• Skip to primary navigation
  • Skip to main content
  • Skip to primary sidebar

virusword.com

Learn Wordpress

  • Home
  • WordPress Shop
    • Fotopress
    • SEO Tool Kit
    • Social Contact
    • Tag Machine 2
    • Video Profits
  • Latest News
  • WordPress
    • Plugins
    • Themes
    • Tutorials
    • Videos
    • Woocommerce
  • About Us
  • Contact Us
    • Terms of Service
    • Privacy Policy
  • Show Search
Hide Search
Home/Woocommerce/WordPress Vulnerability Report – August 30, 2023

WordPress Vulnerability Report – August 30, 2023

Written by

Dan Knauss

on

August 30, 2023

Last Updated on August 30, 2023

Since last week, 56 total vulnerabilities emerged in public disclosure. They may affect over two million WordPress sites. There are 28 plugin vulnerabilities with security patches, so run those updates!

Additionally, there are 28 plugin vulnerabilities with no patch available yet. If you use an unpatched plugin or theme, check their vendors’ intentions and progress on a security release. Suppose no patch is forthcoming or the vulnerable software has been marked “closed” and dropped from the official WordPress theme and plugin repositories. In that case, you should consider deactivation and removal in favor of alternative solutions.

WordPress Core News

“Lionel” was released on August 8, 2023. This release of WordPress was built to help you “create beautiful and compelling websites more efficiently than ever.” See what’s new in WordPress 6.3.

Don’t forget to fully back up your website before installing WordPress 6.3. BackupBuddy, the industry-leading data protection and recovery solution for WordPress, will help you build a strong backup strategy to manage all updates. Embrace the enhanced content creation experience of WordPress 6.3 with confidence — and a backup copy of your website safely stored on a remote server.

WordPress Core Vulnerabilities — Patched

  • No new WordPress core vulnerabilities were disclosed this week.

WordPress core is very secure when it’s properly configured and maintained. Vulnerable plugins not updated by site owners are the most common vector for attacks on WordPress websites. Our weekly WordPress Vulnerability Report, powered by Patchstack, covers new vulnerabilities that have emerged in plugins, themes, and/or WordPress core since last week’s report. Our goal is to spread awareness of emerging security threats and help you decide what to do if you find vulnerable software on your website. For a deeper analysis of recent trends in WordPress vulnerabilities and threat vectors, see our 2022 Annual Vulnerability Report.

These reports are published every Wednesday and include all active vulnerabilities tracked by Patchstack as of Monday since the previous report. This leaves a 48-hour window for the newest emerging vulnerabilities to be patched before full public disclosure. iThemes Security Pro users have access to vulnerability alerts emerging within this window.

Get the weekly WordPress Vulnerability Report delivered to your inbox each Wednesday.

WordPress Plugin Vulnerabilities — Patched

In this section, you’ll find the most recently disclosed WordPress plugin vulnerabilities fixed with a new release from their authors and maintainers. Please apply the updates if you are affected!

These vulnerabilities have been disclosed and scored for their severity, thanks to our friends at Patchstack. Each plugin listing includes the type of vulnerability with its CVE number and CVSS severity rating with links to more technical details. You’ll also see the number of active sites using the plugin and the plugin version release that patches the vulnerability. We start with the most popular plugins, representing the largest target for attackers.

ElementsKit Lite

Product image for ElementsKit Elementor addons.

Plugin Slug
elementskit-lite

Installations
1,000,000+

Vulnerability
Broken Access Control

Patched in Version
2.9.1

Severity Score
Medium

The vulnerability has been patched, so you should update to version 2.9.1.

Hide My WP Ghost – Security Plugin

Product image for Hide My WP Ghost – Security Plugin.

Plugin Slug
hide-my-wp

Installations
200,000+

Vulnerability
Bypass Vulnerability

Patched in Version
5.0.26

Severity Score
Medium

The vulnerability has been patched, so you should update to version 5.0.26.

Slimstat Analytics

Product image for Slimstat Analytics.

Plugin Slug
wp-slimstat

Installations
100,000+

Vulnerability
Broken Access Control

Patched in Version
5.0.6

Severity Score
Medium

The vulnerability has been patched, so you should update to version 5.0.6.

Slimstat Analytics

Product image for Slimstat Analytics.

Plugin Slug
wp-slimstat

Installations
100,000+

Vulnerability
Cross Site Scripting (XSS)

Patched in Version
5.0.9

Severity Score
Medium

The vulnerability has been patched, so you should update to version 5.0.9.

Folders

Product image for Folders – Unlimited Folders to Organize Media Library Folder, Pages, Posts, File Manager.

Plugin Slug
folders

Installations
60,000+

Vulnerability
Arbitrary File Upload

Patched in Version
2.9.3

Severity Score
Critical

The vulnerability has been patched, so you should update to version 2.9.3.

iThemes Sync

Product image for iThemes Sync.

Plugin Slug
ithemes-sync

Installations
50,000+

Vulnerability
Broken Access Control

Patched in Version
2.1.14

Severity Score
Medium

The vulnerability has been patched, so you should update to version 2.1.14.

FV Flowplayer Video Player

Product image for FV Flowplayer Video Player.

Plugin Slug
fv-wordpress-flowplayer

Installations
30,000+

Vulnerability
Cross Site Scripting (XSS)

Patched in Version
7.5.39.7212

Severity Score
High

The vulnerability has been patched, so you should update to version 7.5.39.7212.

Donation Forms by Charitable

Product image for Donation Forms by Charitable – Donations Plugin & Fundraising Platform for WordPress.

Plugin Slug
charitable

Installations
10,000+

Vulnerability
Privilege Escalation

Patched in Version
1.7.0.13

Severity Score
Critical

The vulnerability has been patched, so you should update to version 1.7.0.13.

ReviewX

Product image for ReviewX – Multi-criteria Rating & Reviews for WooCommerce.

Plugin Slug
reviewx

Installations
10,000+

Vulnerability
Broken Access Control

Patched in Version
1.6.18

Severity Score
Medium

The vulnerability has been patched, so you should update to version 1.6.18.

URL Shortify

Product image for URL Shortify – Simple, Powerful and Easy URL Shortener Plugin For WordPress.

Plugin Slug
url-shortify

Installations
10,000+

Vulnerability
Cross Site Scripting (XSS)

Patched in Version
1.7.6

Severity Score
High

The vulnerability has been patched, so you should update to version 1.7.6.

Min Max Control

Product image for Min Max Control – Min Max Quantity & Step Control for WooCommerce.

Plugin Slug
woo-min-max-quantity-step-control-single

Installations
10,000+

Vulnerability
Cross Site Scripting (XSS)

Patched in Version
4.6

Severity Score
High

The vulnerability has been patched, so you should update to version 4.6.

Category Slider for WooCommerce

Product image for Category Slider for WooCommerce.

Plugin Slug
woo-category-slider-grid

Installations
9,000+

Vulnerability
Broken Access Control

Patched in Version
1.4.16

Severity Score
Medium

The vulnerability has been patched, so you should update to version 1.4.16.

Herd Effects

Product image for Herd Effects – fake notifications and social proof plugin.

Plugin Slug
mwp-herd-effect

Installations
5,000+

Vulnerability
Cross Site Request Forgery (CSRF)

Patched in Version
5.2.4

Severity Score
Medium

The vulnerability has been patched, so you should update to version 5.2.4.

Order Tracking Pro

Product image for Order Tracking – WordPress Status Tracking Plugin.

Plugin Slug
order-tracking

Installations
4,000+

Vulnerability
Cross Site Scripting (XSS)

Patched in Version
3.3.7

Severity Score
Medium

The vulnerability has been patched, so you should update to version 3.3.7.

Order Tracking Pro

Product image for Order Tracking – WordPress Status Tracking Plugin.

Plugin Slug
order-tracking

Installations
4,000+

Vulnerability
Cross Site Scripting (XSS)

Patched in Version
3.3.7

Severity Score
High

The vulnerability has been patched, so you should update to version 3.3.7.

DoLogin Security

Plugin Slug
dologin

Installations
3,000+

Vulnerability
Bypass Vulnerability

Patched in Version
3.7

Severity Score
Medium

The vulnerability has been patched, so you should update to version 3.7.

WooCommerce PDF Invoice Builder

Product image for WooCommerce PDF Invoice Builder, Create invoices, packing slips and more.

Plugin Slug
woo-pdf-invoice-builder

Installations
3,000+

Vulnerability
Broken Access Control

Patched in Version
1.2.92

Severity Score
Medium

The vulnerability has been patched, so you should update to version 1.2.92.

WooCommerce PDF Invoice Builder

Product image for WooCommerce PDF Invoice Builder, Create invoices, packing slips and more.

Plugin Slug
woo-pdf-invoice-builder

Installations
3,000+

Vulnerability
Cross Site Scripting (XSS)

Patched in Version
1.2.91

Severity Score
Medium

The vulnerability has been patched, so you should update to version 1.2.91.

WP Adminify

Product image for WP Adminify – WordPress Dashboard Customization | Custom Login | Admin Columns | Dashboard Widget | Media Library Folders.

Plugin Slug
adminify

Installations
1,000+

Vulnerability
Cross Site Scripting (XSS)

Patched in Version
3.1.6

Severity Score
Medium

The vulnerability has been patched, so you should update to version 3.1.6.

Premmerce User Roles

Product image for Premmerce User Roles.

Plugin Slug
premmerce-user-roles

Installations
1,000+

Vulnerability
Broken Access Control

Patched in Version
1.0.13

Severity Score
High

The vulnerability has been patched, so you should update to version 1.0.13.

Save as PDF plugin by Pdfcrowd

Plugin Slug
save-as-pdf-by-pdfcrowd

Installations
1,000+

Vulnerability
Cross Site Scripting (XSS)

Patched in Version
2.16.1

Severity Score
Medium

The vulnerability has been patched, so you should update to version 2.16.1.

Event Tickets with Ticket Scanner

Product image for Event Tickets with Ticket Scanner.

Plugin Slug
event-tickets-with-ticket-scanner

Installations
600+

Vulnerability
Cross Site Scripting (XSS)

Patched in Version
1.5.5

Severity Score
Medium

The vulnerability has been patched, so you should update to version 1.5.5.

Push Notification for Post and BuddyPress

Plugin Slug
push-notification-for-post-and-buddypress

Installations
200+

Vulnerability
Broken Access Control

Patched in Version
1.64

Severity Score
Medium

The vulnerability has been patched, so you should update to version 1.64.

WP VK-??????

Product image for WP VK-???????????/??/?????????.

Plugin Slug
wp-vk

Installations
100+

Vulnerability
Cross Site Request Forgery (CSRF)

Patched in Version
1.3.4

Severity Score
Medium

The vulnerability has been patched, so you should update to version 1.3.4.

Save as Image plugin by Pdfcrowd

Plugin Slug
save-as-image-by-pdfcrowd

Installations
30+

Vulnerability
Cross Site Scripting (XSS)

Patched in Version
2.16.1

Severity Score
Medium

The vulnerability has been patched, so you should update to version 2.16.1.

Appointment booking addon for Gravity Forms

Plugin
gAppointments

Plugin Slug
gAppointments

Vulnerability
Cross Site Scripting (XSS)

Patched in Version
1.10.0

Severity Score
High

The vulnerability has been patched, so you should update to version 1.10.0.

Jupiter X Core

Plugin
JupiterX Core

Plugin Slug
jupiterx-core

Vulnerability
Arbitrary File Upload

Patched in Version
3.3.8

Severity Score
Critical

The vulnerability has been patched, so you should update to version 3.3.8.

Jupiter X Core

Plugin
JupiterX Core

Plugin Slug
jupiterx-core

Vulnerability
Privilege Escalation

Patched in Version
3.4.3

Severity Score
Critical

The vulnerability has been patched, so you should update to version 3.4.3.

WordPress Plugin Vulnerabilities — Unpatched

This section contains plugin vulnerabilities with no known fix. Until a patch is available, you are advised to deactivate the plugin, at minimum, immediately. If there is a high risk of active exploits or the plugin remains unpatched for weeks, you are advised to delete the plugin. You should also delete persistently unpatched plugins the WordPress.org repository has locked and marked “Closed” so they can no longer be downloaded and installed.

Royal Elementor Addons

Product image for Royal Elementor Addons and Templates.

Plugin Slug
royal-elementor-addons

Installations
200,000+

Vulnerability
Cross Site Request Forgery (CSRF)

Patched in Version
No Fix

Severity Score
Medium

The vulnerability has not been patched. You should deactivate the plugin.

Post and Page Builder by BoldGrid

Product image for Post and Page Builder by BoldGrid – Visual Drag and Drop Editor.

Plugin Slug
post-and-page-builder

Installations
100,000+

Vulnerability
Cross Site Request Forgery (CSRF)

Patched in Version
No Fix

Severity Score
Medium

The vulnerability has not been patched. You should deactivate the plugin.

Collapse-O-Matic

Product image for Collapse-O-Matic.

Plugin Slug
jquery-collapse-o-matic

Installations
60,000+

Vulnerability
Cross Site Scripting (XSS)

Patched in Version
No Fix

Severity Score
Medium

The vulnerability has not been patched. You should deactivate the plugin.

Master Elementor Addons

Product image for Master Addons for Elementor.

Plugin Slug
master-addons

Installations
40,000+

Vulnerability
Broken Access Control

Patched in Version
No Fix

Severity Score
Medium

The vulnerability has not been patched. You should deactivate the plugin.

Ultimate Addons for Contact Form 7

Product image for Ultimate Addons for Contact Form 7.

Plugin Slug
ultimate-addons-for-contact-form-7

Installations
20,000+

Vulnerability
Cross Site Scripting (XSS)

Patched in Version
No Fix

Severity Score
High

The vulnerability has not been patched. You should deactivate the plugin.

URL Shortener by MyThemeShop

Product image for URL Shortener by MyThemeShop.

Plugin Slug
mts-url-shortener

Installations
10,000+

Vulnerability
Cross Site Scripting (XSS)

Patched in Version
No Fix

Severity Score
High

The vulnerability has not been patched. You should deactivate the plugin.

Landing Page Builder

Product image for Landing Page Builder – Lead Page – Optin Page – Squeeze Page – WordPress Landing Pages.

Plugin Slug
page-builder-add

Installations
10,000+

Vulnerability
Cross Site Scripting (XSS)

Patched in Version
No Fix

Severity Score
Medium

The vulnerability has not been patched. You should deactivate the plugin.

WP Super Minify

Product image for WP Super Minify.

Plugin Slug
wp-super-minify

Installations
10,000+

Vulnerability
Cross Site Request Forgery (CSRF)

Patched in Version
No Fix

Severity Score
Medium

The vulnerability has not been patched. You should deactivate the plugin.

Easy Coming Soon

Product image for Easy Coming Soon.

Plugin Slug
easy-coming-soon

Installations
7,000+

Vulnerability
Cross Site Scripting (XSS)

Patched in Version
No Fix

Severity Score
Medium

The vulnerability has not been patched. You should deactivate the plugin.

LuckyWP Scripts Control

Product image for LuckyWP Scripts Control.

Plugin Slug
luckywp-scripts-control

Installations
6,000+

Vulnerability
Broken Access Control

Patched in Version
No Fix

Severity Score
Medium

The vulnerability has not been patched. You should deactivate the plugin.

Social Share Boost

Plugin Slug
social-share-boost

Installations
6,000+

Vulnerability
Cross Site Request Forgery (CSRF)

Patched in Version
No Fix

Severity Score
Medium

The vulnerability has not been patched. You should deactivate the plugin.

MakeStories (for Google Web Stories)

Product image for MakeStories (for Google Web Stories).

Plugin Slug
makestories-helper

Installations
5,000+

Vulnerability
Cross Site Request Forgery (CSRF)

Patched in Version
No Fix

Severity Score
Medium

The vulnerability has not been patched. You should deactivate the plugin.

Simple URLs

Product image for Simple URLs – Link Cloaking, Product Displays, and Affiliate Link Management.

Plugin Slug
simple-urls

Installations
5,000+

Vulnerability
Broken Access Control

Patched in Version
No Fix

Severity Score
Medium

The vulnerability has not been patched. You should deactivate the plugin.

Simple URLs

Product image for Simple URLs – Link Cloaking, Product Displays, and Affiliate Link Management.

Plugin Slug
simple-urls

Installations
5,000+

Vulnerability
Cross Site Scripting (XSS)

Patched in Version
No Fix

Severity Score
Medium

The vulnerability has not been patched. You should deactivate the plugin.

Simple URLs

Product image for Simple URLs – Link Cloaking, Product Displays, and Affiliate Link Management.

Plugin Slug
simple-urls

Installations
5,000+

Vulnerability
Cross Site Scripting (XSS)

Patched in Version
No Fix

Severity Score
High

The vulnerability has not been patched. You should deactivate the plugin.

Vertical Marquee Plugin

Product image for Vertical marquee plugin.

Plugin Slug
vertical-marquee-plugin

Installations
4,000+

Vulnerability
Cross Site Scripting (XSS)

Patched in Version
No Fix

Severity Score
Medium

The vulnerability has not been patched. You should deactivate the plugin.

WP users media

Plugin Slug
wp-users-media

Installations
4,000+

Vulnerability
Broken Access Control

Patched in Version
No Fix

Severity Score
Medium

The vulnerability has not been patched. You should deactivate the plugin.

WP Search Analytics

Product image for WP Search Analytics.

Plugin Slug
search-analytics

Installations
2,000+

Vulnerability
Cross Site Scripting (XSS)

Patched in Version
No Fix

Severity Score
High

The vulnerability has not been patched. You should deactivate the plugin.

Sitekit

Product image for Sitekit.

Plugin Slug
sitekit

Installations
2,000+

Vulnerability
Cross Site Scripting (XSS)

Patched in Version
No Fix

Severity Score
Medium

The vulnerability has not been patched. You should deactivate the plugin.

Olive One Click Demo Import

Product image for Olive One Click Demo Import.

Plugin Slug
olive-one-click-demo-import

Installations
1,000+

Vulnerability
Arbitrary File Upload

Patched in Version
No Fix

Severity Score
Critical

The vulnerability has not been patched. You should deactivate the plugin.

Secure Admin IP

Product image for Secure Admin IP.

Plugin Slug
secure-admin-ip

Installations
1,000+

Vulnerability
Broken Access Control

Patched in Version
No Fix

Severity Score
Medium

The vulnerability has not been patched. You should deactivate the plugin.

Cartpauj Register Captcha

Plugin
Cartpauj Register Captcha

Plugin Slug
cartpauj-register-captcha

Vulnerability
Bypass Vulnerability

Patched in Version
No Fix

Severity Score
Medium

The vulnerability has not been patched and the plugin is closed. You should uninstall and delete the plugin.

DX-auto-save-images

Plugin
DX-auto-save-images

Plugin Slug
dx-auto-save-images

Vulnerability
Cross Site Request Forgery (CSRF)

Patched in Version
No Fix

Severity Score
Medium

The vulnerability has not been patched and the plugin is closed. You should uninstall and delete the plugin.

FTP Access

Plugin
FTP Access

Plugin Slug
ftp-access

Vulnerability
Cross Site Scripting (XSS)

Patched in Version
No Fix

Severity Score
Medium

The vulnerability has not been patched and the plugin is closed. You should uninstall and delete the plugin.

GuruWalk Affiliates

Plugin Slug
guruwalk-affiliates

Vulnerability
Cross Site Scripting (XSS)

Patched in Version
No Fix

Severity Score
Medium

The vulnerability has not been patched. You should deactivate the plugin.

Lock User Account

Plugin
Lock User Account

Plugin Slug
lock-user-account

Vulnerability
Cross Site Request Forgery (CSRF)

Patched in Version
No Fix

Severity Score
Medium

The vulnerability has not been patched and the plugin is closed. You should uninstall and delete the plugin.

Maintenance Switch

Plugin
Maintenance Switch

Plugin Slug
maintenance-switch

Vulnerability
Cross Site Request Forgery (CSRF)

Patched in Version
No Fix

Severity Score
Medium

The vulnerability has not been patched and the plugin is closed. You should uninstall and delete the plugin.

Sticky Social Media Icons

Plugin
Sticky Social Media Icons

Plugin Slug
sticky-social-media-icons

Vulnerability
Broken Access Control

Patched in Version
No Fix

Severity Score
Medium

The vulnerability has not been patched and the plugin is closed. You should uninstall and delete the plugin.

WordPress Theme Vulnerabilities

In this section, you’ll find the latest WordPress theme vulnerabilities to be disclosed. You’ll see the same information we provided above for vulnerable plugins, and the same advice applies. If a security update exists, install it immediately. If a vulnerability remains unpatched in a theme you are actively using, you must find an alternative theme. Deactivate and delete persistently unpatched themes and those marked “Closed” in the WordPress.org theme repository. If you have a vulnerable theme installed that you are not actively using, delete it.

  • No new WordPress theme vulnerabilities were disclosed this week.
Dan Knauss

Dan Knauss is StellarWP’s Technical Content Generalist. He’s been a writer, teacher, and freelancer working in open source since the late 1990s and with WordPress since 2004.

Source link

Written by:
Abdul Wahid
Published on:
September 4, 2023

Categories: Woocommerce

Primary Sidebar

Wordpress

  • Content Management Systems (2)
  • Digital Marketing (4)
  • Internet Marketing (28)
  • Latest News (458)
  • Online Business (2)
  • Plugins (519)
  • Themes (521)
  • Videos (1,350)
  • Website Development (1)
  • Woocommerce (589)
  • WordPress (6)

Recent Articles

Unlock Your Internet Marketing Potential with WordPress: Tips, Tools, and Strategies

How to Use WordPress to Achieve Your Internet …

Continue Reading about Unlock Your Internet Marketing Potential with WordPress: Tips, Tools, and Strategies

Unlock Your Internet Marketing Potential: Harnessing the Power of WordPress

How to Use WordPress to Achieve Your Internet …

Continue Reading about Unlock Your Internet Marketing Potential: Harnessing the Power of WordPress

Search our site

Explore more

Get our Wordpress Guide Get Plugins Get Connected

Footer

VirusWord by Promaps, Inc.

Barnes Place
Colombo 7, Western 00700

Copyright © 2025 · Promaps, Inc.

Keep In Touch

  • Email
  • Facebook
  • Instagram
  • Pinterest
  • Twitter