WordPress Vulnerability Report – November 23, 2022

Vulnerable plugins and themes are the #1 reason WordPress websites get hacked. The weekly WordPress Vulnerability Report powered by WPScan covers recent WordPress plugin, theme, and core vulnerabilities and what to do if you run one of the vulnerable plugins or themes on your website.

Each vulnerability will have a severity rating of low, medium, high, or critical. Responsible disclosure and reporting of vulnerabilities is an integral part of keeping the WordPress community safe. Please share this post with your friends to help get the word out and make WordPress safer for everyone!

The Future of Authentication is Passkeys! Login to your WordPress site with Biometrics only available in iThemes Security Pro

The problems of brute force attacks through credential stuffing, phishing attacks, and reused passwords have made our digital lives less secure. We’ve all tried to encourage 2-factor authentication as a protection, but less than 30% of users actually use 2FA. Password-based logins are a problem.

The future of authentication is passkeys, and iThemes Security Pro is the first to bring this breakthrough technology to WordPress sites. Using breakthrough WebAuthn technology based on public/private cryptography, passkeys make passwords obsolete. Now, website admins and end users can have secure logins without the inconvenience of additional two-factor apps, password managers, or complex password requirements.

WordPress Core News

WordPress 6.1.1 was released on November 15, 2022, as a short-cycle maintenance release with 29 bug fixes in Core and 21 bug fixes for the block editor. Because this is a core update, be sure to update to WordPress 6.0.1 as soon as possible! As always, with a major release like this, it makes sense to ensure your site is backed up with BackupBuddy before updating.

  • No new WordPress core vulnerabilities were disclosed this week.

WordPress Core Dropping Support for WordPress Versions 3.7. – 4.0

In more WordPress core security news, the WordPress Security Team will no longer provide security updates for WordPress core versions 3.7 – 4.0. Please make sure all your WordPress sites are running the latest version.

WordPress Plugin Vulnerabilities

In this section, the latest WordPress plugin vulnerabilities have been disclosed. Each plugin listing includes the type of vulnerability, the active installations, the version number if patched, and the severity rating.

SVG Support

Product image for SVG Support.

Plugin
SVG Support
CVE
2022-4022
The vulnerability has been patched, so you should update to version 2.5.2.

Icegram Express

Product image for Icegram Express – Email Subscribers, Newsletters and Marketing Automation Plugin.

CVE
2022-3981
The vulnerability has been patched, so you should update to version 5.5.0.

Booster for WooCommerce

Product image for Booster for WooCommerce.

Vulnerability
Custom Role Creation/Deletion via CSRF
CVE
2022-4016
The vulnerability has been patched, so you should update to version 5.6.7.

Permalink Manager Lite

Product image for Permalink Manager Lite.

Vulnerability
Settings Update via CSRF
CVE
2022-4021
The vulnerability has been patched, so you should update to version 2.2.20.2.

Easy Video Player

Product image for Easy Video Player.

CVE
2022-3937
The vulnerability has been patched, so you should update to version 1.2.2.3.

wpForo Forum

Product image for wpForo Forum.

Plugin
wpForo Forum
Vulnerability
Arbitrary User Deletion via CSRF
The vulnerability has been patched, so you should update to version 2.1.0.

Ezoic

Product image for Ezoic.

Plugin
Ezoic
Vulnerability
Admin+ Stored XSS; Unauthenticated Settings Update to Stored XSS
The vulnerability has been patched, so you should update to version 2.8.9.

Welcart e-Commerce

Product image for Welcart e-Commerce.

Vulnerability
Multiple Subscriber+ Stored Cross-Site Scripting; Subscriber+ Arbitrary Shipping Method Creation/Update/Deletion
CVE
2022-3935
The vulnerability has been patched, so you should update to version 2.8.4.

WP Stripe Checkout

Product image for WP Stripe Checkout.

CVE
2022-3986
The vulnerability has been patched, so you should update to version 1.2.2.21.

Anthologize

Plugin
Anthologize
The vulnerability has been patched, so you should update to version 0.8.1.

Chameleon

Product image for Chameleon.

Plugin
Chameleon
The vulnerability has been patched, so you should update to version 1.4.4.

Easy Form Builder

Product image for Easy Form Builder.

CVE
2022-3906
The vulnerability has been patched, so you should update to version 3.4.0.

Booster Elite for WooCommerce

Plugin
Booster Elite for WooCommerce
Vulnerability
Custom Role Creation/Deletion via CSRF
CVE
2022-4016
The vulnerability has been patched, so you should update to version 1.1.8.

Booster Plus for WooCommerce

Plugin
Booster Plus for WooCommerce
Vulnerability
Custom Role Creation/Deletion via CSRF
CVE
2022-4016
The vulnerability has been patched, so you should update to version 5.6.6.

Cooked Pro

Vulnerability
Unauthenticated PHP Object Injection
CVE
2022-3900
The vulnerability has been patched, so you should update to version 1.7.5.7.

SMSA Shipping for WooCommerce

Plugin
SMSA Shipping for WooCommerce
CVE
2022-4107
The vulnerability has been patched, so you should update to version 1.0.5.

WooCommerce Shipping – DPD baltic

Plugin
WooCommerce Shipping – DPD baltic
CVE
2022-4000
The vulnerability has been patched, so you should update to version 1.2.11.

WordPress Plugin Vulnerabilities – No Known Fix

This section contains plugin vulnerabilities with no known fix. Until a patch is available, immediately uninstall and delete the plugin.

Ultimate Tables

Patched in Version
No Fix
The vulnerability has not been patched and the plugin is closed. You should uninstall and delete the plugin.

WooSwipe WooCommerce Gallery

Patched in Version
No Fix
The vulnerability has not been patched and the plugin is closed. You should uninstall and delete the plugin.

Essential Real Estate

Patched in Version
No Fix
CVE
2022-3933
The vulnerability has not been patched and the plugin is closed. You should uninstall and delete the plugin.

Flat PM

Plugin
Flat PM
Patched in Version
No Fix
CVE
2022-3934
The vulnerability has not been patched and the plugin is closed. You should uninstall and delete the plugin.

GetYourGuide Ticketing

Patched in Version
No Fix
CVE
2022-3609
The vulnerability has not been patched and the plugin is closed. You should uninstall and delete the plugin.

Donation Button

Patched in Version
No Fix
CVE
2022-4005
The vulnerability has not been patched and the plugin is closed. You should uninstall and delete the plugin.

Buddybadges

Patched in Version
No Fix
CVE
2022-3925
The vulnerability has not been patched and the plugin is closed. You should uninstall and delete the plugin.

iFeature Slider

Patched in Version
No Fix
The vulnerability has not been patched and the plugin is closed. You should uninstall and delete the plugin.

WordPress Theme Vulnerabilities

In this section, the latest WordPress theme vulnerabilities have been disclosed. Each theme listing includes the type of vulnerability, the active installations, the version number if patched, and the severity rating.

Listingo

Vulnerability
Unauthenticated Arbitrary File Upload
CVE
2022-3921
The vulnerability has been patched, so you should update to version 3.2.7.

Betheme

CVE
2022-3861
The vulnerability has been patched, so you should update to version 26.6.3.

Never worry about running a vulnerable plugin or theme again.

As you can see from this report, lots of new WordPress plugin and theme vulnerabilities are disclosed each week. We know it can be difficult to stay on top of every reported vulnerability disclosure, so the iThemes Security Pro plugin makes it easy to make sure your site isn’t running a theme, plugin, or WordPress core version with a known vulnerability.

Scans Your Website Twice a Day for Vulnerabilities

Your website’s plugins, themes, and WordPress core versions are checked against the WPScan Vulnerability Database for the latest vulnerability disclosures.

Automatically Updates if a Security Fix is Available

Paired with Version Management, iThemes Security will automatically update a plugin, theme, or WordPress core version if it has a vulnerability.

Emails You if Site Scan Detects a Vulnerability

You can receive an email report if your site is running vulnerable versions of a plugin, theme, or WordPress core. Customize the email addresses that receive scan results.

The Best WordPress Security Plugin to Secure & Protect WordPress Sites

WordPress currently powers over 40% of all websites, so it has become an easy target for hackers with malicious intent. The iThemes Security Pro plugin takes the guesswork out of WordPress security to make it easy to secure & protect your WordPress website. It’s like having a full-time security expert on staff who constantly monitors and protects your WordPress site for you.

The post WordPress Vulnerability Report – November 23, 2022 appeared first on iThemes.

This content was originally published here.