WordPress Vulnerability Report

WordPress Vulnerability Report – June 7, 2023

This week, 101 total vulnerabilities emerged in public disclosure. They may affect over 6 million WordPress sites. Additionally, there are 64 plugin vulnerabilities with no patch available yet, but no new theme vulnerabilities surfaced. If you are using any unpatched plugins or themes, check their vendors' intentions and progress on a security release.

Dan Knauss

This week, 101 total vulnerabilities emerged in public disclosure. They may affect over 6 million WordPress sites. Additionally, there are 64 plugin vulnerabilities with no patch available yet, but no new theme vulnerabilities surfaced. If you are using any unpatched plugins or themes, check their vendors’ intentions and progress on a security release. If no patch is forthcoming or the vulnerable software has been closed and dropped from the official WordPress theme and plugin repositories, you should consider deactivation and removal in favor of alternative solutions.

WordPress Core Vulnerabilities — Patched

No new WordPress core vulnerabilities were disclosed this week.

WordPress core is very secure when it’s properly configured and maintained. Vulnerable plugins that have not been updated by site owners are the most common vector for attacks on WordPress websites. Our weekly WordPress Vulnerability Report, powered by Patchstack, covers new WordPress plugin, theme, and core vulnerabilities that have emerged since last week’s report. Our goal is to spread awareness of emerging security threats and help you decide what to do if you are using vulnerable software on your website. For a deeper analysis of recent trends in WordPress vulnerabilities and threat vectors, see our 2022 Annual Vulnerability Report.

These reports are published every Wednesday and include all active vulnerabilities tracked by Patchstack as of Monday since the previous report. This leaves a 48-hour window for the newest emerging vulnerabilities to be patched before full public disclosure. iThemes Security Pro users have access to vulnerability alerts emerging within this window.

Get SolidWP tips direct in your inbox

Sign up

This field is for validation purposes and should be left unchanged.
Placeholder text
Placeholder text
Thanks

Oops something went wrong, please try submitting again

Get started with confidence — risk free, guaranteed

WordPress Plugin Vulnerabilities — Patched

In this section, you’ll find the most recently disclosed WordPress plugin vulnerabilities that have been fixed with a new release from their authors and maintainers. Please apply the updates if you are affected!

These vulnerabilities have been disclosed and scored for their severity, thanks to our friends at Patchstack. Each plugin listing includes the type of vulnerability with its CVE number and CVSS severity rating with links to more technical details. You’ll also see the number of active sites using the plugin and the plugin version release that patches the vulnerability. We start with the most popular plugins, which represent the largest target for attackers.

Jetpack

Plugin Slug:
jetpack
Installations:
5,000,000+
Vulnerability:
Arbitrary File Overwrite
Patched in Version:
12.1.1
Severity Score:
Critical
The vulnerability has been patched, so you should update to version 12.1.1.

Social Media Share Buttons & Social Sharing Icons

Plugin Slug:
ultimate-social-media-icons
Installations:
200,000+
Vulnerability:
Broken Access Control + CSRF
Patched in Version:
2.8.2
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.8.2.

Download Manager

Plugin Slug:
download-manager
Installations:
100,000+
Vulnerability:
Broken Access Control
Patched in Version:
3.2.71
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.2.71.

Download Monitor

Plugin Slug:
download-monitor
Installations:
100,000+
Vulnerability:
Server Side Request Forgery (SSRF)
Patched in Version:
4.8.2
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 4.8.2.

Brizy Page Builder

Plugin Slug:
brizy
Installations:
90,000+
Vulnerability:
IP Address Spoofing to Protection Mechanism Bypass
Patched in Version:
2.4.19
Severity Score:
Low
The vulnerability has been patched, so you should update to version 2.4.19.

Nested Pages

Plugin Slug:
wp-nested-pages
Installations:
90,000+
Vulnerability:
Missing Authorization to Authenticated (Editor+) Plugin Settings Reset
Patched in Version:
3.2.4
Severity Score:
Low
The vulnerability has been patched, so you should update to version 3.2.4.

VK Blocks

Plugin:
VK Blocks
Plugin Slug:
vk-blocks
Installations:
70,000+
Vulnerability:
Auth. Settings Update
Patched in Version:
1.57.1.2
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.57.1.2.

Uncanny Toolkit for LearnDash

Plugin Slug:
uncanny-learndash-toolkit
Installations:
30,000+
Vulnerability:
Open Redirection
Patched in Version:
3.6.4.4
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.6.4.4.

Uncanny Toolkit for LearnDash

Plugin Slug:
uncanny-learndash-toolkit
Installations:
30,000+
Vulnerability:
Broken Access Control
Patched in Version:
3.6.4.4
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.6.4.4.

Draw Attention

Plugin Slug:
draw-attention
Installations:
20,000+
Vulnerability:
Missing Authorization to Arbitrary Post Featured Image Modification
Patched in Version:
2.0.12
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.0.12.

Favorites

Plugin:
Favorites
Plugin Slug:
favorites
Installations:
20,000+
Vulnerability:
Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode
Patched in Version:
2.3.3
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.3.3.

bbp style pack

Plugin Slug:
bbp-style-pack
Installations:
8,000+
Vulnerability:
Reflected Cross Site Scripting (XSS)
Patched in Version:
5.5.6
Severity Score:
High
The vulnerability has been patched, so you should update to version 5.5.6.

Drop Shadow Boxes

Plugin Slug:
drop-shadow-boxes
Installations:
6,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.7.11
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.7.11.

CRM Perks Forms

Plugin Slug:
crm-perks-forms
Installations:
2,000+
Vulnerability:
Authenticated (Admin+) Stored Cross-Site Scripting
Patched in Version:
1.1.2
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.1.2.

Donation Platform for WooCommerce: Fundraising & Donation Management

Plugin Slug:
wc-donation-platform
Installations:
2,000+
Vulnerability:
Cross-Site Request Forgery to Survey Submission
Patched in Version:
1.2.10
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.2.10.

WP Inventory Manager

Plugin Slug:
wp-inventory-manager
Installations:
2,000+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
2.1.0.14
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.1.0.14.

WP Directory Kit

Plugin Slug:
wpdirectorykit
Installations:
2,000+
Vulnerability:
Reflected Cross-Site Scripting via 'search'
Patched in Version:
1.2.4
Severity Score:
High
The vulnerability has been patched, so you should update to version 1.2.4.
Plugin Slug:
cookie-consent-box
Installations:
1,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.1.7
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.1.7.

JS Jobs Manager

Plugin Slug:
js-jobs
Installations:
1,000+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
2.0.1
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.0.1.

Kanban Boards for WordPress

Plugin Slug:
kanban
Installations:
1,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.5.21
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.5.21.

Telegram Bot & Channel

Plugin Slug:
telegram-bot
Installations:
1,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
3.6.3
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.6.3.

Quick/Bulk Order Form for WooCommerce

Plugin Slug:
woocommerce-bulk-order-form
Installations:
1,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
3.6.0
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.6.0.

WP User Switch

Plugin Slug:
wp-user-switch
Installations:
1,000+
Vulnerability:
Authentication Bypass via Cookie
Patched in Version:
1.0.3
Severity Score:
High
The vulnerability has been patched, so you should update to version 1.0.3.

Front End Users

Plugin Slug:
front-end-only-users
Installations:
900+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
3.2.25
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.2.25.

Call Now Accessibility Button

Plugin Slug:
accessibility-help-button
Installations:
50+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.2
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.2.

B2BKing

Plugin Slug:
b2bking
Vulnerability:
Authenticated Product Price Change
Patched in Version:
4.6.20
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 4.6.20.

Premium Addons PRO

Plugin Slug:
premium-addons-pro
Vulnerability:
Reflected Cross Site Scripting (XSS)
Patched in Version:
2.8.25
Severity Score:
High
The vulnerability has been patched, so you should update to version 2.8.25.

WooCommerce Box Office

Plugin Slug:
woocommerce-box-office
Vulnerability:
Unauthenticated Save Ticket Barcode
Patched in Version:
1.1.52
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.1.52.

WooCommerce Box Office

Plugin Slug:
woocommerce-box-office
Vulnerability:
Contributor+ Stored Cross Site Scripting (XSS)
Patched in Version:
1.1.51
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.1.51.

WordPress Plugin Vulnerabilities — Unpatched

This section contains plugin vulnerabilities with no known fix. Until a patch is available, you are advised to deactivate the plugin, at minimum, immediately. If there is a high risk of active exploits or the plugin remains unpatched for weeks, you are advised to delete the plugin. You should also delete persistently unpatched plugins the WordPress.org repository has locked and marked “Closed” so they can no longer be downloaded and installed.

VK Blocks

Plugin:
VK Blocks
Plugin Slug:
vk-blocks
Installations:
70,000+
Vulnerability:
Auth. Settings Update
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

WPC Smart Wishlist for WooCommerce

Plugin Slug:
woo-smart-wishlist
Installations:
50,000+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Constant Contact Forms

Plugin Slug:
constant-contact-forms
Installations:
40,000+
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

TS Webfonts

Plugin Slug:
ts-webfonts-for-sakura
Installations:
30,000+
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

WordPress Social Login

Plugin Slug:
wordpress-social-login
Installations:
30,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

WordPress Social Login

Plugin Slug:
wordpress-social-login
Installations:
30,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

`OSM – OpenStreetMap

Plugin Slug:
osm
Installations:
20,000+
Vulnerability:
Contributor+ Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Yandex Metrica Counter

Plugin Slug:
counter-yandex-metrica
Installations:
10,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

LWS Hide Login

Plugin Slug:
lws-hide-login
Installations:
10,000+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.
Plugin Slug:
unite-gallery-lite
Installations:
10,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

WP Hide Post

Plugin Slug:
wp-hide-post
Installations:
10,000+
Vulnerability:
Cross Site Request Forgery (CSRF) Leading To Post Status Change
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Call Now Icon Animate

Plugin Slug:
call-now-icon-animate
Installations:
7,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Change WooCommerce Add To Cart Button Text

Plugin Slug:
change-woocommerce-add-to-cart-button-text
Installations:
3,000+
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Google Fonts For WordPress

Plugin Slug:
free-google-fonts
Installations:
3,000+
Vulnerability:
Reflected Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Ajax Pagination and Infinite Scroll

Plugin Slug:
malinky-ajax-pagination
Installations:
3,000+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Online Booking & Scheduling Calendar for WordPress by vcita

Plugin Slug:
meeting-scheduler-by-vcita
Installations:
3,000+
Vulnerability:
Unauth. Stored Cross-Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Online Booking & Scheduling Calendar for WordPress by vcita

Plugin Slug:
meeting-scheduler-by-vcita
Installations:
3,000+
Vulnerability:
Missing Authorization to Account Logout
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Online Booking & Scheduling Calendar for WordPress by vcita

Plugin Slug:
meeting-scheduler-by-vcita
Installations:
3,000+
Vulnerability:
Missing Authorization on REST-API
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Online Booking & Scheduling Calendar for WordPress by vcita

Plugin Slug:
meeting-scheduler-by-vcita
Installations:
3,000+
Vulnerability:
Missing Authorization to Settings Update and Media Upload
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

BBS e-Popup

Plugin Slug:
bbs-e-popup
Installations:
2,000+
Vulnerability:
Reflected Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Contact Form Builder by vcita

Plugin Slug:
contact-form-with-a-meeting-scheduler-by-vcita
Installations:
2,000+
Vulnerability:
Cross-Site Request Forgery to Stored Cross-Site Scripting
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Contact Form Builder by vcita

Plugin Slug:
contact-form-with-a-meeting-scheduler-by-vcita
Installations:
2,000+
Vulnerability:
Auth. Stored Cross-Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

SpamReferrerBlock

Plugin Slug:
spamreferrerblock
Installations:
2,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

SpamReferrerBlock

Plugin Slug:
spamreferrerblock
Installations:
2,000+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

WordPress Tables

Plugin Slug:
wptables
Installations:
2,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

bbPress Toolkit

Plugin Slug:
bbp-toolkit
Installations:
1,000+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

bbPress Toolkit

Plugin Slug:
bbp-toolkit
Installations:
1,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Chilexpress woo oficial

Plugin Slug:
chilexpress-oficial
Installations:
1,000+
Vulnerability:
Reflected Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Dynamic QR Code Generator

Plugin Slug:
dynamic-qr-code-generator
Installations:
1,000+
Vulnerability:
Reflected Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Extended Post Status

Plugin Slug:
extended-post-status
Installations:
1,000+
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Floating Action Button

Plugin Slug:
floating-action-button
Installations:
1,000+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Headless CMS

Plugin Slug:
headless-cms
Installations:
1,000+
Vulnerability:
Broken Authentication
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Woocommerce Order address Print

Plugin Slug:
woocommerce-order-address-print
Installations:
1,000+
Vulnerability:
Reflected Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

WordPress NextGen GalleryView

Plugin Slug:
wordpress-nextgen-galleryview
Installations:
1,000+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

WP-Cache.com

Plugin Slug:
wp-cachecom
Installations:
1,000+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

WP-Cirrus

Plugin:
WP-Cirrus
Plugin Slug:
wp-cirrus
Installations:
1,000+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

WP Full Auto Tags Manager

Plugin Slug:
wp-full-auto-tags-manager
Installations:
1,000+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

WP Report Post

Plugin Slug:
wp-report-post
Installations:
1,000+
Vulnerability:
SQL Injection
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

WP Report Post

Plugin Slug:
wp-report-post
Installations:
1,000+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Worthy – VG WORT Integration für WordPress

Plugin Slug:
wp-worthy
Installations:
1,000+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Contact Form and Calls To Action by vcita

Plugin Slug:
lead-capturing-call-to-actions-by-vcita
Installations:
400+
Vulnerability:
Auth. Stored Cross-Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Contact Form and Calls To Action by vcita

Plugin Slug:
lead-capturing-call-to-actions-by-vcita
Installations:
400+
Vulnerability:
Cross-Site Request Forgery to Stored Cross-Site Scripting
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

CRM and Lead Management by vcita

Plugin Slug:
crm-customer-relationship-management-by-vcita
Installations:
200+
Vulnerability:
Auth. Stored Cross-Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

CRM and Lead Management by vcita

Plugin Slug:
crm-customer-relationship-management-by-vcita
Installations:
200+
Vulnerability:
Cross-Site Request Forgery to Stored Cross-Site Scripting
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

LH Password Changer

Plugin Slug:
lh-password-changer
Installations:
100+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

TPG Redirect

Plugin Slug:
tpg-redirect
Installations:
20+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Blog-in-Blog

Plugin Slug:
blog-in-blog
Vulnerability:
Authenticated (Editor+) Local File Inclusion via Shortcode
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched and the plugin is closed. You should uninstall and delete the plugin.

Blog-in-Blog

Plugin Slug:
blog-in-blog
Vulnerability:
Authenticated (Editor+) Stored Cross-Site Scripting via Shortcode
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched and the plugin is closed. You should uninstall and delete the plugin.

Cart2Cart: Magento to WooCommerce Migration

Plugin Slug:
cart2cart-magento-to-woocommerce-migration
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched and the plugin is closed. You should uninstall and delete the plugin.

Display post meta, term meta, comment meta, and user meta

Plugin Slug:
display-metadata
Vulnerability:
Authenticated(Contributor+) Stored Cross-Site Scripting
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched and the plugin is closed. You should uninstall and delete the plugin.

Feather Login Page

Plugin Slug:
feather-login-page
Vulnerability:
Missing Authorization to Authentication Bypass and Privilege Escalation
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched and the plugin is closed. You should uninstall and delete the plugin.

Feather Login Page

Plugin Slug:
feather-login-page
Vulnerability:
Missing Authorization to Non-Arbitrary User Deletion
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched and the plugin is closed. You should uninstall and delete the plugin.

Feather Login Page

Plugin Slug:
feather-login-page
Vulnerability:
Cross Site Request Forgery (CSRF) to Privilege Escalation
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched and the plugin is closed. You should uninstall and delete the plugin.

Kebo Twitter Feed

Plugin Slug:
kebo-twitter-feed
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched and the plugin is closed. You should uninstall and delete the plugin.

Login Configurator

Plugin Slug:
login-configurator
Vulnerability:
Reflected Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched and the plugin is closed. You should uninstall and delete the plugin.

Page Builder by AZEXO

Plugin Slug:
page-builder-by-azexo
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched and the plugin is closed. You should uninstall and delete the plugin.

Page Builder by AZEXO

Plugin Slug:
page-builder-by-azexo
Vulnerability:
Auth. Stored Cross-Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched and the plugin is closed. You should uninstall and delete the plugin.

Page Builder by AZEXO

Plugin Slug:
page-builder-by-azexo
Vulnerability:
Missing Authorization to Post Creation
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched and the plugin is closed. You should uninstall and delete the plugin.

Page Builder by AZEXO

Plugin Slug:
page-builder-by-azexo
Vulnerability:
Cross-Site Request Forgery to Stored Cross-Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched and the plugin is closed. You should uninstall and delete the plugin.

Web Directory Free

Plugin Slug:
web-directory-free
Vulnerability:
Authenticated (Contributor+) SQL Injection via post_id
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched and the plugin is closed. You should uninstall and delete the plugin.

Wordapp

Plugin:
Wordapp
Plugin Slug:
wordapp
Vulnerability:
Authorization Bypass through Use of Insufficiently Unique Cryptographic Signature
Patched in Version:
No Fix
Severity Score:
Critical
The vulnerability has not been patched and the plugin is closed. You should uninstall and delete the plugin.

WordPress Theme Vulnerabilities

In this section, you’ll find the latest WordPress theme vulnerabilities to be disclosed. You’ll see the same information provided above for vulnerable plugins, and the same advice applies. If a security update exists, install it immediately. If a vulnerability remains unpatched in a theme you are actively using, you will need to find an alternative theme. Deactivate and delete persistently unpatched themes and those that have been “Closed” in the WordPress.org theme repository. If you have a vulnerable theme installed that you are not actively using, simply delete it.

No new WordPress theme vulnerabilities were disclosed this week.

Solid Security is part of Solid Suite — The best foundation for WordPress websites.

Every WordPress site needs security, backups, and management tools. That’s Solid Suite — an integrated bundle of three plugins: Solid Security, Solid Backups, and Solid Central. You also get access to Solid Academy’s learning resources for WordPress professionals. Build your next WordPress website on a solid foundation with Solid Suite!

Get Solid Security

Did you like this article? Spread the word: