This week, 79 total vulnerabilities emerged in public disclosure. They may affect over 3 million WordPress sites. There are 55 plugin vulnerabilities that have security patches available, so run those updates!
Additionally, there are 24 plugin vulnerabilities with no patch available yet. If you are using any unpatched plugins or themes, check their vendors’ intentions and progress on a security release. If no patch is forthcoming or the vulnerable software has been closed and dropped from the official WordPress and repositories, you should consider deactivation and removal in favor of alternative solutions.
WordPress Core Vulnerabilities — Patched
- No new WordPress core vulnerabilities were disclosed this week.
WordPress core is very secure when it’s properly configured and maintained. Vulnerable plugins that have not been updated by site owners are the most common vector for attacks on WordPress websites. Our weekly WordPress Vulnerability Report, powered by Patchstack, covers new WordPress plugin, theme, and core vulnerabilities that have emerged since last week’s report. Our goal is to spread awareness of emerging security threats and help you decide what to do if you are using vulnerable software on your website. For a deeper analysis of recent trends in WordPress vulnerabilities and threat vectors, see our 2022 Annual Vulnerability Report.
These reports are published every Wednesday and include all active vulnerabilities tracked by Patchstack as of Monday since the previous report. This leaves a 48-hour window for the newest emerging vulnerabilities to be patched before full public disclosure. iThemes Security Pro users have access to vulnerability alerts emerging within this window.
WordPress Plugin Vulnerabilities — Patched
In this section, you’ll find the most recently disclosed WordPress plugin vulnerabilities that have been fixed with a new release from their authors and maintainers. Please apply the updates if you are affected!
These vulnerabilities have been disclosed and scored for their severity, thanks to our friends at Patchstack. Each plugin listing includes the type of vulnerability with its CVE number and CVSS severity rating with links to more technical details. You’ll also see the number of active sites using the plugin and the plugin version release that patches the vulnerability. We start with the most popular plugins, which represent the largest target for attackers.
WooCommerce Stripe Payment Gateway
- Vulnerability
- Unauthenticated Broken Access Control
- CVE
- 2023-35049
WooCommerce Stripe Payment Gateway
- Vulnerability
- Insecure Direct Object References (IDOR)
- CVE
- 2023-34000
Password Protected
- Plugin
- Password Protected
- Vulnerability
- Cross Site Scripting (XSS)
- CVE
- 2023-32580
Photo Gallery by 10Web
- CVE
- 2023-33995
Unlimited Elements For Elementor
- CVE
- 2023-33930
Download Monitor
- Plugin
- Download Monitor
- CVE
- 2023-34007
WooCommerce Square
- Plugin
- WooCommerce Square
- Vulnerability
- Insecure Direct Object References (IDOR)
- CVE
- 2023-35876
Conditional Menus
- Plugin
- Conditional Menus
- Vulnerability
- Cross Site Scripting (XSS)
- CVE
- 2023-2654
Dokan
Dynamic Visibility for Elementor
- CVE
- 2023-35046
Super Socializer
- Vulnerability
- Cross Site Scripting (XSS)
- CVE
- 2023-35882
Super Socializer
- Vulnerability
- Reflected Cross Site Scripting (XSS)
- CVE
- 2023-2779
Gutenverse – Gutenberg Blocks – Page Builder for Site Editor
- CVE
- 2023-35875
Stock Manager for WooCommerce
- Vulnerability
- Cross Site Request Forgery (CSRF)
- CVE
- 2023-35091
myCred plugin
- Vulnerability
- Cross Site Request Forgery (CSRF)
- CVE
- 2023-35096
CMS Commander
- Vulnerability
- Authorization Bypass through Use of Insufficiently Unique Cryptographic Signature
- CVE
- 2023-3325
Directorist
- CVE
- 2023-35052
File Renaming on Upload
- Plugin
- File Renaming on Upload
- Vulnerability
- Admin+ Stored Cross Site Scripting (XSS)
- CVE
- 2023-2684
LWS Tools
- Plugin
- LWS Tools
- Vulnerability
- Multiple Cross Site Request Forgery (CSRF)
- CVE
- 2023-35774
SupportCandy
- CVE
- 2023-2719
SupportCandy
- CVE
- 2023-2805
YaySMTP
- Vulnerability
- Unauthenticated Stored Cross Site Scripting (XSS)
- CVE
- 2023-3093
MStore API
- Plugin
- MStore API
- CVE
- 2022-47614
MStore API
- Plugin
- MStore API
- Vulnerability
- Cross Site Request Forgery (CSRF) to Product Limit Update
- CVE
- 2023-3203
MStore API
- Plugin
- MStore API
- Vulnerability
- Cross Site Request Forgery (CSRF) to Order Message Update
- CVE
- 2023-3200
MStore API
- Plugin
- MStore API
- Vulnerability
- Cross Site Request Forgery (CSRF) to Order Title Update
- CVE
- 2023-3199
MStore API
- Plugin
- MStore API
- Vulnerability
- Cross Site Request Forgery (CSRF) to Order Title Update
- CVE
- 2023-3201
MStore API
- Plugin
- MStore API
- Vulnerability
- Cross Site Request Forgery (CSRF) to Order Status Update
- CVE
- 2023-3198
MStore API
- Plugin
- MStore API
- Vulnerability
- Cross Site Request Forgery (CSRF) to Firebase Server Key Update
- CVE
- 2023-3202
MStore API
- Plugin
- MStore API
WP Custom Cursors
- CVE
- 2023-2221
AI ChatBot
- Plugin
- AI ChatBot
- Vulnerability
- Admin+ Stored Cross Site Scripting (XSS)
- CVE
- 2023-2742
AI ChatBot
- Plugin
- AI ChatBot
- Vulnerability
- Admin+ Stored Cross Site Scripting (XSS)
- CVE
- 2023-2811
Integration for Contact Form 7 and Zoho CRM, Bigin
- CVE
- 2023-2527
CHP Ads Block Detector
- Plugin
- CHP Ads Block Detector
- CVE
- 2023-2354
Recipe Maker For Your Food Blog from Zip Recipes
- Vulnerability
- Cross Site Request Forgery (CSRF)
- CVE
- 2023-35089
All Bootstrap Blocks
- Plugin
- All Bootstrap Blocks
- Vulnerability
- Cross Site Request Forgery (CSRF)
- CVE
- 2023-35047
ARMember
- Vulnerability
- Cross Site Scripting (XSS)
- CVE
- 2023-33323
Core Web Vitals & PageSpeed Booster
- CVE
- 2023-35883
Extra User Details
- Plugin
- Extra User Details
- Vulnerability
- Cross Site Request Forgery (CSRF)
- CVE
- 2023-35877
Extra User Details
- Plugin
- Extra User Details
- Vulnerability
- Cross Site Scripting (XSS)
- CVE
- 2023-35878
WP Directory Kit
- Plugin
- WP Directory Kit
- Vulnerability
- Missing Authorization to Plugin Settings Change/Delete, Demo Import, Directory Kit Deletion via wdk_admin_action
- CVE
- 2023-2351
Church Admin
- Plugin
- Church Admin
- Vulnerability
- Reflected Cross Site Scripting (XSS)
- CVE
- 2023-34021
Contact Forms by Cimatti
- CVE
- 2023-35051
WordPress Contact Forms by Cimatti
- Vulnerability
- Cross Site Request Forgery (CSRF) via _accua_forms_form_edit_action
- CVE
- 2023-2563
EventPrime
- Vulnerability
- Reflected Cross Site Scripting (XSS)
- CVE
- 2023-35884
WP PDF Generator
- Plugin
- WP PDF Generator
- Vulnerability
- Cross Site Request Forgery (CSRF)
- CVE
- 2023-35038
Zephyr Project Manager
- Plugin
- Zephyr Project Manager
- Vulnerability
- Cross Site Request Forgery (CSRF)
- CVE
- 2023-34373
LWS Cleaner
- Plugin
- LWS Cleaner
- Vulnerability
- Multiple Cross Site Request Forgery (CSRF)
- CVE
- 2023-35781
WP Sticky Social
- Plugin
- WP Sticky Social
- Vulnerability
- Cross-Site Request Forgery to Stored Cross-Site Scripting
- CVE
- 2023-3320
Booking and Rental Manager
- Plugin
- Booking and Rental Manager for Bike | Car | Resort | Appointment | Dress and all Kinds of Equipment
- Vulnerability
- Cross Site Scripting (XSS)
- CVE
- 2023-35048
Front User Submit | Front Editor
Form Maker
- Plugin
- Contact Form by WD
- Vulnerability
- Missing Authorization in check_score
WooCommerce Brands
- Vulnerability
- Cross Site Request Forgery (CSRF)
- CVE
- 2023-35880
WooCommerce Product Vendors
- Vulnerability
- Shop Manager+ SQL Injection
- CVE
- 2023-35879
WordPress Plugin Vulnerabilities — Unpatched
This section contains plugin vulnerabilities with no known fix. Until a patch is available, you are advised to deactivate the plugin, at minimum, immediately. If there is a high risk of active exploits or the plugin remains unpatched for weeks, you are advised to delete the plugin. You should also delete persistently unpatched plugins the WordPress.org repository has locked and marked “Closed” so they can no longer be downloaded and installed.
Seed Fonts
- Plugin
- Seed Fonts
- Vulnerability
- Cross Site Scripting (XSS)
- Patched in Version
- No Fix
- CVE
- 2023-35779
Flo Forms
- Vulnerability
- Cross Site Scripting (XSS)
- Patched in Version
- No Fix
- CVE
- 2023-35095
MasterStudy LMS
- Vulnerability
- Cross Site Scripting (XSS)
- Patched in Version
- No Fix
- CVE
- 2023-35090
MasterStudy LMS
- Patched in Version
- No Fix
- CVE
- 2023-35093
Form Builder
- Vulnerability
- Cross Site Request Forgery (CSRF)
- Patched in Version
- No Fix
- CVE
- 2023-23795
Google Map Shortcode
- Plugin
- Google Map Shortcode
- Vulnerability
- Reflected Cross Site Scripting (XSS)
- Patched in Version
- No Fix
- CVE
- 2023-35772
WP Matterport Shortcode
- Plugin
- WP Matterport Shortcode
- Vulnerability
- Cross Site Scripting (XSS)
- Patched in Version
- No Fix
- CVE
- 2023-35094
Sermon’e – Sermons Online
- Plugin
- Sermon’e – Sermons Online
- Vulnerability
- Cross Site Scripting (XSS)
- Patched in Version
- No Fix
- CVE
- 2023-35776
Template Debugger
- Plugin
- Template Debugger
- Vulnerability
- Cross Site Request Forgery (CSRF)
- Patched in Version
- No Fix
- CVE
- 2023-35773
Recent Posts Slider
- Plugin
- Recent Posts Slider
- Vulnerability
- Cross Site Request Forgery (CSRF)
- Patched in Version
- No Fix
- CVE
- 2023-35778
Recent Posts Slider
- Plugin
- Recent Posts Slider
- Vulnerability
- Cross Site Scripting (XSS)
- Patched in Version
- No Fix
- CVE
- 2023-35043
Securimage-WP
- Plugin
- Securimage-WP
- Vulnerability
- Cross Site Request Forgery (CSRF)
- Patched in Version
- No Fix
- CVE
- 2023-35044
breadcrumb simple
- Plugin
- breadcrumb simple
- Vulnerability
- Cross Site Scripting (XSS)
- Patched in Version
- No Fix
- CVE
- 2023-35092
Fat Rat Collect
- Patched in Version
- No Fix
- CVE
- 2023-35045
Galleria
- Plugin
- Galleria
- Vulnerability
- Cross Site Request Forgery (CSRF)
- Patched in Version
- No Fix
- CVE
- 2023-35780
Who Hit The Page – Hit Counter
- Vulnerability
- Cross Site Scripting (XSS)
- Patched in Version
- No Fix
- CVE
- 2023-25466
WordPress NextGen GalleryView
- Vulnerability
- Reflected Cross Site Scripting (XSS)
- Patched in Version
- No Fix
- CVE
- 2023-35098
WP Affiliate Links
- Plugin
- WP Affiliate Links
- Vulnerability
- Reflected Cross Site Scripting (XSS)
- Patched in Version
- No Fix
- CVE
- 2023-35097
WP Backup Manager
- Plugin
- WP Backup Manager
- Vulnerability
- Reflected Cross Site Scripting (XSS)
- Patched in Version
- No Fix
- CVE
- 2023-35775
MojoPlug Slide Panel
- Plugin
- MojoPlug Slide Panel
- Vulnerability
- Cross Site Scripting (XSS)
- Patched in Version
- No Fix
- CVE
- 2023-23807
Smoothscroller
- Plugin
- Smoothscroller
- Vulnerability
- Cross Site Scripting (XSS)
- Patched in Version
- No Fix
- CVE
- 2023-23811
wpView
- Vulnerability
- Cross Site Scripting (XSS)
- Patched in Version
- No Fix
- CVE
- 2023-33213
Login Configurator
- Vulnerability
- Cross Site Scripting (XSS)
- Patched in Version
- No Fix
- CVE
- 2023-34369
Upload Resume
- Patched in Version
- No Fix
- CVE
- 2023-2751
In this section, you’ll find the latest WordPress theme vulnerabilities to be disclosed. You’ll see the same information provided above for vulnerable plugins, and the same advice applies. If a security update exists, install it immediately. If a vulnerability remains unpatched in a theme you are actively using, you will need to find an alternative theme. Deactivate and delete persistently unpatched themes and those that have been “Closed” in the WordPress.org theme repository. If you have a vulnerable theme installed that you are not actively using, simply delete it.
- No new WordPress theme vulnerabilities were disclosed this week.
Never worry about running a vulnerable plugin or theme again.
As you can see from this report, new WordPress plugin and theme vulnerabilities are disclosed every week. We know it can be difficult to stay on top of every reported vulnerability disclosure that matters to you, so the Themes Security Pro plugin makes it easy to ensure your site isn’t running a vulnerable theme, plugin, or version of WordPress core.
The Best WordPress Security Plugin to Secure & Protect WordPress Sites
WordPress currently powers over 40% of all websites, so it has become a popular target for hackers with malicious intent. The iThemes Security Pro plugin takes the guesswork out of WordPress security to make it easy to secure & protect your WordPress website. It’s like having a full-time security expert on staff who constantly monitors and protects your WordPress site for you.
The post WordPress Vulnerability Report – June 21, 2023 appeared first on iThemes.
This content was originally published here.