Since last week, 57 total vulnerabilities emerged in public disclosure. They may affect over five million WordPress sites. There are 37 plugin vulnerabilities with security patches, so run those updates!
Additionally, there are 20 plugin vulnerabilities with no patch available yet. If you use an unpatched plugin or theme, check their vendors’ intentions and progress on a security release. Suppose no patch is forthcoming or the vulnerable software has been marked “closed” and dropped from the official WordPress theme and plugin repositories. In that case, you should consider deactivation and removal in favor of alternative solutions.
WordPress Core Vulnerabilities — Patched
- No new WordPress core vulnerabilities were disclosed this week.
WordPress core is very secure when it’s properly configured and maintained. Vulnerable plugins not updated by site owners are the most common vector for attacks on WordPress websites. Our weekly WordPress Vulnerability Report, powered by Patchstack, covers new vulnerabilities that have emerged in plugins, themes, and/or WordPress core since last week’s report. Our goal is to spread awareness of emerging security threats and help you decide what to do if you find vulnerable software on your website. For a deeper analysis of recent trends in WordPress vulnerabilities and threat vectors, see our 2022 Annual Vulnerability Report.
These reports are published every Wednesday and include all active vulnerabilities tracked by Patchstack as of Monday since the previous report. This leaves a 48-hour window for the newest emerging vulnerabilities to be patched before full public disclosure. iThemes Security Pro users have access to vulnerability alerts emerging within this window.
WordPress Plugin Vulnerabilities — Patched
In this section, you’ll find the most recently disclosed WordPress plugin vulnerabilities fixed with a new release from their authors and maintainers. Please apply the updates if you are affected!
These vulnerabilities have been disclosed and scored for their severity, thanks to our friends at Patchstack. Each plugin listing includes the type of vulnerability with its CVE number and CVSS severity rating with links to more technical details. You’ll also see the number of active sites using the plugin and the plugin version release that patches the vulnerability. We start with the most popular plugins, representing the largest target for attackers.
Website Builder by SeedProd
- Vulnerability
- Cross Site Request Forgery (CSRF)
- CVE
- 2023-4975
Essential Addons for Elementor
- CVE
- 2023-41955
Enable Media Replace
- Plugin
- Enable Media Replace
Fluent Forms
- CVE
- 2023-41952
ShortPixel Image Optimizer
WPvivid
- Vulnerability
- Cross Site Scripting (XSS)
WPvivid Backup Plugin
- CVE
- 2023-41243
PageLayer
- Vulnerability
- Cross Site Scripting (XSS)
ProfilePress
- CVE
- 2023-41954
ProfilePress
- CVE
- 2023-41953
Essential Blocks
- CVE
- 2023-4402
Modula
Slimstat Analytics
- Plugin
- Slimstat Analytics
- CVE
- 2023-4598
wpDiscuz
wpDiscuz
- Vulnerability
- Insecure Direct Object References (IDOR)
- CVE
- 2023-3869
wpDiscuz
- Vulnerability
- Insecure Direct Object References (IDOR)
- CVE
- 2023-3998
Booster for WooCommerce
- Plugin
- Booster for WooCommerce
- Vulnerability
- Cross Site Scripting (XSS)
- CVE
- 2023-4945
Booster for WooCommerce
- Plugin
- Booster for WooCommerce
- CVE
- 2023-4796
Feeds for YouTube
- Vulnerability
- Cross Site Scripting (XSS)
- CVE
- 2023-4841
File Manager Pro
- Plugin
- File Manager Pro – Filester
- Vulnerability
- Cross Site Request Forgery (CSRF)
- CVE
- 2023-4827
MapPress Maps for WordPress
- Plugin
- MapPress Maps for WordPress
- Vulnerability
- Cross Site Scripting (XSS)
- CVE
- 2023-4840
PowerPress
- Vulnerability
- Cross Site Scripting (XSS)
WP Customer Reviews
- Plugin
- WP Customer Reviews
- Vulnerability
- Cross Site Scripting (XSS)
- CVE
- 2023-4648
Poptin
- Vulnerability
- Cross Site Scripting (XSS)
- CVE
- 2023-4961
Welcart e-Commerce
- Plugin
- Welcart e-Commerce
WordPress File Upload
- Plugin
- WordPress File Upload
- Vulnerability
- Cross Site Scripting (XSS)
Statify
MasterStudy LMS
- CVE
- 2023-4278
Herd Effects
- Vulnerability
- Cross Site Scripting (XSS)
- CVE
- 2023-4022
WPSchoolPress
- Vulnerability
- Cross Site Request Forgery (CSRF)
Bit Assist
- Vulnerability
- Cross Site Scripting (XSS)
Funnelforms Free
- Plugin
- Interactive Contact Form and Multi Step Form Builder with Drag & Drop Editor – Funnelforms Free
- Vulnerability
- Cross Site Scripting (XSS)
Testimonial Slider Shortcode
- Plugin
- Testimonial Slider Shortcode
- Vulnerability
- Cross Site Scripting (XSS)
Essential Blocks Pro
- CVE
- 2023-4386
Checkout Field Editor
- Vulnerability
- Cross Site Request Forgery (CSRF)
WooCommerce CVR Payment Gateway
- Plugin
- WooCommerce CVR Payment Gateway
- CVE
- 2023-4948
WooCommerce EAN Payment Gateway
- Plugin
- WooCommerce EAN Payment Gateway
- CVE
- 2023-4947
WordPress Plugin Vulnerabilities — Unpatched
This section contains plugin vulnerabilities with no known fix. Until a patch is available, you are advised to deactivate the plugin, at minimum, immediately. If there is a high risk of active exploits or the plugin remains unpatched for weeks, you are advised to delete the plugin. You should also delete persistently unpatched plugins the WordPress.org repository has locked and marked “Closed” so they can no longer be downloaded and installed.
Quiz And Survey Master
- Vulnerability
- Cross Site Request Forgery (CSRF)
- Patched in Version
- No Fix
- Patched in Version
- No Fix
- CVE
- 2023-3392
Allow PHP in Posts and Pages
- Plugin
- Allow PHP in Posts and Pages
- Vulnerability
- Remote Code Execution (RCE)
- Patched in Version
- No Fix
- CVE
- 2023-4994
Awesome Weather Widget
- Vulnerability
- Cross Site Scripting (XSS)
- Patched in Version
- No Fix
- CVE
- 2023-4944
BAN Users
- Patched in Version
- No Fix
- CVE
- 2023-4153
Crayon Syntax Highlighter
- Vulnerability
- Server Side Request Forgery (SSRF)
- Patched in Version
- No Fix
- CVE
- 2023-4893
Dropbox Folder Share
- Vulnerability
- Server Side Request Forgery (SSRF)
- Patched in Version
- No Fix
- CVE
- 2023-3025
Dropbox Folder Share
- Patched in Version
- No Fix
- CVE
- 2023-4488
Horizontal scrolling announcement
- Patched in Version
- No Fix
- CVE
- 2023-4999
Horizontal scrolling announcement
- Vulnerability
- Cross Site Scripting (XSS)
- Patched in Version
- No Fix
- CVE
- 2023-5001
Google Maps Plugin by Intergeo
- Plugin
- Google Maps Plugin by Intergeo
- Vulnerability
- Cross Site Scripting (XSS)
- Patched in Version
- No Fix
- CVE
- 2023-4887
JQuery Accordion Menu Widget
- Plugin
- JQuery Accordion Menu Widget
- Vulnerability
- Cross Site Scripting (XSS)
- Patched in Version
- No Fix
- CVE
- 2023-4890
Leyka
- Patched in Version
- No Fix
- CVE
- 2023-4917
Login with phone number
- Plugin
- Login with phone number
- Vulnerability
- Cross Site Request Forgery (CSRF)
- Patched in Version
- No Fix
- CVE
- 2023-4916
Photospace Responsive
- Vulnerability
- Cross Site Scripting (XSS)
- Patched in Version
- No Fix
- CVE
- 2023-4271
Simplr Registration Form Plus+
- Plugin
- Simplr Registration Form Plus+
- Vulnerability
- Insecure Direct Object References (IDOR)
- Patched in Version
- No Fix
- CVE
- 2023-4213
Super Store Finder
- Patched in Version
- No Fix
- CVE
- 2023-5054
WooCommerce Beta Tester
- Patched in Version
- No Fix
WP User Control
- Patched in Version
- No Fix
- CVE
- 2023-4915
WS Facebook Like Box Widget
- Plugin
- WS Facebook Like Box Widget
- Vulnerability
- Cross Site Scripting (XSS)
- Patched in Version
- No Fix
- CVE
- 2023-4963
In this section, you’ll find the latest WordPress theme vulnerabilities to be disclosed. You’ll see the same information we provided above for vulnerable plugins, and the same advice applies. If a security update exists, install it immediately. If a vulnerability remains unpatched in a theme you are actively using, you must find an alternative theme. Deactivate and delete persistently unpatched themes and those marked “Closed” in the WordPress.org theme repository. If you have a vulnerable theme installed that you are not actively using, delete it.
- No new WordPress theme vulnerabilities were disclosed this week.
Never worry about running a vulnerable plugin or theme again.
As you can see from this report, new WordPress plugin and theme vulnerabilities are disclosed every week. We know it can be difficult to stay on top of every reported vulnerability disclosure that matters to you, so the Themes Security Pro plugin makes it easy to ensure your site isn’t running a vulnerable theme, plugin, or version of WordPress core.
The Best WordPress Security Plugin to Secure & Protect WordPress Sites
WordPress currently powers over 40% of all websites, so it has become a popular target for hackers with malicious intent. The iThemes Security Pro plugin takes the guesswork out of WordPress security to make it easy to secure & protect your WordPress website. It’s like having a full-time security expert on staff who constantly monitors and protects your WordPress site for you.
The post WordPress Vulnerability Report – September 20, 2023 appeared first on iThemes.
This content was originally published here.