Menu
iThemes
WordPress Security, Backups & Maintenance
  • Products
    • iThemes Security Pro
    • BackupBuddy
    • iThemes Sync
    • Why buy from iThemes?
  • Bundles
    • Essentials Bundle
    • Plugin Suite
    • WordPress Web Designer’s Toolkit
    • Customer Spotlights
  • Resources
    • Blog
    • WordPress 101 Tutorials
    • WordPress Ebooks
    • Weekly WordPress Vulnerability Report
    • The Ultimate Guide to Starting a Web Design Business
  • Training
    • Upcoming Webinars
    • Free Webinar Library
    • Premium Courses
    • Become a Member
    • Member Login
  • Support
    • Documentation
    • Get Help
    • Product Updates
    • Upgrade Policy
    • Contact
    • Our Mission: Make People’s Lives Awesome
  • Log In
WordPress News and Updates from iThemes
Categories
  • Product Updates
  • WordPress Backup
  • WordPress Block Editor
  • WordPress Ecommerce
  • WordPress for Freelancers
  • WordPress Security
  • WordPress Tutorials
  • WPprosper

WordPress Vulnerability Report – January 4, 2023

Written by iThemes Editorial Team on January 4, 2023

Last Updated on January 4, 2023

Vulnerable plugins and themes are the #1 reason WordPress websites get hacked. The weekly WordPress Vulnerability Report powered by WPScan covers recent WordPress plugin, theme, and core vulnerabilities and what to do if you run one of the vulnerable plugins or themes on your website.

Each vulnerability will have a severity rating of low, medium, high, or critical. Responsible disclosure and reporting of vulnerabilities is an integral part of keeping the WordPress community safe. Please share this post with your friends to help get the word out and make WordPress safer for everyone!

Contents of the January 4, 2023 Report
  • The Future of Authentication is Passkeys! Login to your WordPress site with Biometrics only available in iThemes Security Pro
  • WordPress Core News
  • WordPress Plugin Vulnerabilities
    • All In One WP Security & Firewall
    • WP Statistics
    • Sassy Social Share
    • Google Analyticator
    • Simple Sitemap
    • Booster for WooCommerce
    • Easy Social Feed – Social Photos Gallery – Post Feed – Like Box
    • Collapse-O-Matic
    • Search & Filter
    • Content Control
    • Page-list
    • OneClick Chat to Order
    • Sitemap
    • Compact WP Audio Player
    • WP Popups
    • Top 10
    • Login Logout Menu
    • ShiftNav – Responsive Mobile Menu
    • Product Slider for WooCommerce
    • Mongoose Page Plugin
    • Rate my Post – WP Rating System
    • WordPress Simple Shopping Cart
    • Structured Content
    • GS Logo Slider
    • Video Conferencing with Zoom
    • Easy Appointments
    • GeoDirectory
    • Portfolio for Elementor, Image Gallery & Post Grid | PowerFolio
    • WP Google My Business Auto Publish
    • Landing Page Builder
    • WPZOOM Portfolio
    • 10WebMapBuilder
    • Word Balloon
    • PDF Viewer
    • Print-O-Matic
    • HashBar – WordPress Notification Bar
    • PixCodes
    • Genesis Columns Advanced
    • Passster
    • Bold Timeline Lite
    • Icon Widget
    • User Verification
    • Survey Maker
    • Pardakht Delkhah
    • Optimize images ALT Text (alt tag) & names for SEO using AI
    • FluentAuth
    • Login as User or Customer
    • Booster for WooCommerce
    • BruteBank – WP Security & Firewall
    • Booster for WooCommerce
    • Justified Gallery
  • WordPress Plugin Vulnerabilities – No Known Fix
    • WP Limit Login Attempts
    • Members Import
    • Accordion Shortcodes
    • CPT Bootstrap Carousel
    • Meteor Slides
    • CBX Petition for WordPress
    • Social Sharing Toolkit
    • MediaElement.js – HTML5 Video & Audio Player
    • EU Cookie Law
  • WordPress Theme Vulnerabilities
    • Multiple themes – Unauthenticated Arbitrary File Upload
  • WordPress Theme Vulnerabilities – No Known Fix
    • Aidreform
    • Kingclub-theme
    • Footysquare
    • Spikes-black
    • Stratfort
    • Spikes
    • Club-theme
    • Soundblast
    • Bolster
  • The Best WordPress Security Plugin to Secure & Protect WordPress Sites

The Future of Authentication is Passkeys! Login to your WordPress site with Biometrics only available in iThemes Security Pro

The problems of brute force attacks through credential stuffing, phishing attacks, and reused passwords have made our digital lives less secure. We’ve all tried to encourage 2-factor authentication as a protection, but less than 30% of users actually use 2FA. Password-based logins are a problem.

The future of authentication is passkeys, and iThemes Security Pro is the first to bring this breakthrough technology to WordPress sites. Using breakthrough WebAuthn technology based on public/private cryptography, passkeys make passwords obsolete. Now, website admins and end users can have secure logins without the inconvenience of additional two-factor apps, password managers, or complex password requirements.

Learn More About Passkeys

WordPress Core News

WordPress 6.1.1 was released on November 15, 2022, as a short-cycle maintenance release with 29 bug fixes in Core and 21 bug fixes for the block editor. Because this is a core update, be sure to update to WordPress 6.1.1 as soon as possible! As always, with a major release like this, it makes sense to ensure your site is backed up with BackupBuddy before updating.

  • No new WordPress core vulnerabilities were disclosed this week.

There is a known unpatched vulnerability in WordPress core affecting all versions of WordPress. If you’re using iThemes Security, you’ve probably been alerted to this. As we are unsure when this very low-severity vulnerability will be patched, emails from iThemes Security will no longer alert for this specific vulnerability. Read our blog post about this vulnerability.

Get the weekly WordPress Vulnerability Report delivered to your inbox each Wednesday.
Subscribe now

WordPress Plugin Vulnerabilities

In this section, the latest WordPress plugin vulnerabilities have been disclosed. Each plugin listing includes the type of vulnerability, the active installations, the version number if patched, the severity rating, and the CVE.

All In One WP Security & Firewall

Product image for All-In-One Security (AIOS) – Security and Firewall.
Plugin
All-In-One Security (AIOS) – Security and Firewall
Plugin Slug
all-in-one-wp-security-and-firewall
Installations
1,000,000+
Vulnerability
Configuration Leak
Patched in Version
5.1.3
Severity Score
Medium
CVE
2022-4346
The vulnerability has been patched, so you should update to version 5.1.3.

WP Statistics

Product image for WP Statistics.
Plugin
WP Statistics
Plugin Slug
wp-statistics
Installations
600,000+
Vulnerability
Authenticated SQLi
Patched in Version
13.2.9
Severity Score
High
CVE
2022-4230
The vulnerability has been patched, so you should update to version 13.2.9.

Sassy Social Share

Product image for Social Sharing Plugin – Sassy Social Share.
Plugin
Social Sharing Plugin – Sassy Social Share
Plugin Slug
sassy-social-share
Installations
100,000+
Vulnerability
Contributor+ Stored XSS
Patched in Version
3.3.45
Severity Score
Medium
CVE
2022-4451
The vulnerability has been patched, so you should update to version 3.3.45.

Google Analyticator

Product image for Analyticator.
Plugin
Analyticator
Plugin Slug
google-analyticator
Installations
100,000+
Vulnerability
Admin+ PHP Object Injection
Patched in Version
6.5.6
Severity Score
Low
CVE
2022-4323
The vulnerability has been patched, so you should update to version 6.5.6.

Simple Sitemap

Product image for Simple Sitemap – Create a Responsive HTML Sitemap.
Plugin
Simple Sitemap – Create a Responsive HTML Sitemap
Plugin Slug
simple-sitemap
Installations
90,000+
Vulnerability
Contributor+ Stored XSS
Patched in Version
3.5.8
Severity Score
Medium
CVE
2022-4472
The vulnerability has been patched, so you should update to version 3.5.8.

Booster for WooCommerce

Product image for Booster for WooCommerce.
Plugin
Booster for WooCommerce
Plugin Slug
woocommerce-jetpack
Installations
70,000+
Vulnerability
Multiple CSRF
Patched in Version
6.0.1
Severity Score
Medium
CVE
2022-4017
The vulnerability has been patched, so you should update to version 6.0.1.

Easy Social Feed – Social Photos Gallery – Post Feed – Like Box

Product image for Easy Social Feed – Social Photos Gallery – Post Feed – Like Box.
Plugin
Easy Social Feed – Social Photos Gallery – Post Feed – Like Box
Plugin Slug
easy-facebook-likebox
Installations
70,000+
Vulnerability
Contributor+ Stored XSS
Patched in Version
6.4.0
Severity Score
Medium
CVE
2022-4474
The vulnerability has been patched, so you should update to version 6.4.0.

Collapse-O-Matic

Product image for Collapse-O-Matic.
Plugin
Collapse-O-Matic
Plugin Slug
jquery-collapse-o-matic
Installations
60,000+
Vulnerability
Contributor+ Stored XSS
Patched in Version
1.8.3
Severity Score
Medium
CVE
2022-4475
The vulnerability has been patched, so you should update to version 1.8.3.

Search & Filter

Product image for Search & Filter.
Plugin
Search & Filter
Plugin Slug
search-filter
Installations
50,000+
Vulnerability
Contributor+ Stored XSS
Patched in Version
1.2.16
Severity Score
Medium
CVE
2022-4467
The vulnerability has been patched, so you should update to version 1.2.16.

Content Control

Product image for Content Control – User Access Restriction Plugin.
Plugin
Content Control – User Access Restriction Plugin
Plugin Slug
content-control
Installations
40,000+
Vulnerability
Contributor+ Stored XSS
Patched in Version
1.1.10
Severity Score
Medium
CVE
2022-4509
The vulnerability has been patched, so you should update to version 1.1.10.

Page-list

Product image for Page-list.
Plugin
Page-list
Plugin Slug
page-list
Installations
40,000+
Vulnerability
Contributor+ Stored XSS
Patched in Version
5.3
Severity Score
Medium
CVE
2022-4485
The vulnerability has been patched, so you should update to version 5.3.

OneClick Chat to Order

Product image for OneClick Chat to Order.
Plugin
OneClick Chat to Order
Plugin Slug
oneclick-whatsapp-order
Installations
30,000+
Vulnerability
Contributor+ Stored XSS via Shortcode
Patched in Version
1.0.4.2
Severity Score
Medium
CVE
2022-4760
The vulnerability has been patched, so you should update to version 1.0.4.2.

Sitemap

Product image for Sitemap.
Plugin
Sitemap
Plugin Slug
sitemap
Installations
30,000+
Vulnerability
Contributor+ Stored XSS
Patched in Version
4.4
Severity Score
Medium
CVE
2022-4545
The vulnerability has been patched, so you should update to version 4.4.

Compact WP Audio Player

Product image for Compact WP Audio Player.
Plugin
Compact WP Audio Player
Plugin Slug
compact-wp-audio-player
Installations
30,000+
Vulnerability
Contributor+ Stored XSS
Patched in Version
1.9.8
Severity Score
Medium
CVE
2022-4542
The vulnerability has been patched, so you should update to version 1.9.8.

WP Popups

Product image for WP Popups – WordPress Popup builder.
Plugin
WP Popups – WordPress Popup builder
Plugin Slug
wp-popups-lite
Installations
30,000+
Vulnerability
Contributor+ Stored XSS
Patched in Version
2.1.4.8
Severity Score
Medium
CVE
2022-4716
The vulnerability has been patched, so you should update to version 2.1.4.8.

Top 10

Product image for Top 10  – Popular posts plugin for WordPress.
Plugin
Top 10 – Popular posts plugin for WordPress
Plugin Slug
top-10
Installations
30,000+
Vulnerability
Contributor+ Stored XSS
Patched in Version
3.2.3
Severity Score
Medium
CVE
2022-4570
The vulnerability has been patched, so you should update to version 3.2.3.

Login Logout Menu

Product image for Login Logout Menu.
Plugin
Login Logout Menu
Plugin Slug
login-logout-menu
Installations
20,000+
Vulnerability
Contributor+ Stored XSS in Shortcode
Patched in Version
1.4.0
Severity Score
Medium
CVE
2022-4625
The vulnerability has been patched, so you should update to version 1.4.0.

ShiftNav – Responsive Mobile Menu

Product image for ShiftNav – Responsive Mobile Menu.
Plugin
ShiftNav – Responsive Mobile Menu
Plugin Slug
shiftnav-responsive-mobile-menu
Installations
20,000+
Vulnerability
Contributor+ Stored XSS in Shortcode
Patched in Version
1.7.2
Severity Score
Medium
CVE
2022-4627
The vulnerability has been patched, so you should update to version 1.7.2.

Product Slider for WooCommerce

Product image for Product Slider for WooCommerce.
Plugin
Product Slider for WooCommerce
Plugin Slug
woo-product-slider
Installations
20,000+
Vulnerability
Contributor+ Stored XSS in Shortcode
Patched in Version
2.6.4
Severity Score
Medium
CVE
2022-4629
The vulnerability has been patched, so you should update to version 2.6.4.

Mongoose Page Plugin

Product image for Mongoose Page Plugin.
Plugin
Mongoose Page Plugin
Plugin Slug
facebook-page-feed-graph-api
Installations
20,000+
Vulnerability
Contributor+ Stored XSS via Shortcode
Patched in Version
1.9.0
Severity Score
Medium
CVE
2022-4675
The vulnerability has been patched, so you should update to version 1.9.0.

Rate my Post – WP Rating System

Product image for Rate my Post – WP Rating System.
Plugin
Rate my Post – WP Rating System
Plugin Slug
rate-my-post
Installations
20,000+
Vulnerability
Contributor+ Stored XSS via Shortcode
Patched in Version
3.3.9
Severity Score
Medium
CVE
2022-4673
The vulnerability has been patched, so you should update to version 3.3.9.

WordPress Simple Shopping Cart

Product image for WordPress Simple Shopping Cart.
Plugin
WordPress Simple Shopping Cart
Plugin Slug
wordpress-simple-paypal-shopping-cart
Installations
20,000+
Vulnerability
Contributor+ Stored XSS via Shortcode
Patched in Version
4.6.2
Severity Score
Medium
CVE
2022-4672
The vulnerability has been patched, so you should update to version 4.6.2.

Structured Content

Product image for Structured Content (JSON-LD) #wpsc.
Plugin
Structured Content (JSON-LD) #wpsc
Plugin Slug
structured-content
Installations
20,000+
Vulnerability
Contributor+ Stored XSS in Shortcode
Patched in Version
1.5.1
Severity Score
Medium
CVE
2022-4715
The vulnerability has been patched, so you should update to version 1.5.1.

GS Logo Slider

Product image for GS Logo Slider – Ticker, Grid, List, Table & Filter Views.
Plugin
GS Logo Slider – Ticker, Grid, List, Table & Filter Views
Plugin Slug
gs-logo-slider
Installations
20,000+
Vulnerability
Contributor+ Stored XSS in Shortcode
Patched in Version
3.3.8
Severity Score
Medium
CVE
2022-4624
The vulnerability has been patched, so you should update to version 3.3.8.

Video Conferencing with Zoom

Product image for Video Conferencing with Zoom.
Plugin
Video Conferencing with Zoom
Plugin Slug
video-conferencing-with-zoom-api
Installations
20,000+
Vulnerability
Contributor+ Stored XSS
Patched in Version
4.0.10
Severity Score
Medium
CVE
2022-4578
The vulnerability has been patched, so you should update to version 4.0.10.

Easy Appointments

Product image for Easy Appointments.
Plugin
Easy Appointments
Plugin Slug
easy-appointments
Installations
20,000+
Vulnerability
Contributor+ Stored XSS in Shortcode
Patched in Version
3.11.2
Severity Score
Medium
CVE
2022-4668
The vulnerability has been patched, so you should update to version 3.11.2.

GeoDirectory

Product image for GeoDirectory –  WordPress Business Directory Plugin and Classified Ads Listings.
Plugin
GeoDirectory – WordPress Business Directory Plugin and Classified Ads Listings
Plugin Slug
geodirectory
Installations
10,000+
Vulnerability
Contributor+ Stored XSS via Shortcode
Patched in Version
2.2.22
Severity Score
Medium
CVE
2022-4775
The vulnerability has been patched, so you should update to version 2.2.22.

Portfolio for Elementor, Image Gallery & Post Grid | PowerFolio

Product image for Portfolio for Elementor, Image Gallery & Post Grid  | PowerFolio.
Plugin
Portfolio for Elementor, Image Gallery & Post Grid | PowerFolio
Plugin Slug
portfolio-elementor
Installations
10,000+
Vulnerability
Contributor+ Stored XSS via Shortcode
Patched in Version
2.3.1
Severity Score
Medium
CVE
2022-4765
The vulnerability has been patched, so you should update to version 2.3.1.

WP Google My Business Auto Publish

Product image for Auto Publish for Google My Business.
Plugin
Auto Publish for Google My Business
Plugin Slug
wp-google-my-business-auto-publish
Installations
10,000+
Vulnerability
Contributor+ Stored XSS via Shortcode
Patched in Version
3.4
Severity Score
Medium
CVE
2022-4790
The vulnerability has been patched, so you should update to version 3.4.

Landing Page Builder

Product image for Landing Page Builder – Lead Page – Optin Page – Squeeze Page – WordPress Landing Pages.
Plugin
Landing Page Builder – Lead Page – Optin Page – Squeeze Page – WordPress Landing Pages
Plugin Slug
page-builder-add
Installations
10,000+
Vulnerability
Contributor+ Cross-Site Scripting via Shortcode
Patched in Version
1.4.9.9
Severity Score
Medium
CVE
2022-4718
The vulnerability has been patched, so you should update to version 1.4.9.9.

WPZOOM Portfolio

Product image for WPZOOM Portfolio.
Plugin
WPZOOM Portfolio
Plugin Slug
wpzoom-portfolio
Installations
10,000+
Vulnerability
Contributor+ Stored XSS via Shortcode
Patched in Version
1.2.2
Severity Score
Medium
CVE
2022-4789
The vulnerability has been patched, so you should update to version 1.2.2.

10WebMapBuilder

Product image for 10WebMapBuilder.
Plugin
10WebMapBuilder
Plugin Slug
wd-google-maps
Installations
10,000+
Vulnerability
Contributor+ Stored XSS via Shortcode
Patched in Version
1.0.72
Severity Score
Medium
CVE
2022-4758
The vulnerability has been patched, so you should update to version 1.0.72.

Word Balloon

Product image for Word Balloon.
Plugin
Word Balloon
Plugin Slug
word-balloon
Installations
10,000+
Vulnerability
Contributor+ Stored XSS via Shortcode
Patched in Version
4.19.3
Severity Score
Medium
CVE
2022-4751
The vulnerability has been patched, so you should update to version 4.19.3.

PDF Viewer

Product image for PDF Viewer.
Plugin
PDF Viewer
Plugin Slug
pdf-viewer
Installations
10,000+
Vulnerability
Contributor+ Stored XSS via Shortcode
Patched in Version
1.0.0
Severity Score
Medium
CVE
2023-0033
The vulnerability has been patched, so you should update to version 1.0.0.

Print-O-Matic

Product image for Print-O-Matic.
Plugin
Print-O-Matic
Plugin Slug
print-o-matic
Installations
10,000+
Vulnerability
Contributor+ Stored XSS via Shortcode
Patched in Version
2.1.8
Severity Score
Medium
CVE
2022-4753
The vulnerability has been patched, so you should update to version 2.1.8.

HashBar – WordPress Notification Bar

Product image for HashBar – WordPress Notification Bar.
Plugin
HashBar – WordPress Notification Bar
Plugin Slug
hashbar-wp-notification-bar
Installations
10,000+
Vulnerability
Contributor+ Stored XSS via Shortcode
Patched in Version
1.3.6
Severity Score
Medium
CVE
2022-4650
The vulnerability has been patched, so you should update to version 1.3.6.

PixCodes

Plugin
PixCodes
Plugin Slug
pixcodes
Installations
10,000+
Vulnerability
Contributor+ Stored XSS in Shortcode
Patched in Version
2.3.7
Severity Score
Medium
CVE
2022-4671
The vulnerability has been patched, so you should update to version 2.3.7.

Genesis Columns Advanced

Product image for Genesis Columns Advanced.
Plugin
Genesis Columns Advanced
Plugin Slug
genesis-columns-advanced
Installations
10,000+
Vulnerability
Contributor+ Stored XSS via Shortcode
Patched in Version
2.0.4
Severity Score
Medium
CVE
2022-4706
The vulnerability has been patched, so you should update to version 2.0.4.

Passster

Product image for Passster – Password Protection.
Plugin
Passster – Password Protection
Plugin Slug
content-protector
Installations
10,000+
Vulnerability
Protection Bypass & Arbitrary Post Access; Contributor+ Stored Cross-Site Scripting
Patched in Version
3.5.5.9
Severity Score
High
CVE
2021-24881
The vulnerability has been patched, so you should update to version 3.5.5.9.

Bold Timeline Lite

Product image for Bold Timeline Lite.
Plugin
Bold Timeline Lite
Plugin Slug
bold-timeline-lite
Installations
10,000+
Vulnerability
Contributor+ Stored XSS via Shortcode
Patched in Version
1.1.5
Severity Score
Medium
CVE
2022-4828
The vulnerability has been patched, so you should update to version 1.1.5.

Icon Widget

Product image for Icon Widget.
Plugin
Icon Widget
Plugin Slug
icon-widget
Installations
9,000+
Vulnerability
Contributor+ Stored XSS via Shortcode
Patched in Version
1.3.0
Severity Score
Medium
CVE
2022-4763
The vulnerability has been patched, so you should update to version 1.3.0.

User Verification

Product image for User Verification.
Plugin
User Verification
Plugin Slug
user-verification
Installations
5,000+
Vulnerability
Authentication Bypass
Patched in Version
1.0.94
Severity Score
Critical
CVE
2022-4693
The vulnerability has been patched, so you should update to version 1.0.94.

Survey Maker

Product image for Survey Maker – Best WordPress Survey Plugin.
Plugin
Survey Maker – Best WordPress Survey Plugin
Plugin Slug
survey-maker
Installations
3,000+
Vulnerability
Unauthenticated Stored XSS
Patched in Version
3.1.4
Severity Score
High
CVE
2023-0038
The vulnerability has been patched, so you should update to version 3.1.4.

Pardakht Delkhah

Product image for ?????? ?????? ??????.
Plugin
?????? ?????? ??????
Plugin Slug
pardakht-delkhah
Installations
1,000+
Vulnerability
Unauthenticated Stored XSS
Patched in Version
2.9.3
Severity Score
High
CVE
2022-4307
The vulnerability has been patched, so you should update to version 2.9.3.

Optimize images ALT Text (alt tag) & names for SEO using AI

Product image for Optimize images ALT Text (alt tag) & names for SEO using AI.
Plugin
Optimize images ALT Text (alt tag) & names for SEO using AI
Plugin Slug
imageseo
Installations
1,000+
Vulnerability
Settings Update via CSRF
Patched in Version
2.0.8
Severity Score
Low
CVE
2022-4548
The vulnerability has been patched, so you should update to version 2.0.8.

FluentAuth

Product image for FluentAuth – The Ultimate Authorization & Security Plugin for WordPress.
Plugin
FluentAuth – The Ultimate Authorization & Security Plugin for WordPress
Plugin Slug
fluent-security
Installations
700+
Vulnerability
Bypass blocks by IP Spoofing
Patched in Version
1.0.2
Severity Score
Medium
CVE
2022-4746
The vulnerability has been patched, so you should update to version 1.0.2.

Login as User or Customer

Product image for Login as User or Customer.
Plugin
Login as User or Customer
Plugin Slug
login-as-customer-or-user
Installations
400+
Vulnerability
Unauthenticated Privilege Escalation to Admin
Patched in Version
3.3
Severity Score
Critical
CVE
2022-4305
The vulnerability has been patched, so you should update to version 3.3.

Booster for WooCommerce

Plugin
Booster Elite for WooCommerce
Plugin Slug
booster-elite-for-woocommerce
Vulnerability
Multiple CSRF
Patched in Version
6.0.1
Severity Score
Medium
CVE
2022-4017
The vulnerability has been patched, so you should update to version 6.0.1.

BruteBank – WP Security & Firewall

Product image for BruteBank – WP Security & Firewall.
Plugin
BruteBank – WP Security & Firewall
Plugin Slug
brutebank
Vulnerability
Settings Update via CSRF
Patched in Version
1.9
Severity Score
Medium
CVE
2022-4443
The vulnerability has been patched, so you should update to version 1.9.

Booster for WooCommerce

Plugin
Booster Plus for WooCommerce
Plugin Slug
booster-plus-for-woocommerce
Vulnerability
Multiple CSRF
Patched in Version
6.0.1
Severity Score
Medium
CVE
2022-4017
The vulnerability has been patched, so you should update to version 6.0.1.

Justified Gallery

Plugin
Justified Gallery
Plugin Slug
justified-gallery
Vulnerability
Contributor+ Stored XSS via Shortcode
Patched in Version
1.7.1
Severity Score
Medium
CVE
2022-4651
The vulnerability has been patched, so you should update to version 1.7.1.

WordPress Plugin Vulnerabilities – No Known Fix

This section contains plugin vulnerabilities with no known fix. Until a patch is available, immediately uninstall and delete the plugin.

WP Limit Login Attempts

Product image for WP Limit Login Attempts.
Plugin
WP Limit Login Attempts
Plugin Slug
wp-limit-login-attempts
Installations
20,000+
Vulnerability
IP Spoofing
Patched in Version
No Fix
Severity Score
Medium
CVE
2022-4303
The vulnerability has not been patched. You should deactivate the plugin.

Members Import

Plugin
Members Import
Plugin Slug
members-import
Vulnerability
XSS via Imported CSV
Patched in Version
No Fix
Severity Score
Medium
CVE
2022-4663
The vulnerability has not been patched and the plugin is closed. You should uninstall and delete the plugin.

Accordion Shortcodes

Plugin
Accordion Shortcodes
Plugin Slug
accordion-shortcodes
Vulnerability
Contributor+ Stored XSS via Shortcode
Patched in Version
No Fix
Severity Score
Medium
CVE
2022-4781
The vulnerability has not been patched and the plugin is closed. You should uninstall and delete the plugin.

CPT Bootstrap Carousel

Plugin
CPT Bootstrap Carousel
Plugin Slug
cpt-bootstrap-carousel
Vulnerability
Contributor+ Stored XSS via Shortcode
Patched in Version
No Fix
Severity Score
Medium
CVE
2022-4834
The vulnerability has not been patched and the plugin is closed. You should uninstall and delete the plugin.

Meteor Slides

Plugin
Meteor Slides
Plugin Slug
meteor-slides
Vulnerability
Contributor+ Stored XSS
Patched in Version
No Fix
Severity Score
Medium
CVE
2022-4486
The vulnerability has not been patched and the plugin is closed. You should uninstall and delete the plugin.

CBX Petition for WordPress

Plugin
CBX Petition for WordPress
Plugin Slug
cbxpetition
Vulnerability
Unauthenticated SQLi
Patched in Version
No Fix
Severity Score
High
CVE
2022-4383
The vulnerability has not been patched and the plugin is closed. You should uninstall and delete the plugin.

Social Sharing Toolkit

Plugin
Social Sharing Toolkit
Plugin Slug
social-sharing-toolkit
Vulnerability
Contributor+ Stored XSS via Shortcode
Patched in Version
No Fix
Severity Score
Medium
CVE
2022-4835
The vulnerability has not been patched and the plugin is closed. You should uninstall and delete the plugin.

MediaElement.js – HTML5 Video & Audio Player

Plugin
MediaElement.js – HTML5 Video & Audio Player
Plugin Slug
media-element-html5-video-and-audio-player
Vulnerability
Contributor+ Stored XSS via Shortcode
Patched in Version
No Fix
Severity Score
Medium
CVE
2022-4699
The vulnerability has not been patched and the plugin is closed. You should uninstall and delete the plugin.

EU Cookie Law

Plugin
EU Cookie Law for GDPR/CCPA
Plugin Slug
eu-cookie-law
Vulnerability
Admin+ Stored XSS
Patched in Version
No Fix
Severity Score
Low
CVE
2022-3811
The vulnerability has not been patched and the plugin is closed. You should uninstall and delete the plugin.

WordPress Theme Vulnerabilities

In this section, the latest WordPress theme vulnerabilities have been disclosed. Each theme listing includes the type of vulnerability, the active installations, the version number if patched, the severity rating, and the CVE.

Multiple themes – Unauthenticated Arbitrary File Upload

Theme
WeStand
Theme Slug
westand
Vulnerability
RCE
Patched in Version
2.1
Severity Score
Critical
CVE
2022-0316
The vulnerability has been patched, so you should update to version 2.1.

WordPress Theme Vulnerabilities – No Known Fix

This section contains theme vulnerabilities with no known fix. Until a patch is available, immediately uninstall and delete the theme.

Aidreform

Theme
aidreform
Theme Slug
aidreform
Vulnerability
Unauthenticated Arbitrary File Upload
Patched in Version
No Fix
Severity Score
Critical
CVE
2022-0316
The vulnerability has not been patched. You should switch themes.

Kingclub-theme

Theme
kingclub-theme
Theme Slug
kingclub-theme
Vulnerability
Unauthenticated Arbitrary File Upload
Patched in Version
No Fix
Severity Score
Critical
CVE
2022-0316
The vulnerability has not been patched. You should switch themes.

Footysquare

Theme
footysquare
Theme Slug
footysquare
Vulnerability
Unauthenticated Arbitrary File Upload
Patched in Version
No Fix
Severity Score
Critical
CVE
2022-0316
The vulnerability has not been patched. You should switch themes.

Spikes-black

Theme
spikes-black
Theme Slug
spikes-black
Vulnerability
Unauthenticated Arbitrary File Upload
Patched in Version
No Fix
Severity Score
Critical
CVE
2022-0316
The vulnerability has not been patched. You should switch themes.

Stratfort

Theme
stratfort
Theme Slug
statfort
Vulnerability
Unauthenticated Arbitrary File Upload
Patched in Version
No Fix
Severity Score
Critical
CVE
2022-0316
The vulnerability has not been patched. You should switch themes.

Spikes

Theme
spikes
Theme Slug
spikes
Vulnerability
Unauthenticated Arbitrary File Upload
Patched in Version
No Fix
Severity Score
Critical
CVE
2022-0316
The vulnerability has not been patched. You should switch themes.

Club-theme

Theme
club-theme
Theme Slug
club-theme
Vulnerability
Unauthenticated Arbitrary File Upload
Patched in Version
No Fix
Severity Score
Critical
CVE
2022-0316
The vulnerability has not been patched. You should switch themes.

Soundblast

Theme
soundblast
Theme Slug
soundblast
Vulnerability
Unauthenticated Arbitrary File Upload
Patched in Version
No Fix
Severity Score
Critical
CVE
2022-0316
The vulnerability has not been patched. You should switch themes.

Bolster

Theme
bolster
Theme Slug
bolster
Vulnerability
Unauthenticated Arbitrary File Upload
Patched in Version
No Fix
Severity Score
Critical
CVE
2022-0316
The vulnerability has not been patched. You should switch themes.

Never worry about running a vulnerable plugin or theme again.

As you can see from this report, lots of new WordPress plugin and theme vulnerabilities are disclosed each week. We know it can be difficult to stay on top of every reported vulnerability disclosure, so the iThemes Security Pro plugin makes it easy to make sure your site isn’t running a theme, plugin, or WordPress core version with a known vulnerability.

Scans Your Website Twice a Day for Vulnerabilities

Your website’s plugins, themes, and WordPress core versions are checked against the WPScan Vulnerability Database for the latest vulnerability disclosures.

Automatically Updates if a Security Fix is Available

Paired with Version Management, iThemes Security will automatically update a plugin, theme, or WordPress core version if it has a vulnerability.

Emails You if Site Scan Detects a Vulnerability

You can receive an email report if your site is running vulnerable versions of a plugin, theme, or WordPress core. Customize the email addresses that receive scan results.

The Best WordPress Security Plugin to Secure & Protect WordPress Sites

WordPress currently powers over 40% of all websites, so it has become an easy target for hackers with malicious intent. The iThemes Security Pro plugin takes the guesswork out of WordPress security to make it easy to secure & protect your WordPress website. It’s like having a full-time security expert on staff who constantly monitors and protects your WordPress site for you.

Buy iThemes Security Pro

iThemes Team
iThemes Editorial Team

Each week, the team at iThemes team publishes new WordPress tutorials and resources, including the Weekly WordPress Vulnerability Report. Since 2008, iThemes has been dedicated to helping you build, maintain, and secure WordPress sites for yourself or for clients. Our mission? Make People’s Lives Awesome.

Share via:

  • Facebook
  • Twitter
  • LinkedIn
  • More
Other related posts
A security-riddled computer monitor. There is a large, orange shield with a slash in the middle of the screen. Surrounding it are a red target, a green skull and crossbones, an orange “bug”, a triangle with an explanation point in the middle and a gray gear.
WordPress Vulnerability Report – January 25, 2023
Turnstile and hCaptcha
New Turnstile and hCaptcha Support in Security Pro 7.3
WordPress vulnerability report
WordPress Vulnerability Report – January 18, 2023
clickjacking
What is Clickjacking and How to Prevent it

Get updates on new themes & plugins plus special discounts

About iThemes

  • The Team
  • Contact Us
  • Website Accessibility Statement
  • Sitemap

Resources

  • Blog
  • Documentation
  • WordPress Tutorials
  • Free WordPress Ebooks
  • Free Webinar Library
  • Free Upcoming Webinars
  • iThemes Training
  • Affiliates

Customers

  • Member Panel Login
  • Support
  • FAQs
  • Upgrade Policy
  • Licensing
  • Terms and Conditions
  • Refund Policy

Top Products

  • BackupBuddy
  • iThemes Security Pro
  • iThemes Sync
  • Restrict Content Pro
  • WPComplete
  • WordPress Plugins
  • Content Upgrades
  • WordPress Landing Page Plugin
  • BackupBuddy Stash

iThemes Media LLC Copyright © 2023 All rights reserved | Privacy Policy

© 2022 All Rights Reserved.

Visit StellarWP Visit Nexcess
Share via
Facebook
Twitter
LinkedIn
Mix
Email
Print
Copy Link
Powered by Social Snap
Copy link
CopyCopied
Powered by Social Snap

Get the Weekly WordPress Vulnerability Report

Vulnerable WordPress plugins and themes are the #1 reason WordPress sites get hacked, but keeping track of every new plugin and theme vulnerability is hard work. Get the weekly WordPress Vulnerability Report delivered right to your inbox to help keep your website secure.
No spam. Unsubscribe anytime.