• Skip to primary navigation
  • Skip to main content
  • Skip to primary sidebar

virusword.com

Learn Wordpress

  • Home
  • WordPress Shop
    • Fotopress
    • SEO Tool Kit
    • Social Contact
    • Tag Machine 2
    • Video Profits
  • Latest News
  • WordPress
    • Plugins
    • Themes
    • Tutorials
    • Videos
    • Woocommerce
  • About Us
  • Contact Us
    • Terms of Service
    • Privacy Policy
  • Show Search
Hide Search
Home/Woocommerce/WordPress Vulnerability Report – June 14, 2023

WordPress Vulnerability Report – June 14, 2023

Written by

Dan Knauss

on

June 14, 2023

Last Updated on June 14, 2023

This week, 56 total vulnerabilities emerged in public disclosure. They may affect over 4 million WordPress sites. There are 37 plugin vulnerabilities and three in themes that have security patches available, so run those updates!

Additionally, there are 16 plugin vulnerabilities with no patch available yet. If you are using any unpatched plugins or themes, check their vendors’ intentions and progress on a security release. If no patch is forthcoming or the vulnerable software has been closed and dropped from the official WordPress theme and plugin repositories, you should consider deactivation and removal in favor of alternative solutions.

WordPress Core Vulnerabilities — Patched

  • No new WordPress core vulnerabilities were disclosed this week.

WordPress core is very secure when it’s properly configured and maintained. Vulnerable plugins that have not been updated by site owners are the most common vector for attacks on WordPress websites. Our weekly WordPress Vulnerability Report, powered by Patchstack, covers new WordPress plugin, theme, and core vulnerabilities that have emerged since last week’s report. Our goal is to spread awareness of emerging security threats and help you decide what to do if you are using vulnerable software on your website. For a deeper analysis of recent trends in WordPress vulnerabilities and threat vectors, see our 2022 Annual Vulnerability Report.

These reports are published every Wednesday and include all active vulnerabilities tracked by Patchstack as of Monday since the previous report. This leaves a 48-hour window for the newest emerging vulnerabilities to be patched before full public disclosure. iThemes Security Pro users have access to vulnerability alerts emerging within this window.

Get the weekly WordPress Vulnerability Report delivered to your inbox each Wednesday.

WordPress Plugin Vulnerabilities — Patched

In this section, you’ll find the most recently disclosed WordPress plugin vulnerabilities that have been fixed with a new release from their authors and maintainers. Please apply the updates if you are affected!

These vulnerabilities have been disclosed and scored for their severity, thanks to our friends at Patchstack. Each plugin listing includes the type of vulnerability with its CVE number and CVSS severity rating with links to more technical details. You’ll also see the number of active sites using the plugin and the plugin version release that patches the vulnerability. We start with the most popular plugins, which represent the largest target for attackers.

Metform Elementor Contact Form Builder

Product image for Metform Elementor Contact Form Builder – Flexible and Design-Friendly Contact Form builder plugin for WordPress.

Plugin Slug
metform

Installations
200,000+

Vulnerability
Authenticated (Subscriber+) Information Disclosure via ‘mf_payment_status’ shortcode

Patched in Version
3.3.2

Severity Score
Medium

The vulnerability has been patched, so you should update to version 3.3.2.

Metform Elementor Contact Form Builder

Product image for Metform Elementor Contact Form Builder – Flexible and Design-Friendly Contact Form builder plugin for WordPress.

Plugin Slug
metform

Installations
200,000+

Vulnerability
Unauthenticated CSV Injection

Patched in Version
3.3.1

Severity Score
Medium

The vulnerability has been patched, so you should update to version 3.3.1.

Metform Elementor Contact Form Builder

Product image for Metform Elementor Contact Form Builder – Flexible and Design-Friendly Contact Form builder plugin for WordPress.

Plugin Slug
metform

Installations
200,000+

Vulnerability
Authenticated (Contributor+) Stored Cross-Site Scripting via mf_first_name shortcode

Patched in Version
3.3.1

Severity Score
Medium

The vulnerability has been patched, so you should update to version 3.3.1.

Metform Elementor Contact Form Builder

Product image for Metform Elementor Contact Form Builder – Flexible and Design-Friendly Contact Form builder plugin for WordPress.

Plugin Slug
metform

Installations
200,000+

Vulnerability
Authenticated (Subscriber+) Information Disclosure via mf_last_name shortcode

Patched in Version
3.3.2

Severity Score
Medium

The vulnerability has been patched, so you should update to version 3.3.2.

Metform Elementor Contact Form Builder

Product image for Metform Elementor Contact Form Builder – Flexible and Design-Friendly Contact Form builder plugin for WordPress.

Plugin Slug
metform

Installations
200,000+

Vulnerability
Authenticated (Subscriber+) Information Disclosure via mf_last_name shortcode

Patched in Version
3.3.2

Severity Score
Medium

The vulnerability has been patched, so you should update to version 3.3.2.

Metform Elementor Contact Form Builder

Product image for Metform Elementor Contact Form Builder – Flexible and Design-Friendly Contact Form builder plugin for WordPress.

Plugin Slug
metform

Installations
200,000+

Vulnerability
Authenticated (Subscriber+) Information Disclosure via mf_thankyou shortcode

Patched in Version
3.3.2

Severity Score
Medium

The vulnerability has been patched, so you should update to version 3.3.2.

Metform Elementor Contact Form Builder

Product image for Metform Elementor Contact Form Builder – Flexible and Design-Friendly Contact Form builder plugin for WordPress.

Plugin Slug
metform

Installations
200,000+

Vulnerability
Authenticated (Contributor+) Stored Cross-Site Scripting via mf_last_name shortcode

Patched in Version
3.3.1

Severity Score
Medium

The vulnerability has been patched, so you should update to version 3.3.1.

Metform Elementor Contact Form Builder

Product image for Metform Elementor Contact Form Builder – Flexible and Design-Friendly Contact Form builder plugin for WordPress.

Plugin Slug
metform

Installations
200,000+

Vulnerability
Authenticated (Subscriber+) Information Disclosure via ‘mf_transaction_id’ shortcode

Patched in Version
3.3.2

Severity Score
Medium

The vulnerability has been patched, so you should update to version 3.3.2.

Metform Elementor Contact Form Builder

Product image for Metform Elementor Contact Form Builder – Flexible and Design-Friendly Contact Form builder plugin for WordPress.

Plugin Slug
metform

Installations
200,000+

Vulnerability
Authenticated (Contributor+) Stored Cross-Site Scripting via mf shortcode

Patched in Version
3.3.1

Severity Score
Medium

The vulnerability has been patched, so you should update to version 3.3.1.

Metform Elementor Contact Form Builder

Product image for Metform Elementor Contact Form Builder – Flexible and Design-Friendly Contact Form builder plugin for WordPress.

Plugin Slug
metform

Installations
200,000+

Vulnerability
Authenticated (Subscriber+) Information Disclosure via mf shortcode

Patched in Version
3.3.2

Severity Score
Medium

The vulnerability has been patched, so you should update to version 3.3.2.

Social Media Share Buttons & Social Sharing Icons

Product image for Social Media Share Buttons & Social Sharing Icons.

Plugin Slug
ultimate-social-media-icons

Installations
200,000+

Vulnerability
CAuthenticated Stored Cross-Site Scripting

Patched in Version
2.8.2

Severity Score
Medium

The vulnerability has been patched, so you should update to version 2.8.2.

WP Mail Logging

Product image for WP Mail Logging.

Plugin Slug
wp-mail-logging

Installations
200,000+

Vulnerability
Unauthenticated Stored Cross-Site Scripting via Email

Patched in Version
1.11.1

Severity Score
High

The vulnerability has been patched, so you should update to version 1.11.1.

FiboSearch – AJAX Search for WooCommerce

Product image for FiboSearch – Ajax Search for WooCommerce.

Plugin Slug
ajax-search-for-woocommerce

Installations
100,000+

Vulnerability
Authenticated (Admin+) Stored Cross-Site Scripting

Patched in Version
1.24.0

Severity Score
Medium

The vulnerability has been patched, so you should update to version 1.24.0.

Visual Composer

Product image for Visual Composer Website Builder, Landing Page Builder, Custom Theme Builder, Maintenance Mode & Coming Soon Pages.

Plugin Slug
visualcomposer

Installations
70,000+

Vulnerability
Multiple Cross-Site Scripting (XSS)

Patched in Version
27.0

Severity Score
Medium

The vulnerability has been patched, so you should update to version 27.0.

VK Blocks

Product image for VK Blocks.

Plugin Slug
vk-blocks

Installations
70,000+

Vulnerability
Auth. Settings Update

Patched in Version
1.57.1.2

Severity Score
Medium

The vulnerability has been patched, so you should update to version 1.57.1.2.

Easy Digital Downloads

Product image for Easy Digital Downloads – Simple eCommerce for Selling Digital Files.

Plugin Slug
easy-digital-downloads

Installations
50,000+

Vulnerability
Cross-Site Request Forgery Leading To Plugin Upgrade

Patched in Version
3.1.2

Severity Score
Medium

The vulnerability has been patched, so you should update to version 3.1.2.

Getwid – Gutenberg Blocks

Product image for Getwid – Gutenberg Blocks.

Plugin Slug
getwid

Installations
50,000+

Vulnerability
Authenticated(Subscriber+) Server Side Request Forgery

Patched in Version
1.8.4

Severity Score
Medium

The vulnerability has been patched, so you should update to version 1.8.4.

Getwid – Gutenberg Blocks

Product image for Getwid – Gutenberg Blocks.

Plugin Slug
getwid

Installations
50,000+

Vulnerability
Improper Authorization via get_remote_templates REST endpoint

Patched in Version
1.8.4

Severity Score
Medium

The vulnerability has been patched, so you should update to version 1.8.4.

PowerPress

Product image for PowerPress Podcasting plugin by Blubrry.

Plugin Slug
powerpress

Installations
40,000+

Vulnerability
Authenticated Stored Cross-Site Scripting

Patched in Version
10.2.4

Severity Score
Medium

The vulnerability has been patched, so you should update to version 10.2.4.

Abandoned Cart Lite for WooCommerce

Product image for Abandoned Cart Lite for WooCommerce.

Plugin Slug
woocommerce-abandoned-cart

Installations
30,000+

Vulnerability
Authentication Bypass

Patched in Version
5.15.0

Severity Score
Critical

The vulnerability has been patched, so you should update to version 5.15.0.

Directorist

Product image for Directorist – WordPress Business Directory Plugin with Classified Ads Listings.

Plugin Slug
directorist

Installations
10,000+

Vulnerability
Authenticated Arbitrary Post Deletion

Patched in Version
7.5.5

Severity Score
High

The vulnerability has been patched, so you should update to version 7.5.5.

Directorist

Product image for Directorist – WordPress Business Directory Plugin with Classified Ads Listings.

Plugin Slug
directorist

Installations
10,000+

Vulnerability
Authenticated Privilege Escalation

Patched in Version
7.5.5

Severity Score
High

The vulnerability has been patched, so you should update to version 7.5.5.

WP Mail Catcher

Product image for Mail logging – WP Mail Catcher.

Plugin Slug
wp-mail-catcher

Installations
10,000+

Vulnerability
Unauthenticated Stored Cross-Site Scripting via Email Subject

Patched in Version
2.1.3

Severity Score
High

The vulnerability has been patched, so you should update to version 2.1.3.

Ultimate Product Catalogue

Product image for Ultimate Product Catalog.

Plugin Slug
ultimate-product-catalogue

Installations
8,000+

Vulnerability
Authenticated SQL Injection

Patched in Version
5.2.6

Severity Score
High

The vulnerability has been patched, so you should update to version 5.2.6.

B2BKing

Product image for B2BKing — Ultimate WooCommerce Wholesale and B2B Solution — Wholesale Order Form, Catalog Mode, Dynamic Pricing & More.

Plugin Slug
b2bking-wholesale-for-woocommerce

Installations
6,000+

Vulnerability
Information Disclosure

Patched in Version
4.6.20

Severity Score
Medium

The vulnerability has been patched, so you should update to version 4.6.20.

B2BKing

Product image for B2BKing — Ultimate WooCommerce Wholesale and B2B Solution — Wholesale Order Form, Catalog Mode, Dynamic Pricing & More.

Plugin Slug
b2bking-wholesale-for-woocommerce

Installations
6,000+

Vulnerability
Price Modification

Patched in Version
4.6.20

Severity Score
Medium

The vulnerability has been patched, so you should update to version 4.6.20.

WP EasyCart

Product image for Shopping Cart & eCommerce Store.

Plugin Slug
wp-easycart

Installations
6,000+

Vulnerability
Authenticated (Administrator+) SQL Injection via ‘orderby’

Patched in Version
5.4.11

Severity Score
High

The vulnerability has been patched, so you should update to version 5.4.11.

Online Booking & Scheduling Calendar for WordPress by vcita

Product image for Online Booking & Scheduling Calendar for WordPress by vcita.

Plugin Slug
meeting-scheduler-by-vcita

Installations
3,000+

Vulnerability
Missing Authorization to Account Logout

Patched in Version
4.3.0

Severity Score
Medium

The vulnerability has been patched, so you should update to version 4.3.0.

CodeColorer

Product image for CodeColorer.

Plugin Slug
codecolorer

Installations
2,000+

Vulnerability
Admin+ Cross-Site Scripting

Patched in Version
0.10.1

Severity Score
Medium

The vulnerability has been patched, so you should update to version 0.10.1.

GD Mail Queue

Product image for GD Mail Queue.

Plugin Slug
gd-mail-queue

Installations
700+

Vulnerability
Unauthenticated Stored Cross-Site Scripting via Email

Patched in Version
4.0

Severity Score
High

The vulnerability has been patched, so you should update to version 4.0.

Gravity Forms Google Sheet Connector

Product image for Gravity Forms Google Sheet Connector.

Plugin Slug
gsheetconnector-gravity-forms

Installations
500+

Vulnerability
Cross Site Request Forgery (CSRF)

Patched in Version
1.3.5

Severity Score
Medium

The vulnerability has been patched, so you should update to version 1.3.5.

Aajoda Testimonials

Product image for Aajoda Testimonials.

Plugin Slug
aajoda-testimonials

Installations
50+

Vulnerability
Admin+ Cross Site Scripting (XSS)

Patched in Version
2.2.2

Severity Score
Medium

The vulnerability has been patched, so you should update to version 2.2.2.

Catalyst Connect Zoho CRM Client Portal

Product image for Catalyst Connect Zoho CRM Client Portal.

Plugin Slug
catalyst-connect-client-portal

Installations
10+

Vulnerability
Reflected Cross Site Scripting (XSS)

Patched in Version
2.1.0

Severity Score
High

The vulnerability has been patched, so you should update to version 2.1.0.

Lana Email Logger

Product image for Lana Email Logger.

Plugin Slug
lana-email-logger

Vulnerability
Unauthenticated Stored Cross-Site Scripting via Email Subject

Patched in Version
1.1.0

Severity Score
High

The vulnerability has been patched, so you should update to version 1.1.0.

WP-Members Membership

Plugin
Members

Plugin Slug
wp-members1

Vulnerability
Missing Authorization to Settings Update

Patched in Version
3.4.8

Severity Score
Medium

The vulnerability has been patched, so you should update to version 3.4.8.

WP Brutal AI

Plugin
WP Brutal AI

Plugin Slug
wpbrutalai

Vulnerability
Admin+ Cross Site Scripting (XSS)

Patched in Version
2.0.1

Severity Score
Medium

The vulnerability has been patched, so you should update to version 2.0.1.

WP Brutal AI

Plugin
WP Brutal AI

Plugin Slug
wpbrutalai

Vulnerability
Admin+ SQL Injection

Patched in Version
2.0.0

Severity Score
High

The vulnerability has been patched, so you should update to version 2.0.0.

WordPress Plugin Vulnerabilities — Unpatched

This section contains plugin vulnerabilities with no known fix. Until a patch is available, you are advised to deactivate the plugin, at minimum, immediately. If there is a high risk of active exploits or the plugin remains unpatched for weeks, you are advised to delete the plugin. You should also delete persistently unpatched plugins the WordPress.org repository has locked and marked “Closed” so they can no longer be downloaded and installed.

VK Blocks

Product image for VK Blocks.

Plugin Slug
vk-blocks

Installations
70,000+

Vulnerability
Auth. Settings Update

Patched in Version
No Fix

Severity Score
Medium

The vulnerability has not been patched. You should deactivate the plugin.

Online Booking & Scheduling Calendar for WordPress by vcita

Product image for Online Booking & Scheduling Calendar for WordPress by vcita.

Plugin Slug
meeting-scheduler-by-vcita

Installations
3,000+

Vulnerability
Unauth. Stored Cross-Site Scripting (XSS)

Patched in Version
No Fix

Severity Score
High

The vulnerability has not been patched. You should deactivate the plugin.

Online Booking & Scheduling Calendar for WordPress by vcita

Product image for Online Booking & Scheduling Calendar for WordPress by vcita.

Plugin Slug
meeting-scheduler-by-vcita

Installations
3,000+

Vulnerability
Missing Authorization on REST-API

Patched in Version
No Fix

Severity Score
Medium

The vulnerability has not been patched. You should deactivate the plugin.

Online Booking & Scheduling Calendar for WordPress by vcita

Product image for Online Booking & Scheduling Calendar for WordPress by vcita.

Plugin Slug
meeting-scheduler-by-vcita

Installations
3,000+

Vulnerability
Missing Authorization to Settings Update and Media Upload

Patched in Version
No Fix

Severity Score
Medium

The vulnerability has not been patched. You should deactivate the plugin.

WordPress Tables

Product image for WordPress Tables.

Plugin Slug
wptables

Installations
2,000+

Vulnerability
Cross Site Scripting (XSS)

Patched in Version
No Fix

Severity Score
High

The vulnerability has not been patched. You should deactivate the plugin.

Contact Form Builder by vcita

Product image for Contact Form Builder by vcita.

Plugin Slug
contact-form-with-a-meeting-scheduler-by-vcita

Installations
1,000+

Vulnerability
Cross-Site Request Forgery to Stored Cross-Site Scripting

Patched in Version
No Fix

Severity Score
Medium

The vulnerability has not been patched. You should deactivate the plugin.

Contact Form Builder by vcita

Product image for Contact Form Builder by vcita.

Plugin Slug
contact-form-with-a-meeting-scheduler-by-vcita

Installations
1,000+

Vulnerability
Auth. Stored Cross Site Scripting (XSS)

Patched in Version
No Fix

Severity Score
Medium

The vulnerability has not been patched. You should deactivate the plugin.

Responsive CSS EDITOR

Plugin Slug
responsive-css-editor

Installations
600+

Vulnerability
Admin+ SQL Injection

Patched in Version
No Fix

Severity Score
High

The vulnerability has not been patched. You should deactivate the plugin.

Contact Form and Calls To Action by vcita

Product image for Contact Form and Calls To Action by vcita.

Plugin Slug
lead-capturing-call-to-actions-by-vcita

Installations
400+

Vulnerability
Auth. Stored Cross Site Scripting (XSS)

Patched in Version
No Fix

Severity Score
Medium

The vulnerability has not been patched. You should deactivate the plugin.

Contact Form and Calls To Action by vcita

Product image for Contact Form and Calls To Action by vcita.

Plugin Slug
lead-capturing-call-to-actions-by-vcita

Installations
400+

Vulnerability
Cross-Site Request Forgery to Stored Cross-Site Scripting

Patched in Version
No Fix

Severity Score
Medium

The vulnerability has not been patched. You should deactivate the plugin.

CRM and Lead Management by vcita

Product image for CRM and Lead Management by vcita.

Plugin Slug
crm-customer-relationship-management-by-vcita

Installations
200+

Vulnerability
Auth. Stored Cross-Site Scripting (XSS)

Patched in Version
No Fix

Severity Score
Medium

The vulnerability has not been patched. You should deactivate the plugin.

CRM and Lead Management by vcita

Product image for CRM and Lead Management by vcita.

Plugin Slug
crm-customer-relationship-management-by-vcita

Installations
200+

Vulnerability
Cross-Site Request Forgery to Stored Cross-Site Scripting

Patched in Version
No Fix

Severity Score
Medium

The vulnerability has not been patched. You should deactivate the plugin.

Page Builder by AZEXO

Plugin
Page Builder with Image Map by AZEXO

Plugin Slug
page-builder-by-azexo

Vulnerability
Cross Site Request Forgery (CSRF)

Patched in Version
No Fix

Severity Score
Medium

The vulnerability has not been patched and the plugin is closed. You should uninstall and delete the plugin.

Page Builder by AZEXO

Plugin
Page Builder with Image Map by AZEXO

Plugin Slug
page-builder-by-azexo

Vulnerability
Auth. Stored Cross-Site Scripting (XSS)

Patched in Version
No Fix

Severity Score
Medium

The vulnerability has not been patched and the plugin is closed. You should uninstall and delete the plugin.

Page Builder by AZEXO

Plugin
Page Builder with Image Map by AZEXO

Plugin Slug
page-builder-by-azexo

Vulnerability
Missing Authorization to Post Creation

Patched in Version
No Fix

Severity Score
Medium

The vulnerability has not been patched and the plugin is closed. You should uninstall and delete the plugin.

Page Builder by AZEXO

Plugin
Page Builder with Image Map by AZEXO

Plugin Slug
page-builder-by-azexo

Vulnerability
Cross-Site Request Forgery to Stored Cross-Site Scripting (XSS)

Patched in Version
No Fix

Severity Score
Medium

The vulnerability has not been patched and the plugin is closed. You should uninstall and delete the plugin.

WordPress Theme Vulnerabilities

In this section, you’ll find the latest WordPress theme vulnerabilities to be disclosed. You’ll see the same information provided above for vulnerable plugins, and the same advice applies. If a security update exists, install it immediately. If a vulnerability remains unpatched in a theme you are actively using, you will need to find an alternative theme. Deactivate and delete persistently unpatched themes and those that have been “Closed” in the WordPress.org theme repository. If you have a vulnerable theme installed that you are not actively using, simply delete it.

Activello

Product image for Activello.

Theme Slug
activello

Downloads
704,036

Vulnerability
Unauthenticated Plugin Activation/Deactivation

Patched in Version
1.4.2

Severity Score
Medium

The vulnerability has been patched, so you should update to version 1.4.2.

Newspaper X

Product image for Newspaper X.

Theme Slug
newspaper-x

Downloads
171,638

Vulnerability
Unauthenticated Plugin Activation/Deactivation

Patched in Version
1.3.2

Severity Score
Medium

The vulnerability has been patched, so you should update to version 1.3.2.

Brilliance

Product image for Brilliance.

Theme Slug
brilliance

Downloads
139,860

Vulnerability
Unauthenticated Plugin Activation/Deactivation

Patched in Version
1.3.0

Severity Score
Medium

The vulnerability has been patched, so you should update to version 1.3.0.
Dan Knauss

Dan Knauss is StellarWP’s Technical Content Generalist. He’s been a writer, teacher, and freelancer working in open source since the late 1990s and with WordPress since 2004.

Source link

Written by:
Abdul Wahid
Published on:
June 18, 2023

Categories: Woocommerce

Primary Sidebar

Wordpress

  • Content Management Systems (2)
  • Digital Marketing (4)
  • Internet Marketing (28)
  • Latest News (458)
  • Online Business (2)
  • Plugins (519)
  • Themes (521)
  • Videos (1,350)
  • Website Development (1)
  • Woocommerce (589)
  • WordPress (6)

Recent Articles

Unlock Your Internet Marketing Potential with WordPress: Tips, Tools, and Strategies

How to Use WordPress to Achieve Your Internet …

Continue Reading about Unlock Your Internet Marketing Potential with WordPress: Tips, Tools, and Strategies

Unlock Your Internet Marketing Potential: Harnessing the Power of WordPress

How to Use WordPress to Achieve Your Internet …

Continue Reading about Unlock Your Internet Marketing Potential: Harnessing the Power of WordPress

Search our site

Explore more

Get our Wordpress Guide Get Plugins Get Connected

Footer

VirusWord by Promaps, Inc.

Barnes Place
Colombo 7, Western 00700

Copyright © 2025 · Promaps, Inc.

Keep In Touch

  • Email
  • Facebook
  • Instagram
  • Pinterest
  • Twitter