Slug
templatesnext-toolkit
Installations
10,000+
Vulnerability
Contributor+ Stored XSS via Shortcode
Patched in Version
3.2.8
Severity Score
Medium
CVE
2022-4678
The vulnerability has been patched, so you should update to version 3.2.8.

Html5 Audio Player

Product image for Html5 Audio Player – Audio Player for WordPress.
Plugin
Html5 Audio Player – Audio Player for WordPress
Plugin Slug
html5-audio-player
Installations
10,000+
Vulnerability
Contributor+ Stored XSS
Patched in Version
2.1.12
Severity Score
Medium
CVE
2023-0170
The vulnerability has been patched, so you should update to version 2.1.12.

WP Customer Area

Product image for WP Customer Area.
Plugin
WP Customer Area
Plugin Slug
customer-area
Installations
10,000+
Vulnerability
RCE via CSRF
Patched in Version
8.1.4
Severity Score
High
CVE
2022-4745
The vulnerability has been patched, so you should update to version 8.1.4.

Clean Login

Product image for Clean Login.
Plugin
Clean Login
Plugin Slug
clean-login
Installations
10,000+
Vulnerability
Contributor+ Stored XSS via Shortcode
Patched in Version
1.13.7
Severity Score
Medium
CVE
2022-4838
The vulnerability has been patched, so you should update to version 1.13.7.

Giveaways and Contests by RafflePress

Product image for Giveaways and Contests by RafflePress – Get More Website Traffic, Email Subscribers, and Social Followers.
Plugin
Giveaways and Contests by RafflePress – Get More Website Traffic, Email Subscribers, and Social Followers
Plugin Slug
rafflepress
Installations
10,000+
Vulnerability
Contributor+ Stored XSS
Patched in Version
1.11.3
Severity Score
Medium
CVE
2023-0176
The vulnerability has been patched, so you should update to version 1.11.3.

Materialis Companion

Plugin
Materialis Companion
Plugin Slug
materialis-companion
Installations
10,000+
Vulnerability
Contributor+ Stored XSS via Shortcode
Patched in Version
1.3.40
Severity Score
Medium
CVE
2022-4762
The vulnerability has been patched, so you should update to version 1.3.40.

Send PDF for Contact Form 7

Product image for Send PDF for Contact Form 7.
Plugin
Send PDF for Contact Form 7
Plugin Slug
send-pdf-for-contact-form-7
Installations
10,000+
Vulnerability
Contributor+ Stored XSS via Shortcode
Patched in Version
0.9.9.2
Severity Score
Medium
CVE
2023-0143
The vulnerability has been patched, so you should update to version 0.9.9.2.

Restaurant Menu

Product image for Restaurant Menu – Food Ordering System – Table Reservation.
Plugin
Restaurant Menu – Food Ordering System – Table Reservation
Plugin Slug
menu-ordering-reservations
Installations
10,000+
Vulnerability
Contributor+ Stored XSS via Shortcode
Patched in Version
2.3.6
Severity Score
Medium
CVE
2022-4657
The vulnerability has been patched, so you should update to version 2.3.6.

YaMaps for WordPress Plugin

Product image for YaMaps for WordPress Plugin.
Plugin
YaMaps for WordPress Plugin
Plugin Slug
yamaps
Installations
10,000+
Vulnerability
Contributor+ Stored XSS
Patched in Version
0.6.26
Severity Score
Medium
CVE
2023-0270
The vulnerability has been patched, so you should update to version 0.6.26.

Easy Accept Payments for PayPal

Product image for Easy Accept Payments for PayPal.
Plugin
Easy Accept Payments for PayPal
Plugin Slug
wordpress-easy-paypal-payment-or-donation-accept-plugin
Installations
10,000+
Vulnerability
Contributor+ Stored XSS
Patched in Version
4.9.10
Severity Score
Medium
CVE
2023-0275
The vulnerability has been patched, so you should update to version 4.9.10.

Breadcrumb

Product image for Breadcrumb.
Plugin
Breadcrumb
Plugin Slug
breadcrumb
Installations
10,000+
Vulnerability
Contributor+ Stored XSS via Shortcode
Patched in Version
1.5.33
Severity Score
Medium
CVE
2022-4836
The vulnerability has been patched, so you should update to version 1.5.33.

WP Blog and Widget

Product image for WP Blog and Widgets.
Plugin
WP Blog and Widgets
Plugin Slug
wp-blog-and-widgets
Installations
10,000+
Vulnerability
Contributor+ Stored XSS via Shortcode
Patched in Version
2.3.1
Severity Score
Medium
CVE
2022-4824
The vulnerability has been patched, so you should update to version 2.3.1.

WP VR

Product image for WP VR – 360 Panorama and Virtual Tour Builder For WordPress.
Plugin
WP VR – 360 Panorama and Virtual Tour Builder For WordPress
Plugin Slug
wpvr
Installations
10,000+
Vulnerability
Contributor+ Stored XSS
Patched in Version
8.2.7
Severity Score
Medium
CVE
2023-0174
The vulnerability has been patched, so you should update to version 8.2.7.

YourChannel: Everything you want in a YouTube plugin

Product image for YourChannel: Everything you want in a YouTube plugin..
Plugin
YourChannel: Everything you want in a YouTube plugin.
Plugin Slug
yourchannel
Installations
10,000+
Vulnerability
Contributor+ Stored XSS via Shortcode; Subscriber+ Stored XSS
Patched in Version
1.2.3
Severity Score
Medium
CVE
2022-4833
The vulnerability has been patched, so you should update to version 1.2.3.

WP-ShowHide

Product image for WP-ShowHide.
Plugin
WP-ShowHide
Plugin Slug
wp-showhide
Installations
10,000+
Vulnerability
Contributor+ Stored XSS via Shortcode
Patched in Version
1.05
Severity Score
Medium
CVE
2022-4825
The vulnerability has been patched, so you should update to version 1.05.

Simple Tooltips

Product image for Simple Tooltips.
Plugin
Simple Tooltips
Plugin Slug
simple-tooltips
Installations
10,000+
Vulnerability
Contributor+ Stored XSS via Shortcode
Patched in Version
2.1.4
Severity Score
Medium
CVE
2022-4826
The vulnerability has been patched, so you should update to version 2.1.4.

jQuery T(-) Countdown Widget

Product image for jQuery T(-) Countdown Widget.
Plugin
jQuery T(-) Countdown Widget
Plugin Slug
jquery-t-countdown-widget
Installations
10,000+
Vulnerability
Contributor+ Stored XSS
Patched in Version
2.3.24
Severity Score
Medium
CVE
2023-0171
The vulnerability has been patched, so you should update to version 2.3.24.

Event Manager and Tickets Selling Plugin for WooCommerce

Product image for Event Manager and Tickets Selling Plugin for WooCommerce.
Plugin
Event Manager and Tickets Selling Plugin for WooCommerce
Plugin Slug
mage-eventpress
Installations
9,000+
Vulnerability
Contributor+ Stored XSS
Patched in Version
3.8.0
Severity Score
Medium
CVE
2023-0144
The vulnerability has been patched, so you should update to version 3.8.0.

YouTube Channel

Product image for My YouTube Channel.
Plugin
My YouTube Channel
Plugin Slug
youtube-channel
Installations
9,000+
Vulnerability
Contributor+ Stored XSS via Shortcode
Patched in Version
3.23.0
Severity Score
Medium
CVE
2022-4756
The vulnerability has been patched, so you should update to version 3.23.0.

EAN for WooCommerce

Product image for EAN for WooCommerce.
Plugin
EAN for WooCommerce
Plugin Slug
ean-for-woocommerce
Installations
9,000+
Vulnerability
Contributor+ Stored XSS
Patched in Version
4.4.3
Severity Score
Medium
CVE
2023-0062
The vulnerability has been patched, so you should update to version 4.4.3.

WC Vendors Marketplace

Product image for WC Vendors Marketplace – The WooCommerce Multivendor Marketplace Solution.
Plugin
WC Vendors Marketplace – The WooCommerce Multivendor Marketplace Solution
Plugin Slug
wc-vendors
Installations
9,000+
Vulnerability
Contributor+ Stored XSS
Patched in Version
2.4.5
Severity Score
Medium
CVE
2023-0072
The vulnerability has been patched, so you should update to version 2.4.5.

Judge.me Product Reviews for WooCommerce

Product image for Judge.me Product Reviews for WooCommerce.
Plugin
Judge.me Product Reviews for WooCommerce
Plugin Slug
judgeme-product-reviews-woocommerce
Installations
8,000+
Vulnerability
Contributor+ Stored XSS
Patched in Version
1.3.21
Severity Score
Medium
CVE
2023-0061
The vulnerability has been patched, so you should update to version 1.3.21.

Responsive Gallery Grid

Product image for Responsive Gallery Grid.
Plugin
Responsive Gallery Grid
Plugin Slug
responsive-gallery-grid
Installations
7,000+
Vulnerability
Contributor+ Stored XSS
Patched in Version
2.3.9
Severity Score
Medium
CVE
2023-0060
The vulnerability has been patched, so you should update to version 2.3.9.

Simple URLs

Product image for Simple URLs – Link Cloaking, Product Displays, and Affiliate Link Management.
Plugin
Simple URLs – Link Cloaking, Product Displays, and Affiliate Link Management
Plugin Slug
simple-urls
Installations
6,000+
Vulnerability
Subscriber+ SQLi; Multiple Reflected XSS
Patched in Version
115
Severity Score
High
CVE
2023-0098
The vulnerability has been patched, so you should update to version 115.

Simple Membership WP

Plugin
Simple Membership WP user Import
Plugin Slug
simple-membership-wp-user-import
Installations
5,000+
Vulnerability
Admin+ SQLi
Patched in Version
1.8
Severity Score
Medium
CVE
2023-0254
The vulnerability has been patched, so you should update to version 1.8.

WPFunnels

Product image for Drag & Drop Sales Funnel Builder for WordPress – WPFunnels.
Plugin
Drag & Drop Sales Funnel Builder for WordPress – WPFunnels
Plugin Slug
wpfunnels
Installations
3,000+
Vulnerability
Contributor+ Stored XSS
Patched in Version
2.6.9
Severity Score
Medium
CVE
2023-0173
The vulnerability has been patched, so you should update to version 2.6.9.

Post Category Image With Grid and Slider

Product image for Post Category Image With Grid and Slider.
Plugin
Post Category Image With Grid and Slider
Plugin Slug
post-category-image-with-grid-and-slider
Installations
3,000+
Vulnerability
Contributor+ Stored XSS via Shortcode
Patched in Version
1.4.8
Severity Score
Medium
CVE
2022-4747
The vulnerability has been patched, so you should update to version 1.4.8.

PDF Generator for WordPress

Product image for PDF Generator for WordPress – Create & Customize PDF for Post, Pages and WooCommerce Products.
Plugin
PDF Generator for WordPress – Create & Customize PDF for Post, Pages and WooCommerce Products
Plugin Slug
pdf-generator-for-wp
Installations
1,000+
Vulnerability
Reflected XSS
Patched in Version
1.1.2
Severity Score
High
CVE
2022-4321
The vulnerability has been patched, so you should update to version 1.1.2.

uTubeVideo Gallery

Plugin
uTubeVideo Gallery
Plugin Slug
utubevideo-gallery
Installations
500+
Vulnerability
Contributor+ Stored XSS
Patched in Version
2.0.8
Severity Score
Medium
CVE
2023-0151
The vulnerability has been patched, so you should update to version 2.0.8.

GamiPress – Vimeo integration

Product image for GamiPress – Vimeo integration.
Plugin
GamiPress – Vimeo integration
Plugin Slug
gamipress-vimeo-integration
Installations
400+
Vulnerability
Contributor+ Stored XSS
Patched in Version
1.0.9
Severity Score
Medium
CVE
2023-0154
The vulnerability has been patched, so you should update to version 1.0.9.

WP FullCalendar

Plugin
WP FullCalendar
Plugin Slug
wp-fullcalendar
Vulnerability
Unauthenticated Arbitrary Post Access
Patched in Version
1.5
Severity Score
High
CVE
2022-3891
The vulnerability has been patched, so you should update to version 1.5.

Hide My WP

Plugin
Hide My WP
Plugin Slug
hide_my_wp
Vulnerability
Unauthenticated SQLi
Patched in Version
6.2.9
Severity Score
High
CVE
2022-4681
The vulnerability has been patched, so you should update to version 6.2.9.

WordPress Plugin Vulnerabilities – No Known Fix

This section contains plugin vulnerabilities with no known fix. Until a patch is available, immediately uninstall and delete the plugin.

Widget Shortcode

Plugin
Widget Shortcode
Plugin Slug
widget-shortcode
Installations
80,000+
Vulnerability
Contributor+ Stored XSS
Patched in Version
No Fix
Severity Score
Medium
CVE
2022-4473
The vulnerability has not been patched. You should deactivate the plugin.

Widgets on Pages

Product image for Widgets on Pages.
Plugin
Widgets on Pages
Plugin Slug
widgets-on-pages
Installations
30,000+
Vulnerability
Contributor+ Stored XSS
Patched in Version
No Fix
Severity Score
Medium
CVE
2022-4488
The vulnerability has not been patched. You should deactivate the plugin.

Rich Table of Contents

Product image for Rich Table of Contents.
Plugin
Rich Table of Contents
Plugin Slug
rich-table-of-content
Installations
30,000+
Vulnerability
Contributor+ Stored XSS
Patched in Version
No Fix
Severity Score
Medium
CVE
2022-4551
The vulnerability has not been patched. You should deactivate the plugin.

WordPrezi

Plugin
WordPrezi
Plugin Slug
wordprezi
Vulnerability
Contributor+ Strored XSS
Patched in Version
No Fix
Severity Score
Medium
CVE
2023-0149
The vulnerability has not been patched and the plugin is closed. You should uninstall and delete the plugin.

Naver Map

Plugin
Naver Map
Plugin Slug
naver-map
Vulnerability
Contributor+ Stored XSS
Patched in Version
No Fix
Severity Score
Medium
CVE
2023-0146
The vulnerability has not been patched and the plugin is closed. You should uninstall and delete the plugin.

Gallery Factory Lite

Plugin
Gallery Factory Lite
Plugin Slug
gallery-factory-lite
Vulnerability
Contributor+ Stored XSS
Patched in Version
No Fix
Severity Score
Medium
CVE
2023-0148
The vulnerability has not been patched and the plugin is closed. You should uninstall and delete the plugin.

ResponsiveVoice Text To Speech

Plugin
ResponsiveVoice Text To Speech
Plugin Slug
responsivevoice-text-to-speech
Vulnerability
Contributor+ Stored XSS
Patched in Version
No Fix
Severity Score
Medium
CVE
2023-0070
The vulnerability has not been patched and the plugin is closed. You should uninstall and delete the plugin.

Vimeo Video Autoplay Automute

Plugin
Vimeo Video Autoplay Automute
Plugin Slug
vimeo-video-autoplay-automute
Vulnerability
Contributor+ Stored XSS
Patched in Version
No Fix
Severity Score
Medium
CVE
2023-0153
The vulnerability has not been patched and the plugin is closed. You should uninstall and delete the plugin.

Flexible Captcha

Plugin
Flexible Captcha
Plugin Slug
flexible-captcha
Vulnerability
Contributor+ Stored XSS
Patched in Version
No Fix
Severity Score
Medium
CVE
2023-0147
The vulnerability has not been patched and the plugin is closed. You should uninstall and delete the plugin.

Cloak Front End Email

Plugin
Cloak Front End Email
Plugin Slug
cloak-front-end-email
Vulnerability
Contributor+ Stored XSS
Patched in Version
No Fix
Severity Score
Medium
CVE
2023-0150
The vulnerability has not been patched and the plugin is closed. You should uninstall and delete the plugin.

WordPress Theme Vulnerabilities

In this section, the latest WordPress theme vulnerabilities have been disclosed. Each theme listing includes the type of vulnerability, the active installations, the version number if patched, the severity rating, and the CVE.

  • Good news! No new WordPress theme vulnerabilities were disclosed this week.

Never worry about running a vulnerable plugin or theme again.

As you can see from this report, lots of new WordPress plugin and theme vulnerabilities are disclosed each week. We know it can be difficult to stay on top of every reported vulnerability disclosure, so the iThemes Security Pro plugin makes it easy to make sure your site isn’t running a theme, plugin, or WordPress core version with a known vulnerability.

Scans Your Website Twice a Day for Vulnerabilities

Your website’s plugins, themes, and WordPress core versions are checked against the WPScan Vulnerability Database for the latest vulnerability disclosures.

Automatically Updates if a Security Fix is Available

Paired with Version Management, iThemes Security will automatically update a plugin, theme, or WordPress core version if it has a vulnerability.

Emails You if Site Scan Detects a Vulnerability

You can receive an email report if your site is running vulnerable versions of a plugin, theme, or WordPress core. Customize the email addresses that receive scan results.

The Best WordPress Security Plugin to Secure & Protect WordPress Sites

WordPress currently powers over 40% of all websites, so it has become an easy target for hackers with malicious intent. The iThemes Security Pro plugin takes the guesswork out of WordPress security to make it easy to secure & protect your WordPress website. It’s like having a full-time security expert on staff who constantly monitors and protects your WordPress site for you.

Buy iThemes Security Pro


iThemes Team
iThemes Editorial Team

Each week, the team at iThemes team publishes new WordPress tutorials and resources, including the Weekly WordPress Vulnerability Report. Since 2008, iThemes has been dedicated to helping you build, maintain, and secure WordPress sites for yourself or for clients. Our mission? Make People’s Lives Awesome.

Share via:

  • Facebook
  • Twitter
  • LinkedIn
  • More
Other related posts
A security-riddled computer monitor. There is a large, orange shield with a slash in the middle of the screen. Surrounding it are a red target, a green skull and crossbones, an orange “bug”, a triangle with an explanation point in the middle and a gray gear.
WordPress Vulnerability Report – January 25, 2023
Turnstile and hCaptcha
New Turnstile and hCaptcha Support in Security Pro 7.3
clickjacking
What is Clickjacking and How to Prevent it
A computer riddled with security issue alerts. There is a large, orange shield with a slash in the middle of the screen. Surrounding it are a red target, a green skull and crossbones, an orange “bug”, a triangle with an explanation point in the middle and a gray gear.
WordPress Vulnerability Report – January 11, 2023

Get updates on new themes & plugins plus special discounts

About iThemes

  • The Team
  • Contact Us
  • Website Accessibility Statement
  • Sitemap

Resources

  • Blog
  • Documentation
  • WordPress Tutorials
  • Free WordPress Ebooks
  • Free Webinar Library
  • Free Upcoming Webinars
  • iThemes Training
  • Affiliates

Customers

  • Member Panel Login
  • Support
  • FAQs
  • Upgrade Policy
  • Licensing
  • Terms and Conditions
  • Refund Policy

Top Products

  • BackupBuddy
  • iThemes Security Pro
  • iThemes Sync
  • Restrict Content Pro
  • WPComplete
  • WordPress Plugins
  • Content Upgrades
  • WordPress Landing Page Plugin
  • BackupBuddy Stash

iThemes Media LLC Copyright © 2023 All rights reserved | Privacy Policy

© 2022 All Rights Reserved.

Visit StellarWP Visit Nexcess
Share via
Facebook
Twitter
LinkedIn
Mix
Email
Print
Copy Link
Powered by Social Snap
Copy link
CopyCopied
Powered by Social Snap

Get the Weekly WordPress Vulnerability Report

Vulnerable WordPress plugins and themes are the #1 reason WordPress sites get hacked, but keeping track of every new plugin and theme vulnerability is hard work. Get the weekly WordPress Vulnerability Report delivered right to your inbox to help keep your website secure.
No spam. Unsubscribe anytime.