Menu
iThemes
WordPress Security, Backups & Maintenance
  • Products
    • iThemes Security Pro
    • BackupBuddy
    • iThemes Sync
    • Why buy from iThemes?
  • Bundles
    • Essentials Bundle
    • Solid Foundations
    • Customer Spotlights
  • Resources
    • Blog
    • WordPress 101 Tutorials
    • WordPress Ebooks
    • Weekly WordPress Vulnerability Report
    • The Ultimate Guide to Starting a Web Design Business
  • Training
    • Upcoming Webinars
    • Free Webinar Library
    • Premium Courses
    • Become a Member
    • Member Login
  • Support
    • Documentation
    • Get Help
    • Product Updates
    • Upgrade Policy
    • Contact
    • Our Mission: Make People’s Lives Awesome
  • Log In
WordPress News and Updates from iThemes
Categories
  • Product Updates
  • WordPress Backup
  • WordPress Block Editor
  • WordPress Ecommerce
  • WordPress for Freelancers
  • WordPress Security
  • WordPress Tutorials
  • WPprosper

WordPress Vulnerability Report – November 16, 2022

Written by iThemes Editorial Team on November 16, 2022

Last Updated on November 16, 2022

Vulnerable plugins and themes are the #1 reason WordPress websites get hacked. The weekly WordPress Vulnerability Report powered by WPScan covers recent WordPress plugin, theme, and core vulnerabilities and what to do if you run one of the vulnerable plugins or themes on your website.

New this week: We’ve added two new data points to the weekly vulnerability report.

First, we’ve added the plugin slug, which is also the name of the directory in which the plugin is installed on your site under wp-content/plugins/. This will help you more easily determine if this plugin is installed on your site(s).

We have also added the CVE unique identifier with a link to the vulnerability report on cve.org. As the iThemes weekly vulnerability report is one of the first to publish notifications of WordPress vulnerabilities, you might notice that upon publication, these links will show that the CVE number is “reserved.” As details of the vulnerability are published, however, you’ll see greater detail about the nature of the specific vulnerability and possibly even a proof of concept of how the vulnerability could have been exploited.

It is our hope that in sharing these data points with you, it makes identifying and understanding the scope of security vulnerabilities much easier.

Each vulnerability will have a severity rating of low, medium, high, or critical. Responsible disclosure and reporting of vulnerabilities is an integral part of keeping the WordPress community safe. Please share this post with your friends to help get the word out and make WordPress safer for everyone!

Contents of the November 16, 2022 Report
  • The Future of Authentication is Passkeys! Login to your WordPress site with Biometrics only available in iThemes Security Pro
  • WordPress Core News
    • WordPress Core Dropping Support for WordPress Versions 3.7. – 4.0
  • WordPress Plugin Vulnerabilities
    • Broken Link Checker
    • Chaty
    • Feed Them Social
    • Blog2Social
    • Advanced Import
    • TeraWallet – For WooCommerce
    • Form Vibes
    • Theme-Demo-Importer
    • Seed Social
    • Salon Booking System
    • WP OAuth Server
    • Export customers list CSV for WooCommerce
    • Comic Book Management System
    • WordPress Countdown Widget
    • WP Affiliate Platform
    • Becustom
    • WP CSV Exporter
  • WordPress Plugin Vulnerabilities – No Known Fix
    • WPUpper Share Buttons
    • Helloprint
    • Advanced WP Columns
    • Follow Me Plugin
    • Simple Video Embedder
    • Transposh WordPress Translation
    • WP Page Builder
    • Uji Countdown
    • Add Comments
    • 3DPrint
    • Clerk
    • Photospace Gallery
    • PostmagThemes Demo
  • WordPress Theme Vulnerabilities
    • Workreap – Freelance Marketplace and Directory
  • The Best WordPress Security Plugin to Secure & Protect WordPress Sites

The Future of Authentication is Passkeys! Login to your WordPress site with Biometrics only available in iThemes Security Pro

The problems of brute force attacks through credential stuffing, phishing attacks, and reused passwords have made our digital lives less secure. We’ve all tried to encourage 2-factor authentication as a protection, but less than 30% of users actually use 2FA. Password-based logins are a problem.

The future of authentication is passkeys, and iThemes Security Pro is the first to bring this breakthrough technology to WordPress sites. Using breakthrough WebAuthn technology based on public/private cryptography, passkeys make passwords obsolete. Now, website admins and end users can have secure logins without the inconvenience of additional two-factor apps, password managers, or complex password requirements.

Learn More About Passkeys

WordPress Core News

WordPress 6.1.1 was released on November 15, 2022, as a short-cycle maintenance release with 29 bug fixes in Core and 21 bug fixes for the block editor. Because this is a core update, be sure to update to WordPress 6.0.1 as soon as possible! As always, with a major release like this, it makes sense to ensure your site is backed up with BackupBuddy before updating.

  • No new WordPress core vulnerabilities were disclosed this week.

WordPress Core Dropping Support for WordPress Versions 3.7. – 4.0

In more WordPress core security news, the WordPress Security Team will no longer provide security updates for WordPress core versions 3.7 – 4.0. Please make sure all your WordPress sites are running the latest version.

Dropping security updates for WordPress versions 3.7 through 4.0
Get the weekly WordPress Vulnerability Report delivered to your inbox each Wednesday.
Subscribe now

WordPress Plugin Vulnerabilities

In this section, the latest WordPress plugin vulnerabilities have been disclosed. Each plugin listing includes the type of vulnerability, the active installations, the version number if patched, and the severity rating.

Broken Link Checker

Product image for Broken Link Checker.
Plugin
Broken Link Checker
Plugin Slug
broken-link-checker
Installations
700,000+
Vulnerability
Admin+ Cross-Site Scripting
Patched in Version
1.11.20
Severity Score
Low
CVE
2022-3922
The vulnerability has been patched, so you should update to version 1.11.20.

Chaty

Product image for Floating Chat Widget: Contact Chat Icons, Telegram Chat, Line, WeChat, Email, SMS, Call Button – Chaty.
Plugin
Floating Chat Widget: Contact Chat Icons, Telegram Chat, Line, WeChat, Email, SMS, Call Button – Chaty
Plugin Slug
chaty
Installations
100,000+
Vulnerability
Admin+ SQLi
Patched in Version
3.0.3
Severity Score
Medium
CVE
2022-3858
The vulnerability has been patched, so you should update to version 3.0.3.

Feed Them Social

Product image for Feed Them Social – for Twitter feed, Youtube and more.
Plugin
Feed Them Social – for Twitter feed, Youtube and more
Plugin Slug
feed-them-social
Installations
70,000+
Vulnerability
Subscriber+ Stored XSS; Settings Update via CSRF
Patched in Version
3.0.1
Severity Score
Medium
CVE
2022-2940
The vulnerability has been patched, so you should update to version 3.0.1.

Blog2Social

Product image for Blog2Social: Social Media Auto Post & Scheduler.
Plugin
Blog2Social: Social Media Auto Post & Scheduler
Plugin Slug
blog2social
Installations
70,000+
Vulnerability
Subscriber+ Settings Update
Patched in Version
6.9.12
Severity Score
Medium
CVE
2022-3622
The vulnerability has been patched, so you should update to version 6.9.12.

Advanced Import

Product image for Advanced Import : One Click Import for WordPress or Theme Demo Data.
Plugin
Advanced Import : One Click Import for WordPress or Theme Demo Data
Plugin Slug
advanced-import
Installations
70,000+
Vulnerability
Arbitrary Plugin Installation & Activation via CSRF
Patched in Version
1.3.8
Severity Score
High
CVE
2022-3677
The vulnerability has been patched, so you should update to version 1.3.8.

TeraWallet – For WooCommerce

Product image for TeraWallet – For WooCommerce.
Plugin
TeraWallet – For WooCommerce
Plugin Slug
woo-wallet
Installations
20,000+
Vulnerability
Subscriber+ Arbitrary Wallet Lock/Unlock via IDOR
Patched in Version
1.4.4
Severity Score
Medium
CVE
2022-3995
The vulnerability has been patched, so you should update to version 1.4.4.

Form Vibes

Product image for Form Vibes – Database Manager for Forms.
Plugin
Form Vibes – Database Manager for Forms
Plugin Slug
form-vibes
Installations
20,000+
Vulnerability
Admin+ SQLi
Patched in Version
1.4.6
Severity Score
Medium
CVE
2022-3764
The vulnerability has been patched, so you should update to version 1.4.6.

Theme-Demo-Importer

Product image for Theme Demo Import.
Plugin
Theme Demo Import
Plugin Slug
theme-demo-import
Installations
10,000+
Vulnerability
Admin+ Arbitrary File Upload
Patched in Version
1.1.1
Severity Score
Medium
CVE
2022-1538
The vulnerability has been patched, so you should update to version 1.1.1.

Seed Social

Product image for Seed Social.
Plugin
Seed Social
Plugin Slug
seed-social
Installations
10,000+
Vulnerability
Admin+ Stored XSS
Patched in Version
2.0.4
Severity Score
Low
CVE
2022-3836
The vulnerability has been patched, so you should update to version 2.0.4.

Salon Booking System

Product image for Salon booking system.
Plugin
Salon booking system
Plugin Slug
salon-booking-system
Installations
8,000+
Vulnerability
Reflected Cross-Site Scripting
Patched in Version
7.9.4
Severity Score
Medium
CVE
2022-43487
The vulnerability has been patched, so you should update to version 7.9.4.

WP OAuth Server

Product image for WP OAuth Server (OAuth Authentication).
Plugin
WP OAuth Server (OAuth Authentication)
Plugin Slug
oauth2-provider
Installations
4,000+
Vulnerability
Admin+ Stored XSS; Client Secret Regeneration via CSRF
Patched in Version
4.2.2
Severity Score
Low
CVE
2022-3892
The vulnerability has been patched, so you should update to version 4.2.2.

Export customers list CSV for WooCommerce

Product image for Export customers list csv for WooCommerce, WordPress users csv, export Guest customer list.
Plugin
Export customers list csv for WooCommerce, WordPress users csv, export Guest customer list
Plugin Slug
export-woocommerce-customer-list
Installations
3,000+
Vulnerability
CSV Injection
Patched in Version
2.0.69
Severity Score
Low
CVE
2022-3603
The vulnerability has been patched, so you should update to version 2.0.69.

Comic Book Management System

Product image for Comic Book Management System.
Plugin
Comic Book Management System
Plugin Slug
comicbookmanagementsystemweeklypicks
Installations
10+
Vulnerability
Admin+ SQLi
Patched in Version
2.2.0
Severity Score
Medium
CVE
2022-3856
The vulnerability has been patched, so you should update to version 2.2.0.

WordPress Countdown Widget

Plugin
WordPress Countdown Widget
Plugin Slug
wordpress-countdown-widget
Vulnerability
Admin+ Stored XSS
Patched in Version
3.1.9.3
Severity Score
Low
CVE
2022-2944
The vulnerability has been patched, so you should update to version 3.1.9.3.

WP Affiliate Platform

Plugin Slug
wp-affiliate-platform
Vulnerability
Affiliate Record Deletion via CSRF; Reflected Cross-Site Scripting; Admin+ Stored XSS
Patched in Version
6.4.0
Severity Score
Medium
CVE
2022-3898
The vulnerability has been patched, so you should update to version 6.4.0.

Becustom

Plugin Slug
becustom
Vulnerability
Settings Update via CSRF
Patched in Version
1.0.5.3
Severity Score
Medium
CVE
2022-3747
The vulnerability has been patched, so you should update to version 1.0.5.3.

WP CSV Exporter

Plugin
WP CSV Exporter
Plugin Slug
wp-csv-exporter
Vulnerability
Admin+ SQLi
Patched in Version
1.3.7
Severity Score
Medium
CVE
2022-3249
The vulnerability has been patched, so you should update to version 1.3.7.

WordPress Plugin Vulnerabilities – No Known Fix

This section contains plugin vulnerabilities with no known fix. Until a patch is available, immediately uninstall and delete the plugin.

WPUpper Share Buttons

Plugin
WPUpper Share Buttons
Plugin Slug
wpupper-share-buttons
Vulnerability
Admin+ Stored XSS
Patched in Version
No Fix
Severity Score
Low
CVE
2022-3838
The vulnerability has not been patched and the plugin is closed. You should uninstall and delete the plugin.

Helloprint

Plugin
Plug your WooCommerce into the largest catalog of customized print products from Helloprint
Plugin Slug
helloprint
Vulnerability
Reflected Cross-Site Scripting
Patched in Version
No Fix
Severity Score
Medium
CVE
2022-3908
The vulnerability has not been patched and the plugin is closed. You should uninstall and delete the plugin.

Advanced WP Columns

Plugin
Advanced WP Columns
Plugin Slug
advanced-wp-columns
Vulnerability
Admin+ Stored Cross-Site Scripting
Patched in Version
No Fix
Severity Score
Low
CVE
2022-3426
The vulnerability has not been patched and the plugin is closed. You should uninstall and delete the plugin.

Follow Me Plugin

Plugin
Follow Me Plugin
Plugin Slug
follow-me
Vulnerability
Stored XSS via CSRF
Patched in Version
No Fix
Severity Score
Medium
CVE
2022-3240
The vulnerability has not been patched and the plugin is closed. You should uninstall and delete the plugin.

Simple Video Embedder

Plugin
Simple Video Embedder
Plugin Slug
simple-video-embedder
Vulnerability
Contributor+ Stored Cross-Site Scripting
Patched in Version
No Fix
Severity Score
Medium
CVE
2022-44590
The vulnerability has not been patched and the plugin is closed. You should uninstall and delete the plugin.

Transposh WordPress Translation

Plugin
Transposh WordPress Translation
Plugin Slug
transposh-translation-filter-for-wordpress
Vulnerability
Settings Update via Authorization Bypass
Patched in Version
No Fix
Severity Score
Medium
CVE
2022-2536
The vulnerability has not been patched and the plugin is closed. You should uninstall and delete the plugin.

WP Page Builder

Plugin
WP Page Builder
Plugin Slug
wp-pagebuilder
Vulnerability
Admin+ Stored Cross-Site
Patched in Version
No Fix
Severity Score
Low
CVE
2022-3830
The vulnerability has not been patched and the plugin is closed. You should uninstall and delete the plugin.

Uji Countdown

Plugin
Uji Countdown
Plugin Slug
uji-countdown
Vulnerability
Admin+ Stored XSS
Patched in Version
No Fix
Severity Score
Low
CVE
2022-3837
The vulnerability has not been patched and the plugin is closed. You should uninstall and delete the plugin.

Add Comments

Plugin
Add Comments
Plugin Slug
add-comments
Vulnerability
Admin+ Stored XSS
Patched in Version
No Fix
Severity Score
Low
CVE
2022-3909
The vulnerability has not been patched and the plugin is closed. You should uninstall and delete the plugin.

3DPrint

Plugin
3DPrint
Plugin Slug
3dprint
Vulnerability
Arbitrary File and Directory Deletion via CSRF
Patched in Version
No Fix
Severity Score
High
CVE
2022-3899
The vulnerability has not been patched. You should deactivate the plugin.

Clerk

Plugin
Clerk
Plugin Slug
clerkio
Vulnerability
Authentication Bypass and API Keys Disclosure
Patched in Version
No Fix
Severity Score
Low
CVE
2022-3907
The vulnerability has not been patched and the plugin is closed. You should uninstall and delete the plugin.

Photospace Gallery

Plugin
Photospace Gallery
Plugin Slug
photospace
Vulnerability
Subscriber+ Stored Cross-Site Scripting
Patched in Version
No Fix
Severity Score
Medium
CVE
2022-3991
The vulnerability has not been patched and the plugin is closed. You should uninstall and delete the plugin.

PostmagThemes Demo

Plugin
PostmagThemes Demo Import
Plugin Slug
postmagthemes-demo-import
Vulnerability
Admin+ Arbitrary File Upload
Patched in Version
No Fix
Severity Score
Medium
CVE
2022-1540
The vulnerability has not been patched and the plugin is closed. You should uninstall and delete the plugin.

WordPress Theme Vulnerabilities

In this section, the latest WordPress theme vulnerabilities have been disclosed. Each theme listing includes the type of vulnerability, the active installations, the version number if patched, and the severity rating.

Workreap – Freelance Marketplace and Directory

Theme
Workreap
Theme Slug
workreap
Vulnerability
Subscriber+ Private Message Disclosure via IDOR
Patched in Version
2.6.3
Severity Score
Medium
CVE
2022-3846
The vulnerability has been patched, so you should update to version 2.6.3.

Never worry about running a vulnerable plugin or theme again.

As you can see from this report, lots of new WordPress plugin and theme vulnerabilities are disclosed each week. We know it can be difficult to stay on top of every reported vulnerability disclosure, so the iThemes Security Pro plugin makes it easy to make sure your site isn’t running a theme, plugin, or WordPress core version with a known vulnerability.

Scans Your Website Twice a Day for Vulnerabilities

Your website’s plugins, themes, and WordPress core versions are checked against the WPScan Vulnerability Database for the latest vulnerability disclosures.

Automatically Updates if a Security Fix is Available

Paired with Version Management, iThemes Security will automatically update a plugin, theme, or WordPress core version if it has a vulnerability.

Emails You if Site Scan Detects a Vulnerability

You can receive an email report if your site is running vulnerable versions of a plugin, theme, or WordPress core. Customize the email addresses that receive scan results.

The Best WordPress Security Plugin to Secure & Protect WordPress Sites

WordPress currently powers over 40% of all websites, so it has become an easy target for hackers with malicious intent. The iThemes Security Pro plugin takes the guesswork out of WordPress security to make it easy to secure & protect your WordPress website. It’s like having a full-time security expert on staff who constantly monitors and protects your WordPress site for you.

Buy iThemes Security Pro


iThemes Team
iThemes Editorial Team

Each week, the team at iThemes team publishes new WordPress tutorials and resources, including the Weekly WordPress Vulnerability Report. Since 2008, iThemes has been dedicated to helping you build, maintain, and secure WordPress sites for yourself or for clients. Our mission? Make People’s Lives Awesome.

Share via:

  • Facebook
  • Twitter
  • LinkedIn
  • More
Other related posts
wordpress vulnerability report - security
WordPress Vulnerability Report – August 30, 2023
WordPress Vulnerability Report
WordPress Vulnerability Report – August 23, 2023
A computer riddled with security issue alerts. There is a large, orange shield with a slash in the middle of the screen. Surrounding it are a red target, a green skull and crossbones, an orange “bug”, a triangle with an explanation point in the middle and a gray gear.
WordPress Vulnerability Report – August 16, 2023
WordPress vulnerability report
WordPress Vulnerability Report – August 9, 2023

Get updates on new themes & plugins plus special discounts

About iThemes

  • Contact Us
  • Website Accessibility Statement
  • Sitemap

Resources

  • Blog
  • Documentation
  • WordPress Tutorials
  • Free WordPress Ebooks
  • Free Webinar Library
  • Free Upcoming Webinars
  • iThemes Training
  • Affiliates

Customers

  • Member Panel Login
  • Support
  • FAQs
  • Upgrade Policy
  • Licensing
  • Terms and Conditions
  • Refund Policy

Top Products

  • BackupBuddy
  • iThemes Security Pro
  • iThemes Sync
  • Restrict Content Pro
  • WPComplete
  • WordPress Plugins
  • Content Upgrades
  • WordPress Landing Page Plugin
  • BackupBuddy Stash

iThemes Media LLC Copyright © 2023 All rights reserved | Privacy Policy

A Liquid Web Brand © 2022 All Rights Reserved.

Get the Weekly WordPress Vulnerability Report

Vulnerable WordPress plugins and themes are the #1 reason WordPress sites get hacked, but keeping track of every new plugin and theme vulnerability is hard work. Get the weekly WordPress Vulnerability Report delivered right to your inbox to help keep your website secure.

Get the Report
Share via
Facebook
Twitter
LinkedIn
Mix
Email
Print
Copy Link
Powered by Social Snap
Copy link
CopyCopied
Powered by Social Snap

Get the Weekly WordPress Vulnerability Report

Vulnerable WordPress plugins and themes are the #1 reason WordPress sites get hacked, but keeping track of every new plugin and theme vulnerability is hard work. Get the weekly WordPress Vulnerability Report delivered right to your inbox to help keep your website secure.
No spam. Unsubscribe anytime.