(855)-537-2266 sales@kerbco.com

Since last week, 89 total vulnerabilities emerged in public disclosure. They may affect over one million WordPress sites. There are 43 plugin vulnerabilities and five theme vulnerabilities with security patches, so run those updates!

Additionally, there are 37 plugin vulnerabilities and four theme vulnerabilities with no patch available yet. If you use an unpatched plugin or theme, check their vendors’ intentions and progress on a security release. Suppose no patch is forthcoming or the vulnerable software has been marked “closed” and dropped from the official WordPress theme and plugin repositories. In that case, you should consider deactivation and removal in favor of alternative solutions.

WordPress Core News

“Lionel” was released on August 8, 2023. This release of WordPress was built to help you “create beautiful and compelling websites more efficiently than ever.” See what’s new in WordPress 6.3.

Don’t forget to fully back up your website before installing WordPress 6.3. BackupBuddy, the industry-leading data protection and recovery solution for WordPress, will help you build a strong backup strategy to manage all updates. Embrace the enhanced content creation experience of WordPress 6.3 with confidence — and a backup copy of your website safely stored on a remote server.

WordPress Core Vulnerabilities — Patched

  • No new WordPress core vulnerabilities were disclosed this week.

WordPress core is very secure when it’s properly configured and maintained. Vulnerable plugins not updated by site owners are the most common vector for attacks on WordPress websites. Our weekly WordPress Vulnerability Report, powered by Patchstack, covers new vulnerabilities that have emerged in plugins, themes, and/or WordPress core since last week’s report. Our goal is to spread awareness of emerging security threats and help you decide what to do if you find vulnerable software on your website. For a deeper analysis of recent trends in WordPress vulnerabilities and threat vectors, see our 2022 Annual Vulnerability Report.

These reports are published every Wednesday and include all active vulnerabilities tracked by Patchstack as of Monday since the previous report. This leaves a 48-hour window for the newest emerging vulnerabilities to be patched before full public disclosure. iThemes Security Pro users have access to vulnerability alerts emerging within this window.

WordPress Plugin Vulnerabilities — Patched

In this section, you’ll find the most recently disclosed WordPress plugin vulnerabilities fixed with a new release from their authors and maintainers. Please apply the updates if you are affected!

These vulnerabilities have been disclosed and scored for their severity, thanks to our friends at Patchstack. Each plugin listing includes the type of vulnerability with its CVE number and CVSS severity rating with links to more technical details. You’ll also see the number of active sites using the plugin and the plugin version release that patches the vulnerability. We start with the most popular plugins, representing the largest target for attackers.

InfiniteWP Client

Product image for InfiniteWP Client.

CVE
2023-2916
The vulnerability has been patched, so you should update to version 1.12.1.

WP-PostRatings

Product image for WP-PostRatings.

The vulnerability has been patched, so you should update to version 1.91.1.

Media from FTP

Product image for Media from FTP.

CVE
2023-4019
The vulnerability has been patched, so you should update to version 11.17.

Smart SEO Tool

Product image for Smart SEO Tool – SEO.

Vulnerability
Cross Site Request Forgery (CSRF)
The vulnerability has been patched, so you should update to version 4.0.2.

WP Remote Users Sync

Product image for WP Remote Users Sync.

Vulnerability
Server Side Request Forgery (SSRF)
CVE
2023-3958
The vulnerability has been patched, so you should update to version 1.2.13.

Plausible Analytics

Product image for Plausible Analytics.

Vulnerability
Cross Site Scripting (XSS)
The vulnerability has been patched, so you should update to version 1.3.4.

DoLogin Security

The vulnerability has been patched, so you should update to version 3.7.

Accordion Slider

Product image for Accordion Slider.

The vulnerability has been patched, so you should update to version 1.9.7.

Event Tickets with Ticket Scanner

Product image for Event Tickets with Ticket Scanner.

Vulnerability
Cross Site Scripting (XSS)
The vulnerability has been patched, so you should update to version 1.5.5.

Paid Memberships Pro CCBill Gateway

Plugin
Paid Memberships Pro CCBill Gateway
The vulnerability has been patched, so you should update to version 0.4.

WordPress Plugin Vulnerabilities — Unpatched

This section contains plugin vulnerabilities with no known fix. Until a patch is available, you are advised to deactivate the plugin, at minimum, immediately. If there is a high risk of active exploits or the plugin remains unpatched for weeks, you are advised to delete the plugin. You should also delete persistently unpatched plugins the WordPress.org repository has locked and marked “Closed” so they can no longer be downloaded and installed.

GD Security Headers

Product image for GD Security Headers.

Vulnerability
Cross Site Scripting (XSS)
Patched in Version
No Fix
The vulnerability has not been patched. You should deactivate the plugin.

LINE Notify

Vulnerability
Cross Site Scripting (XSS)
Patched in Version
No Fix
The vulnerability has not been patched. You should deactivate the plugin.

fitness calculators plugin

Product image for fitness calculators plugin.

Vulnerability
Cross Site Scripting (XSS)
Patched in Version
No Fix
The vulnerability has not been patched. You should deactivate the plugin.

Save as PDF plugin by Pdfcrowd

Vulnerability
Cross Site Scripting (XSS)
Patched in Version
No Fix
The vulnerability has not been patched. You should deactivate the plugin.

Schedule Posts Calendar

Product image for Schedule Posts Calendar.

Vulnerability
Cross Site Request Forgery (CSRF)
Patched in Version
No Fix
The vulnerability has not been patched. You should deactivate the plugin.

Schedule Posts Calendar

Product image for Schedule Posts Calendar.

Vulnerability
Cross Site Scripting (XSS)
Patched in Version
No Fix
The vulnerability has not been patched. You should deactivate the plugin.

Tabs & Accordion

Product image for Tabs & Accordion.

Patched in Version
No Fix
The vulnerability has not been patched. You should deactivate the plugin.

rsvpmaker

Product image for RSVPMaker.

Plugin
RSVPMaker
Vulnerability
Cross Site Scripting (XSS)
Patched in Version
No Fix
The vulnerability has not been patched. You should deactivate the plugin.

rsvpmaker

Product image for RSVPMaker.

Plugin
RSVPMaker
Vulnerability
Cross Site Scripting (XSS)
Patched in Version
No Fix
The vulnerability has not been patched. You should deactivate the plugin.

Save as Image plugin by Pdfcrowd

Vulnerability
Cross Site Scripting (XSS)
Patched in Version
No Fix
The vulnerability has not been patched. You should deactivate the plugin.

Typing Effect

Vulnerability
Cross Site Scripting (XSS)
Patched in Version
No Fix
The vulnerability has not been patched and the plugin is closed. You should uninstall and delete the plugin.

Password Reset with Code for WordPress REST API

Plugin
Password Reset with Code for WordPress REST API
Patched in Version
No Fix
The vulnerability has not been patched and the plugin is closed. You should uninstall and delete the plugin.

BigBlueButton

Vulnerability
Cross Site Scripting (XSS)
Patched in Version
No Fix
The vulnerability has not been patched and the plugin is closed. You should uninstall and delete the plugin.

Carrot

Vulnerability
Cross Site Scripting (XSS)
Patched in Version
No Fix
The vulnerability has not been patched and the plugin is closed. You should uninstall and delete the plugin.

Cartpauj Register Captcha

Patched in Version
No Fix
The vulnerability has not been patched and the plugin is closed. You should uninstall and delete the plugin.

Contact form 7 Custom validation

Plugin
Contact form 7 Custom validation
Patched in Version
No Fix
The vulnerability has not been patched and the plugin is closed. You should uninstall and delete the plugin.

Cleverwise Daily Quotes

Vulnerability
Cross Site Scripting (XSS)
Patched in Version
No Fix
The vulnerability has not been patched and the plugin is closed. You should uninstall and delete the plugin.

Cookies by JM

Vulnerability
Cross Site Scripting (XSS)
Patched in Version
No Fix
The vulnerability has not been patched and the plugin is closed. You should uninstall and delete the plugin.

CT Commerce

Vulnerability
Cross Site Scripting (XSS)
Patched in Version
No Fix
The vulnerability has not been patched and the plugin is closed. You should uninstall and delete the plugin.

Custom Admin Login Page | WPZest

Plugin
Custom Admin Login Page | WPZest
Vulnerability
Cross Site Scripting (XSS)
Patched in Version
No Fix
The vulnerability has not been patched and the plugin is closed. You should uninstall and delete the plugin.

DX-auto-save-images

Vulnerability
Cross Site Request Forgery (CSRF)
Patched in Version
No Fix
The vulnerability has not been patched and the plugin is closed. You should uninstall and delete the plugin.

Mortgage Calculator Estatik

Vulnerability
Cross Site Scripting (XSS)
Patched in Version
No Fix
The vulnerability has not been patched and the plugin is closed. You should uninstall and delete the plugin.

Make Paths Relative

Vulnerability
Cross Site Request Forgery (CSRF)
Patched in Version
No Fix
The vulnerability has not been patched and the plugin is closed. You should uninstall and delete the plugin.

Simple Org Chart

Patched in Version
No Fix
The vulnerability has not been patched and the plugin is closed. You should uninstall and delete the plugin.

Simple Org Chart

Vulnerability
Cross Site Request Forgery (CSRF)
Patched in Version
No Fix
The vulnerability has not been patched and the plugin is closed. You should uninstall and delete the plugin.

Simple Staff List

Vulnerability
Cross Site Scripting (XSS)
Patched in Version
No Fix
The vulnerability has not been patched and the plugin is closed. You should uninstall and delete the plugin.

Donations Made Easy – Smart Donations

Plugin
Donations Made Easy – Smart Donations
Vulnerability
Cross Site Scripting (XSS)
Patched in Version
No Fix
The vulnerability has not been patched and the plugin is closed. You should uninstall and delete the plugin.

Sticky Social Media Icons

Plugin
Sticky Social Media Icons
Patched in Version
No Fix
The vulnerability has not been patched and the plugin is closed. You should uninstall and delete the plugin.

WebLibrarian

Vulnerability
Cross Site Scripting (XSS)
Patched in Version
No Fix
The vulnerability has not been patched and the plugin is closed. You should uninstall and delete the plugin.

Putler Connector for WooCommerce

Plugin
Putler Connector for WooCommerce
Patched in Version
No Fix
The vulnerability has not been patched and the plugin is closed. You should uninstall and delete the plugin.

Putler Connector for WooCommerce

Plugin
Putler Connector for WooCommerce
Patched in Version
No Fix
The vulnerability has not been patched and the plugin is closed. You should uninstall and delete the plugin.

In this section, you’ll find the latest WordPress theme vulnerabilities to be disclosed. You’ll see the same information we provided above for vulnerable plugins, and the same advice applies. If a security update exists, install it immediately. If a vulnerability remains unpatched in a theme you are actively using, you must find an alternative theme. Deactivate and delete persistently unpatched themes and those marked “Closed” in the WordPress.org theme repository. If you have a vulnerable theme installed that you are not actively using, delete it.

Bazaar Lite

Product image for Bazaar Lite.

Theme
Bazaar Lite
Vulnerability
Cross Site Scripting (XSS)
CVE
2023-2813
The vulnerability has been patched, so you should update to version 1.8.6.

Aapna

Product image for Aapna.

Theme
Aapna
Vulnerability
Cross Site Scripting (XSS)
Patched in Version
No Fix
CVE
2023-2813
The vulnerability has not been patched. You should switch themes.

College

Product image for College.

Theme
College
Vulnerability
Cross Site Scripting (XSS)
CVE
2023-2813
The vulnerability has been patched, so you should update to version 1.5.1.

BunnyPressLite

Product image for BunnyPressLite.

Vulnerability
Cross Site Scripting (XSS)
CVE
2023-2813
The vulnerability has been patched, so you should update to version 2.1.

Anfaust

Product image for Anfaust.

Theme
Anfaust
Vulnerability
Cross Site Scripting (XSS)
Patched in Version
No Fix
CVE
2023-2813
The vulnerability has not been patched. You should switch themes.

Brain Power

Product image for Brain Power.

Theme
Brain Power
Vulnerability
Cross Site Scripting (XSS)
Patched in Version
No Fix
CVE
2023-2813
The vulnerability has not been patched. You should switch themes.

Cafe Bistro

Product image for Cafe Bistro.

Theme
Cafe Bistro
Vulnerability
Cross Site Scripting (XSS)
CVE
2023-2813
The vulnerability has been patched, so you should update to version 1.1.4.

Anand

Product image for Anand.

Theme
Anand
Vulnerability
Cross Site Scripting (XSS)
Patched in Version
No Fix
CVE
2023-2813
The vulnerability has not been patched. You should switch themes.

Arendelle

Product image for Arendelle.

Theme
Arendelle
Vulnerability
Cross Site Scripting (XSS)
CVE
2023-2813
The vulnerability has been patched, so you should update to version 1.1.3.

Never worry about running a vulnerable plugin or theme again.

As you can see from this report, new WordPress plugin and theme vulnerabilities are disclosed every week. We know it can be difficult to stay on top of every reported vulnerability disclosure that matters to you, so the Themes Security Pro plugin makes it easy to ensure your site isn’t running a vulnerable theme, plugin, or version of WordPress core.

The post WordPress Vulnerability Report – August 23, 2023 appeared first on iThemes.

This content was originally published here.