• Skip to primary navigation
  • Skip to main content
  • Skip to primary sidebar

virusword.com

Learn Wordpress

  • Home
  • WordPress Shop
    • Fotopress
    • SEO Tool Kit
    • Social Contact
    • Tag Machine 2
    • Video Profits
  • Latest News
  • WordPress
    • Plugins
    • Themes
    • Tutorials
    • Videos
    • Woocommerce
  • About Us
  • Contact Us
    • Terms of Service
    • Privacy Policy
  • Show Search
Hide Search
Home/Woocommerce/WordPress Vulnerability Report – December 21, 2022

WordPress Vulnerability Report – December 21, 2022

Vulnerable plugins and themes are the #1 reason WordPress websites get hacked. The weekly WordPress Vulnerability Report powered by WPScan covers recent WordPress plugin, theme, and core vulnerabilities and what to do if you run one of the vulnerable plugins or themes on your website.

Each vulnerability will have a severity rating of low, medium, high, or critical. Responsible disclosure and reporting of vulnerabilities is an integral part of keeping the WordPress community safe. Please share this post with your friends to help get the word out and make WordPress safer for everyone!

Contents of the December 21, 2022 Report

WordPress Core News

WordPress 6.1.1 was released on November 15, 2022, as a short-cycle maintenance release with 29 bug fixes in Core and 21 bug fixes for the block editor. Because this is a core update, be sure to update to WordPress 6.1.1 as soon as possible! As always, with a major release like this, it makes sense to ensure your site is backed up with BackupBuddy before updating.

WP

Vulnerability
Unauthenticated Blind SSRF via DNS Rebinding

Patched in Version
No Fix

Severity Score
Medium

The vulnerability has not been patched.

This vulnerability was reported by Thomas Chauchefoin, and at this time, it affects all versions of WordPress. However, probable exploitation of this vulnerability is very low, and to fully protect yourself, all you’ll need to do is turn off XML-RPC or pingbacks on your WordPress site.

Get the weekly WordPress Vulnerability Report delivered to your inbox each Wednesday.

WordPress Plugin Vulnerabilities

In this section, the latest WordPress plugin vulnerabilities have been disclosed. Each plugin listing includes the type of vulnerability, the active installations, the version number if patched, the severity rating, and the CVE.

Table of Contents Plus

Product image for Table of Contents Plus.

Plugin Slug
table-of-contents-plus

Installations
300,000+

Vulnerability
Contributor+ Stored XSS

Patched in Version
2212

Severity Score
High

The vulnerability has been patched, so you should update to version 2212.

Download Manager

Product image for Download Manager.

Plugin Slug
download-manager

Installations
100,000+

Vulnerability
Contributor+ Stored XSS

Patched in Version
3.2.62

Severity Score
High

The vulnerability has been patched, so you should update to version 3.2.62.

Smash Balloon Social Post Feed

Product image for Smash Balloon Social Post Feed.

Plugin Slug
custom-facebook-feed

Installations
100,000+

Vulnerability
Contributor+ Stored XSS

Patched in Version
4.1.6

Severity Score
High

The vulnerability has been patched, so you should update to version 4.1.6.

Mesmerize Companion

Plugin Slug
mesmerize-companion

Installations
100,000+

Vulnerability
Contributor+ Stored XSS

Patched in Version
1.6.135

Severity Score
High

The vulnerability has been patched, so you should update to version 1.6.135.

Starter Templates by Kadence WP

Product image for Starter Templates by Kadence WP.

Plugin Slug
kadence-starter-templates

Installations
100,000+

Vulnerability
Admin+ PHP Object Injection

Patched in Version
1.2.17

Severity Score
Medium

The vulnerability has been patched, so you should update to version 1.2.17.

Slimstat Analytics

Product image for Slimstat Analytics.

Plugin Slug
wp-slimstat

Installations
100,000+

Vulnerability
Unauthenticated Stored XSS

Patched in Version
4.9.3

Severity Score
High

The vulnerability has been patched, so you should update to version 4.9.3.

WPtouch

Product image for WPtouch.

Plugin Slug
wptouch

Installations
100,000+

Vulnerability
Admin+ PHP Object Injection; Admin+ Arbitrary File Upload

Patched in Version
4.3.45

Severity Score
Medium

The vulnerability has been patched, so you should update to version 4.3.45.

Royal Elementor Addons

Product image for Royal Elementor Addons (Elementor Templates, Post Grid, Mega Menu & Header Footer Builder, WooCommerce Builder, Product Grid, Slider, Parallax Image & other Free Elementor Widgets).

Plugin Slug
royal-elementor-addons

Installations
100,000+

Vulnerability
Subscriber+ Arbitrary Post Creation; Subscriber+ Arbitrary Post Deletion

Patched in Version
1.3.56

Severity Score
Medium

The vulnerability has been patched, so you should update to version 1.3.56.

Permalink Manager Lite

Product image for Permalink Manager Lite.

Plugin Slug
permalink-manager

Installations
70,000+

Vulnerability
Authenticated Stored XSS

Patched in Version
2.3.0

Severity Score
Medium

The vulnerability has been patched, so you should update to version 2.3.0.

WOOCS

Product image for WOOCS – Currency Switcher for WooCommerce Professional.

Plugin Slug
woocommerce-currency-switcher

Installations
70,000+

Vulnerability
Contributor+ Stored XSS

Patched in Version
1.3.9.4

Severity Score
High

The vulnerability has been patched, so you should update to version 1.3.9.4.

WP Recipe Maker

Product image for WP Recipe Maker.

Plugin Slug
wp-recipe-maker

Installations
50,000+

Vulnerability
Contributor+ Stored XSS

Patched in Version
8.6.1

Severity Score
High

The vulnerability has been patched, so you should update to version 8.6.1.

Metricool

Product image for Metricool.

Plugin Slug
metricool

Installations
40,000+

Vulnerability
Admin+ Stored XSS

Patched in Version
1.18

Severity Score
Low

The vulnerability has been patched, so you should update to version 1.18.

WP Custom Admin Interface

Product image for WP Custom Admin Interface.

Plugin Slug
wp-custom-admin-interface

Installations
30,000+

Vulnerability
Admin+ PHP Object Injection

Patched in Version
7.29

Severity Score
Medium

The vulnerability has been patched, so you should update to version 7.29.

Jetpack CRM

Product image for Jetpack CRM – Clients, Leads, Invoices, Billing, Email Marketing, & Automation.

Plugin Slug
zero-bs-crm

Installations
30,000+

Vulnerability
Contributor+ Stored XSS

Patched in Version
5.5

Severity Score
High

The vulnerability has been patched, so you should update to version 5.5.

Image Hover Effects Ultimate

Product image for Image Hover Effects Ultimate (Image Gallery, Effects, Lightbox, Comparison or Magnifier).

Plugin Slug
image-hover-effects-ultimate

Installations
20,000+

Vulnerability
Admin+ Stored XSS

Patched in Version
9.8.5

Severity Score
Low

The vulnerability has been patched, so you should update to version 9.8.5.

Multi Step Form

Product image for Multi Step Form.

Plugin Slug
multi-step-form

Installations
10,000+

Vulnerability
Admin+ Stored XSS

Patched in Version
1.7.8

Severity Score
Low

The vulnerability has been patched, so you should update to version 1.7.8.

ActiveCampaign for WooCommerce

Plugin Slug
activecampaign-for-woocommerce

Installations
8,000+

Vulnerability
Subscriber+ Error Log Cleanup

Patched in Version
1.9.8

Severity Score
Medium

The vulnerability has been patched, so you should update to version 1.9.8.

Vision Interactive For WordPress

Product image for Vision Interactive For WordPress.

Plugin Slug
vision

Installations
3,000+

Vulnerability
Contributor+ Stored XSS

Patched in Version
1.5.4

Severity Score
High

The vulnerability has been patched, so you should update to version 1.5.4.

Sunshine Photo Cart

Product image for Sunshine Photo Cart.

Plugin Slug
sunshine-photo-cart

Installations
1,000+

Vulnerability
Reflected XSS

Patched in Version
2.9.15

Severity Score
High

The vulnerability has been patched, so you should update to version 2.9.15.

Post Status Notifier Lite

Product image for Post Status Notifier Lite.

Plugin Slug
post-status-notifier-lite

Installations
1,000+

Vulnerability
Reflected XSS

Patched in Version
1.10.1

Severity Score
High

The vulnerability has been patched, so you should update to version 1.10.1.

WordPress Events Calendar Plugin

Product image for WordPress Events Calendar Plugin – connectDaily.

Plugin Slug
connect-daily-web-calendar

Installations
200+

Vulnerability
Multiple Reflected XSS

Patched in Version
1.4.5

Severity Score
High

The vulnerability has been patched, so you should update to version 1.4.5.

WPQA

Plugin
WPQA Builder

Plugin Slug
wpqa

Vulnerability
Missing validation lead to functionality abuse

Patched in Version
5.9.3

Severity Score
Low

The vulnerability has been patched, so you should update to version 5.9.3.

Mautic Integration For WooCommerce

Plugin
Mautic Integration for WooCommerce

Plugin Slug
mautic-integration-for-woocommerce

Vulnerability
Arbitrary Options Update via CSRF

Patched in Version
1.0.3

Severity Score
High

The vulnerability has been patched, so you should update to version 1.0.3.

iPages Flipbook For WordPress

Plugin Slug
ipages-flipbook

Vulnerability
Contributor+ Stored XSS

Patched in Version
1.4.7

Severity Score
Medium

The vulnerability has been patched, so you should update to version 1.4.7.

WordPress Plugin Vulnerabilities – No Known Fix

This section contains plugin vulnerabilities with no known fix. Until a patch is available, immediately uninstall and delete the plugin.

Mega Addons For WPBakery Page Builder

Product image for Mega Addons For WPBakery Page Builder.

Plugin Slug
mega-addons-for-visual-composer

Installations
60,000+

Vulnerability
Subscriber+ Settings Update

Patched in Version
No Fix

Severity Score
Medium

The vulnerability has not been patched. You should deactivate the plugin.

iPanorama 360 WordPress Virtual Tour Builder

Product image for iPanorama 360  WordPress Virtual Tour Builder.

Plugin Slug
ipanorama-360-virtual-tour-builder-lite

Installations
7,000+

Vulnerability
Contributor+ Stored XSS

Patched in Version
No Fix

Severity Score
High

The vulnerability has not been patched. You should deactivate the plugin.

ImageLinks Interactive Image Builder for WordPress

Product image for ImageLinks Interactive Image Builder for WordPress.

Plugin Slug
imagelinks-interactive-image-builder-lite

Installations
3,000+

Vulnerability
Contributor+ Stored XSS

Patched in Version
No Fix

Severity Score
High

The vulnerability has not been patched. You should deactivate the plugin.

WP CSV

Plugin Slug
wp-csv

Vulnerability
Reflected XSS via CSV Import

Patched in Version
No Fix

Severity Score
Medium

The vulnerability has not been patched and the plugin is closed. You should uninstall and delete the plugin.

WP Table Reloaded

Plugin Slug
wp-table-reloaded

Vulnerability
Contributor+ Stored XSS

Patched in Version
No Fix

Severity Score
High

The vulnerability has not been patched and the plugin is closed. You should uninstall and delete the plugin.

Bg Bible References

Plugin Slug
bg-biblie-references

Vulnerability
Reflected XSS

Patched in Version
No Fix

Severity Score
High

The vulnerability has not been patched and the plugin is closed. You should uninstall and delete the plugin.

404 to Start

Plugin Slug
404-to-start

Vulnerability
Admin+ Stored XSS

Patched in Version
No Fix

Severity Score
Low

The vulnerability has not been patched and the plugin is closed. You should uninstall and delete the plugin.

WordPress Theme Vulnerabilities

In this section, the latest WordPress theme vulnerabilities have been disclosed. Each theme listing includes the type of vulnerability, the active installations, the version number if patched, the severity rating, and the CVE.

WPQA

Theme
Himer

Theme Slug
himer

Vulnerability
Missing validation lead to functionality abuse

Patched in Version
No Fix

Severity Score
Low

The vulnerability has not been patched. You should switch themes.

Never worry about running a vulnerable plugin or theme again.

As you can see from this report, lots of new WordPress plugin and theme vulnerabilities are disclosed each week. We know it can be difficult to stay on top of every reported vulnerability disclosure, so the iThemes Security Pro plugin makes it easy to make sure your site isn’t running a theme, plugin, or WordPress core version with a known vulnerability.

Scans Your Website Twice a Day for Vulnerabilities

Your website’s plugins, themes, and WordPress core versions are checked against the WPScan Vulnerability Database for the latest vulnerability disclosures.

Automatically Updates if a Security Fix is Available

Paired with Version Management, iThemes Security will automatically update a plugin, theme, or WordPress core version if it has a vulnerability.

Emails You if Site Scan Detects a Vulnerability

You can receive an email report if your site is running vulnerable versions of a plugin, theme, or WordPress core. Customize the email addresses that receive scan results.

The Best WordPress Security Plugin to Secure & Protect WordPress Sites

WordPress currently powers over 40% of all websites, so it has become an easy target for hackers with malicious intent. The iThemes Security Pro plugin takes the guesswork out of WordPress security to make it easy to secure & protect your WordPress website. It’s like having a full-time security expert on staff who constantly monitors and protects your WordPress site for you.

iThemes Team

Source link

Written by:
Abdul Wahid
Published on:
December 21, 2022

Categories: Woocommerce

Primary Sidebar

Wordpress

  • Content Management Systems (2)
  • Digital Marketing (4)
  • Internet Marketing (28)
  • Latest News (458)
  • Online Business (2)
  • Plugins (519)
  • Themes (521)
  • Videos (1,350)
  • Website Development (1)
  • Woocommerce (589)
  • WordPress (6)

Recent Articles

Unlock Your Internet Marketing Potential with WordPress: Tips, Tools, and Strategies

How to Use WordPress to Achieve Your Internet …

Continue Reading about Unlock Your Internet Marketing Potential with WordPress: Tips, Tools, and Strategies

Unlock Your Internet Marketing Potential: Harnessing the Power of WordPress

How to Use WordPress to Achieve Your Internet …

Continue Reading about Unlock Your Internet Marketing Potential: Harnessing the Power of WordPress

Search our site

Explore more

Get our Wordpress Guide Get Plugins Get Connected

Footer

VirusWord by Promaps, Inc.

Barnes Place
Colombo 7, Western 00700

Copyright © 2025 · Promaps, Inc.

Keep In Touch

  • Email
  • Facebook
  • Instagram
  • Pinterest
  • Twitter