WordPress Vulnerability Report

WordPress Vulnerability Report – March 15, 2023

This week there are 61 plugin and 4 theme vulnerabilities that need your attention if your site is among the 6 million+ sites affected.

Avatar photo
SolidWP Editorial Team

This week there are 37 plugin vulnerabilities (and one theme vulnerability) affecting well over 6 million WordPress sites. Fortunately, all of these have patches available, so run those updates if you use these plugins! Additionally, there are 27 plugin vulnerabilities and 3 theme vulnerabilities with no patch available yet. Check their vendors’ intentions and progress on a patch if you use any of these unpatched plugins or themes. If no security fix is forthcoming or a vulnerable plugin or theme has been “closed” (dropped from the WordPress.org repository), you should consider deactivating it in favor of alternative solutions.

Not included on this week’s list is the Postmatic Replyable plugin, since it was closed in the WordPress directory, possibly due to a CSRF vulnerability reported in CVE-2022-4265. The current release, version 2.2.10 (Trac SVN), can be downloaded from Replyable. It patches a high-severity PHP Object Injection vulnerability.

WordPress core is very secure when it’s properly configured and maintained. Vulnerable plugins that have not been updated by site owners are the most common vector for attacks on WordPress websites. Our weekly WordPress Vulnerability Report, powered by Patchstack, covers new WordPress plugin, theme, and core vulnerabilities that have emerged since last week’s report. Our goal is to spread awareness of emerging security threats and help you decide what to do if you are using vulnerable software on your website. For a deeper analysis of recent trends in WordPress vulnerabilities and threat vectors, see our 2022 Annual Vulnerability Report.

WordPress Core News

WordPress 6.1.1 is the current (short-cycle maintenance) release of WordPress core. It is a minor release issued on November 15, 2022. It features 29 bug fixes in Core and 21 bug fixes for the Gutenberg block editor. You can review a summary of the key updates in this release at WordPress.org.

If your WordPress sites have enabled automatic background updates, they should have upgraded to 6.1.1 automatically. You can download WordPress 6.1.1 from WordPress.org, or visit your WordPress Dashboard, click “Updates,” and then click the “Update Now” button which will appear when any core updates are available. For more information, check out the version 6.1.1 HelpHub documentation page.

WordPress 6.2 is the next major WordPress release, and it’s on track for a March 28, 2023 debut. You can learn more about what’s coming in the WordPress 6.2 RC1 release announcement and the WordPress 6.2 Field Guide.

Get SolidWP tips direct in your inbox

Sign up

This field is for validation purposes and should be left unchanged.
Placeholder text
Placeholder text
Thanks

Oops something went wrong, please try submitting again

Get started with confidence — risk free, guaranteed

WordPress Plugin Vulnerabilities with Patches

In this section, you’ll find the most recently disclosed WordPress plugin vulnerabilities that have been fixed with a new release from their authors and maintainers. Please apply the updates if you are affected!

These vulnerabilities have been disclosed and scored for their severity thanks to our friends at Patchstack. Each plugin listing includes the type of vulnerability with its CVE number and CVSS severity rating with links to more technical details. You’ll also see the number of active sites using the plugin and the plugin version release that patches the vulnerability. We start with the most popular plugins, which represent the largest target for attackers.

Updraft Plus

Plugin Slug:
updraftplus
Installations:
3,000,000+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
1.23.1
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.23.1.

Popup Maker

Plugin Slug:
popup-maker
Installations:
700,000+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
1.18.1
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.18.1.
Plugin Slug:
complianz-gdpr
Installations:
600,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
6.4.2
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 6.4.2.

301 Redirects – Easy Redirect Manager

Plugin Slug:
eps-301-redirects
Installations:
200,000+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
2.73
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.73.
Plugin Slug:
wp-external-links
Installations:
100,000+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
2.58
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.58.

WP Maps

Plugin Slug:
wp-google-map-plugin
Installations:
100,000+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
4.4.3
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 4.4.3.

Ajax Load More

Plugin Slug:
ajax-load-more
Installations:
50,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
5.6.0.3
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 5.6.0.3.

Site Reviews

Plugin Slug:
site-reviews
Installations:
50,000+
Vulnerability:
Broken Access Control
Patched in Version:
6.6.0
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 6.6.0.

Site Reviews

Plugin Slug:
site-reviews
Installations:
50,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
6.6.0
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 6.6.0.

Site Reviews

Plugin Slug:
site-reviews
Installations:
50,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
6.6.0
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 6.6.0.

Klaviyo

Plugin:
Klaviyo
Plugin Slug:
klaviyo
Installations:
30,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
3.0.8
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.0.8.

Customify

Plugin Slug:
customify
Installations:
20,000+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
2.10.5
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.10.5.

Redirect Redirection

Plugin Slug:
redirect-redirection
Installations:
20,000+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
1.1.5
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.1.5.

Reusable Blocks Extended

Plugin Slug:
reusable-blocks-extended
Installations:
10,000+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
0.9.1
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 0.9.1.

Weaver Xtreme Theme Support

Plugin Slug:
weaverx-theme-support
Installations:
10,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
6.2.5
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 6.2.5.

Woo Products Widgets For Elementor

Plugin Slug:
woo-products-widgets-for-elementor
Installations:
8,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.0.8
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.0.8.

W4 Post List

Plugin Slug:
w4-post-list
Installations:
5,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.4.5
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.4.5.

Stock Ticker

Plugin Slug:
stock-ticker
Installations:
4,000+
Vulnerability:
Broken Access Control
Patched in Version:
3.23.1
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.23.1.

Auto Prune Posts

Plugin Slug:
auto-prune-posts
Installations:
2,000+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
2.0.0
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.0.0.

RapidLoad Power-Up for Autoptimize

Plugin Slug:
unusedcss
Installations:
2,000+
Vulnerability:
Broken Access Control
Patched in Version:
1.7.2
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.7.2.

RapidLoad Power-Up for Autoptimize

Plugin Slug:
unusedcss
Installations:
2,000+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
1.7.2
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.7.2.

Mass Delete Unused Tags

Plugin Slug:
mass-delete-unused-tags
Installations:
1,000+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
3.0.0
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.0.0.

PhonePe Payment Solutions

Plugin Slug:
phonepe-payment-solutions
Installations:
1,000+
Vulnerability:
Server Side Request Forgery (SSRF)
Patched in Version:
2.0.0
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.0.0.

Webmention

Plugin:
Webmention
Plugin Slug:
webmention
Installations:
1,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
4.0.9
Severity Score:
High
The vulnerability has been patched, so you should update to version 4.0.9.

LeadSnap

Plugin:
LeadSnap
Plugin Slug:
leadsnap
Installations:
800+
Vulnerability:
PHP Object Injection
Patched in Version:
1.24
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.24.

Mass Delete Taxonomies

Plugin Slug:
mass-delete-tags
Installations:
300+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
4.0.0
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 4.0.0.

WordPress Plugin Vulnerabilities – No Known Fix

This section contains plugin vulnerabilities with no known fix. Until a patch is available, you are advised to deactivate the plugin, at minimum, immediately. If there is a high risk of active exploits or the plugin remains unpatched for weeks, you are advised to delete the plugin. You should also delete persistently unpatched plugins the WordPress.org repository has locked and marked “Closed” so they can no longer be downloaded and installed.

WooCommerce Weight Based Shipping

Plugin Slug:
weight-based-shipping-for-woocommerce
Installations:
60,000+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Print Invoice & Delivery Notes for WooCommerce

Plugin Slug:
woocommerce-delivery-notes
Installations:
40,000+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Data Tables Generator by Supsystic

Plugin Slug:
data-tables-generator-by-supsystic
Installations:
30,000+
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Google XML Sitemap for Videos

Plugin Slug:
xml-sitemaps-for-videos
Installations:
20,000+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

CF7 Invisible reCAPTCHA

Plugin Slug:
cf7-invisible-recaptcha
Installations:
10,000+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Google XML Sitemap for Images

Plugin Slug:
google-image-sitemap
Installations:
10,000+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Contact Form 7 Redirect & Thank You Page

Plugin Slug:
cf7-redirect-thank-you-page
Installations:
6,000+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Yandex.News Feed by Teplitsa

Plugin Slug:
yandexnews-feed-by-teplitsa
Installations:
6,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Daily Prayer Time

Plugin Slug:
daily-prayer-time-for-mosques
Installations:
1,000+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Daily Prayer Time

Plugin Slug:
daily-prayer-time-for-mosques
Installations:
1,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Kopa Framework

Plugin Slug:
kopatheme
Installations:
1,000+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

xili-tidy-tags

Plugin Slug:
xili-tidy-tags
Installations:
1,000+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.
Plugin Slug:
wp-advanced-search
Installations:
800+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

CMS Press

Plugin:
CMS Press
Plugin Slug:
cms-press
Installations:
700+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Backup Bank: WordPress Backup

Plugin Slug:
wp-backup-bank
Installations:
700+
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Chronoforms

Plugin Slug:
chronoforms
Installations:
400+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

WP Basic Elements

Plugin Slug:
wp-basic-elements
Installations:
300+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Exxp

Plugin:
Exxp
Plugin Slug:
exxp-wp
Installations:
200+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

WH Testimonials

Plugin Slug:
wh-testimonials
Installations:
90+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

WordPress Console

Plugin Slug:
wordpress-console
Installations:
40+
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Low
The vulnerability has not been patched. You should deactivate the plugin.

LOGIN AND REGISTRATION ATTEMPTS LIMIT

Plugin Slug:
login-attempts-limit-wp
Installations:
10+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Admin side data storage for Contact Form 7

Plugin Slug:
admin-side-data-storage-for-contact-form-7
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Easy Event calendar

Plugin Slug:
easy-event-calendar
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Tags Cloud Manager

Plugin Slug:
tags-cloud-manager
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

WordPress Theme Vulnerabilities

In this section, you’ll find the latest WordPress theme vulnerabilities to be disclosed. You’ll see the same information provided above for vulnerable plugins, and the same advice applies. If a security update exists, install it immediately. If a vulnerability remains unpatched in a theme you are actively using, you will need to find an alternative theme. Deactivate and delete persistently unpatched themes and those that have been “Closed” in the WordPress.org theme repository. If you have a vulnerable theme installed that you are not actively using, simply delete it.

Real Estate 7

Theme Slug:
realestate-7
Vulnerability:
Broken Access Control
Patched in Version:
3.3.5
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.3.5.

Brilliance

Theme Slug:
brilliance
Downloads:
139,773
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should switch themes.

Regina Lite

Theme Slug:
regina-lite
Downloads:
116,354
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should switch themes.

Intrepidity

Theme Slug:
intrepidity
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should switch themes.

Solid Security is part of Solid Suite — The best foundation for WordPress websites.

Every WordPress site needs security, backups, and management tools. That’s Solid Suite — an integrated bundle of three plugins: Solid Security, Solid Backups, and Solid Central. You also get access to Solid Academy’s learning resources for WordPress professionals. Build your next WordPress website on a solid foundation with Solid Suite!

Get Solid Security

Did you like this article? Spread the word: