WordPress Vulnerability Report

WordPress Vulnerability Report – September 27, 2023

Since last week, 48 total vulnerabilities have emerged in public disclosure. They may affect over three million WordPress sites. There are 39 plugin vulnerabilities with security patches, so run those updates! Additionally, there are nine plugin vulnerabilities with no patch available yet. If you use an unpatched plugin or theme, check their vendors' intentions and progress on a security release.

Dan Knauss

Since last week, 48 total vulnerabilities have emerged in public disclosure. They may affect over three million WordPress sites. There are 39 plugin vulnerabilities with security patches, so run those updates!

Additionally, there are nine plugin vulnerabilities with no patch available yet. If you use an unpatched plugin or theme, check their vendors’ intentions and progress on a security release. Suppose no patch is forthcoming or the vulnerable software has been marked “closed” and dropped from the official WordPress theme and plugin repositories. In that case, you should consider deactivation and removal in favor of alternative solutions.

WordPress Core Vulnerabilities — Patched

No new WordPress core vulnerabilities were disclosed this week.

WordPress core is very secure when it’s properly configured and maintained. Vulnerable plugins not updated by site owners are the most common vector for attacks on WordPress websites. Our weekly WordPress Vulnerability Report, powered by Patchstack, covers new vulnerabilities that have emerged in plugins, themes, and/or WordPress core since last week’s report. Our goal is to spread awareness of emerging security threats and help you decide what to do if you find vulnerable software on your website. For a deeper analysis of recent trends in WordPress vulnerabilities and threat vectors, see our 2022 Annual Vulnerability Report.

These reports are published every Wednesday and include all active vulnerabilities tracked by Patchstack as of Monday since the previous report. This leaves a 48-hour window for the newest emerging vulnerabilities to be patched before full public disclosure. iThemes Security Pro users have access to vulnerability alerts emerging within this window.

WordPress Plugin Vulnerabilities — Patched

In this section, you’ll find the most recently disclosed WordPress plugin vulnerabilities fixed with a new release from their authors and maintainers. Please apply the updates if you are affected!

These vulnerabilities have been disclosed and scored for their severity, thanks to our friends at Patchstack. Each plugin listing includes the type of vulnerability with its CVE number and CVSS severity rating with links to more technical details. You’ll also see the number of active sites using the plugin and the plugin version release that patches the vulnerability. We start with the most popular plugins, representing the largest target for attackers.

Ad Inserter

Plugin Slug:
ad-inserter
Installations:
300,000+
Vulnerability:
Sensitive Data Exposure
Patched in Version:
2.7.31
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.7.31.

Ad Inserter

Plugin Slug:
ad-inserter
Installations:
300,000+
Vulnerability:
Sensitive Data Exposure
Patched in Version:
2.7.31
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.7.31.

Table of Contents Plus

Plugin Slug:
table-of-contents-plus
Installations:
300,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2309
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2309.

WPvivid

Plugin Slug:
wpvivid-backuprestore
Installations:
300,000+
Vulnerability:
Arbitrary File Deletion
Patched in Version:
0.9.90
Severity Score:
High
The vulnerability has been patched, so you should update to version 0.9.90.

WPvivid

Plugin Slug:
wpvivid-backuprestore
Installations:
300,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
0.9.90
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 0.9.90.

iframe

Plugin:
iframe
Plugin Slug:
iframe
Installations:
100,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
4.7
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 4.7.

wpDiscuz

Plugin Slug:
wpdiscuz
Installations:
80,000+
Vulnerability:
SQL Injection
Patched in Version:
7.6.6
Severity Score:
Critical
The vulnerability has been patched, so you should update to version 7.6.6.

Media Library Assistant

Plugin Slug:
media-library-assistant
Installations:
70,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
3.11
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.11.

Connect Matomo (WP-Matomo, WP-Piwik)

Plugin Slug:
wp-piwik
Installations:
60,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.0.29
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.0.29.

Simple Membership

Plugin Slug:
simple-membership
Installations:
50,000+
Vulnerability:
Privilege Escalation
Patched in Version:
4.3.5
Severity Score:
High
The vulnerability has been patched, so you should update to version 4.3.5.

Simple Membership

Plugin Slug:
simple-membership
Installations:
50,000+
Vulnerability:
Privilege Escalation
Patched in Version:
4.3.5
Severity Score:
High
The vulnerability has been patched, so you should update to version 4.3.5.

Copy Anything to Clipboard

Plugin Slug:
copy-the-code
Installations:
10,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.6.5
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.6.5.

Statify

Plugin Slug:
extended-evaluation-for-statify
Installations:
10,000+
Vulnerability:
CSV Injection
Patched in Version:
2.6.4
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.6.4.

Modal Window

Plugin Slug:
modal-window
Installations:
10,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
5.3.6
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 5.3.6.

Options for Twenty Seventeen

Plugin Slug:
options-for-twenty-seventeen
Installations:
10,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.5.1
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.5.1.
Plugin Slug:
wp-mailto-links
Installations:
10,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
3.1.4
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.1.4.

Widget Responsive for Youtube

Plugin Slug:
youtube-widget-responsive
Installations:
10,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.6.2
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.6.2.

iPanorama 360 – WordPress Virtual Tour Builder

Plugin Slug:
ipanorama-360-virtual-tour-builder-lite
Installations:
7,000+
Vulnerability:
SQL Injection
Patched in Version:
1.8.0
Severity Score:
High
The vulnerability has been patched, so you should update to version 1.8.0.

Drag and Drop Multiple File Upload

Plugin Slug:
drag-and-drop-multiple-file-upload-for-woocommerce
Installations:
4,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.1.1
Severity Score:
High
The vulnerability has been patched, so you should update to version 1.1.1.

DoLogin Security

Plugin Slug:
dologin
Installations:
3,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
3.7
Severity Score:
High
The vulnerability has been patched, so you should update to version 3.7.

Import XML and RSS Feeds

Plugin Slug:
import-xml-feed
Installations:
3,000+
Vulnerability:
Remote Code Execution (RCE)
Patched in Version:
2.1.5
Severity Score:
Critical
The vulnerability has been patched, so you should update to version 2.1.5.

Import XML and RSS Feeds

Plugin Slug:
import-xml-feed
Installations:
3,000+
Vulnerability:
Arbitrary File Upload
Patched in Version:
2.1.4
Severity Score:
Critical
The vulnerability has been patched, so you should update to version 2.1.4.

Pretty Google Calendar

Plugin Slug:
pretty-google-calendar
Installations:
2,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.6.0
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.6.0.

WPSchoolPress

Plugin Slug:
wpschoolpress
Installations:
2,000+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
2.2.5
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.2.5.

Leaflet Map

Plugin Slug:
extensions-leaflet-map
Installations:
1,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
3.3.1
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.3.1.

User Avatar – Reloaded

Plugin Slug:
user-avatar-reloaded
Installations:
800+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.2.2
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.2.2.

Memberlite Shortcodes

Plugin Slug:
memberlite-shortcodes
Installations:
700+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.3.9
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.3.9.

Serial Codes Generator and Validator with WooCommerce Support

Plugin Slug:
serial-codes-generator-and-validator
Installations:
600+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.4.15
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.4.15.

User Activity Log Pro

Plugin Slug:
user-activity-log-pro
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.3.4
Severity Score:
High
The vulnerability has been patched, so you should update to version 2.3.4.

User Activity Log Pro

Plugin Slug:
user-activity-log-pro
Vulnerability:
Bypass Vulnerability
Patched in Version:
2.3.4
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.3.4.

WordPress Plugin Vulnerabilities — Unpatched

This section contains plugin vulnerabilities with no known fix. Until a patch is available, you are advised to deactivate the plugin, at minimum, immediately. If there is a high risk of active exploits or the plugin remains unpatched for weeks, you are advised to delete the plugin. You should also delete persistently unpatched plugins the WordPress.org repository has locked and marked “Closed” so they can no longer be downloaded and installed.

Active Directory Integration / LDAP Integration

Plugin Slug:
ldap-login-for-intranet-sites
Installations:
5,000+
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Low
The vulnerability has not been patched. You should deactivate the plugin.

WP Job Portal

Plugin Slug:
wp-job-portal
Installations:
3,000+
Vulnerability:
SQL Injection
Patched in Version:
No Fix
Severity Score:
Critical
The vulnerability has not been patched. You should deactivate the plugin.

Staff / Employee Business Directory for Active Directory

Plugin Slug:
ldap-ad-staff-employee-directory-search
Installations:
10+
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Low
The vulnerability has not been patched. You should deactivate the plugin.

Easy Registration Forms

Plugin Slug:
easy-registration-forms
Vulnerability:
Sensitive Data Exposure
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched and the plugin is closed. You should uninstall and delete the plugin.

Contact Form by FormGet

Plugin Slug:
formget-contact-form
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched and the plugin is closed. You should uninstall and delete the plugin.

Super Store Finder

Plugin Slug:
superstorefinder-wp
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Vrm 360 3D Model Viewer

Plugin Slug:
vrm360
Vulnerability:
Sensitive Data Exposure
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched and the plugin is closed. You should uninstall and delete the plugin.

Charts

Plugin:
wp-charts
Plugin Slug:
wp-charts
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched and the plugin is closed. You should uninstall and delete the plugin.

WordPress Theme Vulnerabilities

In this section, you’ll find the latest WordPress theme vulnerabilities to be disclosed. You’ll see the same information we provided above for vulnerable plugins, and the same advice applies. If a security update exists, install it immediately. If a vulnerability remains unpatched in a theme you are actively using, you must find an alternative theme. Deactivate and delete persistently unpatched themes and those marked “Closed” in the WordPress.org theme repository. If you have a vulnerable theme installed that you are not actively using, delete it.

No new WordPress theme vulnerabilities were disclosed this week.

Solid Security is part of Solid Suite — The best foundation for WordPress websites.

Every WordPress site needs security, backups, and management tools. That’s Solid Suite — an integrated bundle of three plugins: Solid Security, Solid Backups, and Solid Central. You also get access to Solid Academy’s learning resources for WordPress professionals. Build your next WordPress website on a solid foundation with Solid Suite!

Get Solid Security