WordPress Vulnerability Report – September 13, 2023

Since last week, 136 total vulnerabilities emerged in public disclosure. They may affect over four million WordPress sites. There are 76 plugin vulnerabilities and two theme vulnerabilities with security patches, so run those updates!

Additionally, there are 55 plugin vulnerabilities and three theme vulnerabilities with no patch available yet. If you use an unpatched plugin or theme, check their vendors’ intentions and progress on a security release. Suppose no patch is forthcoming or the vulnerable software has been marked “closed” and dropped from the official WordPress theme and plugin repositories. In that case, you should consider deactivation and removal in favor of alternative solutions.

WEBINAR REPLAY NOW AVAILABLE

Discover a streamlined approach to WordPress logins with Passkeys and Solid Security Pro (the new name for iThemes Security Pro). Passkeys are compatible with leading browsers such as Chrome, Firefox, and Safari, as well as biometric logins like Face ID, Touch ID, and Windows Hello. Say goodbye to the hassle of extra two-factor apps, password managers, or intricate password requirements, as website administrators and end users can now enjoy secure logins effortlessly.

Powered by the WebAuthn protocol, these cutting-edge login methods redefine passwordless login experiences, setting the stage for the future of safeguarding sensitive online information, including accessing WordPress sites. Timothy Jacobs, Lead Developer for SolidWP, gives an in-depth exploration of how this innovative technology enhances the WordPress login process for both you and your clients.

WordPress Core News

“Lionel” was released on August 8, 2023. This release of WordPress was built to help you “create beautiful and compelling websites more efficiently than ever.” See what’s new in WordPress 6.3.

Don’t forget to fully back up your website before installing WordPress 6.3. BackupBuddy, the industry-leading data protection and recovery solution for WordPress, will help you build a strong backup strategy to manage all updates. Embrace the enhanced content creation experience of WordPress 6.3 with confidence — and a backup copy of your website safely stored on a remote server.

WordPress Core Vulnerabilities — Patched

  • No new WordPress core vulnerabilities were disclosed this week.

WordPress core is very secure when it’s properly configured and maintained. Vulnerable plugins not updated by site owners are the most common vector for attacks on WordPress websites. Our weekly WordPress Vulnerability Report, powered by Patchstack, covers new vulnerabilities that have emerged in plugins, themes, and/or WordPress core since last week’s report. Our goal is to spread awareness of emerging security threats and help you decide what to do if you find vulnerable software on your website. For a deeper analysis of recent trends in WordPress vulnerabilities and threat vectors, see our 2022 Annual Vulnerability Report.

These reports are published every Wednesday and include all active vulnerabilities tracked by Patchstack as of Monday since the previous report. This leaves a 48-hour window for the newest emerging vulnerabilities to be patched before full public disclosure. iThemes Security Pro users have access to vulnerability alerts emerging within this window.

WordPress Plugin Vulnerabilities — Patched

In this section, you’ll find the most recently disclosed WordPress plugin vulnerabilities fixed with a new release from their authors and maintainers. Please apply the updates if you are affected!

These vulnerabilities have been disclosed and scored for their severity, thanks to our friends at Patchstack. Each plugin listing includes the type of vulnerability with its CVE number and CVSS severity rating with links to more technical details. You’ll also see the number of active sites using the plugin and the plugin version release that patches the vulnerability. We start with the most popular plugins, representing the largest target for attackers.

Activity Log

Product image for Activity Log.

Plugin
Activity Log
CVE
2023-4281
The vulnerability has been patched, so you should update to version 2.8.8.

Slimstat Analytics

Product image for Slimstat Analytics.

CVE
2023-4598
The vulnerability has been patched, so you should update to version 5.0.10.

Media Library Assistant

Product image for Media Library Assistant.

Vulnerability
Remote Code Execution (RCE)
CVE
2023-4634
The vulnerability has been patched, so you should update to version 3.10.

MapPress Maps for WordPress

Product image for MapPress Maps for WordPress.

Vulnerability
Cross Site Scripting (XSS)
CVE
2023-4840
The vulnerability has been patched, so you should update to version 2.88.5.

Simple Membership

Product image for Simple Membership.

Vulnerability
Cross Site Scripting (XSS)
CVE
2023-4719
The vulnerability has been patched, so you should update to version 4.3.6.

Carousel Slider

Product image for Carousel Slider.

The vulnerability has been patched, so you should update to version 2.2.3.

Super Socializer

Product image for Social Share, Social Login and Social Comments Plugin – Super Socializer.

The vulnerability has been patched, so you should update to version 7.13.55.

Meks Easy Photo Feed Widget

Product image for Meks Easy Photo Feed Widget.

Vulnerability
Cross Site Request Forgery (CSRF)
The vulnerability has been patched, so you should update to version 1.2.8.

Meks Simple Flickr Widget

Product image for Meks Simple Flickr Widget.

Vulnerability
Cross Site Request Forgery (CSRF)
The vulnerability has been patched, so you should update to version 1.3.

Meks Easy Ads Widget

Product image for Meks Easy Ads Widget.

Vulnerability
Cross Site Request Forgery (CSRF)
The vulnerability has been patched, so you should update to version 2.0.8.

Meks Smart Author Widget

Product image for Meks Smart Author Widget.

Vulnerability
Cross Site Request Forgery (CSRF)
The vulnerability has been patched, so you should update to version 1.1.4.

Meks ThemeForest Smart Widget

Product image for Meks ThemeForest Smart Widget.

Vulnerability
Cross Site Request Forgery (CSRF)
The vulnerability has been patched, so you should update to version 1.5.

Meks Time Ago

Product image for Meks Time Ago.

Plugin
Meks Time Ago
Vulnerability
Cross Site Request Forgery (CSRF)
The vulnerability has been patched, so you should update to version 1.1.7.

weMail

Product image for weMail – Email Marketing, Newsletter, Optin Forms, Subscribers WordPress Plugin.

Vulnerability
Cross Site Request Forgery (CSRF)
The vulnerability has been patched, so you should update to version 1.14.2.

Slider Pro

Product image for Slider Pro.

Plugin
Slider Pro
The vulnerability has been patched, so you should update to version 4.8.7.

WP Crowdfunding

Product image for WP Crowdfunding.

The vulnerability has been patched, so you should update to version 2.1.6.

Meks Video Importer

Product image for Meks Video Importer.

Vulnerability
Cross Site Request Forgery (CSRF)
The vulnerability has been patched, so you should update to version 1.0.11.

WooCommerce PensoPay

Vulnerability
Cross Site Scripting (XSS)
The vulnerability has been patched, so you should update to version 6.3.2.

Locatoraid Store Locator

Product image for Locatoraid Store Locator.

Vulnerability
Cross Site Scripting (XSS)
CVE
2023-4476
The vulnerability has been patched, so you should update to version 3.9.24.

Meks Audio Player

Product image for Meks Audio Player.

Vulnerability
Cross Site Request Forgery (CSRF)
The vulnerability has been patched, so you should update to version 1.3.

StagTools

Product image for StagTools.

Plugin
StagTools
Vulnerability
Cross Site Scripting (XSS)
The vulnerability has been patched, so you should update to version 2.3.8.

WP Directory Kit

Product image for WP Directory Kit.

The vulnerability has been patched, so you should update to version 1.2.7.

CP Blocks

Product image for CP Blocks.

Plugin
CP Blocks
Vulnerability
Cross Site Request Forgery (CSRF)
The vulnerability has been patched, so you should update to version 1.0.21.

Laposta Signup Basic

Product image for Laposta Signup Basic.

Vulnerability
Cross Site Request Forgery (CSRF)
The vulnerability has been patched, so you should update to version 1.4.2.

Meks Easy Maps

Product image for Meks Easy Maps.

Vulnerability
Cross Site Request Forgery (CSRF)
The vulnerability has been patched, so you should update to version 2.1.4.

Notice Bar

Product image for Notice Bar.

Plugin
Notice Bar
Vulnerability
Cross Site Scripting (XSS)
The vulnerability has been patched, so you should update to version 3.1.1.

POEditor

Product image for POEditor.

Plugin
POEditor
Vulnerability
Cross Site Request Forgery (CSRF)
The vulnerability has been patched, so you should update to version 0.9.5.

WP Pipes

Product image for WP Pipes.

Plugin
WP Pipes
Vulnerability
Cross Site Request Forgery (CSRF)
The vulnerability has been patched, so you should update to version 1.4.1.

Cookie Notice & Consent

Product image for Cookie Notice & Consent.

Vulnerability
Cross Site Scripting (XSS)
The vulnerability has been patched, so you should update to version 1.6.1.

Simple Download Counter

Vulnerability
Cross Site Scripting (XSS)
CVE
2023-4838
The vulnerability has been patched, so you should update to version 1.6.1.

Laposta Signup Embed

Product image for Laposta Signup Embed.

Vulnerability
Cross Site Request Forgery (CSRF)
The vulnerability has been patched, so you should update to version 1.1.1.

Laposta Signup Embed

Product image for Laposta Signup Embed.

The vulnerability has been patched, so you should update to version 1.1.1.

RSVPMaker

Product image for RSVPMaker.

Plugin
RSVPMaker
Vulnerability
Remote Code Execution (RCE)
The vulnerability has been patched, so you should update to version 10.6.7.

PeproDev CF7 Database

Product image for PeproDev CF7 Database.

Vulnerability
Cross Site Scripting (XSS)
The vulnerability has been patched, so you should update to version 1.8.0.

Premium Starter Templates

The vulnerability has been patched, so you should update to version 3.2.6.

Premium Starter Templates

Vulnerability
Server Side Request Forgery (SSRF)
The vulnerability has been patched, so you should update to version 3.2.5.

Newsletter

Vulnerability
Cross Site Scripting (XSS)
CVE
2023-4772
The vulnerability has been patched, so you should update to version 7.9.0.

My Account Page Editor

Plugin
My Account Page Editor for Woocommerce
CVE
2023-4536
The vulnerability has been patched, so you should update to version 1.3.2.

VS Contact Form

The vulnerability has been patched, so you should update to version 14.0.

WordPress Plugin Vulnerabilities — Unpatched

This section contains plugin vulnerabilities with no known fix. Until a patch is available, you are advised to deactivate the plugin, at minimum, immediately. If there is a high risk of active exploits or the plugin remains unpatched for weeks, you are advised to delete the plugin. You should also delete persistently unpatched plugins the WordPress.org repository has locked and marked “Closed” so they can no longer be downloaded and installed.

WooCommerce Conversion Tracking

Product image for WooCommerce Conversion Tracking.

Vulnerability
Cross Site Request Forgery (CSRF)
Patched in Version
No Fix
The vulnerability has not been patched. You should deactivate the plugin.

MailMunch – Grow your Email List

Product image for MailMunch – Grow your Email List.

Vulnerability
Cross Site Request Forgery (CSRF)
Patched in Version
No Fix
The vulnerability has not been patched. You should deactivate the plugin.

Order Delivery Date for WP e-Commerce

Vulnerability
Cross Site Scripting (XSS)
Patched in Version
No Fix
The vulnerability has not been patched. You should deactivate the plugin.

Order Delivery Date for WP e-Commerce

Vulnerability
Cross Site Request Forgery (CSRF)
Patched in Version
No Fix
The vulnerability has not been patched. You should deactivate the plugin.

Outbound Link Manager

Vulnerability
Cross Site Request Forgery (CSRF)
Patched in Version
No Fix
The vulnerability has not been patched. You should deactivate the plugin.

WP Custom Post Template

Vulnerability
Cross Site Request Forgery (CSRF)
Patched in Version
No Fix
The vulnerability has not been patched. You should deactivate the plugin.

Leadster

Product image for Leadster.

Plugin
Leadster
Vulnerability
Cross Site Request Forgery (CSRF)
Patched in Version
No Fix
The vulnerability has not been patched. You should deactivate the plugin.

SendPress Newsletters

Product image for SendPress Newsletters.

Vulnerability
Cross Site Request Forgery (CSRF)
Patched in Version
No Fix
The vulnerability has not been patched. You should deactivate the plugin.

SendPress Newsletters

Product image for SendPress Newsletters.

Vulnerability
Cross Site Scripting (XSS)
Patched in Version
No Fix
The vulnerability has not been patched. You should deactivate the plugin.

Easy WP Cleaner

Product image for Easy WP Cleaner.

Vulnerability
Cross Site Request Forgery (CSRF)
Patched in Version
No Fix
The vulnerability has not been patched. You should deactivate the plugin.

Live News

Product image for Live News.

Plugin
Live News
Vulnerability
Cross Site Request Forgery (CSRF)
Patched in Version
No Fix
The vulnerability has not been patched. You should deactivate the plugin.

Realbig

Vulnerability
Cross Site Request Forgery (CSRF)
Patched in Version
No Fix
The vulnerability has not been patched. You should deactivate the plugin.

Rescue Shortcodes

Product image for Rescue Shortcodes.

Vulnerability
Cross Site Scripting (XSS)
Patched in Version
No Fix
The vulnerability has not been patched. You should deactivate the plugin.

Back To The Top Button

Product image for Back To The Top Button.

Vulnerability
Cross Site Scripting (XSS)
Patched in Version
No Fix
The vulnerability has not been patched. You should deactivate the plugin.

Click To Tweet

Product image for Click To Tweet.

Patched in Version
No Fix
The vulnerability has not been patched. You should deactivate the plugin.

Click To Tweet

Product image for Click To Tweet.

Vulnerability
Cross Site Scripting (XSS)
Patched in Version
No Fix
The vulnerability has not been patched. You should deactivate the plugin.

Exclusive Team for Elementor

Product image for Exclusive Team for Elementor.

Vulnerability
Cross Site Request Forgery (CSRF)
Patched in Version
No Fix
The vulnerability has not been patched. You should deactivate the plugin.

Goods Catalog

Plugin
Goods Catalog
Vulnerability
Cross Site Scripting (XSS)
Patched in Version
No Fix
The vulnerability has not been patched. You should deactivate the plugin.

Stock Quotes List

Product image for Stock Quotes List.

Vulnerability
Cross Site Scripting (XSS)
Patched in Version
No Fix
The vulnerability has not been patched. You should deactivate the plugin.

Sunshine Photo Cart

Product image for Sunshine Photo Cart.

Vulnerability
Insecure Direct Object References (IDOR)
Patched in Version
No Fix
The vulnerability has not been patched. You should deactivate the plugin.

Travel Map

Product image for Travel Map.

Plugin
Travel Map
Vulnerability
Cross Site Scripting (XSS)
Patched in Version
No Fix
The vulnerability has not been patched. You should deactivate the plugin.

UniConsent Cookie Consent CMP for GDPR / CCPA

Product image for UniConsent CMP for GDPR CPRA GPP TCF.

Vulnerability
Cross Site Scripting (XSS)
Patched in Version
No Fix
The vulnerability has not been patched. You should deactivate the plugin.

Product Category Showcase for WooCommerce

Product image for Product Category Showcase for WooCommerce.

Vulnerability
Cross Site Request Forgery (CSRF)
Patched in Version
No Fix
The vulnerability has not been patched. You should deactivate the plugin.

WP iCal Availability

Vulnerability
Cross Site Request Forgery (CSRF)
Patched in Version
No Fix
The vulnerability has not been patched. You should deactivate the plugin.

Insert Estimated Reading Time

Vulnerability
Cross Site Scripting (XSS)
Patched in Version
No Fix
The vulnerability has not been patched. You should deactivate the plugin.

Tilda Publishing

Patched in Version
No Fix
The vulnerability has not been patched. You should deactivate the plugin.

Locations

Product image for Locations.

Plugin
Locations
Vulnerability
Cross Site Scripting (XSS)
Patched in Version
No Fix
The vulnerability has not been patched. You should deactivate the plugin.

All in One B2B for WooCommerce

Plugin
All in One B2B for WooCommerce
Patched in Version
No Fix
CVE
2023-4703
The vulnerability has not been patched. You should deactivate the plugin.

All in One B2B for WooCommerce

Plugin
All in One B2B for WooCommerce
Vulnerability
Cross Site Request Forgery (CSRF)
Patched in Version
No Fix
CVE
2023-3547
The vulnerability has not been patched. You should deactivate the plugin.

Crayon Syntax Highlighter

Vulnerability
Server Side Request Forgery (SSRF)
Patched in Version
No Fix
CVE
2023-4893
The vulnerability has not been patched and the plugin is closed. You should uninstall and delete the plugin.

WordPress CTA

Vulnerability
Cross Site Request Forgery (CSRF)
Patched in Version
No Fix
The vulnerability has not been patched and the plugin is closed. You should uninstall and delete the plugin.

Email posts to subscribers

Plugin
Email posts to subscribers
Vulnerability
Cross Site Scripting (XSS)
Patched in Version
No Fix
The vulnerability has not been patched and the plugin is closed. You should uninstall and delete the plugin.

Email posts to subscribers

Plugin
Email posts to subscribers
Patched in Version
No Fix
The vulnerability has not been patched and the plugin is closed. You should uninstall and delete the plugin.

Export Import Menus

Patched in Version
No Fix
The vulnerability has not been patched and the plugin is closed. You should uninstall and delete the plugin.

Font Awesome 4 Menus

Plugin
Font Awesome 4 Menus
Vulnerability
Cross Site Scripting (XSS)
Patched in Version
No Fix
CVE
2023-4718
The vulnerability has not been patched and the plugin is closed. You should uninstall and delete the plugin.

Google Maps Plugin by Intergeo

Plugin
Google Maps Plugin by Intergeo
Vulnerability
Cross Site Scripting (XSS)
Patched in Version
No Fix
CVE
2023-4887
The vulnerability has not been patched and the plugin is closed. You should uninstall and delete the plugin.

JQuery Accordion Menu Widget

Plugin
JQuery Accordion Menu Widget
Vulnerability
Cross Site Scripting (XSS)
Patched in Version
No Fix
CVE
2023-4890
The vulnerability has not been patched and the plugin is closed. You should uninstall and delete the plugin.

Regpack

Plugin
Regpack
Vulnerability
Cross Site Scripting (XSS)
Patched in Version
No Fix
The vulnerability has not been patched. You should deactivate the plugin.

SIS Handball

Vulnerability
Cross Site Request Forgery (CSRF)
Patched in Version
No Fix
The vulnerability has not been patched and the plugin is closed. You should uninstall and delete the plugin.

Use Memcached

Vulnerability
Cross Site Request Forgery (CSRF)
Patched in Version
No Fix
The vulnerability has not been patched and the plugin is closed. You should uninstall and delete the plugin.

WordPress Social Login

Vulnerability
Cross Site Scripting (XSS)
Patched in Version
No Fix
CVE
2023-4773
The vulnerability has not been patched and the plugin is closed. You should uninstall and delete the plugin.

wpCentral

Vulnerability
Cross Site Request Forgery (CSRF)
Patched in Version
No Fix
The vulnerability has not been patched and the plugin is closed. You should uninstall and delete the plugin.

WP-dTree

Vulnerability
Cross Site Request Forgery (CSRF)
Patched in Version
No Fix
The vulnerability has not been patched and the plugin is closed. You should uninstall and delete the plugin.

WP Gallery Metabox

Vulnerability
Cross Site Request Forgery (CSRF)
Patched in Version
No Fix
The vulnerability has not been patched and the plugin is closed. You should uninstall and delete the plugin.

In this section, you’ll find the latest WordPress theme vulnerabilities to be disclosed. You’ll see the same information we provided above for vulnerable plugins, and the same advice applies. If a security update exists, install it immediately. If a vulnerability remains unpatched in a theme you are actively using, you must find an alternative theme. Deactivate and delete persistently unpatched themes and those marked “Closed” in the WordPress.org theme repository. If you have a vulnerable theme installed that you are not actively using, delete it.

Wishful Blog

Product image for Wishful Blog.

Theme
Wishful Blog
Vulnerability
Cross Site Scripting (XSS)
Patched in Version
No Fix
The vulnerability has not been patched. You should switch themes.

Attorney

Product image for Attorney.

Theme
Attorney
Vulnerability
Cross Site Scripting (XSS)
Patched in Version
No Fix
The vulnerability has not been patched. You should switch themes.

Raise Mag

Product image for Raise Mag.

Theme
Raise Mag
Vulnerability
Cross Site Scripting (XSS)
Patched in Version
No Fix
The vulnerability has not been patched. You should switch themes.

Flatsome

The vulnerability has been patched, so you should update to version 3.17.6.

Woodmart

Vulnerability
Cross Site Scripting (XSS)
The vulnerability has been patched, so you should update to version 7.2.5.

Never worry about running a vulnerable plugin or theme again.

As you can see from this report, new WordPress plugin and theme vulnerabilities are disclosed every week. We know it can be difficult to stay on top of every reported vulnerability disclosure that matters to you, so the Themes Security Pro plugin makes it easy to ensure your site isn’t running a vulnerable theme, plugin, or version of WordPress core.

The post WordPress Vulnerability Report – September 13, 2023 appeared first on iThemes.

This content was originally published here.