WordPress Vulnerability Report – June 14, 2023
DETAILS FROM DAN KNAUSS OF ITHEMES ON JUNE 14, 2023
Last Updated on June 15, 2023
This week, 56 total vulnerabilities emerged in public disclosure. They may affect over 4 million WordPress sites. There are 37 plugin vulnerabilities and three in themes that have security patches available, so run those updates!
Additionally, there are 16 plugin vulnerabilities with no patch available yet. If you are using any unpatched plugins or themes, check their vendors’ intentions and progress on a security release. If no patch is forthcoming or the vulnerable software has been closed and dropped from the official WordPress theme and plugin repositories, you should consider deactivation and removal in favor of alternative solutions.
Is Your WordPress Website Secure?
DID YOU KNOW – A staggering 83% of WordPress websites are not upgraded or updated, is your website one of these?
Hacks happen due to lack of website upkeep and protection, like updating WordPress or plugins, plus using weak passwords. Contrary to popular belief, web designers and website hosting companies are not responsible for the security of your WordPress website; you are. It’s like using your computer without Anti-virus!
WordPress Core Vulnerabilities
No new WordPress core vulnerabilities were disclosed this week.
WordPress Plugin Vulnerabilities – Patched
These are plugin vulnerabilities that have been fixed with the most recent updates, it’s recomended to update all plugins to the newest version to improve site safety.
Jump to section
- Metform Elementor Contact Form Builder
- Metform Elementor Contact Form Builder
- Metform Elementor Contact Form Builder
- Metform Elementor Contact Form Builder
- Metform Elementor Contact Form Builder
- Metform Elementor Contact Form Builder
- Metform Elementor Contact Form Builder
- Metform Elementor Contact Form Builder
- Metform Elementor Contact Form Builder
- Social Media Share Buttons & Social Sharing Icons
- WP Mail Logging
- FiboSearch – AJAX Search For WooCommerce
- Visual Composer
- VK Blocks
- Easy Digital Download
- Getwid – Gutenberg Blocks
- Getwid – Gutenberg Blocks
- PowerPress
- Abandoned Cart Lite For WooCommerce
- Directorist
- Directorist
- WP Mail Catcher
- Ultimate Product Catalogue
- B2BKing
- B2BKing
- WP EasyCart
- Online Booking & Scheduling Calendar For WordPress By Vcita
- CodeColorer
- GD Mail Queue
- Gravity Forms Google Sheet Connector
- Aajoda Testimonials
- Catalyst Connect Zoho CRM Client Portal
- Lana Email Logger
- WP-Members Membership
- WP Brutal AI
- WP Brutal AI
WordPress Plugin Vulnerabilities – Unpatched
These are plugin vulnerabilities that have NOT been fixed with the most recent updates, it’s recomended you deactivate or remove these plugins from your site until they are fixed.
Jump to section
- VK Blocks
- Online Booking & Scheduling Calendar For WordPress By Vcita
- Online Booking & Scheduling Calendar For WordPress By Vcita
- Online Booking & Scheduling Calendar For WordPress By Vcita
- WordPress Tables
- Contact Form Builder By Vcita
- Contact Form Builder By Vcita
- Responsive CSS EDITOR
- Contact Form And Calls To Action By Vcita
- Contact Form And Calls To Action By Vcita
- CRM And Lead Management By Vcita
- CRM And Lead Management By Vcita
- Page Builder By AZEXO
- Page Builder By AZEXO
- Page Builder By AZEXO
- Page Builder By AZEXO
WordPress Theme Vulnerabilities
Jump to section
These are vulnerabilities that have occoured in themes for wordpress. If there is a patch for the issue you should update the theme immediately, if there is no fix you should change your site to a different theme.
- Activello
- Newspaper X
- Brilliance
1 to 9 – Metform Elementor Contact Form Builder
Plugin slug – metform
Installations – 200,000+
Vulnerability – Authenticated (Subscriber+) Information Disclosure via ‘mf_payment_status’ shortcode
Severity – Medium
Patched in version – 3.3.2
CVE code – 2023-0692
Vulnerability – Unauthenticated CSV Injection
Severity – Medium
Patched in version – 3.3.1
CVE code – 2023-0721
Vulnerability – Authenticated (Contributor+) Stored Cross-Site Scripting via mf_first_name shortcode
Severity – Medium
Patched in version – 3.3.1
CVE code – 2023-0708
Vulnerability – Authenticated (Subscriber+) Information Disclosure via mf_last_name shortcode
Severity – Medium
Patched in version – 3.3.2
CVE code – 2023-0691
Vulnerability – Authenticated (Subscriber+) Information Disclosure via mf_thankyou shortcode
Severity – Medium
Patched in version – 3.3.1
CVE code – 2023-0709
Vulnerability – Authenticated (Subscriber+) Information Disclosure via ‘mf_transaction_id’ shortcode
Severity – Medium
Patched in version – 3.3.2
CVE code – 2023-0693
Vulnerability – Authenticated (Contributor+) Stored Cross-Site Scripting via mf shortcode
Severity – Medium
Patched in version – 3.3.1
CVE code – 2023-0695
Vulnerability – Authenticated (Subscriber+) Information Disclosure via mf shortcode
Severity – Medium
Patched in version – 3.3.2
CVE code – 2023-0694
The vulnerabilities have been patched, so you should update to version 3.3.2.
10 – Social Media Share Buttons & Social Sharing Icons
Plugin – Social Media Share Buttons & Social Sharing Icons
Plugin slug – ultimate-social-media-icons
Installations – 200,000+
Vulnerability – CAuthenticated Stored Cross-Site Scripting
Severity – Medium
Patched in version – 2.8.2
CVE code – 2023-1166
The vulnerability has been patched, so you should update to version 2.8.2.
11 – WP Mail Logging
Vulnerability – Unauthenticated Stored Cross-Site Scripting via Email
Severity – High
Patched in version – 1.11.1
CVE code – 2023-3081
The vulnerability has been patched, so you should update to version 1.11.1.
12 – FiboSearch – AJAX Search for WooCommerce
Plugin – FiboSearch – Ajax Search for WooCommerce
Plugin slug – ajax-search-for-woocommerce
Installations – 100,000+
Vulnerability – Authenticated (Admin+) Stored Cross-Site Scripting
Severity – Medium
Patched in version – 1.24.0
CVE code – 2023-2450
The vulnerability has been patched, so you should update to version 1.24.0
13 – Visual Composer
Plugin slug – visualcomposer
Installations – 70,000+
Vulnerability – Multiple Cross-Site Scripting (XSS)
Severity – Medium
Patched in version – 27.0
CVE code – 2020-36722
The vulnerability has been patched, so you should update to version 27.0
Vulnerability – Auth. Settings Update
Severity – Medium
Patched in version – 1.57.1.2
CVE code – 2023-0583
The vulnerability has been patched, so you should update to version 1.57.1.2
15 – Easy Digital Downloads
Plugin – Easy Digital Downloads – Simple eCommerce for Selling Digital Files
Plugin slug – easy-digital-downloads
Installations – 50,000+
Vulnerability – Cross-Site Request Forgery Leading To Plugin Upgrade
Severity – Medium
Patched in version – 3.1.2
The vulnerability has been patched, so you should update to version 3.1.2
16 to 17 – Getwid – Gutenberg Blocks
The vulnerabilites have been patched, so you should update to version 1.8.4
18 – PowerPress
Vulnerability – Authenticated Stored Cross-Site Scripting
Severity – Medium
Patched in version – 10.2.4
The vulnerability has been patched, so you should update to version 10.2.4
19 – Abandoned Cart Lite for WooCommerce
Plugin – Abandoned Cart Lite for WooCommerce
Plugin slug – woocommerce-abandoned-cart
Installations – 30,000+
Vulnerability – Authentication Bypass
Severity – Critical
Patched in version – 5.15.0
CVE code – 2023-2986
The vulnerability has been patched, so you should update to version 5.15.0
20 to 21 – Directorist
Plugin – Directorist – WordPress Business Directory Plugin with Classified Ads Listings
Plugin slug – directorist
Installations – 10,000+
The vulnerabilities have been patched, so you should update to version 7.5.5
22 – WP Mail Catcher
Vulnerability – Unauthenticated Stored Cross-Site Scripting via Email Subject
Severity – High
Patched in version – 2.1.3
CVE code – 2023-3080
The vulnerability has been patched, so you should update to version 2.1.3
23 – Ultimate Product Catalogue
Vulnerability – Authenticated SQL Injection
Severity – High
Patched in version – 5.2.6
CVE code – 2023-2711
The vulnerability has been patched, so you should update to version 5.2.6
24 to 25 – B2BKing
Plugin slug – b2bking-wholesale-for-woocommerce
Installations – 6,000+
The vulnerabilities have been patched, so you should update to version 4.6.20
26 – WP EasyCart
Vulnerability – Authenticated (Administrator+) SQL Injection via ‘orderby’
Severity – High
Patched in version – 5.4.11
CVE code – 2023-3023
The vulnerability has been patched, so you should update to version 5.4.11
27 – Online Booking & Scheduling Calendar for WordPress by vcita
Plugin – Online Booking & Scheduling Calendar for WordPress by vcita
Plugin slug – meeting-scheduler-by-vcita
Installations – 3,000+
Vulnerability – Missing Authorization to Account Logout
Severity – Medium
Patched in version – 4.3.0
CVE code – 2023-2415
The vulnerability has been patched, so you should update to version 4.3.0
Vulnerability – Admin+ Cross-Site Scripting
Severity – Medium
Patched in version – 0.10.1
CVE code – 2023-2795
The vulnerability has been patched, so you should update to version 0.10.1
Vulnerability – Unauthenticated Stored Cross-Site Scripting via Email
Severity – High
Patched in version – 4.0
CVE code – 2023-3122
The vulnerability has been patched, so you should update to version 4.0
30 – Gravity Forms Google Sheet Connector
Plugin – Gravity Forms Google Sheet Connector
Plugin slug – gsheetconnector-gravity-forms
Installations – 500+
Vulnerability – Cross Site Request Forgery (CSRF)
Severity – Medium
Patched in version – 1.3.5
CVE code – 2023-2326
The vulnerability has been patched, so you should update to version 1.3.5
31 – Aajoda Testimonials
Vulnerability – Admin+ Cross Site Scripting (XSS)
Severity – Medium
Patched in version – 2.2.2
CVE code – 2023-2178
The vulnerability has been patched, so you should update to version 2.2.2
32 – Catalyst Connect Zoho CRM Client Portal
Plugin – Catalyst Connect Zoho CRM Client Portal
Plugin slug – catalyst-connect-client-portal
Installations – 10+
Vulnerability – Reflected Cross Site Scripting (XSS)
Severity – High
Patched in version – 2.1.0
CVE code – 2023-0588
The vulnerability has been patched, so you should update to version 2.1.0
Vulnerability – Unauthenticated Stored Cross-Site Scripting via Email Subject
Severity – High
Patched in version – 1.1.0
CVE code – 2023-3166
The vulnerability has been patched, so you should update to version 1.1.0
34 – WP-Members Membership
Plugin – Members
Plugin slug – wp-members1
Vulnerability – Missing Authorization to Settings Update
Severity – Medium
Patched in version – 3.4.8
CVE code – 2023-2869
The vulnerability has been patched, so you should update to version 3.4.8
35 to 36 – WP Brutal AI
Plugin – WP Brutal AI
Plugin slug – wpbrutalai
The vulnerabilities have been patched, so you should update to version 2.0.1
Protect Your WordPress Website Today With Website Guardian
Join hundreds of businesses like yours who trust InterwebDEFENCE to protect their websites and livelihood. Using our proven website security analysis and best-in-class AI ‘Website Guardian” software, we are able to protect, monitor and backup your WordPress website.
Go ahead, keep the good guys In and the bad guys out – Click HERE to see our Website Guardian security plans NOW
PLUS
Find out about our unconditional ‘Double Protection’ Guarantee. This guarantee is better than risk free!
We’ll have you scanned, protected and secure in no time, giving you total peace of mind that your website is safe, leaving you to focus on your business success.
WordPress Plugin Vulnerabilities – Unpatched
The vulnerability has not been patched, it is strongly recomended you deactivate it and find an alternative
2 to 4 – Online Booking & Scheduling Calendar for WordPress by vcita
Plugin – Online Booking & Scheduling Calendar for WordPress by vcita
Plugin slug – meeting-scheduler-by-vcita
Installations – 3,000+
The vulnerabilities have not been patched, it is strongly recomended you deactivate it and find an alternative
The vulnerability has not been patched, it is strongly recomended you deactivate it and find an alternative
6 to 7 – Contact Form Builder by vcita
Plugin – Contact Form Builder by vcita
Plugin slug – contact-form-with-a-meeting-scheduler-by-vcita
Installations – 1,000+
The vulnerabilities have not been patched, it is strongly recomended you deactivate it and find an alternative
8 – Responsive CSS EDITOR
The vulnerability has not been patched, it is strongly recomended you deactivate it and find an alternative
9 to 10 – Contact Form and Calls To Action by vcita
Plugin – Contact Form and Calls To Action by vcita
Plugin slug – lead-capturing-call-to-actions-by-vcita
Installations – 400+
The vulnerabilities have not been patched, it is strongly recomended you deactivate it and find an alternative
11 to 12 – CRM and Lead Management by vcita
Plugin – CRM and Lead Management by vcita
Plugin slug – crm-customer-relationship-management-by-vcita
Installations – 200+
The vulnerabilities have not been patched, it is strongly recomended you deactivate it and find an alternative
13 to 16 – Page Builder by AZEXO
Plugin – Page Builder with Image Map by AZEXO
Plugin slug – page-builder-by-azexo
The vulnerabilities have not been patched, it is strongly recomended you deactivate it and find an alternative
This plugin is also closed and so should be uninstalled and removed from your website.
Protect Your WordPress Website Today With Website Guardian
Join hundreds of businesses like yours who trust InterwebDEFENCE to protect their websites and livelihood. Using our proven website security analysis and best-in-class AI ‘Website Guardian” software, we are able to protect, monitor and backup your WordPress website.
Go ahead, keep the good guys In and the bad guys out – Click HERE to see our Website Guardian security plans NOW
PLUS
Find out about our unconditional ‘Double Protection’ Guarantee. This guarantee is better than risk free!
We’ll have you scanned, protected and secure in no time, giving you total peace of mind that your website is safe, leaving you to focus on your business success.
WordPress Theme Vulnerabilities
Vulnerability – Unauthenticated Plugin Activation/Deactivation
Severity – Medium
Patched in version – 1.4.2
CVE code – 2020-36721
The vulnerability has been patched, so you should update to version 1.4.2
Vulnerability – Unauthenticated Plugin Activation/Deactivation
Severity – Medium
Patched in version – 1.3.2
CVE code – 2020-36721
The vulnerability has been patched, so you should update to version 1.3.2
Vulnerability – Unauthenticated Plugin Activation/Deactivation
Severity – Medium
Patched in version – 1.3.0
CVE code – 2020-36721
The vulnerability has been patched, so you should update to version 1.3.0
Protect Your WordPress Website Today With Website Guardian
Join hundreds of businesses like yours who trust InterwebDEFENCE to protect their websites and livelihood. Using our proven website security analysis and best-in-class AI ‘Website Guardian” software, we are able to protect, monitor and backup your WordPress website.
Go ahead, keep the good guys In and the bad guys out – Click HERE to see our Website Guardian security plans NOW
PLUS
Find out about our unconditional ‘Double Protection’ Guarantee. This guarantee is better than risk free!
We’ll have you scanned, protected and secure in no time, giving you total peace of mind that your website is safe, leaving you to focus on your business success.







