WordPress Vulnerability Report: June 2021, Part 4
Written by Michael Moore of Ithemes on June 23, 2021
Last Updated on June 23, 2021
Vulnerable plugins and themes are the #1 reason WordPress websites get hacked. This post covers recent WordPress plugin, theme, and core vulnerabilities and what to do if you run one of the vulnerable plugins or themes on your website.
Each vulnerability will have a severity rating of Low, Medium, High, or Critical. Responsible disclosure and reporting of vulnerabilities is an integral part of keeping the WordPress community safe. Please share this post with your friends to help get the word out and make WordPress safer for everyone.
Is Your WordPress Website Secure?
DID YOU KNOW – A staggering 83% of WordPress websites are not upgraded or updated, is your website one of these?
Hacks happen due to lack of website upkeep and protection, like updating WordPress or plugins, plus using weak passwords. Contrary to popular belief, web designers and website hosting companies are not responsible for the security of your WordPress website; you are. It’s like using your computer without Anti-virus!
WordPress Core Vulnerabilities
No new WordPress core vulnerabilities have been disclosed so far in June 2021.
WordPress Theme Vulnerabilities
1. Jannah
2. FoodBakery
WordPress Plugin Vulnerabilities
1. BCS BatchLine Book Importer
2. WP SVG Images
3. Vik Rent Car
4. WP FoodBakery
5. wpForo Forum
6. WooCommerce Stock Manager
7. Smooth Scroll Page Up/Down Buttons
8. Request a Quote
9. WP YouTube Lyte
10. WP JobSearch
11. WP Reset
12. Backup by 10Web
13. W3 Total Cache
14. WP Fluent Forms
15. Advanced AJAX Product Filters
16. Filebird
17. 404 to 301
WordPress Plugin Vulnerabilities
1. BCS BatchLine Book Importer

Plugin: BCS BatchLine Book Importer
Vulnerability: Unauthenticated Product Import
Patched in Version: 1.5.8
Severity: High
2. WP SVG Images

Plugin: WP SVG Images
Vulnerability: Authenticated Stored Cross-Site Scripting
Patched in Version: 3.4
Severity: Medium
3. Vik Rent Car

Plugin: Vik Rent Car
Vulnerability: CSRF to Stored XSS
Patched in Version: 1.1.7
Severity: High
4. WP FoodBakery

Plugin: FoodBakery
Vulnerability: Reflected Cross-Site Scripting
Patched in Version: 2.2
Severity: Medium
5. wpforo Forum

Plugin: WPForo Forum
Vulnerability: Open Redirect
Patched in Version: 1.9.7
Severity: Medium
6. WooCommerce Stock Manager

Plugin: WooCommerce Stock Manager
Vulnerability: CSRF to Arbitrary File Upload
Patched in Version: 2.6.0
Severity: High
7. Smooth Scroll Up/Down Buttons

Plugin: Smooth Scroll Page Up/Down Buttons
Vulnerability: Authenticated Stored Cross-Site Scripting
Patched in Version: No known fix
Severity: Medium
8. Request a quote

Plugin: Request a Quote
Vulnerability: Authenticated Stored Cross-Site Scripting
Patched in Version: 2.3.4
Severity: Medium
9. WP Youtube Lyte
Plugin: WP Youtube Lyte
Vulnerability: Authenticated Stored Cross-Site Scripting
Patched in Version: 1.7.16
Severity: Medium
10. WP Jobsearch

Plugin: WP Jobsearch
Vulnerability: Authenticated Stored Cross-Site Scripting
Patched in Version: 1.7.4
Severity: Medium
11. WP Reset

Plugin: WP Reset
Vulnerability: Authenticated Stored Cross-Site Scripting
Patched in Version: 1.90
Severity: Medium
12. Backup by 10Web
Plugin: Backup by 10Web
Vulnerability: Reflected Cross-Site Scripting
Patched in Version: No known fix – plugin closed
Severity: High
13. W3 Total Cache

Plugin: W3 Total Cache
Vulnerability: Authenticated Stored Cross-Site Scripting
Patched in Version: 2.1.3
Severity: Medium
14. WP Fluent Forms

Plugin: WP Fluent Forms
Vulnerability: Cross-Site Request Forgery
Patched in Version: 3.6.67
Severity: High
15. Advanced AJAX Product Filters

Plugin: Advanced AJAX Product Filters
Vulnerability: Unauthenticated Reflected Cross-Site Scripting
Patched in Version: 1.5.4.7
Severity: High
16. Filebird

Plugin: Filebird
Vulnerability: Unauthenticated SQL Injection
Patched in Version: 4.7.3
Severity: High
17. 404 to 301

Plugin: 404 to 301
Vulnerability: Broken Access Control
Patched in Version: 3.0.8
Severity: Medium
WordPress Theme Vulnerabilities
1. Jannah

Theme: Jannah
Vulnerability: Reflected Cross-Site Scripting
Patched in Version: 5.4.5
Severity: High
2. FoodBakery

Theme: FoodBakery
Vulnerability: Reflected Cross-Site Scripting
Patched in Version: 2.2
Severity: Medium
Protect Your WordPress Website Today With Website Guardian
Join hundreds of businesses like yours who trust InterwebDEFENCE to protect their websites and livelihood. Using our proven website security analysis and best-in-class AI ‘Website Guardian” software, we are able to protect, monitor and backup your WordPress website.
Go ahead, keep the good guys In and the bad guys out – Click HERE to see our Website Guardian security plans NOW
PLUS
Find out about our unconditional ‘Double Protection’ Guarantee. This guarantee is better than risk free!
We’ll have you scanned, protected and secure in no time, giving you total peace of mind that your website is safe, leaving you to focus on your business success.