WordPress Vulnerability Report – August 2, 2023

Since last week, 94 total vulnerabilities emerged in public disclosure. They may affect over 7 million WordPress sites. There are 56 plugin vulnerabilities with security patches, so run those updates!

Additionally, there are 35 plugin vulnerabilities and three theme vulnerabilities with no patch available yet. If you use an unpatched plugin or theme, check their vendors’ intentions and progress on a security release. Suppose no patch is forthcoming or the vulnerable software has been marked “closed” and dropped from the official WordPress theme and plugin repositories. In that case, you should consider deactivation and removal in favor of alternative solutions.

FREE ONLINE TRAINING EVENT AUG 8TH @ 1:00 P.M. (CT)

New research from Snicco, WeWatchYourWebsite, Automattic-backed GridPane, and PatchStack claims WordPress security plugins with malware scanners are fundamentally flawed. And they’re being actively defeated by malware in the wild right now!

In this webinar, StellarWP technical writer Dan Knauss will explain the problem with malware scanners and the WordPress security best practices you need to implement to truly keep your sites safe.

WordPress Core Vulnerabilities — Patched

  • No new WordPress core vulnerabilities were disclosed this week.

WordPress core is very secure when it’s properly configured and maintained. Vulnerable plugins not updated by site owners are the most common vector for attacks on WordPress websites. Our weekly WordPress Vulnerability Report, powered by Patchstack, covers new vulnerabilities that have emerged in plugins, themes, and/or WordPress core since last week’s report. Our goal is to spread awareness of emerging security threats and help you decide what to do if you find vulnerable software on your website. For a deeper analysis of recent trends in WordPress vulnerabilities and threat vectors, see our 2022 Annual Vulnerability Report.

These reports are published every Wednesday and include all active vulnerabilities tracked by Patchstack as of Monday since the previous report. This leaves a 48-hour window for the newest emerging vulnerabilities to be patched before full public disclosure. iThemes Security Pro users have access to vulnerability alerts emerging within this window.

WordPress Plugin Vulnerabilities — Patched

In this section, you’ll find the most recently disclosed WordPress plugin vulnerabilities fixed with a new release from their authors and maintainers. Please apply the updates if you are affected!

These vulnerabilities have been disclosed and scored for their severity, thanks to our friends at Patchstack. Each plugin listing includes the type of vulnerability with its CVE number and CVSS severity rating with links to more technical details. You’ll also see the number of active sites using the plugin and the plugin version release that patches the vulnerability. We start with the most popular plugins, representing the largest target for attackers.

Duplicate Post

Product image for Duplicate Post.

Vulnerability
Missing Authorization on handle_installation function
CVE
2023-0958
The vulnerability has been patched, so you should update to version 1.4.0.

Duplicate Post

Product image for Duplicate Post.

Vulnerability
Cross Site Request Forgery (CSRF)
CVE
2023-3977
The vulnerability has been patched, so you should update to version 1.4.0.

TI WooCommerce Wishlist

Product image for TI WooCommerce Wishlist.

The vulnerability has been patched, so you should update to version 2.7.4.

Clone

Product image for Clone.

Plugin
Clone
CVE
2023-0958
The vulnerability has been patched, so you should update to version 2.3.8.

Clone

Product image for Clone.

Plugin
Clone
Vulnerability
Cross Site Request Forgery (CSRF)
CVE
2023-3977
The vulnerability has been patched, so you should update to version 2.3.8.

Backup Migration

Product image for Backup Migration.

CVE
2023-0958
The vulnerability has been patched, so you should update to version 1.2.8.

Backup Migration

Product image for Backup Migration.

Vulnerability
Cross Site Request Forgery (CSRF)
CVE
2023-3977
The vulnerability has been patched, so you should update to version 1.2.8.

Simple Author Box

Product image for Simple Author Box.

Vulnerability
Insecure Direct Object References (IDOR)
CVE
2023-3601
The vulnerability has been patched, so you should update to version 2.52.

Custom Field Template

Product image for Custom Field Template.

Vulnerability
Cross Site Scripting (XSS)
The vulnerability has been patched, so you should update to version 2.6.0.

Enhanced Text Widget

Product image for Enhanced Text Widget.

Vulnerability
Cross Site Request Forgery (CSRF)
CVE
2023-3977
The vulnerability has been patched, so you should update to version 1.5.8.

Redirect Redirection

Product image for Redirection.

Plugin
Redirection
CVE
2023-0958
The vulnerability has been patched, so you should update to version 1.1.4.

Redirect Redirection

Product image for Redirection.

Plugin
Redirection
Vulnerability
Cross Site Request Forgery (CSRF)
CVE
2023-3977
The vulnerability has been patched, so you should update to version 1.1.4.

Media from FTP

Product image for Media from FTP.

The vulnerability has been patched, so you should update to version 11.16.

PHP Everywhere

Product image for PHP Everywhere.

Vulnerability
Remote Code Execution (RCE)
The vulnerability has been patched, so you should update to version 3.0.0.

PHP Everywhere

Product image for PHP Everywhere.

Vulnerability
Remote Code Execution (RCE)
The vulnerability has been patched, so you should update to version 3.0.0.

PHP Everywhere

Product image for PHP Everywhere.

Vulnerability
Remote Code Execution (RCE)
The vulnerability has been patched, so you should update to version 3.0.0.

SSL Mixed Content Fix

Product image for SSL Mixed Content Fix.

Vulnerability
Cross Site Request Forgery (CSRF)
CVE
2023-3977
The vulnerability has been patched, so you should update to version 3.2.4.

Pop-up

Product image for Pop-up.

Plugin
Pop-up
CVE
2023-0958
The vulnerability has been patched, so you should update to version 1.2.0.

Pop-up

Product image for Pop-up.

Plugin
Pop-up
Vulnerability
Cross Site Request Forgery (CSRF)
CVE
2023-3977
The vulnerability has been patched, so you should update to version 1.2.0.

Ultimate Posts Widget

Product image for Ultimate Posts Widget.

Vulnerability
Cross Site Request Forgery (CSRF)
CVE
2023-3977
The vulnerability has been patched, so you should update to version 2.2.5.

User Activity Log

Product image for User Activity Log.

CVE
2023-3435
The vulnerability has been patched, so you should update to version 1.6.5.

Simple Blog Card

Vulnerability
Cross Site Scripting (XSS)
The vulnerability has been patched, so you should update to version 1.31.

Church Admin

Product image for Church Admin.

Plugin
Church Admin
Vulnerability
Server Side Request Forgery (SSRF)
The vulnerability has been patched, so you should update to version 3.8.0.

Local Development

Product image for Local Development.

Vulnerability
Cross Site Request Forgery (CSRF)
The vulnerability has been patched, so you should update to version 2.8.3.

CartFlows Pro

Vulnerability
Cross Site Request Forgery (CSRF)
The vulnerability has been patched, so you should update to version 1.11.13.

Shop as a Customer for WooCommerce

Plugin
Shop as a Customer for WooCommerce
The vulnerability has been patched, so you should update to version 1.2.4.

Shop as a Customer for WooCommerce

Plugin
Shop as a Customer for WooCommerce
The vulnerability has been patched, so you should update to version 1.1.8.

Social Share Icons & Social Share Buttons

Plugin
Social Share Icons & Social Share Buttons
CVE
2023-0958
The vulnerability has been patched, so you should update to version 3.5.8.

Social Share Icons & Social Share Buttons

Plugin
Social Share Icons & Social Share Buttons
Vulnerability
Cross Site Request Forgery (CSRF)
CVE
2023-3977
The vulnerability has been patched, so you should update to version 3.5.8.

Schema Pro

The vulnerability has been patched, so you should update to version 2.7.9.

WP Brutal AI

Vulnerability
Cross Site Scripting (XSS)
CVE
2023-2606
The vulnerability has been patched, so you should update to version 2.06.

WPML String Translation

The vulnerability has been patched, so you should update to version 3.2.6.

WordPress Plugin Vulnerabilities — Unpatched

This section contains plugin vulnerabilities with no known fix. Until a patch is available, you are advised to deactivate the plugin, at minimum, immediately. If there is a high risk of active exploits or the plugin remains unpatched for weeks, you are advised to delete the plugin. You should also delete persistently unpatched plugins the WordPress.org repository has locked and marked “Closed” so they can no longer be downloaded and installed.

Booster for Woocommerce

Product image for Booster for WooCommerce.

Patched in Version
No Fix
The vulnerability has not been patched. You should deactivate the plugin.

WPS Limit Login

Product image for WPS Limit Login.

Patched in Version
No Fix
The vulnerability has not been patched. You should deactivate the plugin.

Banner Management For WooCommerce

Product image for Banner Management For WooCommerce.

Vulnerability
Cross Site Request Forgery (CSRF)
Patched in Version
No Fix
The vulnerability has not been patched. You should deactivate the plugin.

Fraud Prevention For Woocommerce

Product image for Fraud Prevention For Woocommerce.

Vulnerability
Cross Site Request Forgery (CSRF)
Patched in Version
No Fix
The vulnerability has not been patched. You should deactivate the plugin.

MultiParcels Shipping For WooCommerce

Product image for MultiParcels Shipping For WooCommerce.

Vulnerability
Cross Site Scripting (XSS)
Patched in Version
No Fix
The vulnerability has not been patched. You should deactivate the plugin.

WP Quick Post Duplicator

Product image for WP Quick Post Duplicator.

Patched in Version
No Fix
The vulnerability has not been patched. You should deactivate the plugin.

Mobile Address Bar Changer

Product image for Mobile Address Bar Changer.

Vulnerability
Cross Site Request Forgery (CSRF)
Patched in Version
No Fix
The vulnerability has not been patched. You should deactivate the plugin.

Remove Duplicate Posts

Product image for Remove Duplicate Posts.

Patched in Version
No Fix
The vulnerability has not been patched. You should deactivate the plugin.

Web Accessibility By accessiBe

Plugin
Web Accessibility By accessiBe
Vulnerability
Cross Site Scripting (XSS)
Patched in Version
No Fix
The vulnerability has not been patched and the plugin is closed. You should uninstall and delete the plugin.

Web Accessibility By accessiBe

Plugin
Web Accessibility By accessiBe
Vulnerability
Cross Site Scripting (XSS)
Patched in Version
No Fix
The vulnerability has not been patched and the plugin is closed. You should uninstall and delete the plugin.

AGP Font Awesome Collection

Plugin
AGP Font Awesome Collection
Vulnerability
Cross Site Scripting (XSS)
Patched in Version
No Fix
The vulnerability has not been patched and the plugin is closed. You should uninstall and delete the plugin.

Booster Elementor Addons

Patched in Version
No Fix
The vulnerability has not been patched and the plugin is closed. You should uninstall and delete the plugin.

WP Clone Menu

Patched in Version
No Fix
The vulnerability has not been patched and the plugin is closed. You should uninstall and delete the plugin.

Google Map Shortcode

Vulnerability
Cross Site Request Forgery (CSRF)
Patched in Version
No Fix
The vulnerability has not been patched and the plugin is closed. You should uninstall and delete the plugin.

HTTP Auth

Vulnerability
Cross Site Request Forgery (CSRF)
Patched in Version
No Fix
The vulnerability has not been patched and the plugin is closed. You should uninstall and delete the plugin.

Instant CSS

Patched in Version
No Fix
The vulnerability has not been patched and the plugin is closed. You should uninstall and delete the plugin.

LWS Affiliation

Patched in Version
No Fix
The vulnerability has not been patched and the plugin is closed. You should uninstall and delete the plugin.

Meks Smart Social Widget

Plugin
Meks Smart Social Widget
Vulnerability
Cross Site Request Forgery (CSRF)
Patched in Version
No Fix
The vulnerability has not been patched and the plugin is closed. You should uninstall and delete the plugin.

Perelink Pro

Vulnerability
Cross Site Request Forgery (CSRF)
Patched in Version
No Fix
The vulnerability has not been patched and the plugin is closed. You should uninstall and delete the plugin.

Quasar form

Patched in Version
No Fix
The vulnerability has not been patched and the plugin is closed. You should uninstall and delete the plugin.

Saphali Woocommerce Lite

Vulnerability
Cross Site Request Forgery (CSRF)
Patched in Version
No Fix
The vulnerability has not been patched and the plugin is closed. You should uninstall and delete the plugin.

Simple Googlebot Visit

Patched in Version
No Fix
The vulnerability has not been patched and the plugin is closed. You should uninstall and delete the plugin.

Simple Wp Sitemap

Vulnerability
Cross Site Request Forgery (CSRF)
Patched in Version
No Fix
The vulnerability has not been patched and the plugin is closed. You should uninstall and delete the plugin.

Slider Carousel – Responsive Image Slider

Plugin
Slider Carousel – Responsive Image Slider
Patched in Version
No Fix
The vulnerability has not been patched and the plugin is closed. You should uninstall and delete the plugin.

Donations Made Easy – Smart Donations

Plugin
Donations Made Easy – Smart Donations
Patched in Version
No Fix
The vulnerability has not been patched and the plugin is closed. You should uninstall and delete the plugin.

Taboola

Vulnerability
Cross Site Request Forgery (CSRF)
Patched in Version
No Fix
The vulnerability has not been patched and the plugin is closed. You should uninstall and delete the plugin.

tagDiv Composer

Vulnerability
Cross Site Request Forgery (CSRF)
Patched in Version
No Fix
The vulnerability has not been patched. You should deactivate the plugin.

Update Theme and Plugins from Zip File

Plugin
Update Theme and Plugins from Zip File
Vulnerability
Cross Site Request Forgery (CSRF)
Patched in Version
No Fix
The vulnerability has not been patched and the plugin is closed. You should uninstall and delete the plugin.

User Email Verification for WooCommerce

Plugin
User Email Verification for WooCommerce
Vulnerability
Cross Site Scripting (XSS)
Patched in Version
No Fix
The vulnerability has not been patched and the plugin is closed. You should uninstall and delete the plugin.

WordPress Database Administrator

Patched in Version
No Fix
CVE
2023-3211
The vulnerability has not been patched and the plugin is closed. You should uninstall and delete the plugin.

wp tell a friend popup form

Plugin
wp tell a friend popup form
Vulnerability
Cross Site Scripting (XSS)
Patched in Version
No Fix
The vulnerability has not been patched and the plugin is closed. You should uninstall and delete the plugin.

wp tell a friend popup form

Plugin
wp tell a friend popup form
Vulnerability
Cross Site Request Forgery (CSRF)
Patched in Version
No Fix
The vulnerability has not been patched and the plugin is closed. You should uninstall and delete the plugin.

In this section, you’ll find the latest WordPress theme vulnerabilities to be disclosed. You’ll see the same information we provided above for vulnerable plugins, and the same advice applies. If a security update exists, install it immediately. If a vulnerability remains unpatched in a theme you are actively using, you must find an alternative theme. Deactivate and delete persistently unpatched themes and those marked “Closed” in the WordPress.org theme repository. If you have a vulnerable theme installed that you are not actively using, delete it.

nsc

Vulnerability
Prototype Pollution to Reflected Cross Site Scripting (XSS)
Patched in Version
No Fix
CVE
2023-3965
The vulnerability has not been patched. You should switch themes.

Winters

Vulnerability
Prototype Pollution to Reflected Cross Site Scripting (XSS)
Patched in Version
No Fix
CVE
2023-3962
The vulnerability has not been patched. You should switch themes.

Your Journey

Vulnerability
Prototype Pollution to Reflected Cross Site Scripting (XSS)
Patched in Version
No Fix
CVE
2023-3933
The vulnerability has not been patched. You should switch themes.

Never worry about running a vulnerable plugin or theme again.

As you can see from this report, new WordPress plugin and theme vulnerabilities are disclosed every week. We know it can be difficult to stay on top of every reported vulnerability disclosure that matters to you, so the Themes Security Pro plugin makes it easy to ensure your site isn’t running a vulnerable theme, plugin, or version of WordPress core.

The post WordPress Vulnerability Report – August 2, 2023 appeared first on iThemes.

This content was originally published here.