Since last week, 95 total vulnerabilities emerged in public disclosure. They may affect over two million WordPress sites. There are 32 plugin vulnerabilities with security patches, so run those updates!
Additionally, there are 60 plugin vulnerabilities and three theme vulnerabilities with no patch available yet. If you use an unpatched plugin or theme, check their vendors’ intentions and progress on a security release. Suppose no patch is forthcoming or the vulnerable software has been marked “closed” and dropped from the official WordPress theme and plugin repositories. In that case, you should consider deactivation and removal in favor of alternative solutions.
FREE ONLINE TRAINING EVENT SEPT 6TH @ 1:00 P.M. (CT)
Discover essential best practices for safeguarding your WordPress website through proactive security measures. Join WordPress security expert Thomas Raef as he explains the art and science of WordPress security, focusing on three key dimensions: hosting, WordPress configurations, and user management. You’ll also learn how Solid Security equips users with tools that diminish hacking risks, focusing on safeguarding plugins, themes, and user accounts.
WordPress Core News
“Lionel” was released on August 8, 2023. This release of WordPress was built to help you “create beautiful and compelling websites more efficiently than ever.” See what’s new in WordPress 6.3.
Don’t forget to fully back up your website before installing WordPress 6.3. BackupBuddy, the industry-leading data protection and recovery solution for WordPress, will help you build a strong backup strategy to manage all updates. Embrace the enhanced content creation experience of WordPress 6.3 with confidence — and a backup copy of your website safely stored on a remote server.
WordPress Core Vulnerabilities — Patched
- No new WordPress core vulnerabilities were disclosed this week.
WordPress core is very secure when it’s properly configured and maintained. Vulnerable plugins not updated by site owners are the most common vector for attacks on WordPress websites. Our weekly WordPress Vulnerability Report, powered by Patchstack, covers new vulnerabilities that have emerged in plugins, themes, and/or WordPress core since last week’s report. Our goal is to spread awareness of emerging security threats and help you decide what to do if you find vulnerable software on your website. For a deeper analysis of recent trends in WordPress vulnerabilities and threat vectors, see our 2022 Annual Vulnerability Report.
These reports are published every Wednesday and include all active vulnerabilities tracked by Patchstack as of Monday since the previous report. This leaves a 48-hour window for the newest emerging vulnerabilities to be patched before full public disclosure. iThemes Security Pro users have access to vulnerability alerts emerging within this window.
WordPress Plugin Vulnerabilities — Patched
In this section, you’ll find the most recently disclosed WordPress plugin vulnerabilities fixed with a new release from their authors and maintainers. Please apply the updates if you are affected!
These vulnerabilities have been disclosed and scored for their severity, thanks to our friends at Patchstack. Each plugin listing includes the type of vulnerability with its CVE number and CVSS severity rating with links to more technical details. You’ll also see the number of active sites using the plugin and the plugin version release that patches the vulnerability. We start with the most popular plugins, representing the largest target for attackers.
GTranslate
- Vulnerability
- Cross Site Scripting (XSS)
Forminator
- CVE
- 2023-4596
Metform Elementor Contact Form Builder
- CVE
- 2023-0689
Social Media & Share Icons
- Vulnerability
- Cross Site Scripting (XSS)
- CVE
- 2023-41238
GiveWP
- CVE
- 2023-41665
UserFeedback Lite
- Vulnerability
- Cross Site Scripting (XSS)
- CVE
- 2023-39308
Slimstat Analytics
- Plugin
- Slimstat Analytics
- Vulnerability
- Cross Site Scripting (XSS)
- CVE
- 2023-4597
Email Encoder
- Vulnerability
- Cross Site Scripting (XSS)
- CVE
- 2023-4599
Folders
- CVE
- 2023-40204
Popup Box
- Plugin
- Popup box
- Vulnerability
- Cross Site Scripting (XSS)
GS Logo Slider
- Vulnerability
- Cross Site Request Forgery (CSRF)
- CVE
- 2022-47150
WP Project Manager
- Vulnerability
- Cross Site Request Forgery (CSRF)
- CVE
- 2022-47150
WP Project Manager
- CVE
- 2023-34383
WP Super Minify
- Plugin
- WP Super Minify
- Vulnerability
- Cross Site Request Forgery (CSRF)
- CVE
- 2023-27615
Post to Google My Business (Google Business Profile)
- CVE
- 2023-41689
SureCart
- Vulnerability
- Cross Site Scripting (XSS)
- CVE
- 2023-41241
HollerBox
- Vulnerability
- Cross Site Scripting (XSS)
- CVE
- 2023-41657
Order Tracking Pro
- Vulnerability
- Cross Site Scripting (XSS)
- CVE
- 2023-4500
Order Tracking Pro
- Vulnerability
- Cross Site Scripting (XSS)
- CVE
- 2023-4471
Leyka
WP Search Analytics
- Plugin
- WP Search Analytics
- Vulnerability
- Cross Site Scripting (XSS)
- CVE
- 2023-30471
Sitekit
- Plugin
- Sitekit
- Vulnerability
- Cross Site Scripting (XSS)
- CVE
- 2023-27628
Prevent files / folders access
- CVE
- 2023-4238
WP Pipes
- Plugin
- WP Pipes
- Vulnerability
- Cross Site Request Forgery (CSRF)
- CVE
- 2023-40009
Photo Gallery Slideshow & Masonry Tiled Gallery
- Vulnerability
- Cross Site Scripting (XSS)
- CVE
- 2023-41658
RSVPMaker
- Plugin
- RSVPMaker
- CVE
- 2023-41652
AffiliateWP
- CVE
- 2023-4600
All-in-One WP Migration Box Extension
- Plugin
- All-in-One WP Migration Box Extension
- CVE
- 2023-40004
All-in-One WP Migration Dropbox Extension
- Plugin
- All-in-One WP Migration Dropbox Extension
- CVE
- 2023-40004
All-in-One WP Migration Google Drive Extension
- Plugin
- All-in-One WP Migration Google Drive Extension
- CVE
- 2023-40004
All-in-One WP Migration OneDrive Extension
- Plugin
- All-in-One WP Migration OneDrive Extension
- CVE
- 2023-40004
Happy Elementor Addons Pro
- Plugin
- Happy Elementor Addons Pro
- Vulnerability
- Cross Site Scripting (XSS)
- CVE
- 2023-41236
WordPress Plugin Vulnerabilities — Unpatched
This section contains plugin vulnerabilities with no known fix. Until a patch is available, you are advised to deactivate the plugin, at minimum, immediately. If there is a high risk of active exploits or the plugin remains unpatched for weeks, you are advised to delete the plugin. You should also delete persistently unpatched plugins the WordPress.org repository has locked and marked “Closed” so they can no longer be downloaded and installed.
PowerPress Podcasting plugin by Blubrry
- Vulnerability
- Server Side Request Forgery (SSRF)
- Patched in Version
- No Fix
- CVE
- 2023-41239
WooCommerce Conversion Tracking
- Vulnerability
- Cross Site Request Forgery (CSRF)
- Patched in Version
- No Fix
- CVE
- 2022-47150
Ultimate Addons for Contact Form 7
- Vulnerability
- Cross Site Scripting (XSS)
- Patched in Version
- No Fix
- CVE
- 2023-30493
Directorist
- Patched in Version
- No Fix
- CVE
- 2022-47150
Export Import Menus
- Plugin
- Export Import Menus
- Patched in Version
- No Fix
- CVE
- 2023-34385
Legal Pages
- Vulnerability
- Cross Site Request Forgery (CSRF)
- Patched in Version
- No Fix
- CVE
- 2022-47150
URL Shortener by MyThemeShop
- Plugin
- URL Shortener by MyThemeShop
- Vulnerability
- Cross Site Scripting (XSS)
- Patched in Version
- No Fix
- CVE
- 2023-30472
Texty
- Vulnerability
- Cross Site Request Forgery (CSRF)
- Patched in Version
- No Fix
- CVE
- 2022-47150
weMail
- Vulnerability
- Cross Site Request Forgery (CSRF)
- Patched in Version
- No Fix
- CVE
- 2022-47150
Better Elementor Addons
- Plugin
- Better Elementor Addons
- Patched in Version
- No Fix
- CVE
- 2023-41656
Easy Coming Soon
- Plugin
- Easy Coming Soon
- Vulnerability
- Cross Site Scripting (XSS)
- Patched in Version
- No Fix
- CVE
- 2023-25483
Login and Logout Redirect
- Plugin
- Login and Logout Redirect
- Patched in Version
- No Fix
- CVE
- 2023-41648
authLdap
- Plugin
- authLdap
- Vulnerability
- Cross Site Scripting (XSS)
- Patched in Version
- No Fix
- CVE
- 2023-41655
authLdap
- Plugin
- authLdap
- Vulnerability
- Cross Site Request Forgery (CSRF)
- Patched in Version
- No Fix
- CVE
- 2023-41654
LuckyWP Scripts Control
- Plugin
- LuckyWP Scripts Control
- Patched in Version
- No Fix
- CVE
- 2023-29239
Multi-column Tag Map
- Plugin
- Multi-column Tag Map
- Patched in Version
- No Fix
- CVE
- 2023-41651
Responsive Gallery Grid
- Plugin
- Responsive Gallery Grid
- Vulnerability
- Cross Site Request Forgery (CSRF)
- Patched in Version
- No Fix
- CVE
- 2023-41659
Social Share Boost
- Plugin
- Social Share Boost
- Vulnerability
- Cross Site Request Forgery (CSRF)
- Patched in Version
- No Fix
- CVE
- 2023-25033
Unlimited Elementor Inner Sections By BoomDevs
- Vulnerability
- Cross Site Request Forgery (CSRF)
- Patched in Version
- No Fix
- CVE
- 2022-47150
weDocs – Knowledgebase and Documentation Plugin for WordPress
- Vulnerability
- Cross Site Request Forgery (CSRF)
- Patched in Version
- No Fix
- CVE
- 2022-47150
MakeStories (for Google Web Stories)
- Vulnerability
- Cross Site Request Forgery (CSRF)
- Patched in Version
- No Fix
- CVE
- 2023-27448
MyCryptoCheckout
- Vulnerability
- Cross Site Request Forgery (CSRF)
- Patched in Version
- No Fix
- CVE
- 2023-41693
Remove/hide Author, Date, Category Like Entry-Meta
- Vulnerability
- Cross Site Request Forgery (CSRF)
- Patched in Version
- No Fix
- CVE
- 2023-41650
Surfer
- Plugin
- Surfer – WordPress Plugin
- Patched in Version
- No Fix
- CVE
- 2023-35037
Leadster
- Plugin
- Leadster
- Vulnerability
- Cross Site Request Forgery (CSRF)
- Patched in Version
- No Fix
- CVE
- 2023-41668
Ovic Product Bundle
- Plugin
- Ovic Product Bundle
- Patched in Version
- No Fix
- CVE
- 2023-41649
Pricing Deals for WooCommercePricing Deals for WooCommerce
- Patched in Version
- No Fix
- CVE
- 2023-41240
WP users media
- Plugin
- WP Users Media
- Patched in Version
- No Fix
- CVE
- 2023-27428
Migration Plugin DB & Files – WP Synchro
- Vulnerability
- Cross Site Request Forgery (CSRF)
- Patched in Version
- No Fix
- CVE
- 2023-41660
Live News
- Plugin
- Live News
- Vulnerability
- Cross Site Request Forgery (CSRF)
- Patched in Version
- No Fix
- CVE
- 2023-41669
Realbig
- Plugin
- Realbig For WordPress
- Vulnerability
- Cross Site Request Forgery (CSRF)
- Patched in Version
- No Fix
- CVE
- 2023-41694
TelSender
- Patched in Version
- No Fix
- CVE
- 2023-41683
WooCommerce PensoPay
- Plugin
- WooCommerce PensoPay
- Vulnerability
- Cross Site Scripting (XSS)
- Patched in Version
- No Fix
- CVE
- 2023-41691
Hide admin notices – Admin Notification Center
- Vulnerability
- Cross Site Request Forgery (CSRF)
- Patched in Version
- No Fix
- CVE
- 2023-41672
WRC Pricing Tables
- Patched in Version
- No Fix
- CVE
- 2023-32293
Bulk NoIndex & NoFollow Toolkit
- Patched in Version
- No Fix
- CVE
- 2023-41688
Exclusive Team for Elementor
- Plugin
- Exclusive Team for Elementor
- Vulnerability
- Cross Site Request Forgery (CSRF)
- Patched in Version
- No Fix
- CVE
- 2022-47150
Goods Catalog
- Plugin
- Goods Catalog
- Vulnerability
- Cross Site Scripting (XSS)
- Patched in Version
- No Fix
- CVE
- 2023-41687
Olive One Click Demo Import
- Plugin
- Olive One Click Demo Import
- Patched in Version
- No Fix
- CVE
- 2023-29102
Stock Quotes List
- Plugin
- Stock Quotes List
- Vulnerability
- Cross Site Scripting (XSS)
- Patched in Version
- No Fix
- CVE
- 2023-41666
Product Category Showcase for WooCommerce
- Vulnerability
- Cross Site Request Forgery (CSRF)
- Patched in Version
- No Fix
- CVE
- 2022-47150
WiserNotify Social Proof
- Patched in Version
- No Fix
- CVE
- 2023-41690
WP Bannerize Pro
- Plugin
- WP Bannerize Pro
- Vulnerability
- Cross Site Scripting (XSS)
- Patched in Version
- No Fix
- CVE
- 2023-41663
Tilda Publishing
- Plugin
- Tilda Publishing
- Patched in Version
- No Fix
- CVE
- 2023-31234
Easy Newsletter Signups
- Plugin
- Easy Newsletter Signups
- Patched in Version
- No Fix
- CVE
- 2023-41664
Snap Pixel
- Plugin
- Snap Pixel
- Vulnerability
- Cross Site Scripting (XSS)
- Patched in Version
- No Fix
- CVE
- 2023-41242
Woocommerce Support System
- Plugin
- Woocommerce Support System
- Patched in Version
- No Fix
- CVE
- 2023-41686
Woocommerce Support System
- Plugin
- Woocommerce Support System
- Patched in Version
- No Fix
- CVE
- 2023-41685
Localize Remote Images
- Plugin
- Localize Remote Images
- Vulnerability
- Cross Site Request Forgery (CSRF)
- Patched in Version
- No Fix
- CVE
- 2023-41244
Bridge Core
- Vulnerability
- Cross Site Scripting (XSS)
- Patched in Version
- No Fix
- CVE
- 2023-40333
WordPress CTA
- Vulnerability
- Cross Site Request Forgery (CSRF)
- Patched in Version
- No Fix
- CVE
- 2022-47150
Font Awesome 4 Menus
- Plugin
- Font Awesome 4 Menus
- Vulnerability
- Cross Site Scripting (XSS)
- Patched in Version
- No Fix
- CVE
- 2023-4718
GuruWalk Affiliates
- Plugin
- GuruWalk Affiliates
- Vulnerability
- Cross Site Scripting (XSS)
- Patched in Version
- No Fix
- CVE
- 2023-27622
Maintenance Switch
- Vulnerability
- Cross Site Request Forgery (CSRF)
- Patched in Version
- No Fix
- CVE
- 2023-29235
Sermon’e – Sermons Online
- Plugin
- Sermon’e – Sermons Online
- Vulnerability
- Cross Site Scripting (XSS)
- Patched in Version
- No Fix
- CVE
- 2023-41653
SIS Handball
- Vulnerability
- Cross Site Request Forgery (CSRF)
- Patched in Version
- No Fix
- CVE
- 2023-41684
Smarty for WordPress
- Vulnerability
- Cross Site Scripting (XSS)
- Patched in Version
- No Fix
- CVE
- 2023-41661
Use Memcached
- Vulnerability
- Cross Site Request Forgery (CSRF)
- Patched in Version
- No Fix
- CVE
- 2023-41670
WP-dTree
- Vulnerability
- Cross Site Request Forgery (CSRF)
- Patched in Version
- No Fix
- CVE
- 2023-41667
WP-dTree
- Vulnerability
- Cross Site Scripting (XSS)
- Patched in Version
- No Fix
- CVE
- 2023-41662
In this section, you’ll find the latest WordPress theme vulnerabilities to be disclosed. You’ll see the same information we provided above for vulnerable plugins, and the same advice applies. If a security update exists, install it immediately. If a vulnerability remains unpatched in a theme you are actively using, you must find an alternative theme. Deactivate and delete persistently unpatched themes and those marked “Closed” in the WordPress.org theme repository. If you have a vulnerable theme installed that you are not actively using, delete it.
Attorney
- Theme
- Attorney
- Vulnerability
- Cross Site Scripting (XSS)
- Patched in Version
- No Fix
- CVE
- 2023-41692
Arya Multipurpose Pro
- Vulnerability
- Cross Site Scripting (XSS)
- Patched in Version
- No Fix
- CVE
- 2023-41237
Everest News Pro
- Vulnerability
- Cross Site Scripting (XSS)
- Patched in Version
- No Fix
- CVE
- 2023-41235
Never worry about running a vulnerable plugin or theme again.
As you can see from this report, new WordPress plugin and theme vulnerabilities are disclosed every week. We know it can be difficult to stay on top of every reported vulnerability disclosure that matters to you, so the Themes Security Pro plugin makes it easy to ensure your site isn’t running a vulnerable theme, plugin, or version of WordPress core.
The Best WordPress Security Plugin to Secure & Protect WordPress Sites
WordPress currently powers over 40% of all websites, so it has become a popular target for hackers with malicious intent. The iThemes Security Pro plugin takes the guesswork out of WordPress security to make it easy to secure & protect your WordPress website. It’s like having a full-time security expert on staff who constantly monitors and protects your WordPress site for you.
The post WordPress Vulnerability Report – September 6, 2023 appeared first on iThemes.
This content was originally published here.