This week, the total number of patched and unpatched vulnerabilities is low but still may affect over 3.5 million WordPress sites. There are 51 plugin vulnerabilities and one theme with security patches available, so run those updates if you use these plugins! Additionally, there are 16 plugin vulnerabilities with no patch available yet. Three of these have been closed and dropped from the wordpress.org plugin directory. If you use any unpatched plugins or themes, check their vendors’ intentions and progress on a security release. If no patch is forthcoming or the vulnerable plugin or theme has been closed, you should consider deactivation and removal in favor of alternative solutions.
- No new WordPress core vulnerabilities were disclosed this week.
WordPress core is very secure when it’s properly configured and maintained. Vulnerable plugins that have not been updated by site owners are the most common vector for attacks on WordPress websites. Our weekly WordPress Vulnerability Report, powered by Patchstack, covers new WordPress plugin, theme, and core vulnerabilities that have emerged since last week’s report. Our goal is to spread awareness of emerging security threats and help you decide what to do if you are using vulnerable software on your website. For a deeper analysis of recent trends in WordPress vulnerabilities and threat vectors, see our 2022 Annual Vulnerability Report.
WordPress Core News
WordPress 6.2 is the first major release of 2023, with over 900 enhancements and fixes. You’ll notice a reimagined Site Editor, blocks get even better, and new tools and improvements in WordPress 6.2. As always, with a major release like this, ensure your site is backed up with BackupBuddy before updating.
If your WordPress sites have enabled automatic background updates, they should have upgraded to 6.2 automatically. You can download WordPress 6.2 from WordPress.org, or visit your WordPress Dashboard, click “Updates,” and then click the “Update Now” button, which will appear when any core updates are available. For more information, check out the version 6.2 HelpHub documentation page.
WordPress Plugin Vulnerabilities with Patches
In this section, you’ll find the most recently disclosed WordPress plugin vulnerabilities that have been fixed with a new release from their authors and maintainers. Please apply the updates if you are affected!
These vulnerabilities have been disclosed and scored for their severity thanks to our friends at Patchstack. Each plugin listing includes the type of vulnerability with its CVE number and CVSS severity rating with links to more technical details. You’ll also see the number of active sites using the plugin and the plugin version release that patches the vulnerability. We start with the most popular plugins, which represent the largest target for attackers.
Advanced Custom Fields
- Plugin
- Advanced Custom Fields (ACF)
Custom Post Type UI
- Plugin
- Custom Post Type UI
- Vulnerability
- Cross Site Request Forgery (CSRF)
Happy Addons for Elementor
- Plugin
- Happy Addons for Elementor
- Vulnerability
- Cross Site Request Forgery (CSRF)
- CVE
- 2023-28989
Newsletter
- Vulnerability
- Cross Site Scripting (XSS)
Simple Author Box
- Plugin
- Simple Author Box
- Vulnerability
- Cross Site Request Forgery (CSRF)
Advanced Shipment Tracking for WooCommerce
- Vulnerability
- Cross Site Request Forgery (CSRF)
- CVE
- 2022-41635
Maps Widget for Google Maps
- Plugin
- Maps Widget for Google Maps
- Vulnerability
- Cross Site Request Forgery (CSRF)
Popup Anything
- Vulnerability
- Cross Site Request Forgery (CSRF)
- CVE
- 2022-38077
Feed Them Social
- Vulnerability
- Cross Site Request Forgery (CSRF)
Gallery by BestWebSoft
- Vulnerability
- Cross Site Scripting (XSS)
- CVE
- 2023-0764
WP Meta SEO
- Plugin
- WP Meta SEO
- Vulnerability
- Deserialization of untrusted data
- CVE
- 2023-1381
Direct checkout, Add to cart redirect for WooCommerce
- Vulnerability
- Cross Site Scripting (XSS)
- CVE
- 2023-28988
Affiliates Manager
- Plugin
- Affiliates Manager
- Vulnerability
- Cross Site Request Forgery (CSRF)
- CVE
- 2023-28986
MasterStudy LMS
WP Ultimate Review
- Plugin
- Wp Ultimate Review
- Vulnerability
- Cross Site Request Forgery (CSRF)
- CVE
- 2023-28987
WP Ultimate Review
- Plugin
- Wp Ultimate Review
- Vulnerability
- Cross Site Scripting (XSS)
- CVE
- 2023-28751
WP VR
- CVE
- 2023-1414
Zippy
- Plugin
- Zippy
- CVE
- 2023-26533
Magic Post Thumbnail
- Plugin
- Magic Post Thumbnail
- Vulnerability
- Cross Site Scripting (XSS)
- CVE
- 2023-29171
WP EasyCart
- CVE
- 2023-1124
WPMobile.App
- Vulnerability
- Cross Site Scripting (XSS)
- CVE
- 2023-28932
Configurable Tag Cloud
- Plugin
- Configurable Tag Cloud (CTC)
- Vulnerability
- Cross Site Request Forgery (CSRF)
- CVE
- 2023-28995
TF Random Numbers
- CVE
- 2023-0889
Advanced Local Pickup for WooCommerce
- CVE
- 2022-40702
ChatBot
- Plugin
- AI ChatBot
Trending/Popular Post Slider and Widget
- CVE
- 2022-46846
Full Width Banner Slider
- Plugin
- Full Width Banner Slider Wp
- Vulnerability
- Cross Site Scripting (XSS)
- CVE
- 2023-24392
Quick Paypal Payments
- Plugin
- Quick Paypal Payments
- Vulnerability
- Cross Site Scripting (XSS)
Coupon Affiliates
- Vulnerability
- Cross Site Scripting (XSS)
- CVE
- 2023-28992
PropertyHive
- Plugin
- PropertyHive
- Vulnerability
- Cross Site Scripting (XSS)
- CVE
- 2023-29172
Affiliate Toolkit
- Vulnerability
- Cross Site Scripting (XSS)
- CVE
- 2023-23786
Albo Pretorio On line
- Plugin
- Albo Pretorio On line
- Vulnerability
- Cross Site Scripting (XSS)
- CVE
- 2023-28993
Conditional extra fees for woocommerce
- Vulnerability
- Cross Site Scripting (XSS)
- CVE
- 2023-29093
Product Enquiry for WooCommerce
- Vulnerability
- Cross Site Scripting (XSS)
- CVE
- 2023-29170
Order date time for WooCommerce
- Vulnerability
- Cross Site Scripting (XSS)
- CVE
- 2023-28991
Product page shipping calculator for WooCommerce
- Vulnerability
- Cross Site Scripting (XSS)
- CVE
- 2023-29094
WishSuite – Wishlist for WooCommerce
- Vulnerability
- Cross Site Request Forgery (CSRF)
- CVE
- 2023-23731
CopySafe Web Protection
- Plugin
- CopySafe Web Protection
- Vulnerability
- Cross Site Scripting (XSS)
- CVE
- 2023-29098
SMTP Mailing Queue
- Plugin
- SMTP Mailing Queue
- Vulnerability
- Cross Site Scripting (XSS)
HT Builder
- Vulnerability
- Cross Site Request Forgery (CSRF)
Mobile Banner
- Plugin
- Mobile Banner
- Vulnerability
- Cross Site Request Forgery (CSRF)
- CVE
- 2023-28930
Easy Quiz Maker
- Plugin
- Easy Quiz Maker
- Vulnerability
- Cross Site Scripting (XSS)
Welcome Bar
- Plugin
- Welcome Bar
- Vulnerability
- Cross Site Request Forgery (CSRF)
Welcome Bar
- Plugin
- Welcome Bar
Add User Role
- Vulnerability
- Cross Site Request Forgery (CSRF)
- CVE
- 2023-0820
Enhanced WP Contact Form
- Plugin
- Enhanced WP Contact Form
- Vulnerability
- Cross Site Scripting (XSS)
- CVE
- 2023-23812
HappyFiles Pro
- CVE
- 2023-25446
HappyFiles Pro
- CVE
- 2023-25445
Image Over Image For WPBakery Page Builder
- Plugin
- Image Over Image For WPBakery Page Builder
- Vulnerability
- Cross Site Scripting (XSS)
- CVE
- 2023-0399
WC Fields Factory
Slimstat Analytics
WordPress Plugin Vulnerabilities – No Known Fix
This section contains plugin vulnerabilities with no known fix. Until a patch is available, you are advised to deactivate the plugin, at minimum, immediately. If there is a high risk of active exploits or the plugin remains unpatched for weeks, you are advised to delete the plugin. You should also delete persistently unpatched plugins the WordPress.org repository has locked and marked “Closed” so they can no longer be downloaded and installed.
Swatchly – WooCommerce Variation Swatches for Products
- Vulnerability
- Cross Site Request Forgery (CSRF)
- Patched in Version
- No Fix
- CVE
- 2023-23792
PixFields
- Plugin
- PixFields
- Vulnerability
- Cross Site Scripting (XSS)
- Patched in Version
- No Fix
- CVE
- 2022-46844
Easy Media Replace
- Plugin
- Easy Media Replace
- Patched in Version
- No Fix
- CVE
- 2022-46850
HT Menu – WordPress Mega Menu Builder for Elementor
- Vulnerability
- Cross Site Request Forgery (CSRF)
- Patched in Version
- No Fix
- CVE
- 2023-23791
JustTables – WooCommerce Product Table
- Vulnerability
- Cross Site Request Forgery (CSRF)
- Patched in Version
- No Fix
- CVE
- 2023-23803
LionScripts: IP Blocker Lite
- Plugin
- LionScripts: IP Blocker Lite
- Vulnerability
- Cross Site Request Forgery (CSRF)
- Patched in Version
- No Fix
- CVE
- 2023-23993
Really Simple Google Tag Manager
- Vulnerability
- Cross Site Request Forgery (CSRF)
- Patched in Version
- No Fix
- CVE
- 2023-23801
Social Proof (Testimonial) Slider
- Vulnerability
- Cross Site Scripting (XSS)
- Patched in Version
- No Fix
- CVE
- 2023-24389
Premmerce Redirect Manager
- Plugin
- Premmerce Redirect Manager
- Vulnerability
- Cross Site Request Forgery (CSRF)
- Patched in Version
- No Fix
- CVE
- 2023-23787
Premmerce Redirect Manager
- Plugin
- Premmerce Redirect Manager
- Vulnerability
- Cross Site Scripting (XSS)
- Patched in Version
- No Fix
- CVE
- 2023-23789
- Vulnerability
- Cross Site Scripting (XSS)
- Patched in Version
- No Fix
- CVE
- 2023-23788
Woocommerce Custom Checkout Fields Editor With Drag & Drop
- Vulnerability
- Cross Site Scripting (XSS)
- Patched in Version
- No Fix
- CVE
- 2022-46864
Solidres
- Vulnerability
- Cross Site Scripting (XSS)
- Patched in Version
- No Fix
- CVE
- 2023-1377
Gift Cards (Gift Vouchers and Packages) for WooCommerce
- Patched in Version
- No Fix
- CVE
- 2023-28662
Product Specifications for WooCommerce
- Plugin
- Product Specifications for Woocommerce
- Vulnerability
- Cross Site Scripting (XSS)
- Patched in Version
- No Fix
- CVE
- 2022-46858
WC Fields Factory
- Patched in Version
- No Fix
- CVE
- 2023-0277
WordPress Theme Vulnerabilities
In this section, you’ll find the latest WordPress theme vulnerabilities to be disclosed. You’ll see the same information provided above for vulnerable plugins, and the same advice applies. If a security update exists, install it immediately. If a vulnerability remains unpatched in a theme you are actively using, you will need to find an alternative theme. Deactivate and delete persistently unpatched themes and those that have been “Closed” in the WordPress.org theme repository. If you have a vulnerable theme installed that you are not actively using, simply delete it.
Viral Mag
- Theme
- Viral Mag
- CVE
- 2023-28990
Never worry about running a vulnerable plugin or theme again.
As you can see from this report, new WordPress plugin and theme vulnerabilities are disclosed every week. We know it can be difficult to stay on top of every reported vulnerability disclosure that matters to you, so the Themes Security Pro plugin makes it easy to ensure your site isn’t running a vulnerable theme, plugin, or version of WordPress core.
The Best WordPress Security Plugin to Secure & Protect WordPress Sites
WordPress currently powers over 40% of all websites, so it has become a popular target for hackers with malicious intent. The iThemes Security Pro plugin takes the guesswork out of WordPress security to make it easy to secure & protect your WordPress website. It’s like having a full-time security expert on staff who constantly monitors and protects your WordPress site for you.
The post WordPress Vulnerability Report – April 5, 2023 appeared first on iThemes.
This content was originally published here.