(855)-537-2266 sales@kerbco.com

Since last week, 90 total vulnerabilities emerged in public disclosure. They may affect over one million WordPress sites. There are 49 plugin vulnerabilities and five theme vulnerabilities with security patches, so run those updates!

Additionally, there are 35 plugin vulnerabilities and one theme vulnerability with no patch available yet. If you use an unpatched plugin or theme, check their vendors’ intentions and progress on a security release. Suppose no patch is forthcoming or the vulnerable software has been marked “closed” and dropped from the official WordPress theme and plugin repositories. In that case, you should consider deactivation and removal in favor of alternative solutions.

WordPress Core News

WordPress 6.3 “Lionel” is out! This new release of WordPress was built to help you “create beautiful and compelling websites more efficiently than ever.” See what’s new in WordPress 6.3.

Don’t forget to fully back up your website before installing WordPress 6.3. BackupBuddy, the industry-leading data protection and recovery solution for WordPress, will help you build a strong backup strategy to manage all updates. Embrace the enhanced content creation experience of WordPress 6.3 with confidence — and a backup copy of your website safely stored on a remote server.

WordPress Core Vulnerabilities — Patched

  • No new WordPress core vulnerabilities were disclosed this week.

WordPress core is very secure when it’s properly configured and maintained. Vulnerable plugins not updated by site owners are the most common vector for attacks on WordPress websites. Our weekly WordPress Vulnerability Report, powered by Patchstack, covers new vulnerabilities that have emerged in plugins, themes, and/or WordPress core since last week’s report. Our goal is to spread awareness of emerging security threats and help you decide what to do if you find vulnerable software on your website. For a deeper analysis of recent trends in WordPress vulnerabilities and threat vectors, see our 2022 Annual Vulnerability Report.

These reports are published every Wednesday and include all active vulnerabilities tracked by Patchstack as of Monday since the previous report. This leaves a 48-hour window for the newest emerging vulnerabilities to be patched before full public disclosure. iThemes Security Pro users have access to vulnerability alerts emerging within this window.

WordPress Plugin Vulnerabilities — Patched

In this section, you’ll find the most recently disclosed WordPress plugin vulnerabilities fixed with a new release from their authors and maintainers. Please apply the updates if you are affected!

These vulnerabilities have been disclosed and scored for their severity, thanks to our friends at Patchstack. Each plugin listing includes the type of vulnerability with its CVE number and CVSS severity rating with links to more technical details. You’ll also see the number of active sites using the plugin and the plugin version release that patches the vulnerability. We start with the most popular plugins, representing the largest target for attackers.

Header Footer Code Manager

Product image for Header Footer Code Manager.

Vulnerability
Cross Site Request Forgery (CSRF)
The vulnerability has been patched, so you should update to version 1.1.35.

Booking Package

Product image for Booking Package.

Vulnerability
Cross Site Scripting (XSS)
The vulnerability has been patched, so you should update to version 1.6.02.

User Activity Log

Product image for User Activity Log.

The vulnerability has been patched, so you should update to version 1.6.6.

Stock Ticker

Product image for Stock Ticker.

Plugin
Stock Ticker
Vulnerability
Cross Site Scripting (XSS)
The vulnerability has been patched, so you should update to version 3.23.4.

Stock Ticker

Product image for Stock Ticker.

Plugin
Stock Ticker
Vulnerability
Cross Site Scripting (XSS)
The vulnerability has been patched, so you should update to version 3.23.3.

User Activity Tracking and Log

Product image for User Activity Tracking and Log.

Vulnerability
Cross Site Request Forgery (CSRF)
CVE
2023-4150
The vulnerability has been patched, so you should update to version 4.0.9.

Leyka

Product image for Leyka.

Plugin
Leyka
Vulnerability
Cross Site Scripting (XSS)
The vulnerability has been patched, so you should update to version 3.30.3.

WP Testimonials

Product image for WP Testimonials.

Vulnerability
Cross Site Request Forgery (CSRF)
CVE
2023-2830
The vulnerability has been patched, so you should update to version 1.4.3.

POEditor

Product image for POEditor.

Plugin
POEditor
Vulnerability
Cross Site Request Forgery (CSRF)
CVE
2023-4209
The vulnerability has been patched, so you should update to version 0.9.8.

Sign-up Sheets

Product image for Sign-up Sheets.

Vulnerability
Cross Site Request Forgery (CSRF)
The vulnerability has been patched, so you should update to version 2.2.9.

Post Timeline

Product image for Post Timeline.

Plugin
Post Timeline
Vulnerability
Cross Site Scripting (XSS)
CVE
2023-4284
The vulnerability has been patched, so you should update to version 2.2.6.

Advanced Custom Fields Pro premium

Plugin
Advanced Custom Fields PRO
Vulnerability
Cross Site Scripting (XSS)
The vulnerability has been patched, so you should update to version 6.1.8.

ARMember Premium

The vulnerability has been patched, so you should update to version 5.9.3.

Biometric Login for WooCommerce

Plugin
Biometric Login for WooCommerce
The vulnerability has been patched, so you should update to version 1.0.4.

Avada Builder

Vulnerability
Cross Site Scripting (XSS)
The vulnerability has been patched, so you should update to version 3.11.2.

Avada Builder

Vulnerability
Cross Site Request Forgery (CSRF)
The vulnerability has been patched, so you should update to version 3.11.2.

Avada Builder

The vulnerability has been patched, so you should update to version 3.11.2.

Avada Builder

The vulnerability has been patched, so you should update to version 3.11.2.

Jupiter X Core

The vulnerability has been patched, so you should update to version 3.3.5.

Jupiter X Core

The vulnerability has been patched, so you should update to version 3.3.5.

WooCommerce One Page Checkout

Plugin
WooCommerce One Page Checkout
The vulnerability has been patched, so you should update to version 2.4.0.

WordPress Plugin Vulnerabilities — Unpatched

This section contains plugin vulnerabilities with no known fix. Until a patch is available, you are advised to deactivate the plugin, at minimum, immediately. If there is a high risk of active exploits or the plugin remains unpatched for weeks, you are advised to delete the plugin. You should also delete persistently unpatched plugins the WordPress.org repository has locked and marked “Closed” so they can no longer be downloaded and installed.

WP 404 Auto Redirect to Similar Post

Product image for WP 404 Auto Redirect to Similar Post.

Vulnerability
Cross Site Scripting (XSS)
Patched in Version
No Fix
The vulnerability has not been patched. You should deactivate the plugin.

flowpaper

Product image for flowpaper.

Vulnerability
Cross Site Scripting (XSS)
Patched in Version
No Fix
The vulnerability has not been patched. You should deactivate the plugin.

Futurio Extra

Product image for Futurio Extra.

Plugin
Futurio Extra
Vulnerability
Cross Site Request Forgery (CSRF)
Patched in Version
No Fix
The vulnerability has not been patched. You should deactivate the plugin.

Email Template Designer – WP HTML Mail

Product image for Email Template Designer – WP HTML Mail.

Vulnerability
Cross Site Request Forgery (CSRF)
Patched in Version
No Fix
The vulnerability has not been patched. You should deactivate the plugin.

PixTypes

Plugin
PixTypes
Vulnerability
Cross Site Scripting (XSS)
Patched in Version
No Fix
The vulnerability has not been patched. You should deactivate the plugin.

Theme Demo Import

Product image for Theme Demo Import.

Patched in Version
No Fix
The vulnerability has not been patched. You should deactivate the plugin.

WP Categories Widget

Product image for WP Categories Widget.

Vulnerability
Cross Site Scripting (XSS)
Patched in Version
No Fix
The vulnerability has not been patched. You should deactivate the plugin.

Product Attachment for WooCommerce

Product image for Product Attachment for WooCommerce.

Vulnerability
Cross Site Request Forgery (CSRF)
Patched in Version
No Fix
The vulnerability has not been patched. You should deactivate the plugin.

SendPress Newsletters

Product image for SendPress Newsletters.

Patched in Version
No Fix
The vulnerability has not been patched. You should deactivate the plugin.

YITH WooCommerce Waitlist

Product image for YITH WooCommerce Waitlist.

Patched in Version
No Fix
The vulnerability has not been patched. You should deactivate the plugin.

BigBlueButton

Product image for BigBlueButton.

Plugin
BigBlueButton
Vulnerability
Cross Site Scripting (XSS)
Patched in Version
No Fix
The vulnerability has not been patched. You should deactivate the plugin.

Easy Cookie Law

Product image for Easy Cookie Law.

Vulnerability
Cross Site Request Forgery (CSRF)
Patched in Version
No Fix
The vulnerability has not been patched. You should deactivate the plugin.

Make Paths Relative

Product image for Make Paths Relative.

Vulnerability
Cross Site Request Forgery (CSRF)
Patched in Version
No Fix
The vulnerability has not been patched. You should deactivate the plugin.

WP Like Button

Product image for WP Like Button.

Vulnerability
Cross Site Request Forgery (CSRF)
Patched in Version
No Fix
The vulnerability has not been patched. You should deactivate the plugin.

LINE Notify

Vulnerability
Cross Site Scripting (XSS)
Patched in Version
No Fix
The vulnerability has not been patched. You should deactivate the plugin.

Kangu para WooCommerce

Product image for Kangu para WooCommerce.

Vulnerability
Cross Site Scripting (XSS)
Patched in Version
No Fix
The vulnerability has not been patched. You should deactivate the plugin.

SB Child List

Plugin
SB Child List
Vulnerability
Cross Site Request Forgery (CSRF)
Patched in Version
No Fix
The vulnerability has not been patched. You should deactivate the plugin.

wSecure Lite

Plugin
wSecure Lite
Vulnerability
Cross Site Scripting (XSS)
Patched in Version
No Fix
The vulnerability has not been patched. You should deactivate the plugin.

Easy!Appointments

Product image for Easy!Appointments.

Patched in Version
No Fix
The vulnerability has not been patched. You should deactivate the plugin.

WebLibrarian

Product image for WebLibrarian.

Plugin
WebLibrarian
Vulnerability
Cross Site Scripting (XSS)
Patched in Version
No Fix
The vulnerability has not been patched. You should deactivate the plugin.

demon image annotation

Product image for demon image annotation.

Patched in Version
No Fix
The vulnerability has not been patched. You should deactivate the plugin.

Absolute Privacy

Vulnerability
Cross Site Request Forgery (CSRF)
Patched in Version
No Fix
CVE
2023-4276
The vulnerability has not been patched and the plugin is closed. You should uninstall and delete the plugin.

All Users Messenger

Patched in Version
No Fix
CVE
2023-4023
The vulnerability has not been patched and the plugin is closed. You should uninstall and delete the plugin.

Canto

Patched in Version
No Fix
CVE
2023-3452
The vulnerability has not been patched and the plugin is closed. You should uninstall and delete the plugin.

FULL Customer

Patched in Version
No Fix
CVE
2023-4242
The vulnerability has not been patched and the plugin is closed. You should uninstall and delete the plugin.

FULL Customer

Patched in Version
No Fix
CVE
2023-4243
The vulnerability has not been patched and the plugin is closed. You should uninstall and delete the plugin.

Real Estate Manager

Patched in Version
No Fix
CVE
2023-4239
The vulnerability has not been patched and the plugin is closed. You should uninstall and delete the plugin.

Realia

Vulnerability
Cross Site Request Forgery (CSRF)
Patched in Version
No Fix
CVE
2023-4277
The vulnerability has not been patched and the plugin is closed. You should uninstall and delete the plugin.

Donations Made Easy – Smart Donations

Plugin
Donations Made Easy – Smart Donations
Patched in Version
No Fix
The vulnerability has not been patched and the plugin is closed. You should uninstall and delete the plugin.

In this section, you’ll find the latest WordPress theme vulnerabilities to be disclosed. You’ll see the same information we provided above for vulnerable plugins, and the same advice applies. If a security update exists, install it immediately. If a vulnerability remains unpatched in a theme you are actively using, you must find an alternative theme. Deactivate and delete persistently unpatched themes and those marked “Closed” in the WordPress.org theme repository. If you have a vulnerable theme installed that you are not actively using, delete it.

Avada

The vulnerability has been patched, so you should update to version 7.11.2.

Avada

The vulnerability has been patched, so you should update to version 7.11.2.

Avada

Vulnerability
Server Side Request Forgery (SSRF)
The vulnerability has been patched, so you should update to version 7.11.2.

Avada

The vulnerability has been patched, so you should update to version 7.11.2.

BeTheme

The vulnerability has been patched, so you should update to version 27.1.2.

Business Pro

Vulnerability
Cross Site Scripting (XSS)
Patched in Version
No Fix
The vulnerability has not been patched. You should switch themes.

Never worry about running a vulnerable plugin or theme again.

As you can see from this report, new WordPress plugin and theme vulnerabilities are disclosed every week. We know it can be difficult to stay on top of every reported vulnerability disclosure that matters to you, so the Themes Security Pro plugin makes it easy to ensure your site isn’t running a vulnerable theme, plugin, or version of WordPress core.

The post WordPress Vulnerability Report – August 16, 2023 appeared first on iThemes.

This content was originally published here.