• Skip to primary navigation
  • Skip to main content
  • Skip to primary sidebar

virusword.com-Wordpress

Learn Wordpress

  • Home
  • WordPress Shop
    • Fotopress
    • SEO Tool Kit
    • Social Contact
    • Tag Machine 2
    • Video Profits
  • Latest News
  • WordPress
    • Plugins
    • Themes
    • Tutorials
    • Videos
    • Woocommerce
  • About Us
  • Contact Us
    • Terms of Service
    • Privacy Policy
  • Show Search
Hide Search
Home/Woocommerce/WordPress Vulnerability Report – August 16, 2023

WordPress Vulnerability Report – August 16, 2023

Written by

Dan Knauss

on

August 16, 2023

Last Updated on August 16, 2023

Since last week, 90 total vulnerabilities emerged in public disclosure. They may affect over one million WordPress sites. There are 49 plugin vulnerabilities and five theme vulnerabilities with security patches, so run those updates!

Additionally, there are 35 plugin vulnerabilities and one theme vulnerability with no patch available yet. If you use an unpatched plugin or theme, check their vendors’ intentions and progress on a security release. Suppose no patch is forthcoming or the vulnerable software has been marked “closed” and dropped from the official WordPress theme and plugin repositories. In that case, you should consider deactivation and removal in favor of alternative solutions.

WordPress Core News

WordPress 6.3 “Lionel” is out! This new release of WordPress was built to help you “create beautiful and compelling websites more efficiently than ever.” See what’s new in WordPress 6.3.

Don’t forget to fully back up your website before installing WordPress 6.3. BackupBuddy, the industry-leading data protection and recovery solution for WordPress, will help you build a strong backup strategy to manage all updates. Embrace the enhanced content creation experience of WordPress 6.3 with confidence — and a backup copy of your website safely stored on a remote server.

WordPress Core Vulnerabilities — Patched

  • No new WordPress core vulnerabilities were disclosed this week.

WordPress core is very secure when it’s properly configured and maintained. Vulnerable plugins not updated by site owners are the most common vector for attacks on WordPress websites. Our weekly WordPress Vulnerability Report, powered by Patchstack, covers new vulnerabilities that have emerged in plugins, themes, and/or WordPress core since last week’s report. Our goal is to spread awareness of emerging security threats and help you decide what to do if you find vulnerable software on your website. For a deeper analysis of recent trends in WordPress vulnerabilities and threat vectors, see our 2022 Annual Vulnerability Report.

These reports are published every Wednesday and include all active vulnerabilities tracked by Patchstack as of Monday since the previous report. This leaves a 48-hour window for the newest emerging vulnerabilities to be patched before full public disclosure. iThemes Security Pro users have access to vulnerability alerts emerging within this window.

Get the weekly WordPress Vulnerability Report delivered to your inbox each Wednesday.

WordPress Plugin Vulnerabilities — Patched

In this section, you’ll find the most recently disclosed WordPress plugin vulnerabilities fixed with a new release from their authors and maintainers. Please apply the updates if you are affected!

These vulnerabilities have been disclosed and scored for their severity, thanks to our friends at Patchstack. Each plugin listing includes the type of vulnerability with its CVE number and CVSS severity rating with links to more technical details. You’ll also see the number of active sites using the plugin and the plugin version release that patches the vulnerability. We start with the most popular plugins, representing the largest target for attackers.

Header Footer Code Manager

Product image for Header Footer Code Manager.

Plugin Slug
header-footer-code-manager

Installations
400,000+

Vulnerability
Cross Site Request Forgery (CSRF)

Patched in Version
1.1.35

Severity Score
Medium

The vulnerability has been patched, so you should update to version 1.1.35.

Gutenberg Blocks by Kadence Blocks – Page Builder

Product image for Gutenberg Blocks by Kadence Blocks – Page Builder Features.

Plugin Slug
kadence-blocks

Installations
300,000+

Vulnerability
Arbitrary File Upload

Patched in Version
3.1.11

Severity Score
Critical

The vulnerability has been patched, so you should update to version 3.1.11.

Ultimate Member

Product image for Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin.

Plugin Slug
ultimate-member

Installations
200,000+

Vulnerability
Cross Site Request Forgery (CSRF)

Patched in Version
2.6.9

Severity Score
Medium

The vulnerability has been patched, so you should update to version 2.6.9.

EmbedPress

Product image for EmbedPress – Embed PDF, YouTube, Google Docs, Vimeo, Wistia Videos, Audios, Maps & Any Documents in Gutenberg & Elementor.

Plugin Slug
embedpress

Installations
80,000+

Vulnerability
Cross Site Scripting (XSS)

Patched in Version
3.8.3

Severity Score
Medium

The vulnerability has been patched, so you should update to version 3.8.3.

EmbedPress

Product image for EmbedPress – Embed PDF, YouTube, Google Docs, Vimeo, Wistia Videos, Audios, Maps & Any Documents in Gutenberg & Elementor.

Plugin Slug
embedpress

Installations
80,000+

Vulnerability
Broken Access Control

Patched in Version
3.8.3

Severity Score
Medium

The vulnerability has been patched, so you should update to version 3.8.3.

The Post Grid

Product image for The Post Grid – Shortcode, Gutenberg Blocks and Elementor Addon for Post Grid.

Plugin Slug
the-post-grid

Installations
60,000+

Vulnerability
Cross Site Request Forgery (CSRF)

Patched in Version
7.2.8

Severity Score
Medium

The vulnerability has been patched, so you should update to version 7.2.8.

Post Grid Combo

Product image for Post Grid Combo – 36+ Blocks for Gutenberg.

Plugin Slug
post-grid

Installations
50,000+

Vulnerability
Sensitive Data Exposure

Patched in Version
2.2.51

Severity Score
High

The vulnerability has been patched, so you should update to version 2.2.51.

Profile Builder

Product image for Profile Builder – User Profile & User Registration Forms.

Plugin Slug
profile-builder

Installations
50,000+

Vulnerability
Broken Access Control

Patched in Version
3.9.8

Severity Score
Medium

The vulnerability has been patched, so you should update to version 3.9.8.

Chatbot

Product image for AI Engine: ChatGPT Chatbot, Content Generator, GPT 3 & 4, Ultra-Customizable.

Plugin Slug
ai-engine

Installations
30,000+

Vulnerability
Cross Site Scripting (XSS)

Patched in Version
4.7.8

Severity Score
Medium

The vulnerability has been patched, so you should update to version 4.7.8.

Chatbot

Product image for AI Engine: ChatGPT Chatbot, Content Generator, GPT 3 & 4, Ultra-Customizable.

Plugin Slug
ai-engine

Installations
30,000+

Vulnerability
Cross Site Scripting (XSS)

Patched in Version
4.7.8

Severity Score
Medium

The vulnerability has been patched, so you should update to version 4.7.8.

Popup by Supsystic

Product image for Popup by Supsystic.

Plugin Slug
popup-by-supsystic

Installations
20,000+

Vulnerability
Broken Access Control

Patched in Version
1.10.20

Severity Score
Medium

The vulnerability has been patched, so you should update to version 1.10.20.

Themesflat Addons For Elementor

Product image for Themesflat Addons For Elementor.

Plugin Slug
themesflat-addons-for-elementor

Installations
20,000+

Vulnerability
PHP Object Injection

Patched in Version
2.0.1

Severity Score
High

The vulnerability has been patched, so you should update to version 2.0.1.

Booking Package

Product image for Booking Package.

Plugin Slug
booking-package

Installations
10,000+

Vulnerability
Cross Site Scripting (XSS)

Patched in Version
1.6.02

Severity Score
High

The vulnerability has been patched, so you should update to version 1.6.02.

Justified Gallery

Product image for Justified Gallery.

Plugin Slug
justified-gallery

Installations
10,000+

Vulnerability
Broken Access Control

Patched in Version
1.8.0

Severity Score
Medium

The vulnerability has been patched, so you should update to version 1.8.0.

Qubely

Product image for Qubely – Advanced Gutenberg Blocks.

Plugin Slug
qubely

Installations
10,000+

Vulnerability
Broken Access Control

Patched in Version
1.8.6

Severity Score
Medium

The vulnerability has been patched, so you should update to version 1.8.6.

User Activity Log

Product image for User Activity Log.

Plugin Slug
user-activity-log

Installations
10,000+

Vulnerability
Broken Access Control

Patched in Version
1.6.6

Severity Score
Medium

The vulnerability has been patched, so you should update to version 1.6.6.

WP Project Manager

Product image for WP Project Manager – Task, team, and project management plugin featuring kanban board and gantt charts.

Plugin Slug
wedevs-project-manager

Installations
10,000+

Vulnerability
Broken Access Control

Patched in Version
2.6.5

Severity Score
High

The vulnerability has been patched, so you should update to version 2.6.5.

Premium Packages

Product image for Premium Packages – Sell Digital Products Securely.

Plugin Slug
wpdm-premium-packages

Installations
5,000+

Vulnerability
Privilege Escalation

Patched in Version
5.7.5

Severity Score
High

The vulnerability has been patched, so you should update to version 5.7.5.

Stock Ticker

Product image for Stock Ticker.

Plugin Slug
stock-ticker

Installations
4,000+

Vulnerability
Cross Site Scripting (XSS)

Patched in Version
3.23.4

Severity Score
High

The vulnerability has been patched, so you should update to version 3.23.4.

Stock Ticker

Product image for Stock Ticker.

Plugin Slug
stock-ticker

Installations
4,000+

Vulnerability
Cross Site Scripting (XSS)

Patched in Version
3.23.3

Severity Score
High

The vulnerability has been patched, so you should update to version 3.23.3.

Accordion and Accordion Slider

Product image for Accordion and Accordion Slider.

Plugin Slug
accordion-and-accordion-slider

Installations
3,000+

Vulnerability
Broken Access Control

Patched in Version
1.2.5

Severity Score
Medium

The vulnerability has been patched, so you should update to version 1.2.5.

Online Booking & Scheduling Calendar for WordPress by vcita

Product image for Online Booking & Scheduling Calendar for WordPress by vcita.

Plugin Slug
meeting-scheduler-by-vcita

Installations
3,000+

Vulnerability
Cross Site Scripting (XSS)

Patched in Version
4.3.3

Severity Score
High

The vulnerability has been patched, so you should update to version 4.3.3.

Paid Memberships Pro

Product image for Premium Courses & eLearning with Paid Memberships Pro for LearnDash, LifterLMS, Sensei LMS & TutorLMS.

Plugin Slug
pmpro-courses

Installations
3,000+

Vulnerability
Broken Access Control

Patched in Version
1.2.4

Severity Score
Medium

The vulnerability has been patched, so you should update to version 1.2.4.

Paid Memberships Pro

Product image for Premium Courses & eLearning with Paid Memberships Pro for LearnDash, LifterLMS, Sensei LMS & TutorLMS.

Plugin Slug
pmpro-courses

Installations
3,000+

Vulnerability
Cross Site Scripting (XSS)

Patched in Version
1.2.5

Severity Score
Medium

The vulnerability has been patched, so you should update to version 1.2.5.

User Activity Tracking and Log

Product image for User Activity Tracking and Log.

Plugin Slug
user-activity-tracking-and-log

Installations
3,000+

Vulnerability
Cross Site Request Forgery (CSRF)

Patched in Version
4.0.9

Severity Score
Medium

The vulnerability has been patched, so you should update to version 4.0.9.

WooCommerce PDF Invoice Builder

Product image for WooCommerce PDF Invoice Builder, Create invoices, packing slips and more.

Plugin Slug
woo-pdf-invoice-builder

Installations
3,000+

Vulnerability
SQL Injection

Patched in Version
1.2.90

Severity Score
High

The vulnerability has been patched, so you should update to version 1.2.90.

WooCommerce PDF Invoice Builder

Product image for WooCommerce PDF Invoice Builder, Create invoices, packing slips and more.

Plugin Slug
woo-pdf-invoice-builder

Installations
3,000+

Vulnerability
Cross Site Request Forgery (CSRF)

Patched in Version
1.2.91

Severity Score
Medium

The vulnerability has been patched, so you should update to version 1.2.91.

ImageRecycle pdf & image compression

Product image for ImageRecycle pdf & image compression.

Plugin Slug
imagerecycle-pdf-image-compression

Installations
2,000+

Vulnerability
Cross Site Scripting (XSS)

Patched in Version
3.1.12

Severity Score
High

The vulnerability has been patched, so you should update to version 3.1.12.

ImageRecycle pdf & image compression

Product image for ImageRecycle pdf & image compression.

Plugin Slug
imagerecycle-pdf-image-compression

Installations
2,000+

Vulnerability
Cross Site Scripting (XSS)

Patched in Version
3.1.11

Severity Score
High

The vulnerability has been patched, so you should update to version 3.1.11.

Leyka

Product image for Leyka.

Plugin Slug
leyka

Installations
2,000+

Vulnerability
Cross Site Scripting (XSS)

Patched in Version
3.30.3

Severity Score
High

The vulnerability has been patched, so you should update to version 3.30.3.

Portfolio and Projects

Product image for Portfolio and Projects.

Plugin Slug
portfolio-and-projects

Installations
2,000+

Vulnerability
Broken Access Control

Patched in Version
1.3.8

Severity Score
Medium

The vulnerability has been patched, so you should update to version 1.3.8.

WP Testimonials

Product image for WP Testimonials.

Plugin Slug
testimonial-widgets

Installations
2,000+

Vulnerability
Cross Site Request Forgery (CSRF)

Patched in Version
1.4.3

Severity Score
Medium

The vulnerability has been patched, so you should update to version 1.4.3.

Atarim

Product image for Visual Website Collaboration, Feedback & Project Management – Atarim.

Plugin Slug
atarim-visual-collaboration

Installations
1,000+

Vulnerability
Cross Site Scripting (XSS)

Patched in Version
3.9.4

Severity Score
High

The vulnerability has been patched, so you should update to version 3.9.4.

Bubble Menu

Product image for Bubble Menu – circle floating menu.

Plugin Slug
bubble-menu

Installations
1,000+

Vulnerability
Cross Site Scripting (XSS)

Patched in Version
3.0.5

Severity Score
Medium

The vulnerability has been patched, so you should update to version 3.0.5.

Photo Gallery by Ays – Responsive Image Gallery

Product image for Photo Gallery by Ays – Responsive Image Gallery.

Plugin Slug
gallery-photo-gallery

Installations
1,000+

Vulnerability
Cross Site Request Forgery (CSRF)

Patched in Version
5.2.7

Severity Score
Medium

The vulnerability has been patched, so you should update to version 5.2.7.

POEditor

Product image for POEditor.

Plugin Slug
poeditor

Installations
1,000+

Vulnerability
Cross Site Request Forgery (CSRF)

Patched in Version
0.9.8

Severity Score
Medium

The vulnerability has been patched, so you should update to version 0.9.8.

Sign-up Sheets

Product image for Sign-up Sheets.

Plugin Slug
sign-up-sheets

Installations
1,000+

Vulnerability
Cross Site Request Forgery (CSRF)

Patched in Version
2.2.9

Severity Score
Medium

The vulnerability has been patched, so you should update to version 2.2.9.

Post Timeline

Product image for Post Timeline.

Plugin Slug
post-timeline

Installations
800+

Vulnerability
Cross Site Scripting (XSS)

Patched in Version
2.2.6

Severity Score
High

The vulnerability has been patched, so you should update to version 2.2.6.

wpShopGermany – Protected Shops

Plugin Slug
wpshopgermany-protectedshops

Installations
40+

Vulnerability
Cross Site Scripting (XSS)

Patched in Version
2.1

Severity Score
Medium

The vulnerability has been patched, so you should update to version 2.1.

Advanced Custom Fields Pro premium

Plugin
Advanced Custom Fields PRO

Plugin Slug
advanced-custom-fields-pro

Vulnerability
Cross Site Scripting (XSS)

Patched in Version
6.1.8

Severity Score
Medium

The vulnerability has been patched, so you should update to version 6.1.8.

ARMember Premium

Plugin
ARMember Premium

Plugin Slug
armember

Vulnerability
Broken Access Control

Patched in Version
5.9.3

Severity Score
Medium

The vulnerability has been patched, so you should update to version 5.9.3.

Biometric Login for WooCommerce

Plugin
Biometric Login for WooCommerce

Plugin Slug
biometric-login-for-woocommerce

Vulnerability
Privilege Escalation

Patched in Version
1.0.4

Severity Score
Critical

The vulnerability has been patched, so you should update to version 1.0.4.

Avada Builder

Plugin
Fusion Builder

Plugin Slug
fusion-builder

Vulnerability
Cross Site Scripting (XSS)

Patched in Version
3.11.2

Severity Score
High

The vulnerability has been patched, so you should update to version 3.11.2.

Avada Builder

Plugin
Fusion Builder

Plugin Slug
fusion-builder

Vulnerability
Cross Site Request Forgery (CSRF)

Patched in Version
3.11.2

Severity Score
High

The vulnerability has been patched, so you should update to version 3.11.2.

Avada Builder

Plugin
Fusion Builder

Plugin Slug
fusion-builder

Vulnerability
Broken Access Control

Patched in Version
3.11.2

Severity Score
Medium

The vulnerability has been patched, so you should update to version 3.11.2.

Avada Builder

Plugin
Fusion Builder

Plugin Slug
fusion-builder

Vulnerability
SQL Injection

Patched in Version
3.11.2

Severity Score
High

The vulnerability has been patched, so you should update to version 3.11.2.

Jupiter X Core

Plugin
JupiterX Core

Plugin Slug
jupiterx-core

Vulnerability
Broken Access Control

Patched in Version
3.3.5

Severity Score
Medium

The vulnerability has been patched, so you should update to version 3.3.5.

Jupiter X Core

Plugin
JupiterX Core

Plugin Slug
jupiterx-core

Vulnerability
Broken Access Control

Patched in Version
3.3.5

Severity Score
High

The vulnerability has been patched, so you should update to version 3.3.5.

WooCommerce One Page Checkout

Plugin
WooCommerce One Page Checkout

Plugin Slug
woocommerce-one-page-checkout

Vulnerability
Local File Inclusion

Patched in Version
2.4.0

Severity Score
High

The vulnerability has been patched, so you should update to version 2.4.0.

WordPress Plugin Vulnerabilities — Unpatched

This section contains plugin vulnerabilities with no known fix. Until a patch is available, you are advised to deactivate the plugin, at minimum, immediately. If there is a high risk of active exploits or the plugin remains unpatched for weeks, you are advised to delete the plugin. You should also delete persistently unpatched plugins the WordPress.org repository has locked and marked “Closed” so they can no longer be downloaded and installed.

Printful Integration for WooCommerce

Product image for Printful Integration for WooCommerce.

Plugin Slug
printful-shipping-for-woocommerce

Installations
60,000+

Vulnerability
Broken Access Control

Patched in Version
No Fix

Severity Score
Medium

The vulnerability has not been patched. You should deactivate the plugin.

WP 404 Auto Redirect to Similar Post

Product image for WP 404 Auto Redirect to Similar Post.

Plugin Slug
wp-404-auto-redirect-to-similar-post

Installations
50,000+

Vulnerability
Cross Site Scripting (XSS)

Patched in Version
No Fix

Severity Score
Medium

The vulnerability has not been patched. You should deactivate the plugin.

MailChimp Forms by MailMunch

Product image for MailChimp Forms by MailMunch.

Plugin Slug
mailchimp-forms-by-mailmunch

Installations
30,000+

Vulnerability
Broken Access Control

Patched in Version
No Fix

Severity Score
Medium

The vulnerability has not been patched. You should deactivate the plugin.

flowpaper

Product image for flowpaper.

Plugin Slug
flowpaper-lite-pdf-flipbook

Installations
20,000+

Vulnerability
Cross Site Scripting (XSS)

Patched in Version
No Fix

Severity Score
Medium

The vulnerability has not been patched. You should deactivate the plugin.

Futurio Extra

Product image for Futurio Extra.

Plugin Slug
futurio-extra

Installations
20,000+

Vulnerability
Cross Site Request Forgery (CSRF)

Patched in Version
No Fix

Severity Score
Medium

The vulnerability has not been patched. You should deactivate the plugin.

Email Template Designer – WP HTML Mail

Product image for Email Template Designer – WP HTML Mail.

Plugin Slug
wp-html-mail

Installations
20,000+

Vulnerability
Cross Site Request Forgery (CSRF)

Patched in Version
No Fix

Severity Score
Medium

The vulnerability has not been patched. You should deactivate the plugin.

PixTypes

Plugin Slug
pixtypes

Installations
10,000+

Vulnerability
Cross Site Scripting (XSS)

Patched in Version
No Fix

Severity Score
High

The vulnerability has not been patched. You should deactivate the plugin.

Theme Demo Import

Product image for Theme Demo Import.

Plugin Slug
theme-demo-import

Installations
10,000+

Vulnerability
Arbitrary File Upload

Patched in Version
No Fix

Severity Score
Critical

The vulnerability has not been patched. You should deactivate the plugin.

WP Categories Widget

Product image for WP Categories Widget.

Plugin Slug
wp-categories-widget

Installations
8,000+

Vulnerability
Cross Site Scripting (XSS)

Patched in Version
No Fix

Severity Score
High

The vulnerability has not been patched. You should deactivate the plugin.

Product Attachment for WooCommerce

Product image for Product Attachment for WooCommerce.

Plugin Slug
woo-product-attachment

Installations
6,000+

Vulnerability
Cross Site Request Forgery (CSRF)

Patched in Version
No Fix

Severity Score
Medium

The vulnerability has not been patched. You should deactivate the plugin.

SendPress Newsletters

Product image for SendPress Newsletters.

Plugin Slug
sendpress

Installations
5,000+

Vulnerability
Broken Access Control

Patched in Version
No Fix

Severity Score
Medium

The vulnerability has not been patched. You should deactivate the plugin.

YITH WooCommerce Waitlist

Product image for YITH WooCommerce Waitlist.

Plugin Slug
yith-woocommerce-waiting-list

Installations
5,000+

Vulnerability
Broken Access Control

Patched in Version
No Fix

Severity Score
Medium

The vulnerability has not been patched. You should deactivate the plugin.

BigBlueButton

Product image for BigBlueButton.

Plugin Slug
bigbluebutton

Installations
4,000+

Vulnerability
Cross Site Scripting (XSS)

Patched in Version
No Fix

Severity Score
High

The vulnerability has not been patched. You should deactivate the plugin.

Easy Cookie Law

Product image for Easy Cookie Law.

Plugin Slug
easy-cookie-law

Installations
4,000+

Vulnerability
Cross Site Request Forgery (CSRF)

Patched in Version
No Fix

Severity Score
Medium

The vulnerability has not been patched. You should deactivate the plugin.

Make Paths Relative

Product image for Make Paths Relative.

Plugin Slug
make-paths-relative

Installations
4,000+

Vulnerability
Cross Site Request Forgery (CSRF)

Patched in Version
No Fix

Severity Score
Medium

The vulnerability has not been patched. You should deactivate the plugin.

WP Like Button

Product image for WP Like Button.

Plugin Slug
wp-like-button

Installations
4,000+

Vulnerability
Cross Site Request Forgery (CSRF)

Patched in Version
No Fix

Severity Score
Medium

The vulnerability has not been patched. You should deactivate the plugin.

LINE Notify

Plugin Slug
wp-line-notify

Installations
2,000+

Vulnerability
Cross Site Scripting (XSS)

Patched in Version
No Fix

Severity Score
High

The vulnerability has not been patched. You should deactivate the plugin.

Password Reset with Code for WordPress REST API

Product image for Password Reset with Code for WordPress REST API.

Plugin Slug
bdvs-password-reset

Installations
1,000+

Vulnerability
Broken Authentication

Patched in Version
No Fix

Severity Score
Critical

The vulnerability has not been patched. You should deactivate the plugin.

Highcompress Image Compressor

Product image for Highcompress Image Compressor.

Plugin Slug
high-compress

Installations
1,000+

Vulnerability
Broken Access Control

Patched in Version
No Fix

Severity Score
Medium

The vulnerability has not been patched. You should deactivate the plugin.

Kangu para WooCommerce

Product image for Kangu para WooCommerce.

Plugin Slug
kangu

Installations
1,000+

Vulnerability
Cross Site Scripting (XSS)

Patched in Version
No Fix

Severity Score
High

The vulnerability has not been patched. You should deactivate the plugin.

SB Child List

Plugin Slug
sb-child-list

Installations
1,000+

Vulnerability
Cross Site Request Forgery (CSRF)

Patched in Version
No Fix

Severity Score
Medium

The vulnerability has not been patched. You should deactivate the plugin.

WxSync

Plugin Slug
wxsync

Installations
1,000+

Vulnerability
Cross Site Scripting (XSS)

Patched in Version
No Fix

Severity Score
Medium

The vulnerability has not been patched. You should deactivate the plugin.

wSecure Lite

Plugin Slug
wsecure

Installations
900+

Vulnerability
Cross Site Scripting (XSS)

Patched in Version
No Fix

Severity Score
Medium

The vulnerability has not been patched. You should deactivate the plugin.

Easy!Appointments

Product image for Easy!Appointments.

Plugin Slug
easyappointments

Installations
800+

Vulnerability
Arbitrary File Deletion

Patched in Version
No Fix

Severity Score
Medium

The vulnerability has not been patched. You should deactivate the plugin.

Avartan Slider Lite

Product image for Responsive WordPress Slider – Avartan Slider Lite.

Plugin Slug
avartan-slider-lite

Installations
600+

Vulnerability
Cross Site Scripting (XSS)

Patched in Version
No Fix

Severity Score
High

The vulnerability has not been patched. You should deactivate the plugin.

WebLibrarian

Product image for WebLibrarian.

Plugin Slug
weblibrarian

Installations
500+

Vulnerability
Cross Site Scripting (XSS)

Patched in Version
No Fix

Severity Score
High

The vulnerability has not been patched. You should deactivate the plugin.

demon image annotation

Product image for demon image annotation.

Plugin Slug
demon-image-annotation

Installations
10+

Vulnerability
SQL Injection

Patched in Version
No Fix

Severity Score
High

The vulnerability has not been patched. You should deactivate the plugin.

Absolute Privacy

Plugin
Absolute Privacy

Plugin Slug
absolute-privacy

Vulnerability
Cross Site Request Forgery (CSRF)

Patched in Version
No Fix

Severity Score
Medium

The vulnerability has not been patched and the plugin is closed. You should uninstall and delete the plugin.

All Users Messenger

Plugin
All Users Messenger

Plugin Slug
all-users-messenger

Vulnerability
Broken Access Control

Patched in Version
No Fix

Severity Score
Medium

The vulnerability has not been patched and the plugin is closed. You should uninstall and delete the plugin.

Canto

Plugin
Canto

Plugin Slug
canto

Vulnerability
Remote File Inclusion

Patched in Version
No Fix

Severity Score
Critical

The vulnerability has not been patched and the plugin is closed. You should uninstall and delete the plugin.

FULL Customer

Plugin
FULL Customer

Plugin Slug
full-customer

Vulnerability
Sensitive Data Exposure

Patched in Version
No Fix

Severity Score
Medium

The vulnerability has not been patched and the plugin is closed. You should uninstall and delete the plugin.

FULL Customer

Plugin
FULL Customer

Plugin Slug
full-customer

Vulnerability
Broken Access Control

Patched in Version
No Fix

Severity Score
High

The vulnerability has not been patched and the plugin is closed. You should uninstall and delete the plugin.

Real Estate Manager

Plugin
Real Estate Manager

Plugin Slug
real-estate-manager

Vulnerability
Broken Access Control

Patched in Version
No Fix

Severity Score
High

The vulnerability has not been patched and the plugin is closed. You should uninstall and delete the plugin.

Realia

Plugin
Realia

Plugin Slug
realia

Vulnerability
Cross Site Request Forgery (CSRF)

Patched in Version
No Fix

Severity Score
Medium

The vulnerability has not been patched and the plugin is closed. You should uninstall and delete the plugin.

Donations Made Easy – Smart Donations

Plugin
Donations Made Easy – Smart Donations

Plugin Slug
smart-donations

Vulnerability
SQL Injection

Patched in Version
No Fix

Severity Score
High

The vulnerability has not been patched and the plugin is closed. You should uninstall and delete the plugin.

WordPress Theme Vulnerabilities

In this section, you’ll find the latest WordPress theme vulnerabilities to be disclosed. You’ll see the same information we provided above for vulnerable plugins, and the same advice applies. If a security update exists, install it immediately. If a vulnerability remains unpatched in a theme you are actively using, you must find an alternative theme. Deactivate and delete persistently unpatched themes and those marked “Closed” in the WordPress.org theme repository. If you have a vulnerable theme installed that you are not actively using, delete it.

Avada

Theme
Avada

Theme Slug
avada

Vulnerability
Broken Access Control

Patched in Version
7.11.2

Severity Score
Medium

The vulnerability has been patched, so you should update to version 7.11.2.

Avada

Theme
Avada

Theme Slug
avada

Vulnerability
Arbitrary File Upload

Patched in Version
7.11.2

Severity Score
High

The vulnerability has been patched, so you should update to version 7.11.2.

Avada

Theme
Avada

Theme Slug
avada

Vulnerability
Server Side Request Forgery (SSRF)

Patched in Version
7.11.2

Severity Score
High

The vulnerability has been patched, so you should update to version 7.11.2.

Avada

Theme
Avada

Theme Slug
avada

Vulnerability
Arbitrary File Upload

Patched in Version
7.11.2

Severity Score
Critical

The vulnerability has been patched, so you should update to version 7.11.2.

BeTheme

Theme
Betheme

Theme Slug
betheme

Vulnerability
Broken Access Control

Patched in Version
27.1.2

Severity Score
High

The vulnerability has been patched, so you should update to version 27.1.2.

Business Pro

Theme
Business Pro

Theme Slug
business-pro

Vulnerability
Cross Site Scripting (XSS)

Patched in Version
No Fix

Severity Score
High

The vulnerability has not been patched. You should switch themes.
Dan Knauss

Dan Knauss is StellarWP’s Technical Content Generalist. He’s been a writer, teacher, and freelancer working in open source since the late 1990s and with WordPress since 2004.

Source link

Written by:
Abdul Wahid
Published on:
August 19, 2023

Categories: Woocommerce

Primary Sidebar

Wordpress

  • Latest News (348)
  • Plugins (405)
  • Themes (413)
  • Tutorials (510)
  • Videos (1,036)
  • Woocommerce (510)

Recent Articles

How to Install and Setup W3 Total Cache WordPress Plugin? Speed Up Your Site For Free 🚀

Would you like to make your website load faster? …

Continue Reading about How to Install and Setup W3 Total Cache WordPress Plugin? Speed Up Your Site For Free 🚀

Dive into Upsell and Cross-Sell Options

WP Swings has been a dedicated and trusted leader …

Continue Reading about Dive into Upsell and Cross-Sell Options

Search our site

Explore more

Get our Wordpress Guide Get Plugins Get Connected

Footer

VirusWord by Promaps, Inc.

Barnes Place
Colombo 7, Western 00700

Copyright © 2023 · Promaps, Inc.

Keep In Touch

  • Email
  • Facebook
  • Instagram
  • Pinterest
  • Twitter