WordPress Vulnerability Report

WordPress Vulnerability Report – January 4, 2023

Vulnerable plugins and themes are the #1 reason WordPress websites get hacked. The weekly WordPress Vulnerability Report powered by WPScan covers recent WordPress plugin, theme, and core vulnerabilities and what to do if you run one of the vulnerable plugins or themes on your website. Each vulnerability will have a severity rating of low, medium, high, or critical.

Avatar photo
SolidWP Editorial Team

Vulnerable plugins and themes are the #1 reason WordPress websites get hacked. The weekly WordPress Vulnerability Report powered by WPScan covers recent WordPress plugin, theme, and core vulnerabilities and what to do if you run one of the vulnerable plugins or themes on your website.

Each vulnerability will have a severity rating of low, medium, high, or critical. Responsible disclosure and reporting of vulnerabilities is an integral part of keeping the WordPress community safe. Please share this post with your friends to help get the word out and make WordPress safer for everyone!

WordPress Core News

WordPress 6.1.1 was released on November 15, 2022, as a short-cycle maintenance release with 29 bug fixes in Core and 21 bug fixes for the block editor. Because this is a core update, be sure to update to WordPress 6.1.1 as soon as possible! As always, with a major release like this, it makes sense to ensure your site is backed up with BackupBuddy before updating.

No new WordPress core vulnerabilities were disclosed this week.

There is a known unpatched vulnerability in WordPress core affecting all versions of WordPress. If you’re using iThemes Security, you’ve probably been alerted to this. As we are unsure when this very low-severity vulnerability will be patched, emails from iThemes Security will no longer alert for this specific vulnerability. Read our blog post about this vulnerability.

Get SolidWP tips direct in your inbox

Sign up

This field is for validation purposes and should be left unchanged.
Placeholder text
Placeholder text
Thanks

Oops something went wrong, please try submitting again

Get started with confidence — risk free, guaranteed

WordPress Plugin Vulnerabilities

In this section, the latest WordPress plugin vulnerabilities have been disclosed. Each plugin listing includes the type of vulnerability, the active installations, the version number if patched, the severity rating, and the CVE.

All In One WP Security & Firewall

Plugin Slug:
all-in-one-wp-security-and-firewall
Installations:
1,000,000+
Vulnerability:
Configuration Leak
Patched in Version:
5.1.3
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 5.1.3.

WP Statistics

Plugin Slug:
wp-statistics
Installations:
600,000+
Vulnerability:
Authenticated SQLi
Patched in Version:
13.2.9
Severity Score:
High
The vulnerability has been patched, so you should update to version 13.2.9.

Sassy Social Share

Plugin Slug:
sassy-social-share
Installations:
100,000+
Vulnerability:
Contributor+ Stored XSS
Patched in Version:
3.3.45
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.3.45.

Google Analyticator

Plugin Slug:
google-analyticator
Installations:
100,000+
Vulnerability:
Admin+ PHP Object Injection
Patched in Version:
6.5.6
Severity Score:
Low
The vulnerability has been patched, so you should update to version 6.5.6.

Booster for WooCommerce

Plugin Slug:
woocommerce-jetpack
Installations:
70,000+
Vulnerability:
Multiple CSRF
Patched in Version:
6.0.1
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 6.0.1.

Collapse-O-Matic

Plugin Slug:
jquery-collapse-o-matic
Installations:
60,000+
Vulnerability:
Contributor+ Stored XSS
Patched in Version:
1.8.3
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.8.3.

Search & Filter

Plugin Slug:
search-filter
Installations:
50,000+
Vulnerability:
Contributor+ Stored XSS
Patched in Version:
1.2.16
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.2.16.

Page-list

Plugin:
Page-list
Plugin Slug:
page-list
Installations:
40,000+
Vulnerability:
Contributor+ Stored XSS
Patched in Version:
5.3
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 5.3.

OneClick Chat to Order

Plugin Slug:
oneclick-whatsapp-order
Installations:
30,000+
Vulnerability:
Contributor+ Stored XSS via Shortcode
Patched in Version:
1.0.4.2
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.0.4.2.

Sitemap

Plugin:
Sitemap
Plugin Slug:
sitemap
Installations:
30,000+
Vulnerability:
Contributor+ Stored XSS
Patched in Version:
4.4
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 4.4.

Compact WP Audio Player

Plugin Slug:
compact-wp-audio-player
Installations:
30,000+
Vulnerability:
Contributor+ Stored XSS
Patched in Version:
1.9.8
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.9.8.

WP Popups

Plugin Slug:
wp-popups-lite
Installations:
30,000+
Vulnerability:
Contributor+ Stored XSS
Patched in Version:
2.1.4.8
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.1.4.8.

Login Logout Menu

Plugin Slug:
login-logout-menu
Installations:
20,000+
Vulnerability:
Contributor+ Stored XSS in Shortcode
Patched in Version:
1.4.0
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.4.0.

ShiftNav – Responsive Mobile Menu

Plugin Slug:
shiftnav-responsive-mobile-menu
Installations:
20,000+
Vulnerability:
Contributor+ Stored XSS in Shortcode
Patched in Version:
1.7.2
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.7.2.

Product Slider for WooCommerce

Plugin Slug:
woo-product-slider
Installations:
20,000+
Vulnerability:
Contributor+ Stored XSS in Shortcode
Patched in Version:
2.6.4
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.6.4.

Mongoose Page Plugin

Plugin Slug:
facebook-page-feed-graph-api
Installations:
20,000+
Vulnerability:
Contributor+ Stored XSS via Shortcode
Patched in Version:
1.9.0
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.9.0.

Rate my Post – WP Rating System

Plugin Slug:
rate-my-post
Installations:
20,000+
Vulnerability:
Contributor+ Stored XSS via Shortcode
Patched in Version:
3.3.9
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.3.9.

WordPress Simple Shopping Cart

Plugin Slug:
wordpress-simple-paypal-shopping-cart
Installations:
20,000+
Vulnerability:
Contributor+ Stored XSS via Shortcode
Patched in Version:
4.6.2
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 4.6.2.

Structured Content

Plugin Slug:
structured-content
Installations:
20,000+
Vulnerability:
Contributor+ Stored XSS in Shortcode
Patched in Version:
1.5.1
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.5.1.

Video Conferencing with Zoom

Plugin Slug:
video-conferencing-with-zoom-api
Installations:
20,000+
Vulnerability:
Contributor+ Stored XSS
Patched in Version:
4.0.10
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 4.0.10.

Easy Appointments

Plugin Slug:
easy-appointments
Installations:
20,000+
Vulnerability:
Contributor+ Stored XSS in Shortcode
Patched in Version:
3.11.2
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.11.2.

Portfolio for Elementor, Image Gallery & Post Grid | PowerFolio

Plugin Slug:
portfolio-elementor
Installations:
10,000+
Vulnerability:
Contributor+ Stored XSS via Shortcode
Patched in Version:
2.3.1
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.3.1.

WP Google My Business Auto Publish

Plugin Slug:
wp-google-my-business-auto-publish
Installations:
10,000+
Vulnerability:
Contributor+ Stored XSS via Shortcode
Patched in Version:
3.4
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.4.

WPZOOM Portfolio

Plugin Slug:
wpzoom-portfolio
Installations:
10,000+
Vulnerability:
Contributor+ Stored XSS via Shortcode
Patched in Version:
1.2.2
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.2.2.

10WebMapBuilder

Plugin Slug:
wd-google-maps
Installations:
10,000+
Vulnerability:
Contributor+ Stored XSS via Shortcode
Patched in Version:
1.0.72
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.0.72.

Word Balloon

Plugin Slug:
word-balloon
Installations:
10,000+
Vulnerability:
Contributor+ Stored XSS via Shortcode
Patched in Version:
4.19.3
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 4.19.3.

PDF Viewer

Plugin:
PDF Viewer
Plugin Slug:
pdf-viewer
Installations:
10,000+
Vulnerability:
Contributor+ Stored XSS via Shortcode
Patched in Version:
1.0.0
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.0.0.

Print-O-Matic

Plugin Slug:
print-o-matic
Installations:
10,000+
Vulnerability:
Contributor+ Stored XSS via Shortcode
Patched in Version:
2.1.8
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.1.8.

HashBar – WordPress Notification Bar

Plugin Slug:
hashbar-wp-notification-bar
Installations:
10,000+
Vulnerability:
Contributor+ Stored XSS via Shortcode
Patched in Version:
1.3.6
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.3.6.

PixCodes

Plugin:
PixCodes
Plugin Slug:
pixcodes
Installations:
10,000+
Vulnerability:
Contributor+ Stored XSS in Shortcode
Patched in Version:
2.3.7
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.3.7.

Genesis Columns Advanced

Plugin Slug:
genesis-columns-advanced
Installations:
10,000+
Vulnerability:
Contributor+ Stored XSS via Shortcode
Patched in Version:
2.0.4
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.0.4.

Passster

Plugin Slug:
content-protector
Installations:
10,000+
Vulnerability:
Protection Bypass & Arbitrary Post Access; Contributor+ Stored Cross-Site Scripting
Patched in Version:
3.5.5.9
Severity Score:
High
The vulnerability has been patched, so you should update to version 3.5.5.9.

Bold Timeline Lite

Plugin Slug:
bold-timeline-lite
Installations:
10,000+
Vulnerability:
Contributor+ Stored XSS via Shortcode
Patched in Version:
1.1.5
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.1.5.

Icon Widget

Plugin Slug:
icon-widget
Installations:
9,000+
Vulnerability:
Contributor+ Stored XSS via Shortcode
Patched in Version:
1.3.0
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.3.0.

User Verification

Plugin Slug:
user-verification
Installations:
5,000+
Vulnerability:
Authentication Bypass
Patched in Version:
1.0.94
Severity Score:
Critical
The vulnerability has been patched, so you should update to version 1.0.94.

Pardakht Delkhah

Plugin Slug:
pardakht-delkhah
Installations:
1,000+
Vulnerability:
Unauthenticated Stored XSS
Patched in Version:
2.9.3
Severity Score:
High
The vulnerability has been patched, so you should update to version 2.9.3.

Login as User or Customer

Plugin Slug:
login-as-customer-or-user
Installations:
400+
Vulnerability:
Unauthenticated Privilege Escalation to Admin
Patched in Version:
3.3
Severity Score:
Critical
The vulnerability has been patched, so you should update to version 3.3.

Booster for WooCommerce

Plugin Slug:
booster-elite-for-woocommerce
Vulnerability:
Multiple CSRF
Patched in Version:
6.0.1
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 6.0.1.

BruteBank – WP Security & Firewall

Plugin Slug:
brutebank
Vulnerability:
Settings Update via CSRF
Patched in Version:
1.9
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.9.

Booster for WooCommerce

Plugin Slug:
booster-plus-for-woocommerce
Vulnerability:
Multiple CSRF
Patched in Version:
6.0.1
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 6.0.1.
Plugin Slug:
justified-gallery
Vulnerability:
Contributor+ Stored XSS via Shortcode
Patched in Version:
1.7.1
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.7.1.

WordPress Plugin Vulnerabilities – No Known Fix

This section contains plugin vulnerabilities with no known fix. Until a patch is available, immediately uninstall and delete the plugin.

WP Limit Login Attempts

Plugin Slug:
wp-limit-login-attempts
Installations:
20,000+
Vulnerability:
IP Spoofing
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Members Import

Plugin Slug:
members-import
Vulnerability:
XSS via Imported CSV
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched and the plugin is closed. You should uninstall and delete the plugin.

Accordion Shortcodes

Plugin Slug:
accordion-shortcodes
Vulnerability:
Contributor+ Stored XSS via Shortcode
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched and the plugin is closed. You should uninstall and delete the plugin.
Plugin Slug:
cpt-bootstrap-carousel
Vulnerability:
Contributor+ Stored XSS via Shortcode
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched and the plugin is closed. You should uninstall and delete the plugin.

Meteor Slides

Plugin Slug:
meteor-slides
Vulnerability:
Contributor+ Stored XSS
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched and the plugin is closed. You should uninstall and delete the plugin.

CBX Petition for WordPress

Plugin Slug:
cbxpetition
Vulnerability:
Unauthenticated SQLi
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched and the plugin is closed. You should uninstall and delete the plugin.

Social Sharing Toolkit

Plugin Slug:
social-sharing-toolkit
Vulnerability:
Contributor+ Stored XSS via Shortcode
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched and the plugin is closed. You should uninstall and delete the plugin.

MediaElement.js – HTML5 Video & Audio Player

Plugin Slug:
media-element-html5-video-and-audio-player
Vulnerability:
Contributor+ Stored XSS via Shortcode
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched and the plugin is closed. You should uninstall and delete the plugin.
Plugin Slug:
eu-cookie-law
Vulnerability:
Admin+ Stored XSS
Patched in Version:
No Fix
Severity Score:
Low
The vulnerability has not been patched and the plugin is closed. You should uninstall and delete the plugin.

WordPress Theme Vulnerabilities

In this section, the latest WordPress theme vulnerabilities have been disclosed. Each theme listing includes the type of vulnerability, the active installations, the version number if patched, the severity rating, and the CVE.

Multiple themes – Unauthenticated Arbitrary File Upload

Theme:
WeStand
Theme Slug:
westand
Vulnerability:
RCE
Patched in Version:
2.1
Severity Score:
Critical
The vulnerability has been patched, so you should update to version 2.1.

WordPress Theme Vulnerabilities – No Known Fix

This section contains theme vulnerabilities with no known fix. Until a patch is available, immediately uninstall and delete the theme.

Aidreform

Theme:
aidreform
Theme Slug:
aidreform
Vulnerability:
Unauthenticated Arbitrary File Upload
Patched in Version:
No Fix
Severity Score:
Critical
The vulnerability has not been patched. You should switch themes.

Kingclub-theme

Theme Slug:
kingclub-theme
Vulnerability:
Unauthenticated Arbitrary File Upload
Patched in Version:
No Fix
Severity Score:
Critical
The vulnerability has not been patched. You should switch themes.

Footysquare

Theme Slug:
footysquare
Vulnerability:
Unauthenticated Arbitrary File Upload
Patched in Version:
No Fix
Severity Score:
Critical
The vulnerability has not been patched. You should switch themes.

Spikes-black

Theme Slug:
spikes-black
Vulnerability:
Unauthenticated Arbitrary File Upload
Patched in Version:
No Fix
Severity Score:
Critical
The vulnerability has not been patched. You should switch themes.

Stratfort

Theme:
stratfort
Theme Slug:
statfort
Vulnerability:
Unauthenticated Arbitrary File Upload
Patched in Version:
No Fix
Severity Score:
Critical
The vulnerability has not been patched. You should switch themes.

Spikes

Theme:
spikes
Theme Slug:
spikes
Vulnerability:
Unauthenticated Arbitrary File Upload
Patched in Version:
No Fix
Severity Score:
Critical
The vulnerability has not been patched. You should switch themes.

Club-theme

Theme Slug:
club-theme
Vulnerability:
Unauthenticated Arbitrary File Upload
Patched in Version:
No Fix
Severity Score:
Critical
The vulnerability has not been patched. You should switch themes.

Soundblast

Theme Slug:
soundblast
Vulnerability:
Unauthenticated Arbitrary File Upload
Patched in Version:
No Fix
Severity Score:
Critical
The vulnerability has not been patched. You should switch themes.

Bolster

Theme:
bolster
Theme Slug:
bolster
Vulnerability:
Unauthenticated Arbitrary File Upload
Patched in Version:
No Fix
Severity Score:
Critical
The vulnerability has not been patched. You should switch themes.

Solid Security is part of Solid Suite — The best foundation for WordPress websites.

Every WordPress site needs security, backups, and management tools. That’s Solid Suite — an integrated bundle of three plugins: Solid Security, Solid Backups, and Solid Central. You also get access to Solid Academy’s learning resources for WordPress professionals. Build your next WordPress website on a solid foundation with Solid Suite!

Get Solid Security

Did you like this article? Spread the word: