• Skip to primary navigation
  • Skip to main content
  • Skip to primary sidebar

virusword.com

Learn Wordpress

  • Home
  • WordPress Shop
    • Fotopress
    • SEO Tool Kit
    • Social Contact
    • Tag Machine 2
    • Video Profits
  • Latest News
  • WordPress
    • Plugins
    • Themes
    • Tutorials
    • Videos
    • Woocommerce
  • About Us
  • Contact Us
    • Terms of Service
    • Privacy Policy
  • Show Search
Hide Search
Home/Woocommerce/WordPress Vulnerability Report – January 11, 2023

WordPress Vulnerability Report – January 11, 2023

Vulnerable plugins and themes are the #1 reason WordPress websites get hacked. The weekly WordPress Vulnerability Report powered by WPScan covers recent WordPress plugin, theme, and core vulnerabilities and what to do if you run one of the vulnerable plugins or themes on your website.

Each vulnerability will have a severity rating of low, medium, high, or critical. Responsible disclosure and reporting of vulnerabilities is an integral part of keeping the WordPress community safe. Please share this post with your friends to help get the word out and make WordPress safer for everyone!

Contents of the January 11, 2023 Report

The Future of Authentication is Passkeys! Login to your WordPress site with Biometrics only available in iThemes Security Pro

The problems of brute force attacks through credential stuffing, phishing attacks, and reused passwords have made our digital lives less secure. We’ve all tried to encourage 2-factor authentication as a protection, but less than 30% of users actually use 2FA. Password-based logins are a problem.

The future of authentication is passkeys, and iThemes Security Pro is the first to bring this breakthrough technology to WordPress sites. Using breakthrough WebAuthn technology based on public/private cryptography, passkeys make passwords obsolete. Now, website admins and end users can have secure logins without the inconvenience of additional two-factor apps, password managers, or complex password requirements.

WordPress Core News

WordPress 6.1.1 was released on November 15, 2022, as a short-cycle maintenance release with 29 bug fixes in Core and 21 bug fixes for the block editor. Because this is a core update, be sure to update to WordPress 6.1.1 as soon as possible! As always, with a major release like this, it makes sense to ensure your site is backed up with BackupBuddy before updating.

  • No new WordPress core vulnerabilities were disclosed this week.

There is a known unpatched vulnerability in WordPress core affecting all versions of WordPress. If you’re using iThemes Security, you’ve probably been alerted to this. As we are unsure when this very low-severity vulnerability will be patched, emails from iThemes Security will no longer alert for this specific vulnerability. Read our blog post about this vulnerability.

Get the weekly WordPress Vulnerability Report delivered to your inbox each Wednesday.

WordPress Plugin Vulnerabilities

In this section, the latest WordPress plugin vulnerabilities have been disclosed. Each plugin listing includes the type of vulnerability, the active installations, the version number if patched, the severity rating, and the CVE.

Widgets for Google Reviews

Product image for Widgets for Google Reviews.

Plugin Slug
wp-reviews-plugin-for-google

Installations
100,000+

Vulnerability
Contributor+ Stored XSS

Patched in Version
9.8

Severity Score
Medium

The vulnerability has been patched, so you should update to version 9.8.

Strong Testimonials

Product image for Strong Testimonials.

Plugin Slug
strong-testimonials

Installations
100,000+

Vulnerability
Contributor+ Stored XSS via Shortcode

Patched in Version
3.0.3

Severity Score
Medium

The vulnerability has been patched, so you should update to version 3.0.3.

Royal Elementor Addons

Product image for Royal Elementor Addons (Elementor Templates, Post Grid, Mega Menu & Header Footer Builder, WooCommerce Builder, Product Grid, Slider, Parallax Image & other Free Elementor Widgets).

Plugin Slug
royal-elementor-addons

Installations
100,000+

Vulnerability
Menu Template Creation via CSRF; Subscriber+ Arbitrary Template Import; Subscriber+ Template Kit Import; Reflected XSS; Subscriber+ Arbitrary Plugin Deactivation; Subscriber+ Mega Menu Settings Update; Subscriber+ Arbitrary Import Deletion; Subscriber+ Arbitrary Plugin Activation; Subscriber+ Template Condition Update; Subscriber+ Arbitrary Template Activation; Subscriber+ Arbitrary Theme Activation

Patched in Version
1.3.60

Severity Score
Medium

The vulnerability has been patched, so you should update to version 1.3.60.

Simple Sitemap

Product image for Simple Sitemap – Create a Responsive HTML Sitemap.

Plugin Slug
simple-sitemap

Installations
90,000+

Vulnerability
Contributor+ Stored XSS

Patched in Version
3.5.8

Severity Score
Medium

The vulnerability has been patched, so you should update to version 3.5.8.

RSS Aggregator by Feedzy

Product image for RSS Aggregator by Feedzy – Powerful WP Autoblogging and News Aggregator.

Plugin Slug
feedzy-rss-feeds

Installations
50,000+

Vulnerability
Contributor+ Stored XSS

Patched in Version
4.1.1

Severity Score
Medium

The vulnerability has been patched, so you should update to version 4.1.1.

Insert Pages

Plugin Slug
insert-pages

Installations
40,000+

Vulnerability
Contributor+ Stored XSS

Patched in Version
3.7.5

Severity Score
Medium

The vulnerability has been patched, so you should update to version 3.7.5.

News & Blog Designer Pack

Product image for News & Blog Designer Pack – WordPress Blog Plugin — (Blog Post Grid, Blog Post Slider, Blog Post Carousel, Blog Post Ticker, Blog Post Masonry).

Plugin Slug
blog-designer-pack

Installations
30,000+

Vulnerability
Contributor+ Stored XSS via Shortcode

Patched in Version
3.3

Severity Score
Medium

The vulnerability has been patched, so you should update to version 3.3.

Revive Old Posts – Social Media Auto Post and Scheduling Plugin

Product image for Revive Old Posts – Social Media Auto Post and Scheduling Plugin.

Plugin Slug
tweet-old-post

Installations
30,000+

Vulnerability
PHP Object Injection

Patched in Version
9.0.11

Severity Score
Low

The vulnerability has been patched, so you should update to version 9.0.11.

WP Extended Search

Product image for WP Extended Search.

Plugin Slug
wp-extended-search

Installations
20,000+

Vulnerability
Contributor+ Stored XSS via Shortcode

Patched in Version
2.1.2

Severity Score
Medium

The vulnerability has been patched, so you should update to version 2.1.2.

Pricing Tables WordPress Plugin – Easy Pricing Tables

Product image for Pricing Tables WordPress Plugin – Easy Pricing Tables.

Plugin Slug
easy-pricing-tables

Installations
20,000+

Vulnerability
Contributor+ Stored XSS via Shortcode

Patched in Version
3.2.3

Severity Score
Medium

The vulnerability has been patched, so you should update to version 3.2.3.

PDF.js Viewer

Product image for PDF.js Viewer.

Plugin Slug
pdfjs-viewer-shortcode

Installations
20,000+

Vulnerability
Contributor+ Stored XSS via Shortcode

Patched in Version
2.1.8

Severity Score
Medium

The vulnerability has been patched, so you should update to version 2.1.8.

PPWP – WordPress Password Protect Page

Product image for PPWP – Password Protect Pages.

Plugin Slug
password-protect-page

Installations
20,000+

Vulnerability
Contributor+ Stored XSS in Shortcode

Patched in Version
1.8.6

Severity Score
Medium

The vulnerability has been patched, so you should update to version 1.8.6.

Easy Testimonials

Product image for Easy Testimonials.

Plugin Slug
easy-testimonials

Installations
20,000+

Vulnerability
Contributor+ Stored XSS

Patched in Version
3.9.3

Severity Score
Medium

The vulnerability has been patched, so you should update to version 3.9.3.

Page View Count

Product image for Page View Count.

Plugin Slug
page-views-count

Installations
20,000+

Vulnerability
Contributor+ Stored XSS

Patched in Version
2.6.1

Severity Score
Medium

The vulnerability has been patched, so you should update to version 2.6.1.

Post Grid, Post Carousel, & List Category Posts

Product image for Post Grid, Post Carousel, & List Category Posts – by Smart Post Show.

Plugin Slug
post-carousel

Installations
20,000+

Vulnerability
Contributor+ Stored XSS

Patched in Version
2.4.19

Severity Score
Medium

The vulnerability has been patched, so you should update to version 2.4.19.

PDF Viewer

Product image for PDF Viewer.

Plugin Slug
pdf-viewer

Installations
10,000+

Vulnerability
Contributor+ Stored XSS via Shortcode

Patched in Version
1.0.0

Severity Score
Medium

The vulnerability has been patched, so you should update to version 1.0.0.

PixCodes

Plugin Slug
pixcodes

Installations
10,000+

Vulnerability
Contributor+ Stored XSS in Shortcode

Patched in Version
2.3.7

Severity Score
Medium

The vulnerability has been patched, so you should update to version 2.3.7.

WP-ShowHide

Product image for WP-ShowHide.

Plugin Slug
wp-showhide

Installations
10,000+

Vulnerability
Contributor+ Stored XSS via Shortcode

Patched in Version
1.05

Severity Score
Medium

The vulnerability has been patched, so you should update to version 1.05.

miniOrange WordPress SAML SSO Premium

Product image for SAML Single Sign On – SSO Login.

Plugin Slug
miniorange-saml-20-single-sign-on

Installations
10,000+

Vulnerability
Open Redirect in SSO login

Patched in Version
12.1.0

Severity Score
Medium

The vulnerability has been patched, so you should update to version 12.1.0.

miniOrange WordPress SAML SSO Standard

Product image for SAML Single Sign On – SSO Login.

Plugin Slug
miniorange-saml-20-single-sign-on

Installations
10,000+

Vulnerability
Open Redirect in SSO login

Patched in Version
16.0.8

Severity Score
Medium

The vulnerability has been patched, so you should update to version 16.0.8.

miniOrange WordPress SAML SSO Premium Multisite

Product image for SAML Single Sign On – SSO Login.

Plugin Slug
miniorange-saml-20-single-sign-on

Installations
10,000+

Vulnerability
Open Redirect in SSO login

Patched in Version
20.0.7

Severity Score
Medium

The vulnerability has been patched, so you should update to version 20.0.7.

CC Child Pages

Product image for CC Child Pages.

Plugin Slug
cc-child-pages

Installations
10,000+

Vulnerability
Contributor+ Stored XSS via Shortcode

Patched in Version
1.43

Severity Score
Medium

The vulnerability has been patched, so you should update to version 1.43.

YourChannel: Everything you want in a YouTube plugin

Product image for YourChannel: Everything you want in a YouTube plugin..

Plugin Slug
yourchannel

Installations
10,000+

Vulnerability
Contributor+ Stored XSS via Shortcode

Patched in Version
1.2.3

Severity Score
Medium

The vulnerability has been patched, so you should update to version 1.2.3.

Bold Timeline Lite

Product image for Bold Timeline Lite.

Plugin Slug
bold-timeline-lite

Installations
10,000+

Vulnerability
Contributor+ Stored XSS via Shortcode

Patched in Version
1.1.5

Severity Score
Medium

The vulnerability has been patched, so you should update to version 1.1.5.

Clean Login

Product image for Clean Login.

Plugin Slug
clean-login

Installations
10,000+

Vulnerability
Contributor+ Stored XSS via Shortcode

Patched in Version
1.13.7

Severity Score
Medium

The vulnerability has been patched, so you should update to version 1.13.7.

Custom User Profile Fields for User Registration & Member Frontend Profiles with Paid Memberships Pro

Product image for Custom User Profile Fields for User Registration & Member Frontend Profiles with Paid Memberships Pro.

Plugin Slug
pmpro-register-helper

Installations
10,000+

Vulnerability
Contributor+ Stored XSS via Shortcode

Patched in Version
1.8.1

Severity Score
Medium

The vulnerability has been patched, so you should update to version 1.8.1.

CPO Companion

Plugin Slug
cpo-companion

Installations
10,000+

Vulnerability
Admin+ Stored XSS; Contributor+ Stored XSS via Shortcode

Patched in Version
1.1.0

Severity Score
Low

The vulnerability has been patched, so you should update to version 1.1.0.

Portfolio for Elementor, Image Gallery & Post Grid | PowerFolio

Product image for Portfolio for Elementor, Image Gallery & Post Grid  | PowerFolio.

Plugin Slug
portfolio-elementor

Installations
10,000+

Vulnerability
Contributor+ Stored XSS via Shortcode

Patched in Version
2.3.1

Severity Score
Medium

The vulnerability has been patched, so you should update to version 2.3.1.

Themify Shortcodes

Plugin Slug
themify-shortcodes

Installations
10,000+

Vulnerability
Contributor+ Stored XSS via Shortcode

Patched in Version
2.0.8

Severity Score
Medium

The vulnerability has been patched, so you should update to version 2.0.8.

Event Manager and Tickets Selling Plugin for WooCommerce

Product image for Event Manager and Tickets Selling Plugin for WooCommerce.

Plugin Slug
mage-eventpress

Installations
9,000+

Vulnerability
Contributor+ Stored XSS

Patched in Version
3.8.0

Severity Score
Medium

The vulnerability has been patched, so you should update to version 3.8.0.

WP Social Widget

Product image for WP Social Widget.

Plugin Slug
wp-social-widget

Installations
9,000+

Vulnerability
Contributor+ Stored XSS

Patched in Version
2.2.4

Severity Score
Medium

The vulnerability has been patched, so you should update to version 2.2.4.

Icon Widget

Product image for Icon Widget.

Plugin Slug
icon-widget

Installations
9,000+

Vulnerability
Contributor+ Stored XSS via Shortcode

Patched in Version
1.3.0

Severity Score
Medium

The vulnerability has been patched, so you should update to version 1.3.0.

WP Tabs

Product image for WP Tabs – Responsive Tabs Plugin for WordPress.

Plugin Slug
wp-expand-tabs-free

Installations
9,000+

Vulnerability
Contributor+ Stored XSS

Patched in Version
2.1.17

Severity Score
Medium

The vulnerability has been patched, so you should update to version 2.1.17.

Blog Designer – Post and Widget

Product image for Blog Designer – Post and Widget.

Plugin Slug
blog-designer-for-post-and-widget

Installations
9,000+

Vulnerability
Contributor+ Stored XSS via Shortcode

Patched in Version
2.4.1

Severity Score
Medium

The vulnerability has been patched, so you should update to version 2.4.1.

Post Category Image With Grid and Slider

Product image for Post Category Image With Grid and Slider.

Plugin Slug
post-category-image-with-grid-and-slider

Installations
3,000+

Vulnerability
Contributor+ Stored XSS via Shortcode

Patched in Version
1.4.8

Severity Score
Medium

The vulnerability has been patched, so you should update to version 1.4.8.

Survey Maker

Product image for Survey Maker – Best WordPress Survey Plugin.

Plugin Slug
survey-maker

Installations
3,000+

Vulnerability
Unauthenticated Stored XSS

Patched in Version
3.1.4

Severity Score
High

The vulnerability has been patched, so you should update to version 3.1.4.

Posts List Designer by Category

Product image for Posts List Designer by Category – List Category Posts Or Recent Posts.

Plugin Slug
post-list-designer

Installations
1,000+

Vulnerability
Contributor+ Stored XSS via Shortcode

Patched in Version
3.2

Severity Score
Medium

The vulnerability has been patched, so you should update to version 3.2.

Membership For WooCommerce

Product image for Membership For WooCommerce – Add Simple Membership Plans, Recurring Revenue, Product Tags & Send Emails To Members with WooCommerce Membership.

Plugin Slug
membership-for-woocommerce

Installations
400+

Vulnerability
Unauthenticated Arbitrary File Upload

Patched in Version
2.1.7

Severity Score
Critical

The vulnerability has been patched, so you should update to version 2.1.7.

WooCommerce Chained Products

Plugin
Chained Products

Plugin Slug
woocommerce-chained-products

Vulnerability
Unauthenticated Arbitrary Options Update to ‘no’

Patched in Version
2.12.0

Severity Score
Medium

The vulnerability has been patched, so you should update to version 2.12.0.

Justified Gallery

Plugin Slug
justified-gallery

Vulnerability
Contributor+ Stored XSS via Shortcode

Patched in Version
1.7.1

Severity Score
Medium

The vulnerability has been patched, so you should update to version 1.7.1.

AAWP

Plugin Slug
aawp

Vulnerability
Unsafe URL Handling

Patched in Version
3.12.3

Severity Score
Medium

The vulnerability has been patched, so you should update to version 3.12.3.

WordPress Plugin Vulnerabilities – No Known Fix

This section contains plugin vulnerabilities with no known fix. Until a patch is available, immediately uninstall and delete the plugin.

Members Import

Plugin Slug
members-import

Vulnerability
XSS via Imported CSV

Patched in Version
No Fix

Severity Score
Medium

The vulnerability has not been patched and the plugin is closed. You should uninstall and delete the plugin.

CPT Bootstrap Carousel

Plugin Slug
cpt-bootstrap-carousel

Vulnerability
Contributor+ Stored XSS via Shortcode

Patched in Version
No Fix

Severity Score
Medium

The vulnerability has not been patched and the plugin is closed. You should uninstall and delete the plugin.

JetWidgets for Elementor

Plugin Slug
jetwidgets-for-elementor

Vulnerability
Settings Update via CSRF

Patched in Version
No Fix

Severity Score
Medium

The vulnerability has not been patched and the plugin is closed. You should uninstall and delete the plugin.

MediaElement.js – HTML5 Video & Audio Player

Plugin Slug
media-element-html5-video-and-audio-player

Vulnerability
Contributor+ Stored XSS via Shortcode

Patched in Version
No Fix

Severity Score
Medium

The vulnerability has not been patched and the plugin is closed. You should uninstall and delete the plugin.

Social Sharing Toolkit

Plugin Slug
social-sharing-toolkit

Vulnerability
Contributor+ Stored XSS via Shortcode

Patched in Version
No Fix

Severity Score
Medium

The vulnerability has not been patched and the plugin is closed. You should uninstall and delete the plugin.

Accordion Shortcodes

Plugin Slug
accordion-shortcodes

Vulnerability
Contributor+ Stored XSS via Shortcode

Patched in Version
No Fix

Severity Score
Medium

The vulnerability has not been patched and the plugin is closed. You should uninstall and delete the plugin.

FL3R FeelBox

Plugin Slug
fl3r-feelbox

Vulnerability
Settings Update via CSRF to Stored XSS; Moods Reset via CSRF

Patched in Version
No Fix

Severity Score
High

The vulnerability has not been patched and the plugin is closed. You should uninstall and delete the plugin.

WordPress Theme Vulnerabilities

In this section, the latest WordPress theme vulnerabilities have been disclosed. Each theme listing includes the type of vulnerability, the active installations, the version number if patched, the severity rating, and the CVE.

  • Good news! No new WordPress theme vulnerabilities were disclosed this week.

Never worry about running a vulnerable plugin or theme again.

As you can see from this report, lots of new WordPress plugin and theme vulnerabilities are disclosed each week. We know it can be difficult to stay on top of every reported vulnerability disclosure, so the iThemes Security Pro plugin makes it easy to make sure your site isn’t running a theme, plugin, or WordPress core version with a known vulnerability.

Scans Your Website Twice a Day for Vulnerabilities

Your website’s plugins, themes, and WordPress core versions are checked against the WPScan Vulnerability Database for the latest vulnerability disclosures.

Automatically Updates if a Security Fix is Available

Paired with Version Management, iThemes Security will automatically update a plugin, theme, or WordPress core version if it has a vulnerability.

Emails You if Site Scan Detects a Vulnerability

You can receive an email report if your site is running vulnerable versions of a plugin, theme, or WordPress core. Customize the email addresses that receive scan results.

The Best WordPress Security Plugin to Secure & Protect WordPress Sites

WordPress currently powers over 40% of all websites, so it has become an easy target for hackers with malicious intent. The iThemes Security Pro plugin takes the guesswork out of WordPress security to make it easy to secure & protect your WordPress website. It’s like having a full-time security expert on staff who constantly monitors and protects your WordPress site for you.

iThemes Team

Source link

Written by:
Abdul Wahid
Published on:
January 14, 2023

Categories: Woocommerce

Primary Sidebar

Wordpress

  • Content Management Systems (2)
  • Digital Marketing (4)
  • Internet Marketing (28)
  • Latest News (458)
  • Online Business (2)
  • Plugins (519)
  • Themes (521)
  • Videos (1,350)
  • Website Development (1)
  • Woocommerce (589)
  • WordPress (6)

Recent Articles

Unlock Your Internet Marketing Potential with WordPress: Tips, Tools, and Strategies

How to Use WordPress to Achieve Your Internet …

Continue Reading about Unlock Your Internet Marketing Potential with WordPress: Tips, Tools, and Strategies

Unlock Your Internet Marketing Potential: Harnessing the Power of WordPress

How to Use WordPress to Achieve Your Internet …

Continue Reading about Unlock Your Internet Marketing Potential: Harnessing the Power of WordPress

Search our site

Explore more

Get our Wordpress Guide Get Plugins Get Connected

Footer

VirusWord by Promaps, Inc.

Barnes Place
Colombo 7, Western 00700

Copyright © 2025 · Promaps, Inc.

Keep In Touch

  • Email
  • Facebook
  • Instagram
  • Pinterest
  • Twitter