• Skip to primary navigation
  • Skip to main content
  • Skip to primary sidebar

virusword.com

Learn Wordpress

  • Home
  • WordPress Shop
    • Fotopress
    • SEO Tool Kit
    • Social Contact
    • Tag Machine 2
    • Video Profits
  • Latest News
  • WordPress
    • Plugins
    • Themes
    • Tutorials
    • Videos
    • Woocommerce
  • About Us
  • Contact Us
    • Terms of Service
    • Privacy Policy
  • Show Search
Hide Search
Home/Woocommerce/WordPress Vulnerability Report – November 23, 2022

WordPress Vulnerability Report – November 23, 2022

Vulnerable plugins and themes are the #1 reason WordPress websites get hacked. The weekly WordPress Vulnerability Report powered by WPScan covers recent WordPress plugin, theme, and core vulnerabilities and what to do if you run one of the vulnerable plugins or themes on your website.

Each vulnerability will have a severity rating of low, medium, high, or critical. Responsible disclosure and reporting of vulnerabilities is an integral part of keeping the WordPress community safe. Please share this post with your friends to help get the word out and make WordPress safer for everyone!

Contents of the November 23, 2022 Report

The Future of Authentication is Passkeys! Login to your WordPress site with Biometrics only available in iThemes Security Pro

The problems of brute force attacks through credential stuffing, phishing attacks, and reused passwords have made our digital lives less secure. We’ve all tried to encourage 2-factor authentication as a protection, but less than 30% of users actually use 2FA. Password-based logins are a problem.

The future of authentication is passkeys, and iThemes Security Pro is the first to bring this breakthrough technology to WordPress sites. Using breakthrough WebAuthn technology based on public/private cryptography, passkeys make passwords obsolete. Now, website admins and end users can have secure logins without the inconvenience of additional two-factor apps, password managers, or complex password requirements.

WordPress Core News

WordPress 6.1.1 was released on November 15, 2022, as a short-cycle maintenance release with 29 bug fixes in Core and 21 bug fixes for the block editor. Because this is a core update, be sure to update to WordPress 6.0.1 as soon as possible! As always, with a major release like this, it makes sense to ensure your site is backed up with BackupBuddy before updating.

  • No new WordPress core vulnerabilities were disclosed this week.

WordPress Core Dropping Support for WordPress Versions 3.7. – 4.0

In more WordPress core security news, the WordPress Security Team will no longer provide security updates for WordPress core versions 3.7 – 4.0. Please make sure all your WordPress sites are running the latest version.

Get the weekly WordPress Vulnerability Report delivered to your inbox each Wednesday.

WordPress Plugin Vulnerabilities

In this section, the latest WordPress plugin vulnerabilities have been disclosed. Each plugin listing includes the type of vulnerability, the active installations, the version number if patched, and the severity rating.

All-In-One Security

Product image for All-In-One Security (AIOS) – Security and Firewall.

Plugin Slug
all-in-one-wp-security-and-firewall

Installations
1,000,000+

Vulnerability
IP Spoofing; Bulk Actions via CSRF

Patched in Version
5.1.1

Severity Score
Medium

The vulnerability has been patched, so you should update to version 5.1.1.

SVG Support

Product image for SVG Support.

Plugin Slug
svg-support

Installations
1,000,000+

Vulnerability
Author+ Stored XSS

Patched in Version
2.5.2

Severity Score
Medium

The vulnerability has been patched, so you should update to version 2.5.2.

WordPress Popular Posts

Product image for WordPress Popular Posts.

Plugin Slug
wordpress-popular-posts

Installations
200,000+

Vulnerability
Unauthenticated Views Manipulation

Patched in Version
6.1.0

Severity Score
Medium

The vulnerability has been patched, so you should update to version 6.1.0.

Plugin for Google Reviews

Product image for Plugin for Google Reviews.

Plugin Slug
widget-google-reviews

Installations
100,000+

Vulnerability
Subscriber+ Widget Creation

Patched in Version
2.2.3

Severity Score
Medium

The vulnerability has been patched, so you should update to version 2.2.3.

Icegram Express

Product image for Icegram Express – Email Subscribers, Newsletters and Marketing Automation Plugin.

Plugin Slug
email-subscribers

Installations
100,000+

Vulnerability
Subscriber+ SQLi

Patched in Version
5.5.0

Severity Score
High

The vulnerability has been patched, so you should update to version 5.5.0.

Crowdsignal Dashboard

Product image for Crowdsignal Dashboard – Polls, Surveys & more.

Plugin Slug
polldaddy

Installations
90,000+

Vulnerability
Contributor+ Rating Settings Update

Patched in Version
3.0.10

Severity Score
Medium

The vulnerability has been patched, so you should update to version 3.0.10.

Livemesh Addons for Elementor

Product image for Livemesh Addons for Elementor.

Plugin Slug
addons-for-elementor

Installations
90,000+

Vulnerability
Admin+ Stored XSS

Patched in Version
7.2.4

Severity Score
Low

The vulnerability has been patched, so you should update to version 7.2.4.

Booster for WooCommerce

Product image for Booster for WooCommerce.

Plugin Slug
woocommerce-jetpack

Installations
70,000+

Vulnerability
Custom Role Creation/Deletion via CSRF

Patched in Version
5.6.7

Severity Score
Medium

The vulnerability has been patched, so you should update to version 5.6.7.

User Registration

Product image for User Registration – Custom Registration Form, Login Form And User Profile For WordPress.

Plugin Slug
user-registration

Installations
60,000+

Vulnerability
Subscriber+ Arbitrary File Upload

Patched in Version
2.2.4.1

Severity Score
Critical

The vulnerability has been patched, so you should update to version 2.2.4.1.

Permalink Manager Lite

Product image for Permalink Manager Lite.

Plugin Slug
permalink-manager

Installations
60,000+

Vulnerability
Settings Update via CSRF

Patched in Version
2.2.20.2

Severity Score
Medium

The vulnerability has been patched, so you should update to version 2.2.20.2.

Dokan

Product image for Dokan – Best WooCommerce Multivendor Marketplace Solution – Build Your Own Amazon, eBay, Etsy.

Plugin Slug
dokan-lite

Installations
60,000+

Vulnerability
Unauthenticated SQLi

Patched in Version
3.7.6

Severity Score
High

The vulnerability has been patched, so you should update to version 3.7.6.

Easy Video Player

Product image for Easy Video Player.

Plugin Slug
easy-video-player

Installations
40,000+

Vulnerability
Contributor+ Stored XSS

Patched in Version
1.2.2.3

Severity Score
Medium

The vulnerability has been patched, so you should update to version 1.2.2.3.

Jetpack CRM

Product image for Jetpack CRM – Clients, Leads, Invoices, Billing, Email Marketing, & Automation.

Plugin Slug
zero-bs-crm

Installations
30,000+

Vulnerability
Admin+ Cross-Site Scripting

Patched in Version
5.4.3

Severity Score
Low

The vulnerability has been patched, so you should update to version 5.4.3.

wpForo Forum

Product image for wpForo Forum.

Plugin Slug
wpforo

Installations
20,000+

Vulnerability
Arbitrary User Deletion via CSRF

Patched in Version
2.1.0

Severity Score
High

The vulnerability has been patched, so you should update to version 2.1.0.

Ezoic

Product image for Ezoic.

Plugin Slug
ezoic-integration

Installations
20,000+

Vulnerability
Admin+ Stored XSS; Unauthenticated Settings Update to Stored XSS

Patched in Version
2.8.9

Severity Score
Low

The vulnerability has been patched, so you should update to version 2.8.9.

Welcart e-Commerce

Product image for Welcart e-Commerce.

Plugin Slug
usc-e-shop

Installations
20,000+

Vulnerability
Multiple Subscriber+ Stored Cross-Site Scripting; Subscriber+ Arbitrary Shipping Method Creation/Update/Deletion

Patched in Version
2.8.4

Severity Score
Medium

The vulnerability has been patched, so you should update to version 2.8.4.

StopBadBots

Product image for Block Bad Bots and Stop Bad Bots Crawlers and Spiders and Anti Spam Protection.

Plugin Slug
stopbadbots

Installations
10,000+

Vulnerability
Subscriber+ Arbitrary Plugin Installation

Patched in Version
7.24

Severity Score
High

The vulnerability has been patched, so you should update to version 7.24.

Directorist

Product image for Directorist – WordPress Business Directory Plugin with Classified Ads Listings.

Plugin Slug
directorist

Installations
10,000+

Vulnerability
Subscriber+ Arbitrary User Password Update via IDOR

Patched in Version
7.4.2.2

Severity Score
High

The vulnerability has been patched, so you should update to version 7.4.2.2.

Videojs HTML5 Player

Product image for Videojs HTML5 Player.

Plugin Slug
videojs-html5-player

Installations
10,000+

Vulnerability
Contributor+ Stored XSS

Patched in Version
1.1.9

Severity Score
Medium

The vulnerability has been patched, so you should update to version 1.1.9.

Motors

Product image for Motors – Car Dealer, Classifieds & Listing.

Plugin Slug
motors-car-dealership-classified-listings

Installations
9,000+

Vulnerability
Arbitrary File Upload

Patched in Version
1.4.4

Severity Score
Critical

The vulnerability has been patched, so you should update to version 1.4.4.

Booking Calendar

Product image for Booking calendar, Appointment Booking System.

Plugin Slug
booking-calendar

Installations
5,000+

Vulnerability
Unauthenticated Arbitrary File Upload

Patched in Version
3.2.2

Severity Score
Critical

The vulnerability has been patched, so you should update to version 3.2.2.

News Announcement Scroll

Product image for News Announcement Scroll.

Plugin Slug
news-announcement-scroll

Installations
5,000+

Vulnerability
Admin+ Stored XSS

Patched in Version
9.0.0

Severity Score
Low

The vulnerability has been patched, so you should update to version 9.0.0.

WP Stripe Checkout

Product image for WP Stripe Checkout.

Plugin Slug
wp-stripe-checkout

Installations
4,000+

Vulnerability
Contributor+ Stored XSS

Patched in Version
1.2.2.21

Severity Score
Medium

The vulnerability has been patched, so you should update to version 1.2.2.21.

Export Users With Meta

Plugin Slug
user-export-with-their-meta-data

Installations
3,000+

Vulnerability
Subscriber+ CSV Injection

Patched in Version
0.6.10

Severity Score
Low

The vulnerability has been patched, so you should update to version 0.6.10.

Flowplayer Video Player

Product image for Flowplayer Video Player.

Plugin Slug
flowplayer6-video-player

Installations
2,000+

Vulnerability
Contributor+ Stored XSS

Patched in Version
1.0.5

Severity Score
Medium

The vulnerability has been patched, so you should update to version 1.0.5.

Car Dealer

Product image for Car Dealer (Dealership) and Vehicle sales WordPress Plugin.

Plugin Slug
cardealer

Installations
1,000+

Vulnerability
Subscriber+ Arbitrary Plugin Installation

Patched in Version
3.05

Severity Score
High

The vulnerability has been patched, so you should update to version 3.05.

Checkout for PayPal

Product image for Checkout for PayPal.

Plugin Slug
checkout-for-paypal

Installations
1,000+

Vulnerability
Contributor+ Stored XSS

Patched in Version
1.0.14

Severity Score
Medium

The vulnerability has been patched, so you should update to version 1.0.14.

Anthologize

Plugin Slug
anthologize

Installations
900+

Vulnerability
Admin+ Stored XSS

Patched in Version
0.8.1

Severity Score
Low

The vulnerability has been patched, so you should update to version 0.8.1.

Chameleon

Product image for Chameleon.

Plugin Slug
chameleon

Installations
500+

Vulnerability
Admin+ Stored XSS

Patched in Version
1.4.4

Severity Score
Low

The vulnerability has been patched, so you should update to version 1.4.4.

Responsive Lightbox2

Product image for Responsive Lightbox2.

Plugin Slug
responsive-lightbox2

Installations
400+

Vulnerability
Contributor+ Stored XSS

Patched in Version
1.0.4

Severity Score
Medium

The vulnerability has been patched, so you should update to version 1.0.4.

Easy Form Builder

Product image for Easy Form Builder.

Plugin Slug
easy-form-builder

Installations
300+

Vulnerability
Admin+ Stored XSS

Patched in Version
3.4.0

Severity Score
Low

The vulnerability has been patched, so you should update to version 3.4.0.

Booster Elite for WooCommerce

Plugin
Booster Elite for WooCommerce

Plugin Slug
booster-elite-for-woocommerce

Vulnerability
Custom Role Creation/Deletion via CSRF

Patched in Version
1.1.8

Severity Score
Medium

The vulnerability has been patched, so you should update to version 1.1.8.

Booster Plus for WooCommerce

Plugin
Booster Plus for WooCommerce

Plugin Slug
booster-plus-for-woocommerce

Vulnerability
Custom Role Creation/Deletion via CSRF

Patched in Version
5.6.6

Severity Score
Medium

The vulnerability has been patched, so you should update to version 5.6.6.

Cooked Pro

Plugin
Cooked Pro

Plugin Slug
cooked-pro

Vulnerability
Unauthenticated PHP Object Injection

Patched in Version
1.7.5.7

Severity Score
High

The vulnerability has been patched, so you should update to version 1.7.5.7.

SMSA Shipping for WooCommerce

Plugin
SMSA Shipping for WooCommerce

Plugin Slug
smsa-shipping-for-woocommerce

Vulnerability
Subscriber+ Arbitrary File Download

Patched in Version
1.0.5

Severity Score
High

The vulnerability has been patched, so you should update to version 1.0.5.

AntiHacker

Plugin Slug
antihacker

Vulnerability
Subscriber+ Arbitrary Plugin Installation

Patched in Version
4.20

Severity Score
High

The vulnerability has been patched, so you should update to version 4.20.

WooCommerce Shipping – DPD baltic

Plugin
WooCommerce Shipping – DPD baltic

Plugin Slug
woo-shipping-dpd-baltic

Vulnerability
Admin+ Stored XSS; Subscriber+ Arbitrary Options Deletion

Patched in Version
1.2.11

Severity Score
Medium

The vulnerability has been patched, so you should update to version 1.2.11.

WP Memory

Plugin Slug
wp-memory

Vulnerability
Subscriber+ Arbitrary Plugin Installation

Patched in Version
2.46

Severity Score
High

The vulnerability has been patched, so you should update to version 2.46.

WPTools

Plugin Slug
wptools

Vulnerability
Subscriber+ Arbitrary Plugin Installation

Patched in Version
3.43

Severity Score
High

The vulnerability has been patched, so you should update to version 3.43.

WordPress Plugin Vulnerabilities – No Known Fix

This section contains plugin vulnerabilities with no known fix. Until a patch is available, immediately uninstall and delete the plugin.

Ultimate Tables

Plugin Slug
ultimate-tables

Vulnerability
Reflected Cross-Site Scripting

Patched in Version
No Fix

Severity Score
Medium

The vulnerability has not been patched and the plugin is closed. You should uninstall and delete the plugin.

WooSwipe WooCommerce Gallery

Plugin Slug
wooswipe

Vulnerability
Subscriber+ Settings Update

Patched in Version
No Fix

Severity Score
Medium

The vulnerability has not been patched and the plugin is closed. You should uninstall and delete the plugin.

Shortcodes and extra features for Phlox theme

Plugin Slug
auxin-elements

Vulnerability
PHP Objection Injection

Patched in Version
No Fix

Severity Score
Medium

The vulnerability has not been patched and the plugin is closed. You should uninstall and delete the plugin.

Essential Real Estate

Plugin Slug
essential-real-estate

Vulnerability
Reflected Cross-Site-Scripting

Patched in Version
No Fix

Severity Score
Medium

The vulnerability has not been patched and the plugin is closed. You should uninstall and delete the plugin.

Image Hover Effects

Plugin Slug
image-hover-effects

Vulnerability
Admin+ Stored XSS

Patched in Version
No Fix

Severity Score
Low

The vulnerability has not been patched and the plugin is closed. You should uninstall and delete the plugin.

Flat PM

Plugin Slug
flatpm-wp

Vulnerability
Reflected Cross-Site Scripting

Patched in Version
No Fix

Severity Score
Medium

The vulnerability has not been patched and the plugin is closed. You should uninstall and delete the plugin.

GetYourGuide Ticketing

Plugin Slug
getyourguide-ticketing

Vulnerability
Admin+ Stored XSS

Patched in Version
No Fix

Severity Score
Low

The vulnerability has not been patched and the plugin is closed. You should uninstall and delete the plugin.

ProfileGrid

Plugin Slug
profilegrid-user-profiles-groups-and-communities

Vulnerability
Subscriber+ CSV Injection

Patched in Version
No Fix

Severity Score
Medium

The vulnerability has not been patched and the plugin is closed. You should uninstall and delete the plugin.

Donation Button

Plugin Slug
donation-button

Vulnerability
Contributor+ Stored XSS; Subscriber+ Broken Access Control leading to SMS Spam

Patched in Version
No Fix

Severity Score
Medium

The vulnerability has not been patched and the plugin is closed. You should uninstall and delete the plugin.

Helloprint

Plugin Slug
helloprint

Vulnerability
Reflected Cross-Site Scripting

Patched in Version
No Fix

Severity Score
Medium

The vulnerability has not been patched and the plugin is closed. You should uninstall and delete the plugin.

Buddybadges

Plugin Slug
buddybadges

Vulnerability
Admin+ SQLi

Patched in Version
No Fix

Severity Score
Medium

The vulnerability has not been patched and the plugin is closed. You should uninstall and delete the plugin.

iFeature Slider

Plugin Slug
ifeature-slider

Vulnerability
Contributor+ Stored XSS

Patched in Version
No Fix

Severity Score
Medium

The vulnerability has not been patched and the plugin is closed. You should uninstall and delete the plugin.

WordPress Theme Vulnerabilities

In this section, the latest WordPress theme vulnerabilities have been disclosed. Each theme listing includes the type of vulnerability, the active installations, the version number if patched, and the severity rating.

Listingo

Theme
Listingo

Theme Slug
listingo

Vulnerability
Unauthenticated Arbitrary File Upload

Patched in Version
3.2.7

Severity Score
Critical

The vulnerability has been patched, so you should update to version 3.2.7.

Betheme

Theme
Betheme

Theme Slug
betheme

Vulnerability
Contributor+ PHP Object Injection; Subscriber+ PHP Object Injection; Subscriber+ Stored XSS

Patched in Version
26.6.3

Severity Score
Medium

The vulnerability has been patched, so you should update to version 26.6.3.

Never worry about running a vulnerable plugin or theme again.

As you can see from this report, lots of new WordPress plugin and theme vulnerabilities are disclosed each week. We know it can be difficult to stay on top of every reported vulnerability disclosure, so the iThemes Security Pro plugin makes it easy to make sure your site isn’t running a theme, plugin, or WordPress core version with a known vulnerability.

Scans Your Website Twice a Day for Vulnerabilities

Your website’s plugins, themes, and WordPress core versions are checked against the WPScan Vulnerability Database for the latest vulnerability disclosures.

Automatically Updates if a Security Fix is Available

Paired with Version Management, iThemes Security will automatically update a plugin, theme, or WordPress core version if it has a vulnerability.

Emails You if Site Scan Detects a Vulnerability

You can receive an email report if your site is running vulnerable versions of a plugin, theme, or WordPress core. Customize the email addresses that receive scan results.

The Best WordPress Security Plugin to Secure & Protect WordPress Sites

WordPress currently powers over 40% of all websites, so it has become an easy target for hackers with malicious intent. The iThemes Security Pro plugin takes the guesswork out of WordPress security to make it easy to secure & protect your WordPress website. It’s like having a full-time security expert on staff who constantly monitors and protects your WordPress site for you.

iThemes Team

Source link

Written by:
Abdul Wahid
Published on:
November 25, 2022

Categories: Woocommerce

Primary Sidebar

Wordpress

  • Content Management Systems (2)
  • Digital Marketing (4)
  • Internet Marketing (28)
  • Latest News (458)
  • Online Business (2)
  • Plugins (519)
  • Themes (521)
  • Videos (1,350)
  • Website Development (1)
  • Woocommerce (589)
  • WordPress (6)

Recent Articles

Unlock Your Internet Marketing Potential with WordPress: Tips, Tools, and Strategies

How to Use WordPress to Achieve Your Internet …

Continue Reading about Unlock Your Internet Marketing Potential with WordPress: Tips, Tools, and Strategies

Unlock Your Internet Marketing Potential: Harnessing the Power of WordPress

How to Use WordPress to Achieve Your Internet …

Continue Reading about Unlock Your Internet Marketing Potential: Harnessing the Power of WordPress

Search our site

Explore more

Get our Wordpress Guide Get Plugins Get Connected

Footer

VirusWord by Promaps, Inc.

Barnes Place
Colombo 7, Western 00700

Copyright © 2025 · Promaps, Inc.

Keep In Touch

  • Email
  • Facebook
  • Instagram
  • Pinterest
  • Twitter