WordPress Vulnerability Roundup: March 2020, Part 1
Written by Michael Moore on March 11, 2020
Last Updated on November 22nd, 2020
New WordPress plugin and theme vulnerabilities were disclosed during the first week of March. This post covers the recent WordPress plugin, theme, and core vulnerabilities and what to do if you run one of the vulnerable plugins or themes on your website.
The WordPress Vulnerability Roundup is divided into three different categories: WordPress core, WordPress plugins, and WordPress themes.
Each vulnerability will have a severity rating of Low, Medium, High, or Critical. The severity ratings are based on the Common Vulnerability Scoring System.
Is Your WordPress Website Secure?
DID YOU KNOW – A staggering 83% of WordPress websites are not upgraded or updated, is your website one of these?
Hacks happen due to lack of website upkeep and protection, like updating WordPress or plugins, plus using weak passwords. Contrary to popular belief, web designers and website hosting companies are not responsible for the security of your WordPress website; you are. It’s like using your computer without Anti-virus!
WordPress Core Vulnerabilities
No new WordPress core vulnerabilities have been disclosed this month.
WordPress Theme Vulnerabilities
WordPress Plugin Vulnerabilities
1. Under Construction, Coming Soon & Maintenance Mode
2. Abandoned Cart Lite for WooCommerce
3. Forminator
4. Dokan
5. Defender Security
6. Style Kits
7. WP ERP
8. WP Project Manager
9. WP Travel
10. WP GDPR Compliance
WordPress Plugin Vulnerabilities
1. Under Construction, Coming Soon & Maintenance Mode

Vulnerability: Reflected Cross-Site Scripting
Patched in Version: 1.1.2
Severity: Medium – CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
2. Abandoned Cart Lite for WooCommerce

Vulnerability: CSRF Nonce Bypasses
Patched in Version: 5.8.6
Severity: Medium – CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N
3. Forminator

Vulnerability: CSRF Nonce Bypasses
Patched in Version: 1.14.8.1
Severity: Medium – CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N
4. Dokan

Vulnerability: CSRF Nonce Bypasses
Patched in Version: 3.2.1
Severity: Medium – CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N
5. Defender Security

Vulnerability: CSRF Nonce Bypasses
Patched in Version: 2.4.6.1
Severity: Medium – CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N
6. Style Kits

Vulnerability: CSRF Nonce Bypasses
Patched in Version: 1.8.1
Severity: Medium – CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N
7. WP ERP

Vulnerability: CSRF Nonce Bypasses
Patched in Version: 1.7.5
Severity: Medium – CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N
8. WP Project Manager

Vulnerability: CSRF Nonce Bypasses
Patched in Version: 2.4.10
Severity: Medium – CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N
9. WP Travel

Vulnerability: CSRF Nonce Bypasses
Patched in Version: 4.4.7
Severity: Medium – CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N
10. WP GDPR Compliance

Vulnerability: Unauthenticated Stored Cross-Site Scripting
Patched in Version: 1.5.6
Severity: Critical – CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Protect Your WordPress Website Today With Website Guardian
Join hundreds of businesses like yours who trust InterwebDEFENCE to protect their websites and livelihood. Using our proven website security analysis and best-in-class AI ‘Website Guardian” software, we are able to protect, monitor and backup your WordPress website.
Go ahead, keep the good guys In and the bad guys out – Click HERE to see our Website Guardian security plans NOW
PLUS
Find out about our unconditional ‘Double Protection’ Guarantee. This guarantee is better than risk free!
We’ll have you scanned, protected and secure in no time, giving you total peace of mind that your website is safe, leaving you to focus on your business success.