WordPress Vulnerability Roundup: May 2020, Part 2
Written by Michael Moore of iThemes on May 27, 2020
Last Updated on August 17, 2020
New WordPress plugin and theme vulnerabilities were disclosed during the second half of May, so we want to keep you aware. In this post, we cover recent WordPress plugin, theme and core vulnerabilities and what to do if you are running one of the vulnerable plugins or themes on your website.
New WordPress plugin and theme vulnerabilities were disclosed during the second half of April, so we want to keep you aware. In this post, we cover recent WordPress plugin, theme and core vulnerabilities and what to do if you are running one of the vulnerable plugins or themes on your website.
Each vulnerability will have a threat rating of Low, Medium, High, or Critical.
The WordPress Vulnerability Roundup is divided into three different categories: WordPress core, WordPress plugins, and WordPress themes.
Is Your WordPress Website Secure?
DID YOU KNOW – A staggering 83% of WordPress websites are not upgraded or updated, is your website one of these?
Hacks happen due to lack of website upkeep and protection, like updating WordPress or plugins, plus using weak passwords. Contrary to popular belief, web designers and website hosting companies are not responsible for the security of your WordPress website; you are. It’s like using your computer without Anti-virus!
WordPress Core Vulnerabilities
No new WordPress core vulnerabilities have been disclosed this month.
WordPress Theme Vulnerabilities
WordPress Plugin Vulnerabilities
1. Site Kit by Google – Critical
2. Easy Testimonials – Critical
3. WP Product Review – High
4. Login/Signup Popup – Critical
5. Photo Gallery by 10Web – Critical
6. Team Members – Critical
7. Visual Composer Website Builder – High
8. WordPress Infinite Scroll – Critical
9. WP Frontend Profile – Low
10. Paid Memberships Pro – Medium
11. ThirstyAffiliates Affiliate Link Manager – Medium
12. Official MailerLite Sign Up Forms – Critical
13. Add-on SweetAlert Contact Form 7 – Low
14. Form Maker by 10Web – High
WordPress Plugin Vulnerabilities
Several new WordPress plugin vulnerabilities have been discovered this month so far. Make sure to follow the suggested action below to update the plugin or completely uninstall it.
1. Site Kit by Google – Critical

Site Kit by Google versions below 1.8.0 have a Privilege Escalation vulnerability that will allow an an attacker to become a Search Console owner.
The vulnerability is patched, and you should update to version 1.8.0.
2. Easy Testimonials – Critical

Easy Testimonials versions below 3.6 have an Authenticated Stored Cross-Site Scripting vulnerability.
The vulnerability is patched, and you should update to version 3.6.
3. WP Product Review – High

WP Product Review versions below 3.7.6 have an Unauthenticated Stored Cross-Site Scripting vulnerability.
The vulnerability is patched, and you should update to version 3.7.6.
4. Login/Signup Popup – Critical

Login/Signup Popup versions below 1.5 have an Authenticated Stored Cross-Site Scripting vulnerability.
The vulnerability is patched, and you should update to version 1.5.
5. Photo Gallery by 10Web – Critical

Photo Gallery by 10Web versions below 1.5.55 have an Unauthenticated SQL Injection vulnerability.
The vulnerability is patched, and you should update to version 1.5.55.
6. Team Members – Critical

Team Members versions below 5.0.4 have an Authenticated Stored Cross-Site Scripting vulnerability.
The vulnerability is patched, and you should update to version 5.0.4.
7. Visual Composer Website Builder – High

Visual Composer Website Builder versions below 27.0 have multiple Authenticated Cross-Site Scripting vulnerabilities.
The vulnerability is patched, and you should update to version 27.0.
8. WordPress Infinite Scroll – Critical

WordPress Infinite Scroll versions below 5.3.2 have an Authenticated SQL Injection vulnerability.
The vulnerability is patched, and you should update to version 5.3.2.
9. WP Frontend Profile – Low

WP Frontend Profile versions below 1.2.2 have a Cross Site Request Forgery vulnerability.
The vulnerability is patched, and you should update to version 1.2.2.
10. Paid Memberships Pro – Medium

Paid Memberships Pro versions below 2.3.3 have an Authenticated SQL Injection vulnerability.
The vulnerability is patched, and you should update to version 2.3.3.
11. ThirstyAffiliates Affiliate Link Manager – Medium

ThirstyAffiliates Affiliate Link Manager versions below 3.9.3 have an Authenticated Stored Criss-Site Scripting vulnerability.
The vulnerability is patched, and you should update to version 3.9.3.
12. Official MailerLite Sign Up Forms – Critical

Official MailerLite Sign Up Forms versions below 1.4.5 have Multiple CSRF vulnerabilities.
The vulnerability is patched, and you should update to version 1.4.5.
13. Add-on SweetAlert Contact Form 7 – Low

Add-on SweetAlert Contact Form 7 versions below 1.0.8 have an Authenticated Stored Cross-Site Scripting vulnerability.
The vulnerability is patched, and you should update to version 1.0.8.
14. Form Maker by 10Web – High

Form Maker by 10Web versions below have 1.13.36 an Authenticated SQL Injection vulnerability.
The vulnerability is patched, and you should update to version 1.13.36.
How to Be Proactive About WordPress Theme & Plugin Vulnerabilities
Running outdated software is the number one reason WordPress sites are hacked. It is crucial to the security of your WordPress site that you have an update routine. You should be logging into your sites at least once a week to perform updates.
Automatic Updates Can Help
Automatic updates are a great choice for WordPress websites that don’t change very often. Lack of attention often leaves these sites neglected and vulnerable to attacks. Even with recommended security settings, running vulnerable software on your site can give an attacker an entry point into your site.
Protect Your WordPress Website Today With Website Guardian
Join hundreds of businesses like yours who trust InterwebDEFENCE to protect their websites and livelihood. Using our proven website security analysis and best-in-class AI ‘Website Guardian” software, we are able to protect, monitor and backup your WordPress website.
Go ahead, keep the good guys In and the bad guys out – Click HERE to see our Website Guardian security plans NOW
PLUS
Find out about our unconditional ‘Double Protection’ Guarantee. This guarantee is better than risk free!
We’ll have you scanned, protected and secure in no time, giving you total peace of mind that your website is safe, leaving you to focus on your business success.