• Skip to primary navigation
  • Skip to main content
  • Skip to primary sidebar

virusword.com

Learn Wordpress

  • Home
  • WordPress Shop
    • Fotopress
    • SEO Tool Kit
    • Social Contact
    • Tag Machine 2
    • Video Profits
  • Latest News
  • WordPress
    • Plugins
    • Themes
    • Tutorials
    • Videos
    • Woocommerce
  • About Us
  • Contact Us
    • Terms of Service
    • Privacy Policy
  • Show Search
Hide Search
Home/Woocommerce/WordPress Vulnerability Report – August 2, 2023

WordPress Vulnerability Report – August 2, 2023

Written by

Dan Knauss

on

August 2, 2023

Last Updated on August 2, 2023

Since last week, 94 total vulnerabilities emerged in public disclosure. They may affect over 7 million WordPress sites. There are 56 plugin vulnerabilities with security patches, so run those updates!

Additionally, there are 35 plugin vulnerabilities and three theme vulnerabilities with no patch available yet. If you use an unpatched plugin or theme, check their vendors’ intentions and progress on a security release. Suppose no patch is forthcoming or the vulnerable software has been marked “closed” and dropped from the official WordPress theme and plugin repositories. In that case, you should consider deactivation and removal in favor of alternative solutions.

FREE ONLINE TRAINING EVENT AUG 8TH @ 1:00 P.M. (CT)

New research from Snicco, WeWatchYourWebsite, Automattic-backed GridPane, and PatchStack claims WordPress security plugins with malware scanners are fundamentally flawed. And they’re being actively defeated by malware in the wild right now!

In this webinar, StellarWP technical writer Dan Knauss will explain the problem with malware scanners and the WordPress security best practices you need to implement to truly keep your sites safe.

WordPress Core Vulnerabilities — Patched

  • No new WordPress core vulnerabilities were disclosed this week.

WordPress core is very secure when it’s properly configured and maintained. Vulnerable plugins not updated by site owners are the most common vector for attacks on WordPress websites. Our weekly WordPress Vulnerability Report, powered by Patchstack, covers new vulnerabilities that have emerged in plugins, themes, and/or WordPress core since last week’s report. Our goal is to spread awareness of emerging security threats and help you decide what to do if you find vulnerable software on your website. For a deeper analysis of recent trends in WordPress vulnerabilities and threat vectors, see our 2022 Annual Vulnerability Report.

These reports are published every Wednesday and include all active vulnerabilities tracked by Patchstack as of Monday since the previous report. This leaves a 48-hour window for the newest emerging vulnerabilities to be patched before full public disclosure. iThemes Security Pro users have access to vulnerability alerts emerging within this window.

Get the weekly WordPress Vulnerability Report delivered to your inbox each Wednesday.

WordPress Plugin Vulnerabilities — Patched

In this section, you’ll find the most recently disclosed WordPress plugin vulnerabilities fixed with a new release from their authors and maintainers. Please apply the updates if you are affected!

These vulnerabilities have been disclosed and scored for their severity, thanks to our friends at Patchstack. Each plugin listing includes the type of vulnerability with its CVE number and CVSS severity rating with links to more technical details. You’ll also see the number of active sites using the plugin and the plugin version release that patches the vulnerability. We start with the most popular plugins, representing the largest target for attackers.

WPCode

Product image for WPCode – Insert Headers and Footers + Custom Code Snippets – WordPress Code Manager.

Plugin Slug
insert-headers-and-footers

Installations
2,000,000+

Vulnerability
Reflected Cross Site Scripting (XSS)

Patched in Version
2.0.13.1

Severity Score
High

The vulnerability has been patched, so you should update to version 2.0.13.1.

Ninja Forms

Product image for Ninja Forms Contact Form – The Drag and Drop Form Builder for WordPress.

Plugin Slug
ninja-forms

Installations
800,000+

Vulnerability
Reflected Cross Site Scripting (XSS)

Patched in Version
3.6.26

Severity Score
High

The vulnerability has been patched, so you should update to version 3.6.26.

Ninja Forms

Product image for Ninja Forms Contact Form – The Drag and Drop Form Builder for WordPress.

Plugin Slug
ninja-forms

Installations
800,000+

Vulnerability
Subscriber+ Broken Access Control

Patched in Version
3.6.26

Severity Score
High

The vulnerability has been patched, so you should update to version 3.6.26.

Ninja Forms

Product image for Ninja Forms Contact Form – The Drag and Drop Form Builder for WordPress.

Plugin Slug
ninja-forms

Installations
800,000+

Vulnerability
Contributor+ Broken Access Control

Patched in Version
3.6.26

Severity Score
High

The vulnerability has been patched, so you should update to version 3.6.26.

The Events Calendar

Product image for The Events Calendar.

Plugin Slug
the-events-calendar

Installations
800,000+

Vulnerability
Broken Access Control

Patched in Version
6.1.3

Severity Score
Medium

The vulnerability has been patched, so you should update to version 6.1.3.

Duplicate Post

Product image for Duplicate Post.

Plugin Slug
copy-delete-posts

Installations
200,000+

Vulnerability
Missing Authorization on handle_installation function

Patched in Version
1.4.0

Severity Score
Medium

The vulnerability has been patched, so you should update to version 1.4.0.

Duplicate Post

Product image for Duplicate Post.

Plugin Slug
copy-delete-posts

Installations
200,000+

Vulnerability
Cross Site Request Forgery (CSRF)

Patched in Version
1.4.0

Severity Score
Medium

The vulnerability has been patched, so you should update to version 1.4.0.

Social Media Share Buttons & Social Sharing Icons

Product image for Social Media Share Buttons & Social Sharing Icons.

Plugin Slug
ultimate-social-media-icons

Installations
200,000+

Vulnerability
Broken Access Control

Patched in Version
2.8.2

Severity Score
Medium

The vulnerability has been patched, so you should update to version 2.8.2.

Social Media Share Buttons & Social Sharing Icons

Product image for Social Media Share Buttons & Social Sharing Icons.

Plugin Slug
ultimate-social-media-icons

Installations
200,000+

Vulnerability
Cross Site Request Forgery (CSRF)

Patched in Version
2.8.2

Severity Score
Medium

The vulnerability has been patched, so you should update to version 2.8.2.

TI WooCommerce Wishlist

Product image for TI WooCommerce Wishlist.

Plugin Slug
ti-woocommerce-wishlist

Installations
100,000+

Vulnerability
SQL Injection

Patched in Version
2.7.4

Severity Score
Critical

The vulnerability has been patched, so you should update to version 2.7.4.

Clone

Product image for Clone.

Plugin Slug
wp-clone-by-wp-academy

Installations
100,000+

Vulnerability
Broken Access Control

Patched in Version
2.3.8

Severity Score
Medium

The vulnerability has been patched, so you should update to version 2.3.8.

Clone

Product image for Clone.

Plugin Slug
wp-clone-by-wp-academy

Installations
100,000+

Vulnerability
Cross Site Request Forgery (CSRF)

Patched in Version
2.3.8

Severity Score
Medium

The vulnerability has been patched, so you should update to version 2.3.8.

Change WP Admin

Product image for Change WP Admin Login.

Plugin Slug
change-wp-admin-login

Installations
90,000+

Vulnerability
Bypass Vulnerability

Patched in Version
1.1.4

Severity Score
Medium

The vulnerability has been patched, so you should update to version 1.1.4.

Backup Migration

Product image for Backup Migration.

Plugin Slug
backup-backup

Installations
80,000+

Vulnerability
Broken Access Control

Patched in Version
1.2.8

Severity Score
Medium

The vulnerability has been patched, so you should update to version 1.2.8.

Backup Migration

Product image for Backup Migration.

Plugin Slug
backup-backup

Installations
80,000+

Vulnerability
Cross Site Request Forgery (CSRF)

Patched in Version
1.2.8

Severity Score
Medium

The vulnerability has been patched, so you should update to version 1.2.8.

Simple Author Box

Product image for Simple Author Box.

Plugin Slug
simple-author-box

Installations
60,000+

Vulnerability
Insecure Direct Object References (IDOR)

Patched in Version
2.52

Severity Score
Medium

The vulnerability has been patched, so you should update to version 2.52.

Custom Field Template

Product image for Custom Field Template.

Plugin Slug
custom-field-template

Installations
50,000+

Vulnerability
Cross Site Scripting (XSS)

Patched in Version
2.6.0

Severity Score
High

The vulnerability has been patched, so you should update to version 2.6.0.

Enhanced Text Widget

Product image for Enhanced Text Widget.

Plugin Slug
enhanced-text-widget

Installations
50,000+

Vulnerability
Broken Access Control

Patched in Version
1.5.8

Severity Score
Medium

The vulnerability has been patched, so you should update to version 1.5.8.

Enhanced Text Widget

Product image for Enhanced Text Widget.

Plugin Slug
enhanced-text-widget

Installations
50,000+

Vulnerability
Cross Site Request Forgery (CSRF)

Patched in Version
1.5.8

Severity Score
Medium

The vulnerability has been patched, so you should update to version 1.5.8.

ACF Photo Gallery Field

Product image for ACF Photo Gallery Field.

Plugin Slug
navz-photo-gallery

Installations
50,000+

Vulnerability
Broken Access Control

Patched in Version
2.0

Severity Score
Medium

The vulnerability has been patched, so you should update to version 2.0.

Quiz And Survey Master

Product image for Quiz And Survey Master – Best Quiz, Exam and Survey Plugin for WordPress.

Plugin Slug
quiz-master-next

Installations
40,000+

Vulnerability
Cross Site Scripting (XSS)

Patched in Version
8.1.11

Severity Score
Medium

The vulnerability has been patched, so you should update to version 8.1.11.

Redirect Redirection

Product image for Redirection.

Plugin Slug
redirect-redirection

Installations
30,000+

Vulnerability
Broken Access Control

Patched in Version
1.1.4

Severity Score
Medium

The vulnerability has been patched, so you should update to version 1.1.4.

Redirect Redirection

Product image for Redirection.

Plugin Slug
redirect-redirection

Installations
30,000+

Vulnerability
Cross Site Request Forgery (CSRF)

Patched in Version
1.1.4

Severity Score
Medium

The vulnerability has been patched, so you should update to version 1.1.4.

Media from FTP

Product image for Media from FTP.

Plugin Slug
media-from-ftp

Installations
20,000+

Vulnerability
Broken Access Control

Patched in Version
11.16

Severity Score
Medium

The vulnerability has been patched, so you should update to version 11.16.

PHP Everywhere

Product image for PHP Everywhere.

Plugin Slug
php-everywhere

Installations
20,000+

Vulnerability
Remote Code Execution (RCE)

Patched in Version
3.0.0

Severity Score
Critical

The vulnerability has been patched, so you should update to version 3.0.0.

PHP Everywhere

Product image for PHP Everywhere.

Plugin Slug
php-everywhere

Installations
20,000+

Vulnerability
Remote Code Execution (RCE)

Patched in Version
3.0.0

Severity Score
Critical

The vulnerability has been patched, so you should update to version 3.0.0.

PHP Everywhere

Product image for PHP Everywhere.

Plugin Slug
php-everywhere

Installations
20,000+

Vulnerability
Remote Code Execution (RCE)

Patched in Version
3.0.0

Severity Score
Critical

The vulnerability has been patched, so you should update to version 3.0.0.

Video Conferencing with Zoom

Product image for Video Conferencing with Zoom.

Plugin Slug
video-conferencing-with-zoom-api

Installations
20,000+

Vulnerability
Sensitive Data Exposure

Patched in Version
4.2.2

Severity Score
Low

The vulnerability has been patched, so you should update to version 4.2.2.

SSL Mixed Content Fix

Product image for SSL Mixed Content Fix.

Plugin Slug
http-https-remover

Installations
10,000+

Vulnerability
Broken Access Control

Patched in Version
3.2.4

Severity Score
Medium

The vulnerability has been patched, so you should update to version 3.2.4.

SSL Mixed Content Fix

Product image for SSL Mixed Content Fix.

Plugin Slug
http-https-remover

Installations
10,000+

Vulnerability
Cross Site Request Forgery (CSRF)

Patched in Version
3.2.4

Severity Score
Medium

The vulnerability has been patched, so you should update to version 3.2.4.

Pop-up

Product image for Pop-up.

Plugin Slug
pop-up-pop-up

Installations
10,000+

Vulnerability
Broken Access Control

Patched in Version
1.2.0

Severity Score
Medium

The vulnerability has been patched, so you should update to version 1.2.0.

Pop-up

Product image for Pop-up.

Plugin Slug
pop-up-pop-up

Installations
10,000+

Vulnerability
Cross Site Request Forgery (CSRF)

Patched in Version
1.2.0

Severity Score
Medium

The vulnerability has been patched, so you should update to version 1.2.0.

Ultimate Posts Widget

Product image for Ultimate Posts Widget.

Plugin Slug
ultimate-posts-widget

Installations
10,000+

Vulnerability
Broken Access Control

Patched in Version
2.2.5

Severity Score
Medium

The vulnerability has been patched, so you should update to version 2.2.5.

Ultimate Posts Widget

Product image for Ultimate Posts Widget.

Plugin Slug
ultimate-posts-widget

Installations
10,000+

Vulnerability
Cross Site Request Forgery (CSRF)

Patched in Version
2.2.5

Severity Score
Medium

The vulnerability has been patched, so you should update to version 2.2.5.

User Activity Log

Product image for User Activity Log.

Plugin Slug
user-activity-log

Installations
10,000+

Vulnerability
SQL Injection

Patched in Version
1.6.5

Severity Score
Critical

The vulnerability has been patched, so you should update to version 1.6.5.

Assistant

Product image for AI Content Writing Assistant (Content Writer, GPT 3 & 4, ChatGPT, Image Generator) All in One.

Plugin Slug
ai-content-writing-assistant

Installations
4,000+

Vulnerability
Server Side Request Forgery (SSRF)

Patched in Version
1.4.4

Severity Score
Medium

The vulnerability has been patched, so you should update to version 1.4.4.

Simple Blog Card

Plugin Slug
simple-blog-card

Installations
3,000+

Vulnerability
Cross Site Scripting (XSS)

Patched in Version
1.31

Severity Score
Medium

The vulnerability has been patched, so you should update to version 1.31.

Discussion Board

Product image for Discussion Board – WordPress Forum Plugin.

Plugin Slug
wp-discussion-board

Installations
3,000+

Vulnerability
Content Injection

Patched in Version
2.4.9

Severity Score
Medium

The vulnerability has been patched, so you should update to version 2.4.9.

Contact Form Builder by Bit Form

Product image for Contact Form Builder by Bit Form – Easiest Contact Form, Payment Form, Order Form, Calculator Form Builder Plugin for WordPress.

Plugin Slug
bit-form

Installations
2,000+

Vulnerability
Cross Site Scripting (XSS)

Patched in Version
2.2.0

Severity Score
Medium

The vulnerability has been patched, so you should update to version 2.2.0.

RSS Redirect & Feedburner Alternative

Product image for RSS Redirect & Feedburner Alternative.

Plugin Slug
feedburner-alternative-and-rss-redirect

Installations
2,000+

Vulnerability
Broken Access Control

Patched in Version
3.8

Severity Score
Medium

The vulnerability has been patched, so you should update to version 3.8.

RSS Redirect & Feedburner Alternative

Product image for RSS Redirect & Feedburner Alternative.

Plugin Slug
feedburner-alternative-and-rss-redirect

Installations
2,000+

Vulnerability
Cross Site Request Forgery (CSRF)

Patched in Version
3.8

Severity Score
Medium

The vulnerability has been patched, so you should update to version 3.8.

CodeBard’s Patron Button and Widgets for Patreon

Product image for CodeBard's Patron Button and Widgets for Patreon.

Plugin Slug
patron-button-and-widgets-by-codebard

Installations
2,000+

Vulnerability
Cross Site Scripting (XSS)

Patched in Version
2.1.9

Severity Score
High

The vulnerability has been patched, so you should update to version 2.1.9.

QR code MeCard/vCard generator

Product image for QR code MeCard/vCard generator.

Plugin Slug
wp-qrcode-me-v-card

Installations
2,000+

Vulnerability
Broken Access Control

Patched in Version
1.6.1

Severity Score
Medium

The vulnerability has been patched, so you should update to version 1.6.1.

Church Admin

Product image for Church Admin.

Plugin Slug
church-admin

Installations
1,000+

Vulnerability
Server Side Request Forgery (SSRF)

Patched in Version
3.8.0

Severity Score
Medium

The vulnerability has been patched, so you should update to version 3.8.0.

InstaWP Connect

Product image for InstaWP Connect – 1-click WP Staging & Migration (beta).

Plugin Slug
instawp-connect

Installations
1,000+

Vulnerability
Broken Access Control

Patched in Version
0.0.9.19

Severity Score
Critical

The vulnerability has been patched, so you should update to version 0.0.9.19.

Bit Assist

Product image for Chat Button: WhatsApp Chat, Facebook Messenger, Telegram Chat, WeChat, Line Chat, Discord Chat for Customer Support Chat with floating Chat Widget.

Plugin Slug
bit-assist

Installations
900+

Vulnerability
Cross Site Scripting (XSS)

Patched in Version
1.1.9

Severity Score
Medium

The vulnerability has been patched, so you should update to version 1.1.9.

WordPress Job Board and Recruitment Plugin – JobWP

Product image for WordPress Job Board and Recruitment Plugin – JobWP.

Plugin Slug
jobwp

Installations
300+

Vulnerability
Cross Site Scripting (XSS)

Patched in Version
2.0

Severity Score
High

The vulnerability has been patched, so you should update to version 2.0.

Local Development

Product image for Local Development.

Plugin Slug
local-development

Installations
100+

Vulnerability
Cross Site Request Forgery (CSRF)

Patched in Version
2.8.3

Severity Score
Medium

The vulnerability has been patched, so you should update to version 2.8.3.

CartFlows Pro

Plugin
CartFlows Pro

Plugin Slug
cartflows-pro

Vulnerability
Cross Site Request Forgery (CSRF)

Patched in Version
1.11.13

Severity Score
Medium

The vulnerability has been patched, so you should update to version 1.11.13.

Shop as a Customer for WooCommerce

Plugin
Shop as a Customer for WooCommerce

Plugin Slug
shop-as-a-customer-for-woocommerce

Vulnerability
Privilege Escalation

Patched in Version
1.2.4

Severity Score
High

The vulnerability has been patched, so you should update to version 1.2.4.

Shop as a Customer for WooCommerce

Plugin
Shop as a Customer for WooCommerce

Plugin Slug
shop-as-a-customer-for-woocommerce

Vulnerability
Privilege Escalation

Patched in Version
1.1.8

Severity Score
High

The vulnerability has been patched, so you should update to version 1.1.8.

Social Share Icons & Social Share Buttons

Plugin
Social Share Icons & Social Share Buttons

Plugin Slug
ultimate-social-media-plus

Vulnerability
Broken Access Control

Patched in Version
3.5.8

Severity Score
Medium

The vulnerability has been patched, so you should update to version 3.5.8.

Social Share Icons & Social Share Buttons

Plugin
Social Share Icons & Social Share Buttons

Plugin Slug
ultimate-social-media-plus

Vulnerability
Cross Site Request Forgery (CSRF)

Patched in Version
3.5.8

Severity Score
Medium

The vulnerability has been patched, so you should update to version 3.5.8.

Schema Pro

Plugin
Schema Pro

Plugin Slug
wp-schema-pro

Vulnerability
Broken Access Control

Patched in Version
2.7.9

Severity Score
Medium

The vulnerability has been patched, so you should update to version 2.7.9.

WP Brutal AI

Plugin
WP Brutal AI

Plugin Slug
wpbrutalai

Vulnerability
Cross Site Scripting (XSS)

Patched in Version
2.06

Severity Score
Medium

The vulnerability has been patched, so you should update to version 2.06.

WPML String Translation

Plugin
WPML String Translation

Plugin Slug
wpml-string-translation

Vulnerability
SQL Injection

Patched in Version
3.2.6

Severity Score
High

The vulnerability has been patched, so you should update to version 3.2.6.

WordPress Plugin Vulnerabilities — Unpatched

This section contains plugin vulnerabilities with no known fix. Until a patch is available, you are advised to deactivate the plugin, at minimum, immediately. If there is a high risk of active exploits or the plugin remains unpatched for weeks, you are advised to delete the plugin. You should also delete persistently unpatched plugins the WordPress.org repository has locked and marked “Closed” so they can no longer be downloaded and installed.

Optimize Database after Deleting Revisions

Product image for Optimize Database after Deleting Revisions.

Plugin Slug
rvg-optimize-database

Installations
100,000+

Vulnerability
Cross Site Request Forgery (CSRF)

Patched in Version
No Fix

Severity Score
Medium

The vulnerability has not been patched. You should deactivate the plugin.

Booster for Woocommerce

Product image for Booster for WooCommerce.

Plugin Slug
woocommerce-jetpack

Installations
60,000+

Vulnerability
Broken Access Control

Patched in Version
No Fix

Severity Score
High

The vulnerability has not been patched. You should deactivate the plugin.

WPS Limit Login

Product image for WPS Limit Login.

Plugin Slug
wps-limit-login

Installations
60,000+

Vulnerability
Race Condition

Patched in Version
No Fix

Severity Score
Low

The vulnerability has not been patched. You should deactivate the plugin.

Molongui

Product image for Author Box for Authors, Co-Authors, Multiple Authors and Guest Authors – Molongui.

Plugin Slug
molongui-authorship

Installations
9,000+

Vulnerability
Cross Site Scripting (XSS)

Patched in Version
No Fix

Severity Score
High

The vulnerability has not been patched. You should deactivate the plugin.

Banner Management For WooCommerce

Product image for Banner Management For WooCommerce.

Plugin Slug
banner-management-for-woocommerce

Installations
4,000+

Vulnerability
Cross Site Request Forgery (CSRF)

Patched in Version
No Fix

Severity Score
Medium

The vulnerability has not been patched. You should deactivate the plugin.

Fraud Prevention For Woocommerce

Product image for Fraud Prevention For Woocommerce.

Plugin Slug
woo-blocker-lite-prevent-fake-orders-and-blacklist-fraud-customers

Installations
4,000+

Vulnerability
Cross Site Request Forgery (CSRF)

Patched in Version
No Fix

Severity Score
Medium

The vulnerability has not been patched. You should deactivate the plugin.

MultiParcels Shipping For WooCommerce

Product image for MultiParcels Shipping For WooCommerce.

Plugin Slug
multiparcels-shipping-for-woocommerce

Installations
3,000+

Vulnerability
Cross Site Scripting (XSS)

Patched in Version
No Fix

Severity Score
High

The vulnerability has not been patched. You should deactivate the plugin.

WP Quick Post Duplicator

Product image for WP Quick Post Duplicator.

Plugin Slug
wp-quick-post-duplicator

Installations
3,000+

Vulnerability
Broken Access Control

Patched in Version
No Fix

Severity Score
Medium

The vulnerability has not been patched. You should deactivate the plugin.

Mobile Address Bar Changer

Product image for Mobile Address Bar Changer.

Plugin Slug
mobile-address-bar-changer

Installations
1,000+

Vulnerability
Cross Site Request Forgery (CSRF)

Patched in Version
No Fix

Severity Score
Medium

The vulnerability has not been patched. You should deactivate the plugin.

Remove Duplicate Posts

Product image for Remove Duplicate Posts.

Plugin Slug
remove-duplicate-posts

Installations
1,000+

Vulnerability
Broken Access Control

Patched in Version
No Fix

Severity Score
Medium

The vulnerability has not been patched. You should deactivate the plugin.

APIExperts Square for WooCommerce

Product image for APIExperts Square for WooCommerce.

Plugin Slug
woosquare

Installations
1,000+

Vulnerability
Broken Access Control

Patched in Version
No Fix

Severity Score
Medium

The vulnerability has not been patched. You should deactivate the plugin.

Web Accessibility By accessiBe

Plugin
Web Accessibility By accessiBe

Plugin Slug
accessibe

Vulnerability
Cross Site Scripting (XSS)

Patched in Version
No Fix

Severity Score
Medium

The vulnerability has not been patched and the plugin is closed. You should uninstall and delete the plugin.

Web Accessibility By accessiBe

Plugin
Web Accessibility By accessiBe

Plugin Slug
accessibe

Vulnerability
Cross Site Scripting (XSS)

Patched in Version
No Fix

Severity Score
Medium

The vulnerability has not been patched and the plugin is closed. You should uninstall and delete the plugin.

AGP Font Awesome Collection

Plugin
AGP Font Awesome Collection

Plugin Slug
agp-font-awesome-collection

Vulnerability
Cross Site Scripting (XSS)

Patched in Version
No Fix

Severity Score
High

The vulnerability has not been patched and the plugin is closed. You should uninstall and delete the plugin.

Booster Elementor Addons

Plugin
Booster Elementor Addons

Plugin Slug
booster-for-elementor

Vulnerability
Broken Access Control

Patched in Version
No Fix

Severity Score
Medium

The vulnerability has not been patched and the plugin is closed. You should uninstall and delete the plugin.

WP Clone Menu

Plugin
WP Clone Menu

Plugin Slug
clone-menu

Vulnerability
Broken Access Control

Patched in Version
No Fix

Severity Score
Medium

The vulnerability has not been patched and the plugin is closed. You should uninstall and delete the plugin.

Google Map Shortcode

Plugin
Google Map Shortcode

Plugin Slug
google-map-shortcode

Vulnerability
Cross Site Request Forgery (CSRF)

Patched in Version
No Fix

Severity Score
Medium

The vulnerability has not been patched and the plugin is closed. You should uninstall and delete the plugin.

HTTP Auth

Plugin
HTTP Auth

Plugin Slug
http-auth

Vulnerability
Cross Site Request Forgery (CSRF)

Patched in Version
No Fix

Severity Score
Medium

The vulnerability has not been patched and the plugin is closed. You should uninstall and delete the plugin.

Instant CSS

Plugin
Instant CSS

Plugin Slug
instant-css

Vulnerability
Broken Access Control

Patched in Version
No Fix

Severity Score
Medium

The vulnerability has not been patched and the plugin is closed. You should uninstall and delete the plugin.

LWS Affiliation

Plugin
LWS Affiliation

Plugin Slug
lws-affiliation

Vulnerability
Local File Inclusion

Patched in Version
No Fix

Severity Score
Critical

The vulnerability has not been patched and the plugin is closed. You should uninstall and delete the plugin.

Meks Smart Social Widget

Plugin
Meks Smart Social Widget

Plugin Slug
meks-smart-social-widget

Vulnerability
Cross Site Request Forgery (CSRF)

Patched in Version
No Fix

Severity Score
Medium

The vulnerability has not been patched and the plugin is closed. You should uninstall and delete the plugin.

Perelink Pro

Plugin
Perelink Pro

Plugin Slug
perelink

Vulnerability
Cross Site Request Forgery (CSRF)

Patched in Version
No Fix

Severity Score
Medium

The vulnerability has not been patched and the plugin is closed. You should uninstall and delete the plugin.

Quasar form

Plugin
Quasar form

Plugin Slug
quasar-form

Vulnerability
SQL Injection

Patched in Version
No Fix

Severity Score
High

The vulnerability has not been patched and the plugin is closed. You should uninstall and delete the plugin.

Saphali Woocommerce Lite

Plugin
Saphali Woocommerce Lite

Plugin Slug
saphali-woocommerce-lite

Vulnerability
Cross Site Request Forgery (CSRF)

Patched in Version
No Fix

Severity Score
Medium

The vulnerability has not been patched and the plugin is closed. You should uninstall and delete the plugin.

Simple Googlebot Visit

Plugin
Simple Googlebot Visit

Plugin Slug
simple-googlebot-visit

Vulnerability
Broken Access Control

Patched in Version
No Fix

Severity Score
Medium

The vulnerability has not been patched and the plugin is closed. You should uninstall and delete the plugin.

Simple Wp Sitemap

Plugin
Simple Wp Sitemap

Plugin Slug
simple-wp-sitemap

Vulnerability
Cross Site Request Forgery (CSRF)

Patched in Version
No Fix

Severity Score
Medium

The vulnerability has not been patched and the plugin is closed. You should uninstall and delete the plugin.

Slider Carousel – Responsive Image Slider

Plugin
Slider Carousel – Responsive Image Slider

Plugin Slug
slider-images

Vulnerability
Broken Access Control

Patched in Version
No Fix

Severity Score
Medium

The vulnerability has not been patched and the plugin is closed. You should uninstall and delete the plugin.

Donations Made Easy – Smart Donations

Plugin
Donations Made Easy – Smart Donations

Plugin Slug
smart-donations

Vulnerability
Broken Access Control

Patched in Version
No Fix

Severity Score
Medium

The vulnerability has not been patched and the plugin is closed. You should uninstall and delete the plugin.

Taboola

Plugin
Taboola

Plugin Slug
taboola

Vulnerability
Cross Site Request Forgery (CSRF)

Patched in Version
No Fix

Severity Score
Medium

The vulnerability has not been patched and the plugin is closed. You should uninstall and delete the plugin.

tagDiv Composer

Plugin
tagDiv Composer

Plugin Slug
td-composer

Vulnerability
Cross Site Request Forgery (CSRF)

Patched in Version
No Fix

Severity Score
High

The vulnerability has not been patched. You should deactivate the plugin.

Update Theme and Plugins from Zip File

Plugin
Update Theme and Plugins from Zip File

Plugin Slug
update-theme-and-plugins-from-zip-file

Vulnerability
Cross Site Request Forgery (CSRF)

Patched in Version
No Fix

Severity Score
Medium

The vulnerability has not been patched and the plugin is closed. You should uninstall and delete the plugin.

User Email Verification for WooCommerce

Plugin
User Email Verification for WooCommerce

Plugin Slug
woo-confirmation-email

Vulnerability
Cross Site Scripting (XSS)

Patched in Version
No Fix

Severity Score
High

The vulnerability has not been patched and the plugin is closed. You should uninstall and delete the plugin.

WordPress Database Administrator

Plugin
WP Database Administrator

Plugin Slug
wp-database-admin

Vulnerability
SQL Injection

Patched in Version
No Fix

Severity Score
Critical

The vulnerability has not been patched and the plugin is closed. You should uninstall and delete the plugin.

wp tell a friend popup form

Plugin
wp tell a friend popup form

Plugin Slug
wp-tell-a-friend-popup-form

Vulnerability
Cross Site Scripting (XSS)

Patched in Version
No Fix

Severity Score
Medium

The vulnerability has not been patched and the plugin is closed. You should uninstall and delete the plugin.

wp tell a friend popup form

Plugin
wp tell a friend popup form

Plugin Slug
wp-tell-a-friend-popup-form

Vulnerability
Cross Site Request Forgery (CSRF)

Patched in Version
No Fix

Severity Score
Medium

The vulnerability has not been patched and the plugin is closed. You should uninstall and delete the plugin.

WordPress Theme Vulnerabilities

In this section, you’ll find the latest WordPress theme vulnerabilities to be disclosed. You’ll see the same information we provided above for vulnerable plugins, and the same advice applies. If a security update exists, install it immediately. If a vulnerability remains unpatched in a theme you are actively using, you must find an alternative theme. Deactivate and delete persistently unpatched themes and those marked “Closed” in the WordPress.org theme repository. If you have a vulnerable theme installed that you are not actively using, delete it.

nsc

Theme
nsc

Theme Slug
nsc

Vulnerability
Prototype Pollution to Reflected Cross Site Scripting (XSS)

Patched in Version
No Fix

Severity Score
High

The vulnerability has not been patched. You should switch themes.

Winters

Theme
winters

Theme Slug
winters

Vulnerability
Prototype Pollution to Reflected Cross Site Scripting (XSS)

Patched in Version
No Fix

Severity Score
High

The vulnerability has not been patched. You should switch themes.

Your Journey

Theme
yourjourney

Theme Slug
yourjourney

Vulnerability
Prototype Pollution to Reflected Cross Site Scripting (XSS)

Patched in Version
No Fix

Severity Score
High

The vulnerability has not been patched. You should switch themes.
Dan Knauss

Dan Knauss is StellarWP’s Technical Content Generalist. He’s been a writer, teacher, and freelancer working in open source since the late 1990s and with WordPress since 2004.

Source link

Written by:
Abdul Wahid
Published on:
August 5, 2023

Categories: Woocommerce

Primary Sidebar

Wordpress

  • Content Management Systems (2)
  • Digital Marketing (4)
  • Internet Marketing (6)
  • Latest News (458)
  • Online Business (2)
  • Plugins (519)
  • Themes (521)
  • Videos (1,350)
  • Website Development (1)
  • Woocommerce (589)
  • WordPress (6)

Recent Articles

Unlock Your Internet Marketing Success with WordPress: The Ultimate CMS for Achieving Online Goals

WordPress: A Powerhouse for Achieving Internet …

Continue Reading about Unlock Your Internet Marketing Success with WordPress: The Ultimate CMS for Achieving Online Goals

Unlock Your Internet Marketing Potential with WordPress: A Comprehensive Guide

How to Use WordPress to Achieve Your Internet …

Continue Reading about Unlock Your Internet Marketing Potential with WordPress: A Comprehensive Guide

Search our site

Explore more

Get our Wordpress Guide Get Plugins Get Connected

Footer

VirusWord by Promaps, Inc.

Barnes Place
Colombo 7, Western 00700

Copyright © 2025 · Promaps, Inc.

Keep In Touch

  • Email
  • Facebook
  • Instagram
  • Pinterest
  • Twitter