Menu
iThemes
WordPress Security, Backups & Maintenance
  • Products
    • iThemes Security Pro
    • BackupBuddy
    • iThemes Sync
    • Why buy from iThemes?
  • Bundles
    • Essentials Bundle
    • Solid Foundations
    • Customer Spotlights
  • Resources
    • Blog
    • WordPress 101 Tutorials
    • WordPress Ebooks
    • Weekly WordPress Vulnerability Report
    • The Ultimate Guide to Starting a Web Design Business
  • Training
    • Upcoming Webinars
    • Free Webinar Library
    • Premium Courses
    • Become a Member
    • Member Login
  • Support
    • Documentation
    • Get Help
    • Product Updates
    • Upgrade Policy
    • Contact
    • Our Mission: Make People’s Lives Awesome
  • Log In
WordPress News and Updates from iThemes
Categories
  • Product Updates
  • WordPress Backup
  • WordPress Block Editor
  • WordPress Ecommerce
  • WordPress for Freelancers
  • WordPress Security
  • WordPress Tutorials
  • WPprosper

WordPress Vulnerability Report – July 12, 2023

Written by Dan Knauss on July 12, 2023

Last Updated on July 13, 2023

Since last week, 82 total vulnerabilities emerged in public disclosure. They may affect over 4 million WordPress sites. There are 46 plugin vulnerabilities and one theme vulnerability with security patches available, so run those updates!

Additionally, there are 34 plugin vulnerabilities and one theme vulnerability with no patch available yet. If you discover you are using an unpatched plugin or theme, check their vendors’ intentions and progress on a security release. If no patch is forthcoming or the vulnerable software has been marked “closed” and dropped from the official WordPress theme and plugin repositories, you should consider deactivation and removal in favor of alternative solutions.

From WPTavern: All-In-One Security Plugin Patches Sensitive Data Exposure Vulnerability in Version 5.2.0. AIOS is used by over a million sites. See Sarah Gooding’s post at the Tavern for more details. Ideally, AIOS users should apply the security update and reset all user passwords.

WordPress Core Vulnerabilities — Patched

  • No new WordPress core vulnerabilities were disclosed this week.

WordPress core is very secure when it’s properly configured and maintained. Vulnerable plugins that have not been updated by site owners are the most common vector for attacks on WordPress websites. Our weekly WordPress Vulnerability Report, powered by Patchstack, covers new WordPress plugin, theme, and core vulnerabilities that have emerged since last week’s report. Our goal is to spread awareness of emerging security threats and help you decide what to do if you are using vulnerable software on your website. For a deeper analysis of recent trends in WordPress vulnerabilities and threat vectors, see our 2022 Annual Vulnerability Report.

Contents of the July 12, 2023 Report
  1. WordPress Core Vulnerabilities – Patched
  2. WordPress Plugin Vulnerabilities – Patched
    1. WP-Optimize
    2. Ninja Forms
    3. Forminator
    4. POST SMTP Mailer
    5. POST SMTP Mailer
    6. ShopLentor
    7. WP Content Copy Protection & No Right Click
    8. LearnPress
    9. LearnPress
    10. HTTP Headers
    11. HTTP Headers
    12. All-in-one Floating Contact Form
    13. JetFormBuilder
    14. Visibility Logic for Elementor
    15. IP2Location Country Blocker
    16. ND Shortcodes
    17. wpForo Forum
    18. Yasr – Yet Another Stars Rating
    19. Booking Package SAASPROJECT
    20. Cryptocurrency Widgets – Price Ticker & Coins List
    21. Image Regenerate & Select Crop
    22. WP Mail Log
    23. Companion Sitemap Generator
    24. Buy Me a Coffee – Button and Widget Plugin
    25. Buy Me a Coffee – Button and Widget Plugin
    26. Buy Me a Coffee
    27. WP Dummy Content Generator
    28. WP Dummy Content Generator
    29. WebwinkelKeu
    30. ARMember
    31. Gift Cards
    32. Masteriyo – LMS
    33. BuddyBuilder BuddyPress Builder for Elementor
    34. Terms descriptions
    35. Sublanguage
    36. WP Reroute Email
    37. WPFactory Helper
    38. RSVPMaker
    39. Getnet Argentina para Woocommerce
    40. My Content Management
    41. Auto Location for WP Job Manager via Google
    42. tagDiv Cloud Library
    43. WooCommerce GoCardless Gateway
    44. WooCommerce Ship to Multiple Addresses
    45. WooCommerce Ship to Multiple Addresses
    46. WooCommerce Warranty Requests
  3. WordPress Plugin Vulnerabilities – Unpatched
    1. oAuth Twitter Feed for Developers
    2. Video Gallery – YouTube Playlist, Channel Gallery by YotuWP
    3. Media Library Helper by Codexin
    4. Secondary Title
    5. Classified Listing
    6. Mobile Call Now & Map Buttons
    7. Social Share Boost
    8. Simple Light Weight Social Share (Tweet, Like, Share and Linkedin)
    9. WPFunnels
    10. Animated Number Counters
    11. Social Media Icons Widget
    12. Kingkong Board
    13. Menubar
    14. Product Category Tree
    15. WP RSS Images
    16. Image Social Feed Plugin
    17. Simple Giveaways
    18. Coming Soon Page
    19. Simple Site Verify
    20. WP-Cirrus
    21. WP Full Stripe Free
    22. Baidu Tongji generator
    23. Querlo Chatbot
    24. BadgeOS
    25. BadgeOS
    26. BadgeOS
    27. Livestream Notice
    28. Mail Control
    29. Premium Addons PRO
    30. Premium Addons PRO
    31. Reservation.Studio Widget
    32. SMTP Mail
    33. WordPress Mobile Pack
    34. WP Default Feature Image
  4. WordPress Theme Vulnerabilities
    1. Consulting
    2. WPLMS
  5. The Best WordPress Security Plugin to Secure & Protect WordPress Sites

These reports are published every Wednesday and include all active vulnerabilities tracked by Patchstack as of Monday since the previous report. This leaves a 48-hour window for the newest emerging vulnerabilities to be patched before full public disclosure. iThemes Security Pro users have access to vulnerability alerts emerging within this window.

Get the weekly WordPress Vulnerability Report delivered to your inbox each Wednesday.
Subscribe now

WordPress Plugin Vulnerabilities — Patched

In this section, you’ll find the most recently disclosed WordPress plugin vulnerabilities that have been fixed with a new release from their authors and maintainers. Please apply the updates if you are affected!

These vulnerabilities have been disclosed and scored for their severity, thanks to our friends at Patchstack. Each plugin listing includes the type of vulnerability with its CVE number and CVSS severity rating with links to more technical details. You’ll also see the number of active sites using the plugin and the plugin version release that patches the vulnerability. We start with the most popular plugins, which represent the largest target for attackers.

WP-Optimize

Product image for WP-Optimize – Cache, Clean, Compress..
Plugin
WP-Optimize – Cache, Clean, Compress.
Plugin Slug
wp-optimize
Installations
1,000,000+
Vulnerability
Reflected Cross Site Scripting (XSS)
Patched in Version
3.2.13
Severity Score
High
CVE
2023-1119
The vulnerability has been patched, so you should update to version 3.2.13.

Ninja Forms

Product image for Ninja Forms Contact Form – The Drag and Drop Form Builder for WordPress.
Plugin
Ninja Forms Contact Form – The Drag and Drop Form Builder for WordPress
Plugin Slug
ninja-forms
Installations
900,000+
Vulnerability
Denial of Service Attack
Patched in Version
3.6.26
Severity Score
Medium
CVE
2023-35909
The vulnerability has been patched, so you should update to version 3.6.26.

Forminator

Product image for Forminator – Contact Form, Payment Form & Custom Form Builder.
Plugin
Forminator – Contact Form, Payment Form & Custom Form Builder
Plugin Slug
forminator
Installations
400,000+
Vulnerability
Unauth. Race Condition
Patched in Version
1.24.1
Severity Score
Low
CVE
2023-2010
The vulnerability has been patched, so you should update to version 1.24.1.

POST SMTP Mailer

Product image for POST SMTP Mailer – Email log, Delivery Failure Notifications and Best Mail SMTP for WordPress.
Plugin
POST SMTP Mailer – Email log, Delivery Failure Notifications and Best Mail SMTP for WordPress
Plugin Slug
post-smtp
Installations
300,000+
Vulnerability
Account Takeover via Cross Site Request Forgery (CSRF)
Patched in Version
2.5.7
Severity Score
High
CVE
2023-3179
The vulnerability has been patched, so you should update to version 2.5.7.

POST SMTP Mailer

Product image for POST SMTP Mailer – Email log, Delivery Failure Notifications and Best Mail SMTP for WordPress.
Plugin
POST SMTP Mailer – Email log, Delivery Failure Notifications and Best Mail SMTP for WordPress
Plugin Slug
post-smtp
Installations
300,000+
Vulnerability
Arbitrary Log Deletion via Cross Site Request Forgery (CSRF)
Patched in Version
2.5.7
Severity Score
Medium
CVE
2023-3178
The vulnerability has been patched, so you should update to version 2.5.7.

ShopLentor

Product image for ShopLentor – WooCommerce Builder for Elementor & Gutenberg +10 Modules – All in One Solution (formerly WooLentor).
Plugin
ShopLentor – WooCommerce Builder for Elementor & Gutenberg +10 Modules – All in One Solution (formerly WooLentor)
Plugin Slug
woolentor-addons
Installations
100,000+
Vulnerability
Cross Site Request Forgery (CSRF)
Patched in Version
2.6.3
Severity Score
Medium
CVE
2022-47172
The vulnerability has been patched, so you should update to version 2.6.3.

WP Content Copy Protection & No Right Click

Product image for WP Content Copy Protection & No Right Click.
Plugin
WP Content Copy Protection & No Right Click
Plugin Slug
wp-content-copy-protector
Installations
100,000+
Vulnerability
Cross Site Scripting (XSS)
Patched in Version
3.5.6
Severity Score
Medium
CVE
2023-36678
The vulnerability has been patched, so you should update to version 3.5.6.

LearnPress

Product image for LearnPress – WordPress LMS Plugin.
Plugin
LearnPress – WordPress LMS Plugin
Plugin Slug
learnpress
Installations
90,000+
Vulnerability
Authenticated Broken Access Control
Patched in Version
4.2.3.1
Severity Score
High
CVE
2023-36516
The vulnerability has been patched, so you should update to version 4.2.3.1.

LearnPress

Product image for LearnPress – WordPress LMS Plugin.
Plugin
LearnPress – WordPress LMS Plugin
Plugin Slug
learnpress
Installations
90,000+
Vulnerability
Unauthenticated Broken Access Control
Patched in Version
4.2.3.1
Severity Score
High
CVE
2023-36515
The vulnerability has been patched, so you should update to version 4.2.3.1.

HTTP Headers

Product image for HTTP Headers.
Plugin
HTTP Headers
Plugin Slug
http-headers
Installations
40,000+
Vulnerability
Cross Site Scripting (XSS)
Patched in Version
1.19.0
Severity Score
Medium
CVE
2023-37874
The vulnerability has been patched, so you should update to version 1.19.0.

HTTP Headers

Product image for HTTP Headers.
Plugin
HTTP Headers
Plugin Slug
http-headers
Installations
40,000+
Vulnerability
Admin+ Remote Code Execution (RCE)
Patched in Version
1.18.11
Severity Score
High
CVE
2023-1208
The vulnerability has been patched, so you should update to version 1.18.11.

All-in-one Floating Contact Form

Product image for All-in-one Floating Contact Form, Call, Chat, and 50+ Social Icon Tabs  – My Sticky Elements.
Plugin
All-in-one Floating Contact Form, Call, Chat, and 50+ Social Icon Tabs – My Sticky Elements
Plugin Slug
mystickyelements
Installations
40,000+
Vulnerability
Admin+ Stored Cross Site Scripting (XSS)
Patched in Version
2.1.2
Severity Score
Medium
CVE
2023-3248
The vulnerability has been patched, so you should update to version 2.1.2.

JetFormBuilder

Product image for JetFormBuilder — Dynamic Blocks Form Builder.
Plugin
JetFormBuilder — Dynamic Blocks Form Builder
Plugin Slug
jetformbuilder
Installations
30,000+
Vulnerability
Authenticated Privilege Escalation
Patched in Version
3.0.9
Severity Score
High
CVE
2023-37866
The vulnerability has been patched, so you should update to version 3.0.9.

Visibility Logic for Elementor

Product image for Visibility Logic for Elementor.
Plugin
Visibility Logic for Elementor
Plugin Slug
visibility-logic-elementor
Installations
30,000+
Vulnerability
Cross Site Request Forgery (CSRF)
Patched in Version
2.3.5
Severity Score
Medium
CVE
2022-47169
The vulnerability has been patched, so you should update to version 2.3.5.

IP2Location Country Blocker

Product image for IP2Location Country Blocker.
Plugin
IP2Location Country Blocker
Plugin Slug
ip2location-country-blocker
Installations
20,000+
Vulnerability
IP Bypass Vulnerability
Patched in Version
2.29.2
Severity Score
Medium
CVE
2023-37865
The vulnerability has been patched, so you should update to version 2.29.2.

ND Shortcodes

Product image for ND Shortcodes.
Plugin
ND Shortcodes
Plugin Slug
nd-shortcodes
Installations
20,000+
Vulnerability
Auth. Cross Site Scripting (XSS)
Patched in Version
7.0
Severity Score
Medium
CVE
2022-4623
The vulnerability has been patched, so you should update to version 7.0.

wpForo Forum

Product image for wpForo Forum.
Plugin
wpForo Forum
Plugin Slug
wpforo
Installations
20,000+
Vulnerability
Reflected Cross Site Scripting (XSS)
Patched in Version
2.1.9
Severity Score
High
CVE
2023-2309
The vulnerability has been patched, so you should update to version 2.1.9.

Yasr – Yet Another Stars Rating

Product image for Yasr – Yet Another Stars Rating.
Plugin
Yasr – Yet Another Stars Rating
Plugin Slug
yet-another-stars-rating
Installations
20,000+
Vulnerability
Race Condition
Patched in Version
3.3.9
Severity Score
Low
CVE
2023-37867
The vulnerability has been patched, so you should update to version 3.3.9.

Booking Package SAASPROJECT

Product image for Booking Package.
Plugin
Booking Package
Plugin Slug
booking-package
Installations
10,000+
Vulnerability
Unauthenticated Privilege Escalation
Patched in Version
1.5.99
Severity Score
High
CVE
2023-37389
The vulnerability has been patched, so you should update to version 1.5.99.

Cryptocurrency Widgets – Price Ticker & Coins List

Product image for Cryptocurrency Widgets – Price Ticker & Coins List.
Plugin
Cryptocurrency Widgets – Price Ticker & Coins List
Plugin Slug
cryptocurrency-price-ticker-widget
Installations
10,000+
Vulnerability
Broken Access Control
Patched in Version
2.6.3
Severity Score
Medium
CVE
2023-36681
The vulnerability has been patched, so you should update to version 2.6.3.

Image Regenerate & Select Crop

Product image for Image Regenerate & Select Crop.
Plugin
Image Regenerate & Select Crop
Plugin Slug
image-regenerate-select-crop
Installations
10,000+
Vulnerability
Broken Access Control
Patched in Version
7.2.0
Severity Score
Medium
CVE
2023-36680
The vulnerability has been patched, so you should update to version 7.2.0.

WP Mail Log

Product image for WP Mail Log.
Plugin
WP Mail Log
Plugin Slug
wp-mail-log
Installations
10,000+
Vulnerability
Unauthenticated Stored Cross Site Scripting (XSS) via Email
Patched in Version
1.1.2
Severity Score
High
CVE
2023-3088
The vulnerability has been patched, so you should update to version 1.1.2.

Companion Sitemap Generator

Product image for Companion Sitemap Generator – HTML & XML.
Plugin
Companion Sitemap Generator – HTML & XML
Plugin Slug
companion-sitemap-generator
Installations
9,000+
Vulnerability
Reflected Cross Site Scripting (XSS)
Patched in Version
4.5.3
Severity Score
High
CVE
2023-1780
The vulnerability has been patched, so you should update to version 4.5.3.

Buy Me a Coffee – Button and Widget Plugin

Product image for Buy Me a Coffee – Button and Widget Plugin.
Plugin
Buy Me a Coffee – Button and Widget Plugin
Plugin Slug
buymeacoffee
Installations
6,000+
Vulnerability
Cross Site Request Forgery (CSRF)
Patched in Version
3.8
Severity Score
Medium
CVE
2023-2079
The vulnerability has been patched, so you should update to version 3.8.

Buy Me a Coffee – Button and Widget Plugin

Product image for Buy Me a Coffee – Button and Widget Plugin.
Plugin
Buy Me a Coffee – Button and Widget Plugin
Plugin Slug
buymeacoffee
Installations
6,000+
Vulnerability
Missing Authorization
Patched in Version
3.8
Severity Score
Medium
CVE
2023-2078
The vulnerability has been patched, so you should update to version 3.8.

Buy Me a Coffee

Product image for Buy Me a Coffee – Button and Widget Plugin.
Plugin
Buy Me a Coffee – Button and Widget Plugin
Plugin Slug
buymeacoffee
Installations
6,000+
Vulnerability
Broken Access Control
Patched in Version
3.8
Severity Score
Medium
CVE
2023-25030
The vulnerability has been patched, so you should update to version 3.8.

WP Dummy Content Generator

Product image for WP Dummy Content Generator.
Plugin
WP Dummy Content Generator
Plugin Slug
wp-dummy-content-generator
Installations
4,000+
Vulnerability
Broken Access Control
Patched in Version
3.0.0
Severity Score
Medium
CVE
2023-37394
The vulnerability has been patched, so you should update to version 3.0.0.

WP Dummy Content Generator

Product image for WP Dummy Content Generator.
Plugin
WP Dummy Content Generator
Plugin Slug
wp-dummy-content-generator
Installations
4,000+
Vulnerability
Cross Site Request Forgery (CSRF)
Patched in Version
3.0.0
Severity Score
Medium
CVE
2023-37392
The vulnerability has been patched, so you should update to version 3.0.0.

WebwinkelKeu

Plugin
WebwinkelKeur: Webshop keurmerk & reviews for WordPress
Plugin Slug
webwinkelkeur
Installations
3,000+
Vulnerability
Cross Site Request Forgery (CSRF)
Patched in Version
3.25
Severity Score
Medium
CVE
2023-36691
The vulnerability has been patched, so you should update to version 3.25.

ARMember

Product image for ARMember – Membership Plugin, Content Restriction, Member Levels, User Profile & User signup.
Plugin
ARMember – Membership Plugin, Content Restriction, Member Levels, User Profile & User signup
Plugin Slug
armember-membership
Installations
2,000+
Vulnerability
Cross Site Request Forgery (CSRF)
Patched in Version
4.0.6
Severity Score
Medium
CVE
2022-47424
The vulnerability has been patched, so you should update to version 4.0.6.

Gift Cards

Product image for Gift Cards (Gift Vouchers and Packages) (WooCommerce Supported).
Plugin
Gift Cards (Gift Vouchers and Packages) (WooCommerce Supported)
Plugin Slug
gift-voucher
Installations
2,000+
Vulnerability
Cross Site Request Forgery (CSRF) in new_voucher_template.php
Patched in Version
4.3.6
Severity Score
Medium
The vulnerability has been patched, so you should update to version 4.3.6.

Masteriyo – LMS

Product image for LMS by Masteriyo – WordPress Learning Management System, eLearning Platform, Online Education System & Online Course Builder.
Plugin
LMS by Masteriyo – WordPress Learning Management System, eLearning Platform, Online Education System & Online Course Builder
Plugin Slug
learning-management-system
Installations
2,000+
Vulnerability
Sensitive Data Exposure
Patched in Version
1.6.8
Severity Score
Medium
The vulnerability has been patched, so you should update to version 1.6.8.

BuddyBuilder BuddyPress Builder for Elementor

Product image for BuddyPress Builder for Elementor – BuddyBuilder.
Plugin
BuddyPress Builder for Elementor – BuddyBuilder
Plugin Slug
stax-buddy-builder
Installations
2,000+
Vulnerability
Cross Site Request Forgery (CSRF)
Patched in Version
1.7.4
Severity Score
Medium
The vulnerability has been patched, so you should update to version 1.7.4.

Terms descriptions

Product image for Terms descriptions.
Plugin
Terms descriptions
Plugin Slug
terms-descriptions
Installations
2,000+
Vulnerability
Reflected Cross Site Scripting (XSS)
Patched in Version
3.4.5
Severity Score
High
CVE
2023-28779
The vulnerability has been patched, so you should update to version 3.4.5.

Sublanguage

Product image for Sublanguage.
Plugin
Sublanguage
Plugin Slug
sublanguage
Installations
1,000+
Vulnerability
Broken Access Control
Patched in Version
2.10
Severity Score
Medium
CVE
2023-36695
The vulnerability has been patched, so you should update to version 2.10.

WP Reroute Email

Product image for WP Reroute Email.
Plugin
WP Reroute Email
Plugin Slug
wp-reroute-email
Installations
1,000+
Vulnerability
Unauthenticated Stored Cross Site Scripting (XSS) via Email Subject
Patched in Version
1.5.0
Severity Score
High
CVE
2023-3168
The vulnerability has been patched, so you should update to version 1.5.0.

WPFactory Helper

Product image for WPFactory Helper.
Plugin
WPFactory Helper
Plugin Slug
wpcodefactory-helper
Installations
1,000+
Vulnerability
Reflected Cross Site Scripting (XSS)
Patched in Version
1.5.3
Severity Score
High
CVE
2023-36689
The vulnerability has been patched, so you should update to version 1.5.3.

RSVPMaker

Product image for RSVPMaker.
Plugin
RSVPMaker
Plugin Slug
rsvpmaker
Installations
400+
Vulnerability
SQL Injection
Patched in Version
10.5.5
Severity Score
High
CVE
2023-29095
The vulnerability has been patched, so you should update to version 10.5.5.

Getnet Argentina para Woocommerce

Product image for Getnet Argentina para Woocommerce.
Plugin
Getnet Argentina para Woocommerce
Plugin Slug
integrar-getnet-con-woo
Installations
200+
Vulnerability
Authorization Bypass via webhook
Patched in Version
0.0.5
Severity Score
High
CVE
2023-3525
The vulnerability has been patched, so you should update to version 0.0.5.

My Content Management

Product image for My Content Management.
Plugin
My Content Management
Plugin Slug
my-content-management
Installations
200+
Vulnerability
Cross Site Scripting (XSS)
Patched in Version
1.7.7
Severity Score
Medium
CVE
2023-34377
The vulnerability has been patched, so you should update to version 1.7.7.

Auto Location for WP Job Manager via Google

Plugin
Auto Location for WP Job Manager via Google
Plugin Slug
auto-location-for-wp-job-manager
Installations
100+
Vulnerability
Admin+ Cross Site Scripting (XSS)
Patched in Version
1.1
Severity Score
Medium
CVE
2023-3344
The vulnerability has been patched, so you should update to version 1.1.

tagDiv Cloud Library

Plugin
tagDiv Cloud Library
Plugin Slug
td-cloud-library
Vulnerability
Unauthenticated Arbitrary User Metadata Update to Privilege Escalation
Patched in Version
2.7
Severity Score
Critical
CVE
2023-1597
The vulnerability has been patched, so you should update to version 2.7.

WooCommerce GoCardless Gateway

Plugin
WooCommerce GoCardless Gateway
Plugin Slug
woocommerce-gateway-gocardless
Vulnerability
Unauth. Insecure Direct Object References (IDOR)
Patched in Version
2.5.7
Severity Score
High
CVE
2023-37871
The vulnerability has been patched, so you should update to version 2.5.7.

WooCommerce Ship to Multiple Addresses

Plugin
WooCommerce Ship to Multiple Addresses
Plugin Slug
woocommerce-shipping-multiple-addresses
Vulnerability
Reflected Cross Site Scripting (XSS)
Patched in Version
3.8.6
Severity Score
High
CVE
2023-37873
The vulnerability has been patched, so you should update to version 3.8.6.

WooCommerce Ship to Multiple Addresses

Plugin
WooCommerce Ship to Multiple Addresses
Plugin Slug
woocommerce-shipping-multiple-addresses
Vulnerability
Broken Access Control
Patched in Version
3.8.6
Severity Score
Medium
CVE
2023-37872
The vulnerability has been patched, so you should update to version 3.8.6.

WooCommerce Warranty Requests

Plugin
WooCommerce Warranty Requests
Plugin Slug
woocommerce-warranty
Vulnerability
Broken Access Control
Patched in Version
2.2.0
Severity Score
High
CVE
2023-37870
The vulnerability has been patched, so you should update to version 2.2.0.

WordPress Plugin Vulnerabilities — Unpatched

This section contains plugin vulnerabilities with no known fix. Until a patch is available, you are advised to deactivate the plugin, at minimum, immediately. If there is a high risk of active exploits or the plugin remains unpatched for weeks, you are advised to delete the plugin. You should also delete persistently unpatched plugins the WordPress.org repository has locked and marked “Closed” so they can no longer be downloaded and installed.

oAuth Twitter Feed for Developers

Plugin
oAuth Twitter Feed for Developers
Plugin Slug
oauth-twitter-feed-for-developers
Installations
60,000+
Vulnerability
Cross Site Scripting (XSS)
Patched in Version
No Fix
Severity Score
Medium
CVE
2023-25042
The vulnerability has not been patched. You should deactivate the plugin.

Video Gallery – YouTube Playlist, Channel Gallery by YotuWP

Product image for Video Gallery – YouTube Playlist, Channel Gallery by YotuWP.
Plugin
Video Gallery – YouTube Playlist, Channel Gallery by YotuWP
Plugin Slug
yotuwp-easy-youtube-embed
Installations
30,000+
Vulnerability
Cross Site Scripting (XSS)
Patched in Version
No Fix
Severity Score
Medium
CVE
2023-25477
The vulnerability has not been patched. You should deactivate the plugin.

Media Library Helper by Codexin

Product image for Bulk edit image alt tag, caption & description  – WordPress Media Library Helper by Codexin.
Plugin
Bulk edit image alt tag, caption & description – WordPress Media Library Helper by Codexin
Plugin Slug
media-library-helper
Installations
10,000+
Vulnerability
Cross Site Request Forgery (CSRF)
Patched in Version
No Fix
Severity Score
Medium
CVE
2023-37386
The vulnerability has not been patched. You should deactivate the plugin.

Secondary Title

Product image for Secondary Title.
Plugin
Secondary Title
Plugin Slug
secondary-title
Installations
10,000+
Vulnerability
Cross Site Scripting (XSS)
Patched in Version
No Fix
Severity Score
Medium
CVE
2023-28773
The vulnerability has not been patched. You should deactivate the plugin.

Classified Listing

Product image for Classified Listing – Classified ads & Business Directory Plugin.
Plugin
Classified Listing – Classified ads & Business Directory Plugin
Plugin Slug
classified-listing
Installations
9,000+
Vulnerability
Cross Site Request Forgery (CSRF) Leading To Thumbnail Removal
Patched in Version
No Fix
Severity Score
Medium
CVE
2023-37387
The vulnerability has not been patched. You should deactivate the plugin.

Mobile Call Now & Map Buttons

Product image for Mobile Call Now & Map Buttons.
Plugin
Mobile Call Now & Map Buttons
Plugin Slug
mobile-call-now-map-buttons
Installations
9,000+
Vulnerability
Cross Site Scripting (XSS)
Patched in Version
No Fix
Severity Score
Medium
CVE
2023-24401
The vulnerability has not been patched. You should deactivate the plugin.

Social Share Boost

Plugin
Social Share Boost
Plugin Slug
social-share-boost
Installations
6,000+
Vulnerability
Cross Site Scripting (XSS)
Patched in Version
No Fix
Severity Score
Medium
CVE
2023-25044
The vulnerability has not been patched. You should deactivate the plugin.

Simple Light Weight Social Share (Tweet, Like, Share and Linkedin)

Product image for Simple Light Weight Social Share (Tweet, Like, Share and Linkedin).
Plugin
Simple Light Weight Social Share (Tweet, Like, Share and Linkedin)
Plugin Slug
only-tweet-like-share-and-google-1
Installations
5,000+
Vulnerability
Cross Site Scripting (XSS)
Patched in Version
No Fix
Severity Score
Medium
CVE
2023-37388
The vulnerability has not been patched. You should deactivate the plugin.

WPFunnels

Product image for Drag & Drop Sales Funnel Builder for WordPress – WPFunnels.
Plugin
Drag & Drop Sales Funnel Builder for WordPress – WPFunnels
Plugin Slug
wpfunnels
Installations
5,000+
Vulnerability
Insecure Direct Object References (IDOR)
Patched in Version
No Fix
Severity Score
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Animated Number Counters

Product image for Animated Number Counters.
Plugin
Animated Number Counters
Plugin Slug
animated-number-counters
Installations
3,000+
Vulnerability
Cross Site Scripting (XSS)
Patched in Version
No Fix
Severity Score
Medium
CVE
2023-24393
The vulnerability has not been patched. You should deactivate the plugin.

Social Media Icons Widget

Plugin
Social Media Icons Widget
Plugin Slug
spoontalk-social-media-icons-widget
Installations
3,000+
Vulnerability
Cross Site Request Forgery (CSRF)
Patched in Version
No Fix
Severity Score
Medium
CVE
2023-25036
The vulnerability has not been patched. You should deactivate the plugin.

Kingkong Board

Product image for Kingkong Board.
Plugin
Kingkong Board
Plugin Slug
kingkong-board
Installations
2,000+
Vulnerability
Broken Access Control
Patched in Version
No Fix
Severity Score
Medium
CVE
2023-36694
The vulnerability has not been patched. You should deactivate the plugin.

Menubar

Plugin
Menubar
Plugin Slug
menubar
Installations
2,000+
Vulnerability
Cross Site Request Forgery (CSRF)
Patched in Version
No Fix
Severity Score
Medium
CVE
2023-36687
The vulnerability has not been patched. You should deactivate the plugin.

Product Category Tree

Product image for Product Category Tree.
Plugin
Product Category Tree
Plugin Slug
product-category-tree
Installations
2,000+
Vulnerability
Broken Access Control
Patched in Version
No Fix
Severity Score
Medium
CVE
2023-29173
The vulnerability has not been patched. You should deactivate the plugin.

WP RSS Images

Plugin
WP RSS Images
Plugin Slug
wp-rss-images
Installations
2,000+
Vulnerability
Cross Site Request Forgery (CSRF)
Patched in Version
No Fix
Severity Score
Medium
CVE
2023-36693
The vulnerability has not been patched. You should deactivate the plugin.

Image Social Feed Plugin

Product image for Image Social Feed Plugin.
Plugin
Image Social Feed Plugin
Plugin Slug
add-instagram
Installations
1,000+
Vulnerability
Cross Site Scripting (XSS)
Patched in Version
No Fix
Severity Score
Medium
CVE
2023-24412
The vulnerability has not been patched. You should deactivate the plugin.

Simple Giveaways

Product image for Simple Giveaways – Grow your business, email lists and traffic with contests.
Plugin
Simple Giveaways – Grow your business, email lists and traffic with contests
Plugin Slug
giveasap
Installations
1,000+
Vulnerability
Broken Access Control
Patched in Version
No Fix
Severity Score
Medium
CVE
2023-23893
The vulnerability has not been patched. You should deactivate the plugin.

Coming Soon Page

Product image for Coming Soon Page – Responsive Coming Soon & Maintenance Mode.
Plugin
Coming Soon Page – Responsive Coming Soon & Maintenance Mode
Plugin Slug
responsive-coming-soon-page
Installations
1,000+
Vulnerability
SQL Injection
Patched in Version
No Fix
Severity Score
High
CVE
2022-46849
The vulnerability has not been patched. You should deactivate the plugin.

Simple Site Verify

Product image for Simple Site Verify.
Plugin
Simple Site Verify
Plugin Slug
simple-site-verify
Installations
1,000+
Vulnerability
Cross Site Scripting (XSS)
Patched in Version
No Fix
Severity Score
Medium
CVE
2023-36688
The vulnerability has not been patched. You should deactivate the plugin.

WP-Cirrus

Plugin
WP-Cirrus
Plugin Slug
wp-cirrus
Installations
1,000+
Vulnerability
Cross Site Scripting (XSS)
Patched in Version
No Fix
Severity Score
Medium
CVE
2023-36692
The vulnerability has not been patched. You should deactivate the plugin.

WP Full Stripe Free

Product image for WP Full Stripe Free.
Plugin
WP Full Stripe Free
Plugin Slug
wp-full-stripe-free
Installations
1,000+
Vulnerability
Cross Site Scripting (XSS)
Patched in Version
No Fix
Severity Score
Medium
CVE
2023-28934
The vulnerability has not been patched. You should deactivate the plugin.

Baidu Tongji generator

Plugin
Baidu Tongji generator
Plugin Slug
baidu-tongji-generator
Installations
100+
Vulnerability
Cross Site Request Forgery (CSRF)
Patched in Version
No Fix
Severity Score
Medium
CVE
2023-31230
The vulnerability has not been patched. You should deactivate the plugin.

Querlo Chatbot

Plugin
Querlo Chatbot
Plugin Slug
querlo-chatbots
Installations
10+
Vulnerability
Cross Site Scripting (XSS)
Patched in Version
No Fix
Severity Score
Medium
CVE
2023-3418
The vulnerability has not been patched. You should deactivate the plugin.

BadgeOS

Plugin
BadgeOS
Plugin Slug
badgeos
Vulnerability
Authenticated (Subscriber+) Insecure Direct Object References (IDOR) to Arbitrary Post Title Overwrite
Patched in Version
No Fix
Severity Score
Medium
CVE
2023-2172
The vulnerability has not been patched and the plugin is closed. You should uninstall and delete the plugin.

BadgeOS

Plugin
BadgeOS
Plugin Slug
badgeos
Vulnerability
Authenticated (Subscriber+) Insecure Direct Object References (IDOR) to Arbitrary Post Deletion
Patched in Version
No Fix
Severity Score
Medium
CVE
2023-2173
The vulnerability has not been patched and the plugin is closed. You should uninstall and delete the plugin.

BadgeOS

Plugin
BadgeOS
Plugin Slug
badgeos
Vulnerability
Authenticated (Contributor+) Stored Cross Site Scripting (XSS) via Shortcode
Patched in Version
No Fix
Severity Score
Medium
CVE
2023-2171
The vulnerability has not been patched and the plugin is closed. You should uninstall and delete the plugin.

Livestream Notice

Product image for Livestream Notice.
Plugin
Livestream Notice
Plugin Slug
livestream-notice
Vulnerability
Cross Site Scripting (XSS)
Patched in Version
No Fix
Severity Score
Medium
CVE
2023-27621
The vulnerability has not been patched. You should deactivate the plugin.

Mail Control

Plugin
Mail Control
Plugin Slug
mail-control
Vulnerability
Unauthenticated Stored Cross Site Scripting (XSS) via Email Subject
Patched in Version
No Fix
Severity Score
High
CVE
2023-3158
The vulnerability has not been patched and the plugin is closed. You should uninstall and delete the plugin.

Premium Addons PRO

Plugin
Premium Addons PRO
Plugin Slug
premium-addons-pro
Vulnerability
Broken Access Control
Patched in Version
No Fix
Severity Score
Medium
CVE
2023-37869
The vulnerability has not been patched. You should deactivate the plugin.

Premium Addons PRO

Plugin
Premium Addons PRO
Plugin Slug
premium-addons-pro
Vulnerability
Sensitive Data Exposure
Patched in Version
No Fix
Severity Score
Medium
CVE
2023-37868
The vulnerability has not been patched. You should deactivate the plugin.

Reservation.Studio Widget

Product image for Reservation.Studio widget.
Plugin
Reservation.Studio widget
Plugin Slug
reservation-studio-widget
Vulnerability
Cross Site Scripting (XSS)
Patched in Version
No Fix
Severity Score
Medium
CVE
2023-24397
The vulnerability has not been patched. You should deactivate the plugin.

SMTP Mail

Plugin
SMTP Mail
Plugin Slug
smtp-mail
Vulnerability
Unauthenticated Stored Cross Site Scripting (XSS) via Email Subject
Patched in Version
No Fix
Severity Score
High
CVE
2023-3092
The vulnerability has not been patched and the plugin is closed. You should uninstall and delete the plugin.

WordPress Mobile Pack

Plugin
WordPress Mobile Pack
Plugin Slug
wordpress-mobile-pack
Vulnerability
Cross Site Request Forgery (CSRF)
Patched in Version
No Fix
Severity Score
Medium
CVE
2023-37391
The vulnerability has not been patched and the plugin is closed. You should uninstall and delete the plugin.

WP Default Feature Image

Product image for WP Default Feature Image.
Plugin
WP Default Feature Image
Plugin Slug
wp-default-feature-image
Vulnerability
Cross Site Scripting (XSS)
Patched in Version
No Fix
Severity Score
Medium
CVE
2023-25488
The vulnerability has not been patched. You should deactivate the plugin.

WordPress Theme Vulnerabilities

In this section, you’ll find the latest WordPress theme vulnerabilities to be disclosed. You’ll see the same information provided above for vulnerable plugins, and the same advice applies. If a security update exists, install it immediately. If a vulnerability remains unpatched in a theme you are actively using, you will need to find an alternative theme. Deactivate and delete persistently unpatched themes and those that have been “Closed” in the WordPress.org theme repository. If you have a vulnerable theme installed that you are not actively using, simply delete it.

Consulting

Product image for Consulting.
Theme
Consulting
Theme Slug
consulting
Downloads
382,480
Vulnerability
Local File Inclusion
Patched in Version
No Fix
Severity Score
High
CVE
2023-37385
The vulnerability has not been patched. You should switch themes.

WPLMS

Theme
WPLMS
Theme Slug
wplms
Vulnerability
Cross Site Request Forgery (CSRF)
Patched in Version
4.900
Severity Score
High
CVE
2023-36690
The vulnerability has been patched, so you should update to version 4.900.


Never worry about running a vulnerable plugin or theme again.

As you can see from this report, new WordPress plugin and theme vulnerabilities are disclosed every week. We know it can be difficult to stay on top of every reported vulnerability disclosure that matters to you, so the Themes Security Pro plugin makes it easy to ensure your site isn’t running a vulnerable theme, plugin, or version of WordPress core.

Scans Your Website Twice a Day for Vulnerabilities

Your website’s plugins, themes, and WordPress core versions are checked against the Patchstack Vulnerability Database for the latest vulnerability disclosures.

Automatically Updates if a Security Fix is Available

Paired with Version Management, iThemes Security will automatically update a plugin, theme, or WordPress core version if it has a vulnerability.

Emails You a Warning if Site Scan Detects a Vulnerability

You can receive an email report if your site is running vulnerable versions of a plugin, theme, or WordPress core. Customize the email addresses that receive scan results.

iThemes Security Pro

The Best WordPress Security Plugin to Secure & Protect WordPress Sites

WordPress currently powers over 40% of all websites, so it has become a popular target for hackers with malicious intent. The iThemes Security Pro plugin takes the guesswork out of WordPress security to make it easy to secure & protect your WordPress website. It’s like having a full-time security expert on staff who constantly monitors and protects your WordPress site for you.

Buy iThemes Security Pro


Dan Knauss
Dan Knauss

Dan Knauss is StellarWP’s Technical Content Generalist. He’s been a writer, teacher, and freelancer working in open source since the late 1990s and with WordPress since 2004.

Share via:

  • Facebook
  • Twitter
  • LinkedIn
  • More
Other related posts
wordpress vulnerability report - security
WordPress Vulnerability Report – August 30, 2023
WordPress Vulnerability Report
WordPress Vulnerability Report – August 23, 2023
A computer riddled with security issue alerts. There is a large, orange shield with a slash in the middle of the screen. Surrounding it are a red target, a green skull and crossbones, an orange “bug”, a triangle with an explanation point in the middle and a gray gear.
WordPress Vulnerability Report – August 16, 2023
WordPress vulnerability report
WordPress Vulnerability Report – August 9, 2023

Get updates on new themes & plugins plus special discounts

About iThemes

  • Contact Us
  • Website Accessibility Statement
  • Sitemap

Resources

  • Blog
  • Documentation
  • WordPress Tutorials
  • Free WordPress Ebooks
  • Free Webinar Library
  • Free Upcoming Webinars
  • iThemes Training
  • Affiliates

Customers

  • Member Panel Login
  • Support
  • FAQs
  • Upgrade Policy
  • Licensing
  • Terms and Conditions
  • Refund Policy

Top Products

  • BackupBuddy
  • iThemes Security Pro
  • iThemes Sync
  • Restrict Content Pro
  • WPComplete
  • WordPress Plugins
  • Content Upgrades
  • WordPress Landing Page Plugin
  • BackupBuddy Stash

iThemes Media LLC Copyright © 2023 All rights reserved | Privacy Policy

A Liquid Web Brand © 2022 All Rights Reserved.

Get the Weekly WordPress Vulnerability Report

Vulnerable WordPress plugins and themes are the #1 reason WordPress sites get hacked, but keeping track of every new plugin and theme vulnerability is hard work. Get the weekly WordPress Vulnerability Report delivered right to your inbox to help keep your website secure.

Get the Report
Share via
Facebook
Twitter
LinkedIn
Mix
Email
Print
Copy Link
Powered by Social Snap
Copy link
CopyCopied
Powered by Social Snap

Get the Weekly WordPress Vulnerability Report

Vulnerable WordPress plugins and themes are the #1 reason WordPress sites get hacked, but keeping track of every new plugin and theme vulnerability is hard work. Get the weekly WordPress Vulnerability Report delivered right to your inbox to help keep your website secure.
No spam. Unsubscribe anytime.