Menu
iThemes
WordPress Security, Backups & Maintenance
  • Products
    • iThemes Security Pro
    • BackupBuddy
    • iThemes Sync
    • Why buy from iThemes?
  • Bundles
    • Essentials Bundle
    • Solid Foundations
    • Customer Spotlights
  • Resources
    • Blog
    • WordPress 101 Tutorials
    • WordPress Ebooks
    • Weekly WordPress Vulnerability Report
    • The Ultimate Guide to Starting a Web Design Business
  • Training
    • Upcoming Webinars
    • Free Webinar Library
    • Premium Courses
    • Become a Member
    • Member Login
  • Support
    • Documentation
    • Get Help
    • Product Updates
    • Upgrade Policy
    • Contact
    • Our Mission: Make People’s Lives Awesome
  • Log In
WordPress News and Updates from iThemes
Categories
  • Product Updates
  • WordPress Backup
  • WordPress Block Editor
  • WordPress Ecommerce
  • WordPress for Freelancers
  • WordPress Security
  • WordPress Tutorials
  • WPprosper

WordPress Vulnerability Report – September 6, 2023

Written by Dan Knauss on September 6, 2023

Last Updated on September 6, 2023

Since last week, 95 total vulnerabilities emerged in public disclosure. They may affect over two million WordPress sites. There are 32 plugin vulnerabilities with security patches, so run those updates!

Additionally, there are 60 plugin vulnerabilities and three theme vulnerabilities with no patch available yet. If you use an unpatched plugin or theme, check their vendors’ intentions and progress on a security release. Suppose no patch is forthcoming or the vulnerable software has been marked “closed” and dropped from the official WordPress theme and plugin repositories. In that case, you should consider deactivation and removal in favor of alternative solutions.

FREE ONLINE TRAINING EVENT SEPT 6TH @ 1:00 P.M. (CT)

Discover essential best practices for safeguarding your WordPress website through proactive security measures. Join WordPress security expert Thomas Raef as he explains the art and science of WordPress security, focusing on three key dimensions: hosting, WordPress configurations, and user management. You’ll also learn how Solid Security equips users with tools that diminish hacking risks, focusing on safeguarding plugins, themes, and user accounts.

Register now, FREE!

WordPress Core News

“Lionel” was released on August 8, 2023. This release of WordPress was built to help you “create beautiful and compelling websites more efficiently than ever.” See what’s new in WordPress 6.3.

Don’t forget to fully back up your website before installing WordPress 6.3. BackupBuddy, the industry-leading data protection and recovery solution for WordPress, will help you build a strong backup strategy to manage all updates. Embrace the enhanced content creation experience of WordPress 6.3 with confidence — and a backup copy of your website safely stored on a remote server.


WordPress Core Vulnerabilities — Patched

  • No new WordPress core vulnerabilities were disclosed this week.

WordPress core is very secure when it’s properly configured and maintained. Vulnerable plugins not updated by site owners are the most common vector for attacks on WordPress websites. Our weekly WordPress Vulnerability Report, powered by Patchstack, covers new vulnerabilities that have emerged in plugins, themes, and/or WordPress core since last week’s report. Our goal is to spread awareness of emerging security threats and help you decide what to do if you find vulnerable software on your website. For a deeper analysis of recent trends in WordPress vulnerabilities and threat vectors, see our 2022 Annual Vulnerability Report.

Contents of the September 6, 2023 Report
  1. FREE ONLINE TRAINING EVENT SEPT 6TH @ 1:00 P.M. (CT)
  2. WordPress Core News
  3. WordPress Core Vulnerabilities – Patched
  4. WordPress Plugin Vulnerabilities – Patched
    1. GTranslate
    2. Forminator
    3. Metform Elementor Contact Form Builder
    4. Social Media & Share Icons
    5. GiveWP
    6. UserFeedback Lite
    7. Slimstat Analytics
    8. Email Encoder
    9. Folders
    10. Popup Box
    11. GS Logo Slider
    12. WP Project Manager
    13. WP Project Manager
    14. WP Super Minify
    15. Post to Google My Business (Google Business Profile)
    16. SureCart
    17. HollerBox
    18. Order Tracking Pro
    19. Order Tracking Pro
    20. Leyka
    21. WP Search Analytics
    22. Sitekit
    23. Prevent files / folders access
    24. WP Pipes
    25. Photo Gallery Slideshow & Masonry Tiled Gallery
    26. RSVPMaker
    27. AffiliateWP
    28. All-in-One WP Migration Box Extension
    29. All-in-One WP Migration Dropbox Extension
    30. All-in-One WP Migration Google Drive Extension
    31. All-in-One WP Migration OneDrive Extension
    32. Happy Elementor Addons Pro
  5. WordPress Plugin Vulnerabilities – Unpatched
    1. PowerPress Podcasting plugin by Blubrry
    2. WooCommerce Conversion Tracking
    3. Ultimate Addons for Contact Form 7
    4. Directorist
    5. Export Import Menus
    6. Legal Pages
    7. URL Shortener by MyThemeShop
    8. Texty
    9. weMail
    10. Better Elementor Addons
    11. Easy Coming Soon
    12. Login and Logout Redirect
    13. authLdap
    14. authLdap
    15. LuckyWP Scripts Control
    16. Multi-column Tag Map
    17. Responsive Gallery Grid
    18. Social Share Boost
    19. Unlimited Elementor Inner Sections By BoomDevs
    20. weDocs – Knowledgebase and Documentation Plugin for WordPress
    21. MakeStories (for Google Web Stories)
    22. MyCryptoCheckout
    23. Remove/hide Author, Date, Category Like Entry-Meta
    24. Surfer
    25. Leadster
    26. Ovic Product Bundle
    27. Pricing Deals for WooCommercePricing Deals for WooCommerce
    28. WP users media
    29. Migration Plugin DB & Files – WP Synchro
    30. Live News
    31. Realbig
    32. TelSender
    33. WooCommerce PensoPay
    34. Hide admin notices – Admin Notification Center
    35. WRC Pricing Tables
    36. Bulk NoIndex & NoFollow Toolkit
    37. Exclusive Team for Elementor
    38. Goods Catalog
    39. Olive One Click Demo Import
    40. Stock Quotes List
    41. Product Category Showcase for WooCommerce
    42. WiserNotify Social Proof
    43. WP Bannerize Pro
    44. Tilda Publishing
    45. Easy Newsletter Signups
    46. Snap Pixel
    47. Woocommerce Support System
    48. Woocommerce Support System
    49. Localize Remote Images
    50. Bridge Core
    51. WordPress CTA
    52. Font Awesome 4 Menus
    53. GuruWalk Affiliates
    54. Maintenance Switch
    55. Sermon'e – Sermons Online
    56. SIS Handball
    57. Smarty for WordPress
    58. Use Memcached
    59. WP-dTree
    60. WP-dTree
  6. WordPress Theme Vulnerabilities
    1. Attorney
    2. Arya Multipurpose Pro
    3. Everest News Pro
  7. The Best WordPress Security Plugin to Secure & Protect WordPress Sites

These reports are published every Wednesday and include all active vulnerabilities tracked by Patchstack as of Monday since the previous report. This leaves a 48-hour window for the newest emerging vulnerabilities to be patched before full public disclosure. iThemes Security Pro users have access to vulnerability alerts emerging within this window.

Get the weekly WordPress Vulnerability Report delivered to your inbox each Wednesday.
Subscribe now

WordPress Plugin Vulnerabilities — Patched

In this section, you’ll find the most recently disclosed WordPress plugin vulnerabilities fixed with a new release from their authors and maintainers. Please apply the updates if you are affected!

These vulnerabilities have been disclosed and scored for their severity, thanks to our friends at Patchstack. Each plugin listing includes the type of vulnerability with its CVE number and CVSS severity rating with links to more technical details. You’ll also see the number of active sites using the plugin and the plugin version release that patches the vulnerability. We start with the most popular plugins, representing the largest target for attackers.

GTranslate

Product image for Translate WordPress with GTranslate.
Plugin
Translate WordPress with GTranslate
Plugin Slug
gtranslate
Installations
500,000+
Vulnerability
Cross Site Scripting (XSS)
Patched in Version
3.0.4
Severity Score
Medium
The vulnerability has been patched, so you should update to version 3.0.4.

Forminator

Product image for Forminator – Contact Form, Payment Form & Custom Form Builder.
Plugin
Forminator – Contact Form, Payment Form & Custom Form Builder
Plugin Slug
forminator
Installations
400,000+
Vulnerability
Arbitrary File Upload
Patched in Version
1.25.0
Severity Score
Critical
CVE
2023-4596
The vulnerability has been patched, so you should update to version 1.25.0.

Metform Elementor Contact Form Builder

Product image for Metform Elementor Contact Form Builder.
Plugin
Metform Elementor Contact Form Builder
Plugin Slug
metform
Installations
200,000+
Vulnerability
Sensitive Data Exposure
Patched in Version
3.3.2
Severity Score
Medium
CVE
2023-0689
The vulnerability has been patched, so you should update to version 3.3.2.

Social Media & Share Icons

Product image for Social Media Share Buttons & Social Sharing Icons.
Plugin
Social Media Share Buttons & Social Sharing Icons
Plugin Slug
ultimate-social-media-icons
Installations
200,000+
Vulnerability
Cross Site Scripting (XSS)
Patched in Version
2.8.4
Severity Score
High
CVE
2023-41238
The vulnerability has been patched, so you should update to version 2.8.4.

GiveWP

Product image for GiveWP – Donation Plugin and Fundraising Platform.
Plugin
GiveWP – Donation Plugin and Fundraising Platform
Plugin Slug
give
Installations
100,000+
Vulnerability
Privilege Escalation
Patched in Version
2.33.1
Severity Score
High
CVE
2023-41665
The vulnerability has been patched, so you should update to version 2.33.1.

UserFeedback Lite

Product image for User Feedback – Create Interactive Feedback Form, User Surveys, and Polls in Seconds.
Plugin
User Feedback – Create Interactive Feedback Form, User Surveys, and Polls in Seconds
Plugin Slug
userfeedback-lite
Installations
100,000+
Vulnerability
Cross Site Scripting (XSS)
Patched in Version
1.0.8
Severity Score
High
CVE
2023-39308
The vulnerability has been patched, so you should update to version 1.0.8.

Slimstat Analytics

Product image for Slimstat Analytics.
Plugin
Slimstat Analytics
Plugin Slug
wp-slimstat
Installations
100,000+
Vulnerability
Cross Site Scripting (XSS)
Patched in Version
5.0.10
Severity Score
Medium
CVE
2023-4597
The vulnerability has been patched, so you should update to version 5.0.10.

Email Encoder

Product image for Email Encoder – Protect Email Addresses and Phone Numbers.
Plugin
Email Encoder – Protect Email Addresses and Phone Numbers
Plugin Slug
email-encoder-bundle
Installations
80,000+
Vulnerability
Cross Site Scripting (XSS)
Patched in Version
2.1.8
Severity Score
Medium
CVE
2023-4599
The vulnerability has been patched, so you should update to version 2.1.8.

Folders

Product image for Folders – Unlimited Folders to Organize Media Library Folder, Pages, Posts, File Manager.
Plugin
Folders – Unlimited Folders to Organize Media Library Folder, Pages, Posts, File Manager
Plugin Slug
folders
Installations
60,000+
Vulnerability
Arbitrary File Upload
Patched in Version
2.9.3
Severity Score
Critical
CVE
2023-40204
The vulnerability has been patched, so you should update to version 2.9.3.

Popup Box

Product image for Popup box.
Plugin
Popup box
Plugin Slug
ays-popup-box
Installations
20,000+
Vulnerability
Cross Site Scripting (XSS)
Patched in Version
3.7.2
Severity Score
Medium
The vulnerability has been patched, so you should update to version 3.7.2.

GS Logo Slider

Product image for Logo Slider – Logo Showcase, Logo Carousel, Logo Gallery and Client Logo Presentation.
Plugin
Logo Slider – Logo Showcase, Logo Carousel, Logo Gallery and Client Logo Presentation
Plugin Slug
gs-logo-slider
Installations
20,000+
Vulnerability
Cross Site Request Forgery (CSRF)
Patched in Version
3.4.3
Severity Score
Medium
CVE
2022-47150
The vulnerability has been patched, so you should update to version 3.4.3.

WP Project Manager

Product image for WP Project Manager – Task, team, and project management plugin featuring kanban board and gantt charts.
Plugin
WP Project Manager – Task, team, and project management plugin featuring kanban board and gantt charts
Plugin Slug
wedevs-project-manager
Installations
10,000+
Vulnerability
Cross Site Request Forgery (CSRF)
Patched in Version
2.6.1
Severity Score
Medium
CVE
2022-47150
The vulnerability has been patched, so you should update to version 2.6.1.

WP Project Manager

Product image for WP Project Manager – Task, team, and project management plugin featuring kanban board and gantt charts.
Plugin
WP Project Manager – Task, team, and project management plugin featuring kanban board and gantt charts
Plugin Slug
wedevs-project-manager
Installations
10,000+
Vulnerability
SQL Injection
Patched in Version
2.6.1
Severity Score
High
CVE
2023-34383
The vulnerability has been patched, so you should update to version 2.6.1.

WP Super Minify

Product image for WP Super Minify.
Plugin
WP Super Minify
Plugin Slug
wp-super-minify
Installations
10,000+
Vulnerability
Cross Site Request Forgery (CSRF)
Patched in Version
1.6
Severity Score
Medium
CVE
2023-27615
The vulnerability has been patched, so you should update to version 1.6.

Post to Google My Business (Google Business Profile)

Product image for Post to Google My Business (Google Business Profile).
Plugin
Post to Google My Business (Google Business Profile)
Plugin Slug
post-to-google-my-business
Installations
9,000+
Vulnerability
Broken Access Control
Patched in Version
3.1.15
Severity Score
Medium
CVE
2023-41689
The vulnerability has been patched, so you should update to version 3.1.15.

SureCart

Product image for WordPress Ecommerce For Creating Fast Online Stores – By SureCart.
Plugin
WordPress Ecommerce For Creating Fast Online Stores – By SureCart
Plugin Slug
surecart
Installations
8,000+
Vulnerability
Cross Site Scripting (XSS)
Patched in Version
2.5.1
Severity Score
Medium
CVE
2023-41241
The vulnerability has been patched, so you should update to version 2.5.1.

HollerBox

Product image for Fast & Effective Popups & Lead-Generation for WordPress – HollerBox.
Plugin
Fast & Effective Popups & Lead-Generation for WordPress – HollerBox
Plugin Slug
holler-box
Installations
5,000+
Vulnerability
Cross Site Scripting (XSS)
Patched in Version
2.3.3
Severity Score
Medium
CVE
2023-41657
The vulnerability has been patched, so you should update to version 2.3.3.

Order Tracking Pro

Product image for Order Tracking – WordPress Status Tracking Plugin.
Plugin
Order Tracking – WordPress Status Tracking Plugin
Plugin Slug
order-tracking
Installations
4,000+
Vulnerability
Cross Site Scripting (XSS)
Patched in Version
3.3.7
Severity Score
Medium
CVE
2023-4500
The vulnerability has been patched, so you should update to version 3.3.7.

Order Tracking Pro

Product image for Order Tracking – WordPress Status Tracking Plugin.
Plugin
Order Tracking – WordPress Status Tracking Plugin
Plugin Slug
order-tracking
Installations
4,000+
Vulnerability
Cross Site Scripting (XSS)
Patched in Version
3.3.7
Severity Score
High
CVE
2023-4471
The vulnerability has been patched, so you should update to version 3.3.7.

Leyka

Product image for Leyka.
Plugin
Leyka
Plugin Slug
leyka
Installations
2,000+
Vulnerability
Cross Site Scripting (XSS)
Patched in Version
3.30.3
Severity Score
Medium
CVE
2023-2995
The vulnerability has been patched, so you should update to version 3.30.3.

WP Search Analytics

Product image for WP Search Analytics.
Plugin
WP Search Analytics
Plugin Slug
search-analytics
Installations
2,000+
Vulnerability
Cross Site Scripting (XSS)
Patched in Version
1.4.8
Severity Score
High
CVE
2023-30471
The vulnerability has been patched, so you should update to version 1.4.8.

Sitekit

Product image for Sitekit.
Plugin
Sitekit
Plugin Slug
sitekit
Installations
2,000+
Vulnerability
Cross Site Scripting (XSS)
Patched in Version
1.4
Severity Score
Medium
CVE
2023-27628
The vulnerability has been patched, so you should update to version 1.4.

Prevent files / folders access

Product image for Prevent files / folders access.
Plugin
Prevent files / folders access
Plugin Slug
prevent-file-access
Installations
1,000+
Vulnerability
Arbitrary File Upload
Patched in Version
2.5.2
Severity Score
High
CVE
2023-4238
The vulnerability has been patched, so you should update to version 2.5.2.

WP Pipes

Product image for WP Pipes.
Plugin
WP Pipes
Plugin Slug
wp-pipes
Installations
1,000+
Vulnerability
Cross Site Request Forgery (CSRF)
Patched in Version
1.4.1
Severity Score
Medium
CVE
2023-40009
The vulnerability has been patched, so you should update to version 1.4.1.

Photo Gallery Slideshow & Masonry Tiled Gallery

Product image for Photo Gallery Slideshow & Masonry Tiled Gallery.
Plugin
Photo Gallery Slideshow & Masonry Tiled Gallery
Plugin Slug
wp-responsive-photo-gallery
Installations
1,000+
Vulnerability
Cross Site Scripting (XSS)
Patched in Version
1.0.14
Severity Score
High
CVE
2023-41658
The vulnerability has been patched, so you should update to version 1.0.14.

RSVPMaker

Product image for RSVPMaker.
Plugin
RSVPMaker
Plugin Slug
rsvpmaker
Installations
400+
Vulnerability
SQL Injection
Patched in Version
10.6.7
Severity Score
High
CVE
2023-41652
The vulnerability has been patched, so you should update to version 10.6.7.

AffiliateWP

Plugin
AffiliateWP
Plugin Slug
affiliatewp
Vulnerability
Broken Access Control
Patched in Version
2.14.1
Severity Score
Medium
CVE
2023-4600
The vulnerability has been patched, so you should update to version 2.14.1.

All-in-One WP Migration Box Extension

Plugin
All-in-One WP Migration Box Extension
Plugin Slug
all-in-one-wp-migration-box-extension
Vulnerability
Broken Access Control
Patched in Version
1.54
Severity Score
High
CVE
2023-40004
The vulnerability has been patched, so you should update to version 1.54.

All-in-One WP Migration Dropbox Extension

Plugin
All-in-One WP Migration Dropbox Extension
Plugin Slug
all-in-one-wp-migration-dropbox-extension
Vulnerability
Broken Access Control
Patched in Version
3.76
Severity Score
High
CVE
2023-40004
The vulnerability has been patched, so you should update to version 3.76.

All-in-One WP Migration Google Drive Extension

Plugin
All-in-One WP Migration Google Drive Extension
Plugin Slug
all-in-one-wp-migration-gdrive-extension
Vulnerability
Broken Access Control
Patched in Version
2.80
Severity Score
High
CVE
2023-40004
The vulnerability has been patched, so you should update to version 2.80.

All-in-One WP Migration OneDrive Extension

Plugin
All-in-One WP Migration OneDrive Extension
Plugin Slug
all-in-one-wp-migration-onedrive-extension
Vulnerability
Broken Access Control
Patched in Version
1.67
Severity Score
High
CVE
2023-40004
The vulnerability has been patched, so you should update to version 1.67.

Happy Elementor Addons Pro

Plugin
Happy Elementor Addons Pro
Plugin Slug
happy-elementor-addons-pro
Vulnerability
Cross Site Scripting (XSS)
Patched in Version
2.8.1
Severity Score
High
CVE
2023-41236
The vulnerability has been patched, so you should update to version 2.8.1.

WordPress Plugin Vulnerabilities — Unpatched

This section contains plugin vulnerabilities with no known fix. Until a patch is available, you are advised to deactivate the plugin, at minimum, immediately. If there is a high risk of active exploits or the plugin remains unpatched for weeks, you are advised to delete the plugin. You should also delete persistently unpatched plugins the WordPress.org repository has locked and marked “Closed” so they can no longer be downloaded and installed.

PowerPress Podcasting plugin by Blubrry

Product image for PowerPress Podcasting plugin by Blubrry.
Plugin
PowerPress Podcasting plugin by Blubrry
Plugin Slug
powerpress
Installations
40,000+
Vulnerability
Server Side Request Forgery (SSRF)
Patched in Version
No Fix
Severity Score
Medium
CVE
2023-41239
The vulnerability has not been patched. You should deactivate the plugin.

WooCommerce Conversion Tracking

Product image for WooCommerce Conversion Tracking.
Plugin
WooCommerce Conversion Tracking
Plugin Slug
woocommerce-conversion-tracking
Installations
40,000+
Vulnerability
Cross Site Request Forgery (CSRF)
Patched in Version
No Fix
Severity Score
Medium
CVE
2022-47150
The vulnerability has not been patched. You should deactivate the plugin.

Ultimate Addons for Contact Form 7

Product image for Ultimate Addons for Contact Form 7.
Plugin
Ultimate Addons for Contact Form 7
Plugin Slug
ultimate-addons-for-contact-form-7
Installations
20,000+
Vulnerability
Cross Site Scripting (XSS)
Patched in Version
No Fix
Severity Score
High
CVE
2023-30493
The vulnerability has not been patched. You should deactivate the plugin.

Directorist

Product image for Directorist – WordPress Business Directory Plugin with Classified Ads Listings.
Plugin
Directorist – WordPress Business Directory Plugin with Classified Ads Listings
Plugin Slug
directorist
Installations
10,000+
Vulnerability
Broken Access Control
Patched in Version
No Fix
Severity Score
Medium
CVE
2022-47150
The vulnerability has not been patched. You should deactivate the plugin.

Export Import Menus

Product image for Export Import Menus.
Plugin
Export Import Menus
Plugin Slug
export-import-menus
Installations
10,000+
Vulnerability
Arbitrary File Upload
Patched in Version
No Fix
Severity Score
Critical
CVE
2023-34385
The vulnerability has not been patched. You should deactivate the plugin.

Legal Pages

Product image for Legal Pages – Privacy Policy, Terms & Conditions, GDPR, CCPA, and Cookie Notice Generator.
Plugin
Legal Pages – Privacy Policy, Terms & Conditions, GDPR, CCPA, and Cookie Notice Generator
Plugin Slug
legal-pages
Installations
10,000+
Vulnerability
Cross Site Request Forgery (CSRF)
Patched in Version
No Fix
Severity Score
Medium
CVE
2022-47150
The vulnerability has not been patched. You should deactivate the plugin.

URL Shortener by MyThemeShop

Product image for URL Shortener by MyThemeShop.
Plugin
URL Shortener by MyThemeShop
Plugin Slug
mts-url-shortener
Installations
10,000+
Vulnerability
Cross Site Scripting (XSS)
Patched in Version
No Fix
Severity Score
High
CVE
2023-30472
The vulnerability has not been patched. You should deactivate the plugin.

Texty

Product image for Texty – SMS Notification for WordPress, WooCommerce, Dokan and more.
Plugin
Texty – SMS Notification for WordPress, WooCommerce, Dokan and more
Plugin Slug
texty
Installations
10,000+
Vulnerability
Cross Site Request Forgery (CSRF)
Patched in Version
No Fix
Severity Score
Medium
CVE
2022-47150
The vulnerability has not been patched. You should deactivate the plugin.

weMail

Product image for weMail – Email Marketing, Newsletter, Optin Forms, Subscribers WordPress Plugin.
Plugin
weMail – Email Marketing, Newsletter, Optin Forms, Subscribers WordPress Plugin
Plugin Slug
wemail
Installations
10,000+
Vulnerability
Cross Site Request Forgery (CSRF)
Patched in Version
No Fix
Severity Score
Medium
CVE
2022-47150
The vulnerability has not been patched. You should deactivate the plugin.

Better Elementor Addons

Product image for Better Elementor Addons.
Plugin
Better Elementor Addons
Plugin Slug
better-elementor-addons
Installations
7,000+
Vulnerability
Broken Access Control
Patched in Version
No Fix
Severity Score
Medium
CVE
2023-41656
The vulnerability has not been patched. You should deactivate the plugin.

Easy Coming Soon

Product image for Easy Coming Soon.
Plugin
Easy Coming Soon
Plugin Slug
easy-coming-soon
Installations
7,000+
Vulnerability
Cross Site Scripting (XSS)
Patched in Version
No Fix
Severity Score
Medium
CVE
2023-25483
The vulnerability has not been patched. You should deactivate the plugin.

Login and Logout Redirect

Product image for Login and Logout Redirect.
Plugin
Login and Logout Redirect
Plugin Slug
login-and-logout-redirect
Installations
7,000+
Vulnerability
Open Redirection
Patched in Version
No Fix
Severity Score
Medium
CVE
2023-41648
The vulnerability has not been patched. You should deactivate the plugin.

authLdap

Plugin
authLdap
Plugin Slug
authldap
Installations
6,000+
Vulnerability
Cross Site Scripting (XSS)
Patched in Version
No Fix
Severity Score
Medium
CVE
2023-41655
The vulnerability has not been patched. You should deactivate the plugin.

authLdap

Plugin
authLdap
Plugin Slug
authldap
Installations
6,000+
Vulnerability
Cross Site Request Forgery (CSRF)
Patched in Version
No Fix
Severity Score
Medium
CVE
2023-41654
The vulnerability has not been patched. You should deactivate the plugin.

LuckyWP Scripts Control

Product image for LuckyWP Scripts Control.
Plugin
LuckyWP Scripts Control
Plugin Slug
luckywp-scripts-control
Installations
6,000+
Vulnerability
Broken Access Control
Patched in Version
No Fix
Severity Score
Medium
CVE
2023-29239
The vulnerability has not been patched. You should deactivate the plugin.

Multi-column Tag Map

Product image for Multi-column Tag Map.
Plugin
Multi-column Tag Map
Plugin Slug
multi-column-tag-map
Installations
6,000+
Vulnerability
Broken Access Control
Patched in Version
No Fix
Severity Score
Medium
CVE
2023-41651
The vulnerability has not been patched. You should deactivate the plugin.

Responsive Gallery Grid

Product image for Responsive Gallery Grid.
Plugin
Responsive Gallery Grid
Plugin Slug
responsive-gallery-grid
Installations
6,000+
Vulnerability
Cross Site Request Forgery (CSRF)
Patched in Version
No Fix
Severity Score
Medium
CVE
2023-41659
The vulnerability has not been patched. You should deactivate the plugin.

Social Share Boost

Plugin
Social Share Boost
Plugin Slug
social-share-boost
Installations
6,000+
Vulnerability
Cross Site Request Forgery (CSRF)
Patched in Version
No Fix
Severity Score
Medium
CVE
2023-25033
The vulnerability has not been patched. You should deactivate the plugin.

Unlimited Elementor Inner Sections By BoomDevs

Product image for Unlimited Elementor Inner Sections By BoomDevs.
Plugin
Unlimited Elementor Inner Sections By BoomDevs
Plugin Slug
unlimited-elementor-inner-sections-by-boomdevs
Installations
6,000+
Vulnerability
Cross Site Request Forgery (CSRF)
Patched in Version
No Fix
Severity Score
Medium
CVE
2022-47150
The vulnerability has not been patched. You should deactivate the plugin.

weDocs – Knowledgebase and Documentation Plugin for WordPress

Product image for weDocs – Knowledgebase and Documentation Plugin for WordPress.
Plugin
weDocs – Knowledgebase and Documentation Plugin for WordPress
Plugin Slug
wedocs
Installations
6,000+
Vulnerability
Cross Site Request Forgery (CSRF)
Patched in Version
No Fix
Severity Score
Medium
CVE
2022-47150
The vulnerability has not been patched. You should deactivate the plugin.

MakeStories (for Google Web Stories)

Product image for MakeStories (for Google Web Stories).
Plugin
MakeStories (for Google Web Stories)
Plugin Slug
makestories-helper
Installations
5,000+
Vulnerability
Cross Site Request Forgery (CSRF)
Patched in Version
No Fix
Severity Score
Medium
CVE
2023-27448
The vulnerability has not been patched. You should deactivate the plugin.

MyCryptoCheckout

Product image for MyCryptoCheckout – Bitcoin, Ethereum, and 100+ altcoins for WooCommerce.
Plugin
MyCryptoCheckout – Bitcoin, Ethereum, and 100+ altcoins for WooCommerce
Plugin Slug
mycryptocheckout
Installations
5,000+
Vulnerability
Cross Site Request Forgery (CSRF)
Patched in Version
No Fix
Severity Score
Medium
CVE
2023-41693
The vulnerability has not been patched. You should deactivate the plugin.

Remove/hide Author, Date, Category Like Entry-Meta

Product image for Remove/hide Author, Date, Category Like Entry-Meta.
Plugin
Remove/hide Author, Date, Category Like Entry-Meta
Plugin Slug
removehide-author-date-category-like-entry-meta
Installations
5,000+
Vulnerability
Cross Site Request Forgery (CSRF)
Patched in Version
No Fix
Severity Score
Medium
CVE
2023-41650
The vulnerability has not been patched. You should deactivate the plugin.

Surfer

Product image for Surfer – WordPress Plugin.
Plugin
Surfer – WordPress Plugin
Plugin Slug
surferseo
Installations
5,000+
Vulnerability
Broken Access Control
Patched in Version
No Fix
Severity Score
High
CVE
2023-35037
The vulnerability has not been patched. You should deactivate the plugin.

Leadster

Product image for Leadster.
Plugin
Leadster
Plugin Slug
leadster-marketing-conversacional
Installations
4,000+
Vulnerability
Cross Site Request Forgery (CSRF)
Patched in Version
No Fix
Severity Score
Medium
CVE
2023-41668
The vulnerability has not been patched. You should deactivate the plugin.

Ovic Product Bundle

Product image for Ovic Product Bundle.
Plugin
Ovic Product Bundle
Plugin Slug
ovic-product-bundle
Installations
4,000+
Vulnerability
Broken Access Control
Patched in Version
No Fix
Severity Score
Medium
CVE
2023-41649
The vulnerability has not been patched. You should deactivate the plugin.

Pricing Deals for WooCommercePricing Deals for WooCommerce

Plugin
Pricing Deals for WooCommerce
Plugin Slug
pricing-deals-for-woocommerce
Installations
4,000+
Vulnerability
Broken Access Control
Patched in Version
No Fix
Severity Score
Medium
CVE
2023-41240
The vulnerability has not been patched. You should deactivate the plugin.

WP users media

Plugin
WP Users Media
Plugin Slug
wp-users-media
Installations
4,000+
Vulnerability
Broken Access Control
Patched in Version
No Fix
Severity Score
Medium
CVE
2023-27428
The vulnerability has not been patched. You should deactivate the plugin.

Migration Plugin DB & Files – WP Synchro

Product image for WP Synchro – WordPress Migration Plugin for Database & Files.
Plugin
WP Synchro – WordPress Migration Plugin for Database & Files
Plugin Slug
wpsynchro
Installations
4,000+
Vulnerability
Cross Site Request Forgery (CSRF)
Patched in Version
No Fix
Severity Score
Medium
CVE
2023-41660
The vulnerability has not been patched. You should deactivate the plugin.

Live News

Product image for Live News.
Plugin
Live News
Plugin Slug
live-news-lite
Installations
3,000+
Vulnerability
Cross Site Request Forgery (CSRF)
Patched in Version
No Fix
Severity Score
Medium
CVE
2023-41669
The vulnerability has not been patched. You should deactivate the plugin.

Realbig

Plugin
Realbig For WordPress
Plugin Slug
realbig-media
Installations
3,000+
Vulnerability
Cross Site Request Forgery (CSRF)
Patched in Version
No Fix
Severity Score
Medium
CVE
2023-41694
The vulnerability has not been patched. You should deactivate the plugin.

TelSender

Product image for TelSender – ?ontact form 7, Events, Wpforms  and wooccommerce to telegram bot.
Plugin
TelSender – ?ontact form 7, Events, Wpforms and wooccommerce to telegram bot
Plugin Slug
telsender
Installations
3,000+
Vulnerability
Broken Access Control
Patched in Version
No Fix
Severity Score
Medium
CVE
2023-41683
The vulnerability has not been patched. You should deactivate the plugin.

WooCommerce PensoPay

Plugin
WooCommerce PensoPay
Plugin Slug
woo-pensopay
Installations
3,000+
Vulnerability
Cross Site Scripting (XSS)
Patched in Version
No Fix
Severity Score
High
CVE
2023-41691
The vulnerability has not been patched. You should deactivate the plugin.

Hide admin notices – Admin Notification Center

Plugin
Hide admin notices – Admin Notification Center
Plugin Slug
wp-admin-notification-center
Installations
2,000+
Vulnerability
Cross Site Request Forgery (CSRF)
Patched in Version
No Fix
Severity Score
Medium
CVE
2023-41672
The vulnerability has not been patched. You should deactivate the plugin.

WRC Pricing Tables

Product image for WRC Pricing Tables – WordPress Responsive CSS3 Pricing Tables.
Plugin
WRC Pricing Tables – WordPress Responsive CSS3 Pricing Tables
Plugin Slug
wrc-pricing-tables
Installations
2,000+
Vulnerability
Broken Access Control
Patched in Version
No Fix
Severity Score
Medium
CVE
2023-32293
The vulnerability has not been patched. You should deactivate the plugin.

Bulk NoIndex & NoFollow Toolkit

Plugin
Bulk NoIndex & NoFollow Toolkit
Plugin Slug
bulk-noindex-nofollow-toolkit-by-mad-fish
Installations
1,000+
Vulnerability
Broken Access Control
Patched in Version
No Fix
Severity Score
Medium
CVE
2023-41688
The vulnerability has not been patched. You should deactivate the plugin.

Exclusive Team for Elementor

Product image for Exclusive Team for Elementor.
Plugin
Exclusive Team for Elementor
Plugin Slug
exclusive-team-for-elementor
Installations
1,000+
Vulnerability
Cross Site Request Forgery (CSRF)
Patched in Version
No Fix
Severity Score
Medium
CVE
2022-47150
The vulnerability has not been patched. You should deactivate the plugin.

Goods Catalog

Plugin
Goods Catalog
Plugin Slug
goods-catalog
Installations
1,000+
Vulnerability
Cross Site Scripting (XSS)
Patched in Version
No Fix
Severity Score
Medium
CVE
2023-41687
The vulnerability has not been patched. You should deactivate the plugin.

Olive One Click Demo Import

Product image for Olive One Click Demo Import.
Plugin
Olive One Click Demo Import
Plugin Slug
olive-one-click-demo-import
Installations
1,000+
Vulnerability
Arbitrary File Upload
Patched in Version
No Fix
Severity Score
Critical
CVE
2023-29102
The vulnerability has not been patched. You should deactivate the plugin.

Stock Quotes List

Product image for Stock Quotes List.
Plugin
Stock Quotes List
Plugin Slug
stock-quotes-list
Installations
1,000+
Vulnerability
Cross Site Scripting (XSS)
Patched in Version
No Fix
Severity Score
Medium
CVE
2023-41666
The vulnerability has not been patched. You should deactivate the plugin.

Product Category Showcase for WooCommerce

Product image for Product Category Showcase for WooCommerce.
Plugin
Product Category Showcase for WooCommerce
Plugin Slug
wc-category-showcase
Installations
1,000+
Vulnerability
Cross Site Request Forgery (CSRF)
Patched in Version
No Fix
Severity Score
Medium
CVE
2022-47150
The vulnerability has not been patched. You should deactivate the plugin.

WiserNotify Social Proof

Product image for WiserNotify Social Proof & FOMO Notification, WooCommerce Sales Popup, Review Popups, Notification Bars & Urgency Widgets.
Plugin
WiserNotify Social Proof & FOMO Notification, WooCommerce Sales Popup, Review Popups, Notification Bars & Urgency Widgets
Plugin Slug
wiser-notify
Installations
1,000+
Vulnerability
Broken Access Control
Patched in Version
No Fix
Severity Score
Medium
CVE
2023-41690
The vulnerability has not been patched. You should deactivate the plugin.

WP Bannerize Pro

Product image for WP Bannerize Pro.
Plugin
WP Bannerize Pro
Plugin Slug
wp-bannerize-pro
Installations
1,000+
Vulnerability
Cross Site Scripting (XSS)
Patched in Version
No Fix
Severity Score
High
CVE
2023-41663
The vulnerability has not been patched. You should deactivate the plugin.

Tilda Publishing

Plugin
Tilda Publishing
Plugin Slug
tilda-publishing
Installations
900+
Vulnerability
Broken Access Control
Patched in Version
No Fix
Severity Score
Medium
CVE
2023-31234
The vulnerability has not been patched. You should deactivate the plugin.

Easy Newsletter Signups

Product image for Easy Newsletter Signups.
Plugin
Easy Newsletter Signups
Plugin Slug
easy-newsletter-signups
Installations
800+
Vulnerability
Broken Access Control
Patched in Version
No Fix
Severity Score
Medium
CVE
2023-41664
The vulnerability has not been patched. You should deactivate the plugin.

Snap Pixel

Product image for Snap Pixel.
Plugin
Snap Pixel
Plugin Slug
snap-pixel
Installations
800+
Vulnerability
Cross Site Scripting (XSS)
Patched in Version
No Fix
Severity Score
Medium
CVE
2023-41242
The vulnerability has not been patched. You should deactivate the plugin.

Woocommerce Support System

Product image for Woocommerce Support System.
Plugin
Woocommerce Support System
Plugin Slug
wc-support-system
Installations
300+
Vulnerability
Broken Access Control
Patched in Version
No Fix
Severity Score
Medium
CVE
2023-41686
The vulnerability has not been patched. You should deactivate the plugin.

Woocommerce Support System

Product image for Woocommerce Support System.
Plugin
Woocommerce Support System
Plugin Slug
wc-support-system
Installations
300+
Vulnerability
SQL Injection
Patched in Version
No Fix
Severity Score
High
CVE
2023-41685
The vulnerability has not been patched. You should deactivate the plugin.

Localize Remote Images

Plugin
Localize Remote Images
Plugin Slug
localize-remote-images
Installations
10+
Vulnerability
Cross Site Request Forgery (CSRF)
Patched in Version
No Fix
Severity Score
Medium
CVE
2023-41244
The vulnerability has not been patched. You should deactivate the plugin.

Bridge Core

Plugin
Bridge Core
Plugin Slug
bridge-core
Vulnerability
Cross Site Scripting (XSS)
Patched in Version
No Fix
Severity Score
High
CVE
2023-40333
The vulnerability has not been patched. You should deactivate the plugin.

WordPress CTA

Plugin
WordPress CTA
Plugin Slug
easy-sticky-sidebar
Vulnerability
Cross Site Request Forgery (CSRF)
Patched in Version
No Fix
Severity Score
Medium
CVE
2022-47150
The vulnerability has not been patched and the plugin is closed. You should uninstall and delete the plugin.

Font Awesome 4 Menus

Plugin
Font Awesome 4 Menus
Plugin Slug
font-awesome-4-menus
Vulnerability
Cross Site Scripting (XSS)
Patched in Version
No Fix
Severity Score
Medium
CVE
2023-4718
The vulnerability has not been patched and the plugin is closed. You should uninstall and delete the plugin.

GuruWalk Affiliates

Plugin
GuruWalk Affiliates
Plugin Slug
guruwalk-affiliates
Vulnerability
Cross Site Scripting (XSS)
Patched in Version
No Fix
Severity Score
Medium
CVE
2023-27622
The vulnerability has not been patched. You should deactivate the plugin.

Maintenance Switch

Plugin
Maintenance Switch
Plugin Slug
maintenance-switch
Vulnerability
Cross Site Request Forgery (CSRF)
Patched in Version
No Fix
Severity Score
Medium
CVE
2023-29235
The vulnerability has not been patched and the plugin is closed. You should uninstall and delete the plugin.

Sermon’e – Sermons Online

Plugin
Sermon’e – Sermons Online
Plugin Slug
sermone-online-sermons-management
Vulnerability
Cross Site Scripting (XSS)
Patched in Version
No Fix
Severity Score
High
CVE
2023-41653
The vulnerability has not been patched and the plugin is closed. You should uninstall and delete the plugin.

SIS Handball

Plugin
SIS Handball
Plugin Slug
sis-handball
Vulnerability
Cross Site Request Forgery (CSRF)
Patched in Version
No Fix
Severity Score
Medium
CVE
2023-41684
The vulnerability has not been patched and the plugin is closed. You should uninstall and delete the plugin.

Smarty for WordPress

Plugin
Smarty for WordPress
Plugin Slug
smarty-for-wordpress
Vulnerability
Cross Site Scripting (XSS)
Patched in Version
No Fix
Severity Score
Medium
CVE
2023-41661
The vulnerability has not been patched and the plugin is closed. You should uninstall and delete the plugin.

Use Memcached

Plugin
Use Memcached
Plugin Slug
use-memcached
Vulnerability
Cross Site Request Forgery (CSRF)
Patched in Version
No Fix
Severity Score
Medium
CVE
2023-41670
The vulnerability has not been patched and the plugin is closed. You should uninstall and delete the plugin.

WP-dTree

Plugin
WP-dTree
Plugin Slug
wp-dtree-30
Vulnerability
Cross Site Request Forgery (CSRF)
Patched in Version
No Fix
Severity Score
Medium
CVE
2023-41667
The vulnerability has not been patched and the plugin is closed. You should uninstall and delete the plugin.

WP-dTree

Plugin
WP-dTree
Plugin Slug
wp-dtree-30
Vulnerability
Cross Site Scripting (XSS)
Patched in Version
No Fix
Severity Score
High
CVE
2023-41662
The vulnerability has not been patched and the plugin is closed. You should uninstall and delete the plugin.

WordPress Theme Vulnerabilities

In this section, you’ll find the latest WordPress theme vulnerabilities to be disclosed. You’ll see the same information we provided above for vulnerable plugins, and the same advice applies. If a security update exists, install it immediately. If a vulnerability remains unpatched in a theme you are actively using, you must find an alternative theme. Deactivate and delete persistently unpatched themes and those marked “Closed” in the WordPress.org theme repository. If you have a vulnerable theme installed that you are not actively using, delete it.

Attorney

Product image for Attorney.
Theme
Attorney
Theme Slug
attorney
Downloads
51,489
Vulnerability
Cross Site Scripting (XSS)
Patched in Version
No Fix
Severity Score
High
CVE
2023-41692
The vulnerability has not been patched. You should switch themes.

Arya Multipurpose Pro

Theme
Arya Multipurpose Pro
Theme Slug
arya-multipurpose-pro
Vulnerability
Cross Site Scripting (XSS)
Patched in Version
No Fix
Severity Score
High
CVE
2023-41237
The vulnerability has not been patched. You should switch themes.

Everest News Pro

Theme
Everest News Pro
Theme Slug
everest-news-pro
Vulnerability
Cross Site Scripting (XSS)
Patched in Version
No Fix
Severity Score
High
CVE
2023-41235
The vulnerability has not been patched. You should switch themes.


Never worry about running a vulnerable plugin or theme again.

As you can see from this report, new WordPress plugin and theme vulnerabilities are disclosed every week. We know it can be difficult to stay on top of every reported vulnerability disclosure that matters to you, so the Themes Security Pro plugin makes it easy to ensure your site isn’t running a vulnerable theme, plugin, or version of WordPress core.

Scans Your Website Twice a Day for Vulnerabilities

Your website’s plugins, themes, and WordPress core versions are checked against the Patchstack Vulnerability Database for the latest vulnerability disclosures.

Automatically Updates if a Security Fix is Available

Paired with Version Management, iThemes Security will automatically update a plugin, theme, or WordPress core version if it has a vulnerability.

Emails You a Warning if Site Scan Detects a Vulnerability

You can receive an email report if your site is running vulnerable versions of a plugin, theme, or WordPress core. Customize the email addresses that receive scan results.

iThemes Security Pro

The Best WordPress Security Plugin to Secure & Protect WordPress Sites

WordPress currently powers over 40% of all websites, so it has become a popular target for hackers with malicious intent. The iThemes Security Pro plugin takes the guesswork out of WordPress security to make it easy to secure & protect your WordPress website. It’s like having a full-time security expert on staff who constantly monitors and protects your WordPress site for you.

Buy iThemes Security Pro


Dan Knauss
Dan Knauss

Dan Knauss is StellarWP’s Technical Content Generalist. He’s been a writer, teacher, and freelancer working in open source since the late 1990s and with WordPress since 2004.

Share via:

  • Facebook
  • Twitter
  • LinkedIn
  • More
Other related posts
wordpress vulnerability report - security
WordPress Vulnerability Report – August 30, 2023
WordPress Vulnerability Report
WordPress Vulnerability Report – August 23, 2023
A computer riddled with security issue alerts. There is a large, orange shield with a slash in the middle of the screen. Surrounding it are a red target, a green skull and crossbones, an orange “bug”, a triangle with an explanation point in the middle and a gray gear.
WordPress Vulnerability Report – August 16, 2023
WordPress vulnerability report
WordPress Vulnerability Report – August 9, 2023

Get updates on new themes & plugins plus special discounts

About iThemes

  • Contact Us
  • Website Accessibility Statement
  • Sitemap

Resources

  • Blog
  • Documentation
  • WordPress Tutorials
  • Free WordPress Ebooks
  • Free Webinar Library
  • Free Upcoming Webinars
  • iThemes Training
  • Affiliates

Customers

  • Member Panel Login
  • Support
  • FAQs
  • Upgrade Policy
  • Licensing
  • Terms and Conditions
  • Refund Policy

Top Products

  • BackupBuddy
  • iThemes Security Pro
  • iThemes Sync
  • Restrict Content Pro
  • WPComplete
  • WordPress Plugins
  • Content Upgrades
  • WordPress Landing Page Plugin
  • BackupBuddy Stash

iThemes Media LLC Copyright © 2023 All rights reserved | Privacy Policy

A Liquid Web Brand © 2022 All Rights Reserved.

Get the Weekly WordPress Vulnerability Report

Vulnerable WordPress plugins and themes are the #1 reason WordPress sites get hacked, but keeping track of every new plugin and theme vulnerability is hard work. Get the weekly WordPress Vulnerability Report delivered right to your inbox to help keep your website secure.

Get the Report
Share via
Facebook
Twitter
LinkedIn
Mix
Email
Print
Copy Link
Powered by Social Snap
Copy link
CopyCopied
Powered by Social Snap

Get the Weekly WordPress Vulnerability Report

Vulnerable WordPress plugins and themes are the #1 reason WordPress sites get hacked, but keeping track of every new plugin and theme vulnerability is hard work. Get the weekly WordPress Vulnerability Report delivered right to your inbox to help keep your website secure.
No spam. Unsubscribe anytime.