Menu
iThemes
WordPress Security, Backups & Maintenance
  • Products
    • iThemes Security Pro
    • BackupBuddy
    • iThemes Sync
    • Why buy from iThemes?
  • Bundles
    • Essentials Bundle
    • Plugin Suite
    • WordPress Web Designer’s Toolkit
    • Customer Spotlights
  • Resources
    • Blog
    • WordPress 101 Tutorials
    • WordPress Ebooks
    • Weekly WordPress Vulnerability Report
    • The Ultimate Guide to Starting a Web Design Business
  • Training
    • Upcoming Webinars
    • Free Webinar Library
    • Premium Courses
    • Become a Member
    • Member Login
  • Support
    • Documentation
    • Get Help
    • Product Updates
    • Upgrade Policy
    • Contact
    • Our Mission: Make People’s Lives Awesome
  • Log In
WordPress News and Updates from iThemes
Categories
  • Product Updates
  • WordPress Backup
  • WordPress Block Editor
  • WordPress Ecommerce
  • WordPress for Freelancers
  • WordPress Security
  • WordPress Tutorials
  • WPprosper

WordPress Vulnerability Report – January 25, 2023

Written by iThemes Editorial Team on January 25, 2023

Last Updated on January 25, 2023

Vulnerable plugins and themes are the #1 reason WordPress websites get hacked. The weekly WordPress Vulnerability Report powered by WPScan covers recent WordPress plugin, theme, and core vulnerabilities and what to do if you run one of the vulnerable plugins or themes on your website.

Each vulnerability will have a severity rating of low, medium, high, or critical. Responsible disclosure and reporting of vulnerabilities is an integral part of keeping the WordPress community safe. Please share this post with your friends to help get the word out and make WordPress safer for everyone!

Contents of the January 25, 2023 Report
  • The Future of Authentication is Passkeys! Login to your WordPress site with Biometrics only available in iThemes Security Pro
  • WordPress Core News
  • WordPress Plugin Vulnerabilities
    • Enable Media Replace
    • Spectra
    • GiveWP
    • Parsi Date
    • Better Font Awesome
    • LearnPress Plugin
    • Customer Reviews for WooCommerce
    • Themify Portfolio Post
    • Spotlight Social Feeds
    • Meks Flexible Shortcodes
    • WP Visitor Statistics (Real Time Traffic)
    • WP Google Review Slider
    • TemplatesNext ToolKit
    • WP Customer Area
    • Easy Accept Payments for PayPal
    • Easy Affiliate Links
    • WP TripAdvisor Review Slider
    • Custom 404 Pro
    • PickPlugins Product Slider for WooCommerce
    • YaMaps for WordPress Plugin
    • Social Like Box and Page by WpDevArt
    • WP FullCalendar
    • WP Font Awesome
    • WP Review Slider
    • Product Slider and Carousel with Category for WooCommerce
    • Zoho Forms
    • Youzify
    • Judge.me Product Reviews for WooCommerce
    • Timed Content
    • Location Weather
    • Responsive Gallery Grid
    • Watu Quiz
    • Lightweight Accordion
    • Pinpoint Booking System
    • Simple URLs
    • WP Helper Lite
    • GPT3 AI Content Writer
    • WP Airbnb Review Slider
    • WP Yelp Review Slider
    • Shortcode for Font Awesome
    • uTubeVideo Gallery
    • GigPress
    • Lightbox Gallery
    • Rich Table of Contents
  • WordPress Plugin Vulnerabilities – No Known Fix
    • YARPP – Yet Another Related Posts Plugin
    • Easy PayPal Buy Now Button
    • Markup
    • Page Builder: Live Composer
    • FL3R FeelBox
    • Oi Yandex.Maps
    • Youtube Channel Gallery
    • Intuitive Custom Post Order
    • Youtube Shortcode
    • Amazon JS
    • Widget Shortcode
    • Amr Shortcode Any Widget
    • WP TopBar
    • Widgets on Pages
    • Twenty20 Image Before-After
    • Mapwiz
  • WordPress Theme Vulnerabilities
  • The Best WordPress Security Plugin to Secure & Protect WordPress Sites

The Future of Authentication is Passkeys! Login to your WordPress site with Biometrics only available in iThemes Security Pro

The problems of brute force attacks through credential stuffing, phishing attacks, and reused passwords have made our digital lives less secure. We’ve all tried to encourage 2-factor authentication as a protection, but less than 30% of users actually use 2FA. Password-based logins are a problem.

The future of authentication is passkeys, and iThemes Security Pro is the first to bring this breakthrough technology to WordPress sites. Using breakthrough WebAuthn technology based on public/private cryptography, passkeys make passwords obsolete. Now, website admins and end users can have secure logins without the inconvenience of additional two-factor apps, password managers, or complex password requirements.

Learn More About Passkeys

WordPress Core News

WordPress 6.1.1 was released on November 15, 2022, as a short-cycle maintenance release with 29 bug fixes in Core and 21 bug fixes for the block editor. Because this is a core update, be sure to update to WordPress 6.1.1 as soon as possible! As always, with a major release like this, it makes sense to ensure your site is backed up with BackupBuddy before updating.

  • No new WordPress core vulnerabilities were disclosed this week.

There is a known unpatched vulnerability in WordPress core affecting all versions of WordPress. If you’re using iThemes Security, you’ve probably been alerted to this. As we are unsure when this very low-severity vulnerability will be patched, emails from iThemes Security will no longer alert for this specific vulnerability. Read our blog post about this vulnerability.

Get the weekly WordPress Vulnerability Report delivered to your inbox each Wednesday.
Subscribe now

WordPress Plugin Vulnerabilities

In this section, the latest WordPress plugin vulnerabilities have been disclosed. Each plugin listing includes the type of vulnerability, the active installations, the version number if patched, the severity rating, and the CVE.

Enable Media Replace

Product image for Enable Media Replace.
Plugin
Enable Media Replace
Plugin Slug
enable-media-replace
Installations
600,000+
Vulnerability
Author+ Arbitrary File Upload
Patched in Version
4.0.2
Severity Score
Critical
CVE
2023-0255
The vulnerability has been patched, so you should update to version 4.0.2.

Spectra

Product image for Spectra – WordPress Gutenberg Blocks.
Plugin
Spectra – WordPress Gutenberg Blocks
Plugin Slug
ultimate-addons-for-gutenberg
Installations
400,000+
Vulnerability
Stored Cross-Side Scripting
Patched in Version
1.15.0
Severity Score
Medium
CVE
2020-36656
The vulnerability has been patched, so you should update to version 1.15.0.

GiveWP

Product image for GiveWP – Donation Plugin and Fundraising Platform.
Plugin
GiveWP – Donation Plugin and Fundraising Platform
Plugin Slug
give
Installations
100,000+
Vulnerability
Contributor+ Stored XSS; Unauthenticated SQLi
Patched in Version
2.24.1
Severity Score
Medium
CVE
2022-4448
The vulnerability has been patched, so you should update to version 2.24.1.

Parsi Date

Product image for Parsi Date.
Plugin
Parsi Date
Plugin Slug
wp-parsidate
Installations
100,000+
Vulnerability
Reflected Cross-Site Scripting
Patched in Version
4.0.2
Severity Score
Medium
The vulnerability has been patched, so you should update to version 4.0.2.

Better Font Awesome

Product image for Better Font Awesome.
Plugin
Better Font Awesome
Plugin Slug
better-font-awesome
Installations
100,000+
Vulnerability
Contributor+ Stored XSS
Patched in Version
2.0.4
Severity Score
Medium
CVE
2022-4512
The vulnerability has been patched, so you should update to version 2.0.4.

LearnPress Plugin

Product image for LearnPress – WordPress LMS Plugin.
Plugin
LearnPress – WordPress LMS Plugin
Plugin Slug
learnpress
Installations
100,000+
Vulnerability
Unauthenticated LFI; Subscriber+ SQLi; Unauthenticated SQLi
Patched in Version
4.2.0
Severity Score
Critical
CVE
2022-47615
The vulnerability has been patched, so you should update to version 4.2.0.

Customer Reviews for WooCommerce

Product image for Customer Reviews for WooCommerce.
Plugin
Customer Reviews for WooCommerce
Plugin Slug
customer-reviews-woocommerce
Installations
50,000+
Vulnerability
Contributor+ LFI; Contributor+ Stored XSS
Patched in Version
5.17.0
Severity Score
Critical
CVE
2023-0080
The vulnerability has been patched, so you should update to version 5.17.0.

Themify Portfolio Post

Plugin
Themify Portfolio Post
Plugin Slug
themify-portfolio-post
Installations
50,000+
Vulnerability
Contributor+ Stored XSS
Patched in Version
1.2.2
Severity Score
Medium
CVE
2023-0362
The vulnerability has been patched, so you should update to version 1.2.2.

Spotlight Social Feeds

Product image for Spotlight Social Feeds [Block, Shortcode, and Widget].
Plugin
Spotlight Social Feeds [Block, Shortcode, and Widget]
Plugin Slug
spotlight-social-photo-feeds
Installations
50,000+
Vulnerability
Contributor+ Stored XSS
Patched in Version
1.4.3
Severity Score
Medium
CVE
2023-0379
The vulnerability has been patched, so you should update to version 1.4.3.

Meks Flexible Shortcodes

Product image for Meks Flexible Shortcodes.
Plugin
Meks Flexible Shortcodes
Plugin Slug
meks-flexible-shortcodes
Installations
30,000+
Vulnerability
Contributor+ Stored XSS
Patched in Version
1.3.5
Severity Score
Medium
CVE
2022-4562
The vulnerability has been patched, so you should update to version 1.3.5.

WP Visitor Statistics (Real Time Traffic)

Product image for WP Visitor Statistics (Real Time Traffic).
Plugin
WP Visitor Statistics (Real Time Traffic)
Plugin Slug
wp-stats-manager
Installations
20,000+
Vulnerability
Contributor+ Stored XSS via Shortcode
Patched in Version
6.5
Severity Score
Medium
CVE
2022-4656
The vulnerability has been patched, so you should update to version 6.5.

WP Google Review Slider

Product image for WP Google Review Slider.
Plugin
WP Google Review Slider
Plugin Slug
wp-google-places-review-slider
Installations
20,000+
Vulnerability
Subscriber+ SQLi
Patched in Version
11.8
Severity Score
High
CVE
2023-0259
The vulnerability has been patched, so you should update to version 11.8.

TemplatesNext ToolKit

Product image for TemplatesNext ToolKit.
Plugin
TemplatesNext ToolKit
Plugin Slug
templatesnext-toolkit
Installations
10,000+
Vulnerability
Contributor+ Stored XSS via Shortcode; Contributor+ Stored XSS
Patched in Version
3.2.9
Severity Score
Medium
CVE
2022-4678
The vulnerability has been patched, so you should update to version 3.2.9.

WP Customer Area

Product image for WP Customer Area.
Plugin
WP Customer Area
Plugin Slug
customer-area
Installations
10,000+
Vulnerability
Unauthorised Actions via CSRF
Patched in Version
8.1.4
Severity Score
Medium
CVE
2022-4745
The vulnerability has been patched, so you should update to version 8.1.4.

Easy Accept Payments for PayPal

Product image for Easy Accept Payments for PayPal.
Plugin
Easy Accept Payments for PayPal
Plugin Slug
wordpress-easy-paypal-payment-or-donation-accept-plugin
Installations
10,000+
Vulnerability
Contributor+ Stored XSS
Patched in Version
4.9.10
Severity Score
Medium
CVE
2023-0275
The vulnerability has been patched, so you should update to version 4.9.10.

Easy Affiliate Links

Product image for Easy Affiliate Links.
Plugin
Easy Affiliate Links
Plugin Slug
easy-affiliate-links
Installations
10,000+
Vulnerability
Contributor+ Stored XSS
Patched in Version
3.7.1
Severity Score
Medium
CVE
2023-0375
The vulnerability has been patched, so you should update to version 3.7.1.

WP TripAdvisor Review Slider

Product image for WP TripAdvisor Review Slider.
Plugin
WP TripAdvisor Review Slider
Plugin Slug
wp-tripadvisor-review-slider
Installations
10,000+
Vulnerability
Subscriber+ SQLi
Patched in Version
10.8
Severity Score
High
CVE
2023-0261
The vulnerability has been patched, so you should update to version 10.8.

Custom 404 Pro

Product image for Custom 404 Pro.
Plugin
Custom 404 Pro
Plugin Slug
custom-404-pro
Installations
10,000+
Vulnerability
Logs Deletion via CSRF
Patched in Version
3.7.2
Severity Score
Medium
CVE
2023-0385
The vulnerability has been patched, so you should update to version 3.7.2.

PickPlugins Product Slider for WooCommerce

Product image for Product Slider for WooCommerce by PickPlugins.
Plugin
Product Slider for WooCommerce by PickPlugins
Plugin Slug
woocommerce-products-slider
Installations
10,000+
Vulnerability
Contributor+ Stored XSS
Patched in Version
1.13.42
Severity Score
Medium
CVE
2023-0166
The vulnerability has been patched, so you should update to version 1.13.42.

YaMaps for WordPress Plugin

Product image for YaMaps for WordPress Plugin.
Plugin
YaMaps for WordPress Plugin
Plugin Slug
yamaps
Installations
10,000+
Vulnerability
Contributor+ Stored XSS
Patched in Version
0.6.26
Severity Score
Medium
CVE
2023-0270
The vulnerability has been patched, so you should update to version 0.6.26.

Social Like Box and Page by WpDevArt

Product image for Social Like Box and Page by WpDevArt.
Plugin
Social Like Box and Page by WpDevArt
Plugin Slug
like-box
Installations
10,000+
Vulnerability
Contributor+ Stored XSS
Patched in Version
0.8.41
Severity Score
Medium
CVE
2023-0177
The vulnerability has been patched, so you should update to version 0.8.41.

WP FullCalendar

Plugin
WP FullCalendar
Plugin Slug
wp-fullcalendar
Installations
10,000+
Vulnerability
Unauthenticated Arbitrary Post Access
Patched in Version
1.5
Severity Score
High
CVE
2022-3891
The vulnerability has been patched, so you should update to version 1.5.

WP Font Awesome

Product image for WP Font Awesome.
Plugin
WP Font Awesome
Plugin Slug
wp-font-awesome
Installations
10,000+
Vulnerability
Contributor+ Stored XSS
Patched in Version
1.7.9
Severity Score
Medium
CVE
2023-0271
The vulnerability has been patched, so you should update to version 1.7.9.

WP Review Slider

Product image for WP Review Slider.
Plugin
WP Review Slider
Plugin Slug
wp-facebook-reviews
Installations
10,000+
Vulnerability
Subscriber+ SQLi
Patched in Version
12.2
Severity Score
High
CVE
2023-0260
The vulnerability has been patched, so you should update to version 12.2.

Product Slider and Carousel with Category for WooCommerce

Product image for Product Slider and Carousel with Category for WooCommerce.
Plugin
Product Slider and Carousel with Category for WooCommerce
Plugin Slug
woo-product-slider-and-carousel-with-category
Installations
10,000+
Vulnerability
Contributor+ Stored XSS via Shortcode
Patched in Version
2.8
Severity Score
Medium
CVE
2022-4791
The vulnerability has been patched, so you should update to version 2.8.

Zoho Forms

Product image for Form plugin for WordPress – Zoho Forms.
Plugin
Form plugin for WordPress – Zoho Forms
Plugin Slug
zoho-forms
Installations
10,000+
Vulnerability
Contributor+ Stored XSS
Patched in Version
3.0.1
Severity Score
Medium
CVE
2023-0169
The vulnerability has been patched, so you should update to version 3.0.1.

Youzify

Product image for Youzify – BuddyPress Community, User Profile, Social Network & Membership Plugin for WordPress.
Plugin
Youzify – BuddyPress Community, User Profile, Social Network & Membership Plugin for WordPress
Plugin Slug
youzify
Installations
9,000+
Vulnerability
Contributor+ Stored XSS
Patched in Version
1.2.2
Severity Score
Medium
CVE
2023-0059
The vulnerability has been patched, so you should update to version 1.2.2.

Judge.me Product Reviews for WooCommerce

Product image for Judge.me Product Reviews for WooCommerce.
Plugin
Judge.me Product Reviews for WooCommerce
Plugin Slug
judgeme-product-reviews-woocommerce
Installations
8,000+
Vulnerability
Contributor+ Stored XSS
Patched in Version
1.3.21
Severity Score
Medium
CVE
2023-0061
The vulnerability has been patched, so you should update to version 1.3.21.

Timed Content

Plugin
Timed Content
Plugin Slug
timed-content
Installations
8,000+
Vulnerability
Contributor+ Stored XSS
Patched in Version
2.73
Severity Score
Medium
CVE
2023-0067
The vulnerability has been patched, so you should update to version 2.73.

Location Weather

Product image for Location Weather.
Plugin
Location Weather
Plugin Slug
location-weather
Installations
8,000+
Vulnerability
Contributor+ Stored XSS
Patched in Version
1.3.4
Severity Score
Medium
CVE
2023-0360
The vulnerability has been patched, so you should update to version 1.3.4.

Responsive Gallery Grid

Product image for Responsive Gallery Grid.
Plugin
Responsive Gallery Grid
Plugin Slug
responsive-gallery-grid
Installations
7,000+
Vulnerability
Contributor+ Stored XSS
Patched in Version
2.3.9
Severity Score
Medium
CVE
2023-0060
The vulnerability has been patched, so you should update to version 2.3.9.

Watu Quiz

Product image for Watu Quiz.
Plugin
Watu Quiz
Plugin Slug
watu
Installations
6,000+
Vulnerability
Admin+ Stored XSS; Reflected XSS
Patched in Version
3.3.8.3
Severity Score
Low
CVE
2023-0429
The vulnerability has been patched, so you should update to version 3.3.8.3.

Lightweight Accordion

Product image for Lightweight Accordion.
Plugin
Lightweight Accordion
Plugin Slug
lightweight-accordion
Installations
6,000+
Vulnerability
Contributor+ Stored XSS
Patched in Version
1.5.15
Severity Score
Medium
CVE
2023-0373
The vulnerability has been patched, so you should update to version 1.5.15.

Pinpoint Booking System

Product image for Pinpoint Booking System – #1 WordPress Booking Plugin.
Plugin
Pinpoint Booking System – #1 WordPress Booking Plugin
Plugin Slug
booking-system
Installations
6,000+
Vulnerability
Subscriber+ SQLi
Patched in Version
2.9.9.2.9
Severity Score
High
CVE
2023-0220
The vulnerability has been patched, so you should update to version 2.9.9.2.9.

Simple URLs

Product image for Simple URLs – Link Cloaking, Product Displays, and Affiliate Link Management.
Plugin
Simple URLs – Link Cloaking, Product Displays, and Affiliate Link Management
Plugin Slug
simple-urls
Installations
6,000+
Vulnerability
Subscriber+ SQLi; Multiple Reflected XSS
Patched in Version
115
Severity Score
High
CVE
2023-0098
The vulnerability has been patched, so you should update to version 115.

WP Helper Lite

Product image for WP Helper Premium.
Plugin
WP Helper Premium
Plugin Slug
wp-helper-lite
Installations
3,000+
Vulnerability
Reflected Cross-Site Scripting
Patched in Version
4.3
Severity Score
High
CVE
2023-0448
The vulnerability has been patched, so you should update to version 4.3.

GPT3 AI Content Writer

Product image for GPT AI Power: Content Writer & ChatGPT & Image Generator & WooCommerce Product Writer & AI Training.
Plugin
GPT AI Power: Content Writer & ChatGPT & Image Generator & WooCommerce Product Writer & AI Training
Plugin Slug
gpt3-ai-content-generator
Installations
3,000+
Vulnerability
Subscriber+ Arbitrary Post Content Update
Patched in Version
1.4.38
Severity Score
Medium
CVE
2023-0405
The vulnerability has been patched, so you should update to version 1.4.38.

WP Airbnb Review Slider

Product image for WP Airbnb Review Slider.
Plugin
WP Airbnb Review Slider
Plugin Slug
wp-airbnb-review-slider
Installations
2,000+
Vulnerability
Subscriber+ SQLi
Patched in Version
3.3
Severity Score
High
CVE
2023-0262
The vulnerability has been patched, so you should update to version 3.3.

WP Yelp Review Slider

Product image for WP Yelp Review Slider.
Plugin
WP Yelp Review Slider
Plugin Slug
wp-yelp-review-slider
Installations
1,000+
Vulnerability
Subscriber+ SQLi
Patched in Version
7.1
Severity Score
High
CVE
2023-0263
The vulnerability has been patched, so you should update to version 7.1.

Shortcode for Font Awesome

Product image for Shortcode for Font Awesome.
Plugin
Shortcode for Font Awesome
Plugin Slug
shortcode-for-font-awesome
Installations
700+
Vulnerability
Contributor+ Stored XSS
Patched in Version
1.4.1
Severity Score
Medium
CVE
2023-0419
The vulnerability has been patched, so you should update to version 1.4.1.

uTubeVideo Gallery

Plugin
uTubeVideo Gallery
Plugin Slug
utubevideo-gallery
Installations
500+
Vulnerability
Contributor+ Stored XSS
Patched in Version
2.0.8
Severity Score
Medium
CVE
2023-0151
The vulnerability has been patched, so you should update to version 2.0.8.

GigPress

Plugin
GigPress
Plugin Slug
gigpress
Vulnerability
Contributor+ Stored XSS via Shortcode
Patched in Version
2.3.28
Severity Score
Medium
CVE
2022-4759
The vulnerability has been patched, so you should update to version 2.3.28.

Lightbox Gallery

Plugin
Lightbox Gallery
Plugin Slug
lightbox-gallery
Vulnerability
Contributor+ Stored XSS via Shortcode
Patched in Version
0.9.5
Severity Score
Medium
CVE
2022-4682
The vulnerability has been patched, so you should update to version 0.9.5.

Rich Table of Contents

Plugin
Rich Table of Contents
Plugin Slug
rich-table-of-content
Vulnerability
Contributor+ Stored XSS
Patched in Version
1.3.8
Severity Score
Medium
CVE
2022-4551
The vulnerability has been patched, so you should update to version 1.3.8.

WordPress Plugin Vulnerabilities – No Known Fix

This section contains plugin vulnerabilities with no known fix. Until a patch is available, immediately uninstall and delete the plugin.

YARPP – Yet Another Related Posts Plugin

Product image for YARPP – Yet Another Related Posts Plugin.
Plugin
YARPP – Yet Another Related Posts Plugin
Plugin Slug
yet-another-related-posts-plugin
Installations
100,000+
Vulnerability
Contributor+ Stored XSS
Patched in Version
No Fix
Severity Score
Medium
CVE
2022-4471
The vulnerability has not been patched. You should deactivate the plugin.

Easy PayPal Buy Now Button

Product image for Easy PayPal Buy Now Button.
Plugin
Easy PayPal Buy Now Button
Plugin Slug
wp-ecommerce-paypal
Installations
30,000+
Vulnerability
Contributor+ Stored XSS in Shortcode
Patched in Version
No Fix
Severity Score
Medium
CVE
2022-4628
The vulnerability has not been patched. You should deactivate the plugin.

Markup

Product image for Markup (JSON-LD) structured in schema.org.
Plugin
Markup (JSON-LD) structured in schema.org
Plugin Slug
wp-structuring-markup
Installations
30,000+
Vulnerability
Contributor+ Stored XSS via Shortcode
Patched in Version
No Fix
Severity Score
Medium
CVE
2022-4666
The vulnerability has not been patched. You should deactivate the plugin.

Page Builder: Live Composer

Product image for Page Builder: Live Composer.
Plugin
Page Builder: Live Composer
Plugin Slug
live-composer-page-builder
Installations
20,000+
Vulnerability
Contributor+ Stored XSS via Shortcode
Patched in Version
No Fix
Severity Score
Medium
CVE
2022-4669
The vulnerability has not been patched. You should deactivate the plugin.

FL3R FeelBox

Plugin
FL3R FeelBox
Plugin Slug
fl3r-feelbox
Vulnerability
Unauthenticated SQLi
Patched in Version
No Fix
Severity Score
High
CVE
2022-4445
The vulnerability has not been patched and the plugin is closed. You should uninstall and delete the plugin.

Oi Yandex.Maps

Plugin
Oi Yandex.Maps for WordPress
Plugin Slug
oi-yamaps
Vulnerability
Contributor+ Stored XSS
Patched in Version
No Fix
Severity Score
Medium
CVE
2023-22721
The vulnerability has not been patched and the plugin is closed. You should uninstall and delete the plugin.

Youtube Channel Gallery

Plugin
Youtube Channel Gallery
Plugin Slug
youtube-channel-gallery
Vulnerability
Contributor+ Stored XSS via Shortcode
Patched in Version
No Fix
Severity Score
Medium
CVE
2022-4783
The vulnerability has not been patched and the plugin is closed. You should uninstall and delete the plugin.

Intuitive Custom Post Order

Plugin
Intuitive Custom Post Order
Plugin Slug
intuitive-custom-post-order
Vulnerability
Subscriber+ Arbitrary Menu Order Update
Patched in Version
No Fix
Severity Score
Medium
CVE
2022-4385
The vulnerability has not been patched and the plugin is closed. You should uninstall and delete the plugin.

Youtube Shortcode

Plugin
Youtube shortcode
Plugin Slug
youtube-shortcode
Vulnerability
Contributor+ Stored XSS
Patched in Version
No Fix
Severity Score
Medium
CVE
2023-23687
The vulnerability has not been patched and the plugin is closed. You should uninstall and delete the plugin.

Amazon JS

Plugin
Amazon JS
Plugin Slug
amazonjs
Vulnerability
Contributor+ Stored XSS
Patched in Version
No Fix
Severity Score
Medium
CVE
2023-0075
The vulnerability has not been patched and the plugin is closed. You should uninstall and delete the plugin.

Widget Shortcode

Plugin
Widget Shortcode
Plugin Slug
widget-shortcode
Vulnerability
Contributor+ Stored XSS
Patched in Version
No Fix
Severity Score
Medium
CVE
2022-4473
The vulnerability has not been patched and the plugin is closed. You should uninstall and delete the plugin.

Amr Shortcode Any Widget

Plugin
amr shortcode any widget
Plugin Slug
amr-shortcode-any-widget
Vulnerability
Contributor+ Stored XSS
Patched in Version
No Fix
Severity Score
Medium
CVE
2022-4458
The vulnerability has not been patched and the plugin is closed. You should uninstall and delete the plugin.

WP TopBar

Plugin
WP-TopBar
Plugin Slug
wp-topbar
Vulnerability
Admin+ SQLi
Patched in Version
No Fix
Severity Score
Medium
CVE
2023-23824
The vulnerability has not been patched and the plugin is closed. You should uninstall and delete the plugin.

Widgets on Pages

Plugin
Widgets on Pages
Plugin Slug
widgets-on-pages
Vulnerability
Contributor+ Stored XSS
Patched in Version
No Fix
Severity Score
Medium
CVE
2022-4488
The vulnerability has not been patched and the plugin is closed. You should uninstall and delete the plugin.

Twenty20 Image Before-After

Plugin
Twenty20 Image Before-After
Plugin Slug
twenty20
Vulnerability
Contributor+ Stored XSS
Patched in Version
No Fix
Severity Score
Medium
CVE
2022-4580
The vulnerability has not been patched and the plugin is closed. You should uninstall and delete the plugin.

Mapwiz

Plugin
Mapwiz
Plugin Slug
mapwiz
Vulnerability
Admin+ SQLi
Patched in Version
No Fix
Severity Score
Medium
CVE
2022-4546
The vulnerability has not been patched and the plugin is closed. You should uninstall and delete the plugin.

WordPress Theme Vulnerabilities

In this section, the latest WordPress theme vulnerabilities have been disclosed. Each theme listing includes the type of vulnerability, the active installations, the version number if patched, the severity rating, and the CVE.

  • Good news! No new WordPress theme vulnerabilities were disclosed this week.


Never worry about running a vulnerable plugin or theme again.

As you can see from this report, lots of new WordPress plugin and theme vulnerabilities are disclosed each week. We know it can be difficult to stay on top of every reported vulnerability disclosure, so the iThemes Security Pro plugin makes it easy to make sure your site isn’t running a theme, plugin, or WordPress core version with a known vulnerability.

Scans Your Website Twice a Day for Vulnerabilities

Your website’s plugins, themes, and WordPress core versions are checked against the WPScan Vulnerability Database for the latest vulnerability disclosures.

Automatically Updates if a Security Fix is Available

Paired with Version Management, iThemes Security will automatically update a plugin, theme, or WordPress core version if it has a vulnerability.

Emails You if Site Scan Detects a Vulnerability

You can receive an email report if your site is running vulnerable versions of a plugin, theme, or WordPress core. Customize the email addresses that receive scan results.

The Best WordPress Security Plugin to Secure & Protect WordPress Sites

WordPress currently powers over 40% of all websites, so it has become an easy target for hackers with malicious intent. The iThemes Security Pro plugin takes the guesswork out of WordPress security to make it easy to secure & protect your WordPress website. It’s like having a full-time security expert on staff who constantly monitors and protects your WordPress site for you.

Buy iThemes Security Pro


iThemes Team
iThemes Editorial Team

Each week, the team at iThemes team publishes new WordPress tutorials and resources, including the Weekly WordPress Vulnerability Report. Since 2008, iThemes has been dedicated to helping you build, maintain, and secure WordPress sites for yourself or for clients. Our mission? Make People’s Lives Awesome.

Share via:

  • Facebook
  • Twitter
  • LinkedIn
  • More
Other related posts
A computer riddled with security issue alerts. There is a large, orange shield with a slash in the middle of the screen. Surrounding it are a red target, a green skull and crossbones, an orange “bug”, a triangle with an explanation point in the middle and a gray gear.
WordPress Vulnerability Report – March 22, 2023
website-backdoor
What is a Website Backdoor? How to Remove and Prevent the Hack
A security-riddled computer monitor. There is a large, orange shield with a slash in the middle of the screen. Surrounding it are a red target, a green skull and crossbones, an orange “bug”, a triangle with an explanation point in the middle and a gray gear.
WordPress Vulnerability Report – March 15, 2023
ip hack
What is an IP Hack?

Get updates on new themes & plugins plus special discounts

About iThemes

  • Contact Us
  • Website Accessibility Statement
  • Sitemap

Resources

  • Blog
  • Documentation
  • WordPress Tutorials
  • Free WordPress Ebooks
  • Free Webinar Library
  • Free Upcoming Webinars
  • iThemes Training
  • Affiliates

Customers

  • Member Panel Login
  • Support
  • FAQs
  • Upgrade Policy
  • Licensing
  • Terms and Conditions
  • Refund Policy

Top Products

  • BackupBuddy
  • iThemes Security Pro
  • iThemes Sync
  • Restrict Content Pro
  • WPComplete
  • WordPress Plugins
  • Content Upgrades
  • WordPress Landing Page Plugin
  • BackupBuddy Stash

iThemes Media LLC Copyright © 2023 All rights reserved | Privacy Policy

A Liquid Web Brand © 2022 All Rights Reserved.

Get the Weekly WordPress Vulnerability Report

Vulnerable WordPress plugins and themes are the #1 reason WordPress sites get hacked, but keeping track of every new plugin and theme vulnerability is hard work. Get the weekly WordPress Vulnerability Report delivered right to your inbox to help keep your website secure.

Get the Report
Share via
Facebook
Twitter
LinkedIn
Mix
Email
Print
Copy Link
Powered by Social Snap
Copy link
CopyCopied
Powered by Social Snap

Get the Weekly WordPress Vulnerability Report

Vulnerable WordPress plugins and themes are the #1 reason WordPress sites get hacked, but keeping track of every new plugin and theme vulnerability is hard work. Get the weekly WordPress Vulnerability Report delivered right to your inbox to help keep your website secure.
No spam. Unsubscribe anytime.