PERFORMANCE & CREATIVITY

We integrate research, strategy, design, engineering and operations to imagine, create and deliver some of the world's most engaging products and services.

Περιοχή
Marousi-Attika
box 15124

WordPress Vulnerability Report – June 21, 2023

WordPress Core Vulnerabilities — Patched

  • No new WordPress core vulnerabilities were disclosed this week.

WordPress Plugin Vulnerabilities — Patched

In this section, you’ll find the most recently disclosed WordPress plugin vulnerabilities that have been fixed with a new release from their authors and maintainers. Please apply the updates if you are affected!

These vulnerabilities have been disclosed and scored for their severity, thanks to our friends at Patchstack. Each plugin listing includes the type of vulnerability with its CVE number and CVSS severity rating with links to more technical details. You’ll also see the number of active sites using the plugin and the plugin version release that patches the vulnerability. We start with the most popular plugins, which represent the largest target for attackers.

WooCommerce Stripe Payment Gateway

Product image for WooCommerce Stripe Payment Gateway.

PLUGIN SLUGwoocommerce-gateway-stripe
INSTALLATIONS900,000+
VULNERABILITYUnauthenticated Broken Access Control
PATCHED IN VERSION7.4.1
SEVERITY SCOREHigh
The vulnerability has been patched, so you should update to version 7.4.1.

WooCommerce Stripe Payment Gateway

Product image for WooCommerce Stripe Payment Gateway.

PLUGIN SLUGwoocommerce-gateway-stripe
INSTALLATIONS900,000+
VULNERABILITYInsecure Direct Object References (IDOR)
PATCHED IN VERSION7.4.1
SEVERITY SCOREHigh
The vulnerability has been patched, so you should update to version 7.4.1.

Password Protected

Product image for Password Protected.

PLUGIN SLUGpassword-protected
INSTALLATIONS300,000+
VULNERABILITYCross Site Scripting (XSS)
PATCHED IN VERSION2.6.3
SEVERITY SCOREMedium
The vulnerability has been patched, so you should update to version 2.6.3.

Download Monitor

Product image for Download Monitor.

PLUGIN SLUGdownload-monitor
INSTALLATIONS100,000+
VULNERABILITYArbitrary File Upload
PATCHED IN VERSION4.8.4
SEVERITY SCORECritical
The vulnerability has been patched, so you should update to version 4.8.4.

WooCommerce Square

Product image for WooCommerce Square.

PLUGIN SLUGwoocommerce-square
INSTALLATIONS100,000+
VULNERABILITYInsecure Direct Object References (IDOR)
PATCHED IN VERSION3.8.2
SEVERITY SCOREHigh
The vulnerability has been patched, so you should update to version 3.8.2.

 Conditional Menus

PLUGIN SLUGconditional-menus
INSTALLATIONS70,000+
VULNERABILITYCross Site Scripting (XSS)
PATCHED IN VERSION1.2.1
SEVERITY SCOREHigh
The vulnerability has been patched, so you should update to version 1.2.1.

Dynamic Visibility for Elementor

Product image for Dynamic Visibility for Elementor.

PLUGIN SLUGdynamic-visibility-for-elementor
INSTALLATIONS40,000+
VULNERABILITYBroken Access Control
PATCHED IN VERSION5.0.6
SEVERITY SCOREMedium
The vulnerability has been patched, so you should update to version 5.0.6.

Stock Manager for WooCommerce

Product image for Stock Manager for WooCommerce.

PLUGIN SLUGwoocommerce-stock-manager
INSTALLATIONS30,000+
VULNERABILITYCross Site Request Forgery (CSRF)
PATCHED IN VERSION2.11.0
SEVERITY SCOREMedium
The vulnerability has been patched, so you should update to version 2.11.0.

CMS Commander

Product image for CMS Commander – Manage Multiple Sites.

PLUGIN SLUGcms-commander-client
INSTALLATIONS10,000+
VULNERABILITYAuthorization Bypass through Use of Insufficiently Unique Cryptographic Signature
PATCHED IN VERSION2.288
SEVERITY SCOREHigh
The vulnerability has been patched, so you should update to version 2.288.

File Renaming on Upload

Product image for File Renaming on Upload.

PLUGIN SLUGfile-renaming-on-upload
INSTALLATIONS10,000+
VULNERABILITYAdmin+ Stored Cross Site Scripting (XSS)
PATCHED IN VERSION2.5.2
SEVERITY SCOREMedium
The vulnerability has been patched, so you should update to version 2.5.2.

LWS Tools

Product image for LWS Tools.

PLUGINLWS Tools
PLUGIN SLUGlws-tools
INSTALLATIONS10,000+
VULNERABILITYMultiple Cross Site Request Forgery (CSRF)
PATCHED IN VERSION2.4.2
SEVERITY SCOREMedium
The vulnerability has been patched, so you should update to version 2.4.2.

YaySMTP

Product image for YaySMTP – Simple WP SMTP Mail.

PLUGIN SLUGyaysmtp
INSTALLATIONS6,000+
VULNERABILITYUnauthenticated Stored Cross Site Scripting (XSS)
PATCHED IN VERSION2.4.6
SEVERITY SCOREHigh
The vulnerability has been patched, so you should update to version 2.4.6.

MStore API

Product image for MStore API.

PLUGIN SLUGmstore-api
INSTALLATIONS5,000+
VULNERABILITYSQL Injection
PATCHED IN VERSION3.9.8
SEVERITY SCOREHigh
The vulnerability has been patched, so you should update to version 3.9.8.

MStore API

Product image for MStore API.

PLUGIN SLUGmstore-api
INSTALLATIONS5,000+
VULNERABILITYCross Site Request Forgery (CSRF) to Product Limit Update
PATCHED IN VERSION3.9.7
SEVERITY SCOREMedium
The vulnerability has been patched, so you should update to version 3.9.7.

MStore API

Product image for MStore API.

PLUGIN SLUGmstore-api
INSTALLATIONS5,000+
VULNERABILITYCross Site Request Forgery (CSRF) to Order Message Update
PATCHED IN VERSION3.9.7
SEVERITY SCOREMedium
The vulnerability has been patched, so you should update to version 3.9.7.

MStore API

Product image for MStore API.

PLUGIN SLUGmstore-api
INSTALLATIONS5,000+
VULNERABILITYCross Site Request Forgery (CSRF) to Order Title Update
PATCHED IN VERSION3.9.7
SEVERITY SCOREMedium
The vulnerability has been patched, so you should update to version 3.9.7.

MStore API

Product image for MStore API.

PLUGIN SLUGmstore-api
INSTALLATIONS5,000+
VULNERABILITYCross Site Request Forgery (CSRF) to Order Title Update
PATCHED IN VERSION3.9.7
SEVERITY SCOREMedium
The vulnerability has been patched, so you should update to version 3.9.7.

MStore API

Product image for MStore API.

PLUGIN SLUGmstore-api
INSTALLATIONS5,000+
VULNERABILITYCross Site Request Forgery (CSRF) to Order Status Update
PATCHED IN VERSION3.9.7
SEVERITY SCOREMedium
The vulnerability has been patched, so you should update to version 3.9.7.

MStore API

Product image for MStore API.

PLUGIN SLUGmstore-api
INSTALLATIONS5,000+
VULNERABILITYCross Site Request Forgery (CSRF) to Firebase Server Key Update
PATCHED IN VERSION3.9.7
SEVERITY SCOREMedium
The vulnerability has been patched, so you should update to version 3.9.7.

MStore API

Product image for MStore API.

PLUGIN SLUGmstore-api
INSTALLATIONS5,000+
VULNERABILITYMissing Authorization
PATCHED IN VERSION3.9.6
SEVERITY SCOREMedium
The vulnerability has been patched, so you should update to version 3.9.6.

WP Custom Cursors

Product image for WP Custom Cursors | WordPress Cursor Plugin.

PLUGIN SLUGwp-custom-cursors
INSTALLATIONS5,000+
VULNERABILITYAdmin+ SQL Injection
PATCHED IN VERSION3.2
SEVERITY SCOREHigh
The vulnerability has been patched, so you should update to version 3.2.

AI ChatBot

Product image for AI ChatBot.

PLUGIN SLUGchatbot
INSTALLATIONS4,000+
VULNERABILITYAdmin+ Stored Cross Site Scripting (XSS)
PATCHED IN VERSION4.5.5
SEVERITY SCOREMedium
The vulnerability has been patched, so you should update to version 4.5.5.

AI ChatBot

Product image for AI ChatBot.

PLUGIN SLUGchatbot
INSTALLATIONS4,000+
VULNERABILITYAdmin+ Stored Cross Site Scripting (XSS)
PATCHED IN VERSION4.5.6
SEVERITY SCOREMedium
The vulnerability has been patched, so you should update to version 4.5.6.

Integration for Contact Form 7 and Zoho CRM, Bigin

Product image for Integration for Contact Form 7 and Zoho CRM, Bigin.

PLUGIN SLUGcf7-zoho
INSTALLATIONS3,000+
VULNERABILITYAdmin+ SQL Injection
PATCHED IN VERSION1.2.4
SEVERITY SCOREHigh
The vulnerability has been patched, so you should update to version 1.2.4.

CHP Ads Block Detector

Product image for CHP Ads Block Detector.

PLUGIN SLUGchp-ads-block-detector
INSTALLATIONS3,000+
VULNERABILITYAuthenticated (Subscriber+) Stored Cross Site Scripting (XSS)
PATCHED IN VERSION3.9.8
SEVERITY SCOREMedium
The vulnerability has been patched, so you should update to version 3.9.8.

Recipe Maker For Your Food Blog from Zip Recipes

Product image for Recipe Maker For Your Food Blog from Zip Recipes.

PLUGIN SLUGzip-recipes
INSTALLATIONS3,000+
VULNERABILITYCross Site Request Forgery (CSRF)
PATCHED IN VERSION8.0.8
SEVERITY SCOREMedium
The vulnerability has been patched, so you should update to version 8.0.8.

All Bootstrap Blocks

Product image for All Bootstrap Blocks.

PLUGIN SLUGall-bootstrap-blocks
INSTALLATIONS2,000+
VULNERABILITYCross Site Request Forgery (CSRF)
PATCHED IN VERSION1.3.7
SEVERITY SCOREMedium
The vulnerability has been patched, so you should update to version 1.3.7.

Core Web Vitals & PageSpeed Booster

Product image for Core Web Vitals & PageSpeed Booster.

PLUGIN SLUGcore-web-vitals-pagespeed-booster
INSTALLATIONS2,000+
VULNERABILITYOpen Redirection
PATCHED IN VERSION1.0.13
SEVERITY SCOREMedium
The vulnerability has been patched, so you should update to version 1.0.13.

Extra User Details

Product image for Extra User Details.

PLUGIN SLUGextra-user-details
INSTALLATIONS2,000+
VULNERABILITYCross Site Request Forgery (CSRF)
PATCHED IN VERSION0.5.1
SEVERITY SCOREMedium
The vulnerability has been patched, so you should update to version 0.5.1.

Extra User Details

Product image for Extra User Details.

PLUGIN SLUGextra-user-details
INSTALLATIONS2,000+
VULNERABILITYCross Site Scripting (XSS)
PATCHED IN VERSION0.5.1
SEVERITY SCOREMedium
The vulnerability has been patched, so you should update to version 0.5.1.

WP Directory Kit

Product image for WP Directory Kit.

PLUGIN SLUGwpdirectorykit
INSTALLATIONS2,000+
VULNERABILITYMissing Authorization to Plugin Settings Change/Delete, Demo Import, Directory Kit Deletion via wdk_admin_action
PATCHED IN VERSION1.2.4
SEVERITY SCOREMedium
The vulnerability has been patched, so you should update to version 1.2.4.

Church Admin

Product image for Church Admin.

PLUGIN SLUGchurch-admin
INSTALLATIONS1,000+
VULNERABILITYReflected Cross Site Scripting (XSS)
PATCHED IN VERSION3.7.30
SEVERITY SCOREHigh
The vulnerability has been patched, so you should update to version 3.7.30.

Contact Forms by Cimatti

Product image for WordPress Contact Forms by Cimatti.

PLUGIN SLUGcontact-forms
INSTALLATIONS1,000+
VULNERABILITYBroken Access Control
PATCHED IN VERSION1.5.8
SEVERITY SCOREMedium
The vulnerability has been patched, so you should update to version 1.5.8.

WordPress Contact Forms by Cimatti

Product image for WordPress Contact Forms by Cimatti.

PLUGIN SLUGcontact-forms
INSTALLATIONS1,000+
VULNERABILITYCross Site Request Forgery (CSRF) via _accua_forms_form_edit_action
PATCHED IN VERSION1.5.8
SEVERITY SCOREMedium
The vulnerability has been patched, so you should update to version 1.5.8.

WP PDF Generator

Product image for WP PDF Generator.

PLUGIN SLUGwp-pdf-generator
INSTALLATIONS1,000+
VULNERABILITYCross Site Request Forgery (CSRF)
PATCHED IN VERSION1.2.3
SEVERITY SCOREMedium
The vulnerability has been patched, so you should update to version 1.2.3.

Zephyr Project Manager

Product image for Zephyr Project Manager.

PLUGIN SLUGzephyr-project-manager
INSTALLATIONS1,000+
VULNERABILITYCross Site Request Forgery (CSRF)
PATCHED IN VERSION3.3.94
SEVERITY SCOREMedium
The vulnerability has been patched, so you should update to version 3.3.94.

LWS Cleaner

Product image for LWS Cleaner.

PLUGIN SLUGlws-cleaner
INSTALLATIONS900+
VULNERABILITYMultiple Cross Site Request Forgery (CSRF)
PATCHED IN VERSION2.3.1
SEVERITY SCOREMedium
The vulnerability has been patched, so you should update to version 2.3.1.

WP Sticky Social

Product image for WP Sticky Social.

PLUGIN SLUGwp-sticky-social
INSTALLATIONS300+
VULNERABILITYCross-Site Request Forgery to Stored Cross-Site Scripting
PATCHED IN VERSION1.0.2
SEVERITY SCOREHigh
The vulnerability has been patched, so you should update to version 1.0.2.

Form Maker

PLUGINContact Form by WD
PLUGIN SLUGcontact-form-maker
VULNERABILITYMissing Authorization in check_score
PATCHED IN VERSION1.15.17
SEVERITY SCOREMedium
The vulnerability has been patched, so you should update to version 1.15.17.

WooCommerce Brands

PLUGINWooCommerce Brands
PLUGIN SLUGwoocommerce-brands
VULNERABILITYCross Site Request Forgery (CSRF)
PATCHED IN VERSION1.6.50
SEVERITY SCOREMedium
The vulnerability has been patched, so you should update to version 1.6.50.

WooCommerce Product Vendors

PLUGINWooCommerce Product Vendors
PLUGIN SLUGwoocommerce-product-vendors
VULNERABILITYShop Manager+ SQL Injection
PATCHED IN VERSION2.1.79
SEVERITY SCOREHigh
The vulnerability has been patched, so you should update to version 2.1.79.


WordPress Plugin Vulnerabilities — Unpatched

This section contains plugin vulnerabilities with no known fix. Until a patch is available, you are advised to deactivate the plugin, at minimum, immediately. If there is a high risk of active exploits or the plugin remains unpatched for weeks, you are advised to delete the plugin. You should also delete persistently unpatched plugins the WordPress.org repository has locked and marked “Closed” so they can no longer be downloaded and installed.

Seed Fonts

Product image for Seed Fonts.

PLUGIN SLUGseed-fonts
INSTALLATIONS20,000+
VULNERABILITYCross Site Scripting (XSS)
PATCHED IN VERSIONNo Fix
SEVERITY SCOREMedium
The vulnerability has not been patched. You should deactivate the plugin.

Flo Forms

Product image for Flo Forms – Easy Drag & Drop Form Builder.

PLUGIN SLUGflo-forms
INSTALLATIONS10,000+
VULNERABILITYCross Site Scripting (XSS)
PATCHED IN VERSIONNo Fix
SEVERITY SCOREMedium
The vulnerability has not been patched. You should deactivate the plugin.

Form Builder

Product image for Form Builder | Create Responsive Contact Forms.

PLUGIN SLUGcontact-form-add
INSTALLATIONS6,000+
VULNERABILITYCross Site Request Forgery (CSRF)
PATCHED IN VERSIONNo Fix
SEVERITY SCOREHigh
The vulnerability has not been patched. You should deactivate the plugin.

Google Map Shortcode

PLUGIN SLUGgoogle-map-shortcode
INSTALLATIONS4,000+
VULNERABILITYReflected Cross Site Scripting (XSS)
PATCHED IN VERSIONNo Fix
SEVERITY SCOREHigh
The vulnerability has not been patched. You should deactivate the plugin.

WP Matterport Shortcode

Product image for WP Matterport Shortcode.

PLUGIN SLUGshortcode-gallery-for-matterport-showcase
INSTALLATIONS4,000+
VULNERABILITYCross Site Scripting (XSS)
PATCHED IN VERSIONNo Fix
SEVERITY SCOREMedium
The vulnerability has not been patched. You should deactivate the plugin.

Sermon’e – Sermons Online

Product image for Sermon'e – Sermons Online.

PLUGIN SLUGsermone-online-sermons-management
INSTALLATIONS3,000+
VULNERABILITYCross Site Scripting (XSS)
PATCHED IN VERSIONNo Fix
SEVERITY SCOREMedium
The vulnerability has not been patched. You should deactivate the plugin.

Template Debugger

Product image for Template Debugger.

PLUGIN SLUGquick-edit-template-link
INSTALLATIONS2,000+
VULNERABILITYCross Site Request Forgery (CSRF)
PATCHED IN VERSIONNo Fix
SEVERITY SCOREMedium
The vulnerability has not been patched. You should deactivate the plugin.

Recent Posts Slider

Product image for Recent Posts Slider.

PLUGIN SLUGrecent-posts-slider
INSTALLATIONS2,000+
VULNERABILITYCross Site Request Forgery (CSRF)
PATCHED IN VERSIONNo Fix
SEVERITY SCOREMedium
The vulnerability has not been patched. You should deactivate the plugin.

Recent Posts Slider

Product image for Recent Posts Slider.

PLUGIN SLUGrecent-posts-slider
INSTALLATIONS2,000+
VULNERABILITYCross Site Scripting (XSS)
PATCHED IN VERSIONNo Fix
SEVERITY SCOREHigh
The vulnerability has not been patched. You should deactivate the plugin.

Securimage-WP

Product image for Securimage-WP.

PLUGIN SLUGsecurimage-wp
INSTALLATIONS2,000+
VULNERABILITYCross Site Request Forgery (CSRF)
PATCHED IN VERSIONNo Fix
SEVERITY SCOREMedium
The vulnerability has not been patched. You should deactivate the plugin.

breadcrumb simple

Product image for breadcrumb simple.

PLUGIN SLUGbreadcrumb-simple
INSTALLATIONS1,000+
VULNERABILITYCross Site Scripting (XSS)
PATCHED IN VERSIONNo Fix
SEVERITY SCOREMedium
The vulnerability has not been patched. You should deactivate the plugin.

Fat Rat Collect

Product image for ????(Fat Rat Collect) ????????????????, ???????????????????????????.

PLUGIN
PLUGIN SLUGfat-rat-collect
INSTALLATIONS1,000+
VULNERABILITYBroken Access Control
PATCHED IN VERSIONNo Fix
SEVERITY SCOREMedium
The vulnerability has not been patched. You should deactivate the plugin.

Galleria

Product image for Galleria.

PLUGINGalleria
PLUGIN SLUGgalleria
INSTALLATIONS1,000+
VULNERABILITYCross Site Request Forgery (CSRF)
PATCHED IN VERSIONNo Fix
SEVERITY SCOREMedium
The vulnerability has not been patched. You should deactivate the plugin.

Who Hit The Page – Hit Counter

Product image for Who Hit The Page – Hit Counter.

PLUGIN SLUGwho-hit-the-page-hit-counter
INSTALLATIONS1,000+
VULNERABILITYCross Site Scripting (XSS)
PATCHED IN VERSIONNo Fix
SEVERITY SCOREMedium
The vulnerability has not been patched. You should deactivate the plugin.

WordPress NextGen GalleryView

PLUGIN SLUGwordpress-nextgen-galleryview
INSTALLATIONS1,000+
VULNERABILITYReflected Cross Site Scripting (XSS)
PATCHED IN VERSIONNo Fix
SEVERITY SCOREHigh
The vulnerability has not been patched. You should deactivate the plugin.

WP Affiliate Links

PLUGIN SLUGwp-affiliate-links
INSTALLATIONS1,000+
VULNERABILITYReflected Cross Site Scripting (XSS)
PATCHED IN VERSIONNo Fix
SEVERITY SCOREHigh
The vulnerability has not been patched. You should deactivate the plugin.

WP Backup Manager

Product image for WP Backup Manager.

PLUGIN SLUGwp-backup-manager
INSTALLATIONS1,000+
VULNERABILITYReflected Cross Site Scripting (XSS)
PATCHED IN VERSIONNo Fix
SEVERITY SCOREHigh
The vulnerability has not been patched. You should deactivate the plugin.

MojoPlug Slide Panel

Product image for MojoPlug Slide Panel.

PLUGIN SLUGmojoplug-slide-panel
INSTALLATIONS800+
VULNERABILITYCross Site Scripting (XSS)
PATCHED IN VERSIONNo Fix
SEVERITY SCOREMedium
The vulnerability has not been patched. You should deactivate the plugin.

Smoothscroller

Product image for Smoothscroller.

PLUGIN SLUGsmoothscroller
INSTALLATIONS800+
VULNERABILITYCross Site Scripting (XSS)
PATCHED IN VERSIONNo Fix
SEVERITY SCOREMedium
The vulnerability has not been patched. You should deactivate the plugin.

wpView

Product image for Display Custom Fields – wpView.

PLUGIN SLUGwpview
INSTALLATIONS200+
VULNERABILITYCross Site Scripting (XSS)
PATCHED IN VERSIONNo Fix
SEVERITY SCOREMedium
The vulnerability has not been patched. You should deactivate the plugin.

Login Configurator

PLUGINLogin Configurator
PLUGIN SLUGlogin-configurator
VULNERABILITYCross Site Scripting (XSS)
PATCHED IN VERSIONNo Fix
SEVERITY SCOREMedium
The vulnerability has not been patched and the plugin is closed. You should uninstall and delete the plugin.

Upload Resume

PLUGINUpload Resume
PLUGIN SLUGresume-upload-form
VULNERABILITYCaptcha Bypass Vulnerability
PATCHED IN VERSIONNo Fix
SEVERITY SCOREMedium
The vulnerability has not been patched and the plugin is closed. You should uninstall and delete the plugin.