• Skip to primary navigation
  • Skip to main content
  • Skip to primary sidebar

virusword.com

Learn Wordpress

  • Home
  • WordPress Shop
    • Fotopress
    • SEO Tool Kit
    • Social Contact
    • Tag Machine 2
    • Video Profits
  • Latest News
  • WordPress
    • Plugins
    • Themes
    • Tutorials
    • Videos
    • Woocommerce
  • About Us
  • Contact Us
    • Terms of Service
    • Privacy Policy
  • Show Search
Hide Search
Home/Woocommerce/WordPress Vulnerability Report – March 2, 2022

WordPress Vulnerability Report – March 2, 2022

Written by

Michael Moore

on

March 2, 2022

Last Updated on March 3, 2022

Vulnerable plugins and themes are the #1 reason WordPress websites get hacked. The weekly WordPress Vulnerability Report powered by WPScan covers recent WordPress plugin, theme, and core vulnerabilities, and what to do if you run one of the vulnerable plugins or themes on your website.

Each vulnerability will have a severity rating of Low, Medium, High, or Critical. Responsible disclosure and reporting of vulnerabilities is an integral part of keeping the WordPress community safe. New in this report: vulnerabilities are now listed in order by the number of active installs, rather than the date of the disclosure.

Please share this post with your friends to help get the word out and make WordPress safer for everyone!

Contents of the March 2, 2022 Report

Next Week: WordPress Disaster Week

March 8 – 10, 2022

A FREE ONLINE TRAINING EVENT

Are you ready if disaster strikes your WordPress website today? From running an update that breaks everything to hacks or accidentally deleting an important file, the reality is it’s not a matter of if but when something will go wrong with your site. To help you combat the threat of website disasters, we’re hosting the biggest free, online WordPress security training event of the year so that EVERYONE can have a plan if and when a website catastrophe strikes.

WordPress Core Vulnerabilities

WordPress 5.9.1 was released on February 22, 2022, as a maintenance update with 33 bug fixes. Be sure to update to WordPress 5.9.1 as soon as possible!

  • No new WordPress core vulnerabilities were disclosed this week.

WordPress Plugin Vulnerabilities

In this section, the latest WordPress plugin vulnerabilities have been disclosed. Each plugin listing includes the type of vulnerability, the active installations, the version number if patched, and the severity rating.

WooCommerce

Product image for WooCommerce.

Plugin
WooCommerce

Installations
5,000,000+

Vulnerability
Path Traversal via Importers; Subscriber+ Arbitrary Comment Deletion

Patched in Version
6.2.1

Severity Score
Medium

The vulnerability has been patched, so you should update to version 6.2.1.

Header Footer Code Manager

Product image for Header Footer Code Manager.

Plugin
Header Footer Code Manager

Installations
300,000+

Vulnerability
Reflected Cross-Site Scripting

Patched in Version
1.1.17

Severity Score
Medium

The vulnerability has been patched, so you should update to version 1.1.17.

Advanced Contact Form 7 DB

Product image for Advanced Contact form 7 DB.

Plugin
Advanced Contact form 7 DB

Installations
90,000+

Vulnerability
Subscriber+ Arbitrary File Deletion

Patched in Version
1.8.7

Severity Score
High

The vulnerability has been patched, so you should update to version 1.8.7.

3D FlipBook

Product image for 3D FlipBook – PDF Flipbook Viewer, Flipbook Image Gallery.

Plugin
3D FlipBook – PDF Flipbook Viewer, Flipbook Image Gallery

Installations
70,000+

Vulnerability
Subscriber+ Stored Cross-Site Scripting

Patched in Version
1.12.1

Severity Score
High

The vulnerability has been patched, so you should update to version 1.12.1.

BulletProof Security

Product image for BulletProof Security.

Plugin
BulletProof Security

Installations
50,000+

Vulnerability
Admin+ Stored Cross-Site Scripting (XSS)

Patched in Version
5.8

Severity Score
Low

The vulnerability has been patched, so you should update to version 5.8.

Simple Membership

Product image for Simple Membership.

Plugin
Simple Membership

Installations
50,000+

Vulnerability
Arbitrary Transaction Deletion via CSRF

Patched in Version
4.1.0

Severity Score
Medium

The vulnerability has been patched, so you should update to version 4.1.0.

Amelia

Product image for Amelia – Events & Appointments Booking Calendar.

Plugin
Amelia – Events & Appointments Booking Calendar

Installations
40,000+

Vulnerability
Manager+ RCE; Arbitrary Customer Deletion via CSRF; Reflected Cross-Site Scripting

Patched in Version
1.0.46

Severity Score
Medium

The vulnerability has been patched, so you should update to version 1.0.46.

Photoswipe Masonry Gallery

Product image for Photoswipe Masonry Gallery.

Plugin
Photoswipe Masonry Gallery

Installations
10,000+

Vulnerability
Subscriber+ Stored Cross-Site Scripting

Patched in Version
1.2.15

Severity Score
Medium

The vulnerability has been patched, so you should update to version 1.2.15.

400+ Plugins, Themes Impacted by Insecure Freemius Version

This week, it was discovered that many plugins and themes are using an insecure version of the Freemius Framework, which is used to power their upsell paths from free to Pro.

As of this report, over 400 plugins and 25 themes are impacted. Because the list is so large, we’re reporting an abbreviated list of the plugins impacted in the table below.

Actions to take:

  • Update all your themes and plugins to the latest versions.
  • Be sure to turn on automatic updates for your plugins and themes as developers continue to release updates.
  • Activate the iThemes Security Site Scan module to get a notification if we find that you are running a vulnerable plugin or theme.
  • Turn on Version Management in iThemes Security to handle automatic vulnerability patching.

WordPress Plugin Vulnerabilities – No Known Fix

This section contains plugin vulnerabilities with no known fix. Until a patch is available, immediately uninstall and delete the plugin.

RW Divi Unite Gallery

Plugin
RW Divi Unite Gallery

Vulnerability
Security Bypass

Patched in Version
No Fix

Severity Score
Critical

The vulnerability has not been patched. You should deactivate the plugin.

WordPress Theme Vulnerabilities

In this section, the latest WordPress theme vulnerabilities have been disclosed. Each theme listing includes the type of vulnerability, the active installations, the version number if patched, and the severity rating.

Brand

Product image for Brand.

Theme
Brand

Downloads
32,856

Vulnerability
Unauthorized AJAX Calls via Freemius

Patched in Version
No Fix

Severity Score
Medium

The vulnerability has not been patched. You should deactivate the theme.

WP Sierra

Product image for WP Sierra.

Theme
WP Sierra

Downloads
31,752

Vulnerability
Unauthorized AJAX Calls via Freemius

Patched in Version
No Fix

Severity Score
Medium

The vulnerability has not been patched. You should deactivate the theme.

Hasium

Product image for Hasium.

Theme
Hasium

Downloads
22,993

Vulnerability
Unauthorized AJAX Calls via Freemius

Patched in Version
No Fix

Severity Score
Medium

The vulnerability has not been patched. You should deactivate the theme.

Broadcast Lite

Product image for Broadcast Lite.

Theme
Broadcast Lite

Downloads
18,658

Vulnerability
Unauthorized AJAX Calls via Freemius

Patched in Version
No Fix

Severity Score
Medium

The vulnerability has not been patched. You should deactivate the theme.

Speculor

Product image for Speculor.

Theme
Speculor

Downloads
17,282

Vulnerability
Unauthorized AJAX Calls via Freemius

Patched in Version
No Fix

Severity Score
Medium

The vulnerability has not been patched. You should deactivate the theme.

Aquarella Lite

Product image for Aquarella Lite.

Theme
Aquarella Lite

Downloads
16,577

Vulnerability
Unauthorized AJAX Calls via Freemius

Patched in Version
No Fix

Severity Score
Medium

The vulnerability has not been patched. You should deactivate the theme.

Meridia

Product image for Meridia.

Theme
Meridia

Downloads
16,053

Vulnerability
Unauthorized AJAX Calls via Freemius

Patched in Version
No Fix

Severity Score
Medium

The vulnerability has not been patched. You should deactivate the theme.

ConsultPress Lite

Product image for ConsultPress Lite.

Theme
ConsultPress Lite

Downloads
15,862

Vulnerability
Unauthorized AJAX Calls via Freemius

Patched in Version
No Fix

Severity Score
Medium

The vulnerability has not been patched. You should deactivate the theme.

Everse

Product image for Everse.

Theme
Everse

Downloads
15,104

Vulnerability
Unauthorized AJAX Calls via Freemius

Patched in Version
No Fix

Severity Score
Medium

The vulnerability has not been patched. You should deactivate the theme.

Shuban

Product image for Shuban.

Theme
Shuban

Downloads
13,771

Vulnerability
NO AUTHORISATION

Patched in Version
No Fix

Severity Score
Medium

The vulnerability has not been patched. You should deactivate the theme.

Purus

Product image for Purus.

Theme
Purus

Downloads
13,553

Vulnerability
NO AUTHORISATION

Patched in Version
No Fix

Severity Score
Medium

The vulnerability has not been patched. You should deactivate the theme.

Elation

Product image for Elation.

Theme
Elation

Downloads
11,843

Vulnerability
NO AUTHORISATION

Patched in Version
No Fix

Severity Score
Medium

The vulnerability has not been patched. You should deactivate the theme.

Purosa

Product image for Purosa.

Theme
Purosa

Downloads
10,138

Vulnerability
NO AUTHORISATION

Patched in Version
1.1.0

Severity Score
Medium

The vulnerability has been patched, so you should update to version 1.1.0.

Elasta

Product image for Elasta.

Theme
Elasta

Downloads
9,863

Vulnerability
NO AUTHORISATION

Patched in Version
1.0.8

Severity Score
Medium

The vulnerability has been patched, so you should update to version 1.0.8.

LearnMore

Product image for LearnMore.

Theme
LearnMore

Downloads
9,621

Vulnerability
NO AUTHORISATION

Patched in Version
No Fix

Severity Score
Medium

The vulnerability has not been patched. You should deactivate the theme.

NicheBase

Product image for NicheBase.

Theme
NicheBase

Downloads
6,638

Vulnerability
NO AUTHORISATION

Patched in Version
1.2.2

Severity Score
Medium

The vulnerability has been patched, so you should update to version 1.2.2.

Bani

Product image for Bani.

Theme
Bani

Downloads
6,015

Vulnerability
NO AUTHORISATION

Patched in Version
No Fix

Severity Score
Medium

The vulnerability has not been patched. You should deactivate the theme.

Arendelle

Product image for Arendelle.

Theme
Arendelle

Downloads
5,950

Vulnerability
NO AUTHORISATION

Patched in Version
No Fix

Severity Score
Medium

The vulnerability has not been patched. You should deactivate the theme.

Cuisine Palace

Product image for Cuisine Palace.

Theme
Cuisine Palace

Downloads
5,651

Vulnerability
NO AUTHORISATION

Patched in Version
No Fix

Severity Score
Medium

The vulnerability has not been patched. You should deactivate the theme.

Nokke

Product image for Nokke.

Theme
Nokke

Downloads
3,809

Vulnerability
NO AUTHORISATION

Patched in Version
No Fix

Severity Score
Medium

The vulnerability has not been patched. You should deactivate the theme.

Amela

Product image for Amela.

Theme
Amela

Downloads
3,645

Vulnerability
NO AUTHORISATION

Patched in Version
No Fix

Severity Score
Medium

The vulnerability has not been patched. You should deactivate the theme.

Viralike

Product image for Viralike.

Theme
Viralike

Downloads
2,510

Vulnerability
NO AUTHORISATION

Patched in Version
No Fix

Severity Score
Medium

The vulnerability has not been patched. You should deactivate the theme.

Villar

Product image for Villar.

Theme
Villar

Downloads
2,037

Vulnerability
NO AUTHORISATION

Patched in Version
1.0.8

Severity Score
Medium

The vulnerability has been patched, so you should update to version 1.0.8.

Unakit

Product image for Unakit.

Theme
Unakit

Downloads
1,792

Vulnerability
NO AUTHORISATION

Patched in Version
No Fix

Severity Score
Medium

The vulnerability has not been patched. You should deactivate the theme.

WP Moose

Product image for WP Moose.

Theme
WP Moose

Downloads
1,567

Vulnerability
NO AUTHORISATION

Patched in Version
1.0.1

Severity Score
Medium

The vulnerability has been patched, so you should update to version 1.0.1.

How to Protect Your WordPress Website From Vulnerable Plugins and Themes

As you can see from this report, lots of new WordPress plugin and theme vulnerabilities are disclosed each week. We know it can be difficult to stay on top of every reported vulnerability disclosure, so the iThemes Security Pro plugin makes it easy to make sure your site isn’t running a theme, plugin, or WordPress core version with a known vulnerability.

Get iThemes Security Pro with 24/7 Website Security Monitoring

iThemes Security Pro, our WordPress security plugin, offers 50+ ways to secure and protect your website from common WordPress security vulnerabilities. With WordPress, two-factor authentication, brute force protection, strong password enforcement, and more, you can add extra layers of security to your website.

Get iThemes Security Pro

Michael Moore

Each week, Michael puts together the WordPress Vulnerability Report to help keep your sites safe. As Product Manager at iThemes, he helps us continue to improve the iThemes product lineup. He’s a giant nerd & loves learning about all things tech, old & new. You can find Michael hanging out with his wife & daughter, reading or listening to music when not working.

WordPress Vulnerability Report

Source link

Written by:
Abdul Wahid
Published on:
March 6, 2022

Categories: Woocommerce

Primary Sidebar

Wordpress

  • Content Management Systems (2)
  • Digital Marketing (4)
  • Internet Marketing (28)
  • Latest News (458)
  • Online Business (2)
  • Plugins (519)
  • Themes (521)
  • Videos (1,350)
  • Website Development (1)
  • Woocommerce (589)
  • WordPress (6)

Recent Articles

Unlock Your Internet Marketing Potential with WordPress: Tips, Tools, and Strategies

How to Use WordPress to Achieve Your Internet …

Continue Reading about Unlock Your Internet Marketing Potential with WordPress: Tips, Tools, and Strategies

Unlock Your Internet Marketing Potential: Harnessing the Power of WordPress

How to Use WordPress to Achieve Your Internet …

Continue Reading about Unlock Your Internet Marketing Potential: Harnessing the Power of WordPress

Search our site

Explore more

Get our Wordpress Guide Get Plugins Get Connected

Footer

VirusWord by Promaps, Inc.

Barnes Place
Colombo 7, Western 00700

Copyright © 2025 · Promaps, Inc.

Keep In Touch

  • Email
  • Facebook
  • Instagram
  • Pinterest
  • Twitter