WordPress Vulnerability Report – June 14, 2023

by | Jun 15, 2023 | Security

DETAILS FROM DAN KNAUSS OF ITHEMES ON JUNE 14, 2023

original available here

Last Updated on June 15, 2023

 

This week, 56 total vulnerabilities emerged in public disclosure. They may affect over 4 million WordPress sites. There are 37 plugin vulnerabilities and three in themes that have security patches available, so run those updates!

Additionally, there are 16 plugin vulnerabilities with no patch available yet. If you are using any unpatched plugins or themes, check their vendors’ intentions and progress on a security release. If no patch is forthcoming or the vulnerable software has been closed and dropped from the official WordPress theme and plugin repositories, you should consider deactivation and removal in favor of alternative solutions.

Is Your WordPress Website Secure?

DID YOU KNOW – A staggering 83% of WordPress websites are not upgraded or updated, is your website one of these?

Hacks happen due to lack of website upkeep and protection, like updating WordPress or plugins, plus using weak passwords. Contrary to popular belief, web designers and website hosting companies are not responsible for the security of your WordPress website; you are. It’s like using your computer without Anti-virus!

WordPress Core Vulnerabilities

No new WordPress core vulnerabilities were disclosed this week. 

WordPress Plugin Vulnerabilities – Patched

These are plugin vulnerabilities that have been fixed with the most recent updates, it’s recomended to update all plugins to the newest version to improve site safety.

Jump to section

  1. Metform Elementor Contact Form Builder
  2. Metform Elementor Contact Form Builder
  3. Metform Elementor Contact Form Builder
  4. Metform Elementor Contact Form Builder
  5. Metform Elementor Contact Form Builder
  6. Metform Elementor Contact Form Builder
  7. Metform Elementor Contact Form Builder
  8. Metform Elementor Contact Form Builder
  9. Metform Elementor Contact Form Builder
  10. Social Media Share Buttons & Social Sharing Icons
  11. WP Mail Logging
  12. FiboSearch – AJAX Search For WooCommerce
  13. Visual Composer
  14. VK Blocks
  15. Easy Digital Download
  16. Getwid – Gutenberg Blocks
  17. Getwid – Gutenberg Blocks
  18. PowerPress
  19. Abandoned Cart Lite For WooCommerce
  20. Directorist
  21. Directorist
  22. WP Mail Catcher
  23. Ultimate Product Catalogue
  24. B2BKing
  25. B2BKing
  26. WP EasyCart
  27. Online Booking & Scheduling Calendar For WordPress By Vcita
  28. CodeColorer
  29. GD Mail Queue
  30. Gravity Forms Google Sheet Connector
  31. Aajoda Testimonials
  32. Catalyst Connect Zoho CRM Client Portal
  33. Lana Email Logger
  34. WP-Members Membership
  35. WP Brutal AI
  36. WP Brutal AI

WordPress Plugin Vulnerabilities – Unpatched

These are plugin vulnerabilities that have NOT been fixed with the most recent updates, it’s recomended you deactivate or remove these plugins from your site until they are fixed.

Jump to section

  1. VK Blocks
  2. Online Booking & Scheduling Calendar For WordPress By Vcita
  3. Online Booking & Scheduling Calendar For WordPress By Vcita
  4. Online Booking & Scheduling Calendar For WordPress By Vcita
  5. WordPress Tables
  6. Contact Form Builder By Vcita
  7. Contact Form Builder By Vcita
  8. Responsive CSS EDITOR
  9. Contact Form And Calls To Action By Vcita
  10. Contact Form And Calls To Action By Vcita
  11. CRM And Lead Management By Vcita
  12. CRM And Lead Management By Vcita
  13. Page Builder By AZEXO
  14. Page Builder By AZEXO
  15. Page Builder By AZEXO
  16. Page Builder By AZEXO

WordPress Theme Vulnerabilities

Jump to section

These are vulnerabilities that have occoured in themes for wordpress. If there is a patch for the issue you should update the theme immediately, if there is no fix you should change your site to a different theme.

  1. Activello
  2. Newspaper X
  3. Brilliance
WordPress Plugin Vulnerabilities – Patched

1 to 9 – Metform Elementor Contact Form Builder

Vulnerability – Authenticated (Subscriber+) Information Disclosure via ‘mf_payment_status’ shortcode

Severity – Medium 

Patched in version – 3.3.2

CVE code2023-0692

VulnerabilityUnauthenticated CSV Injection

Severity – Medium 

Patched in version – 3.3.1

CVE code2023-0721

Vulnerability – Authenticated (Contributor+) Stored Cross-Site Scripting via mf_first_name shortcode

Severity – Medium 

Patched in version – 3.3.1

CVE code2023-0708

Vulnerability – Authenticated (Subscriber+) Information Disclosure via mf_last_name shortcode

Severity – Medium 

Patched in version – 3.3.2

CVE code2023-0691

Vulnerability – Authenticated (Subscriber+) Information Disclosure via mf_thankyou shortcode

Severity – Medium 

Patched in version – 3.3.1

CVE code2023-0709

Vulnerability – Authenticated (Subscriber+) Information Disclosure via ‘mf_transaction_id’ shortcode

Severity – Medium 

Patched in version – 3.3.2

CVE code2023-0693

Vulnerability – Authenticated (Contributor+) Stored Cross-Site Scripting via mf shortcode

Severity – Medium 

Patched in version – 3.3.1

CVE code2023-0695

Vulnerability – Authenticated (Subscriber+) Information Disclosure via mf shortcode

Severity – Medium 

Patched in version – 3.3.2

CVE code2023-0694

The vulnerabilities have been patched, so you should update to version 3.3.2.

10 – Social Media Share Buttons & Social Sharing Icons

PluginSocial Media Share Buttons & Social Sharing Icons

Plugin slug – ultimate-social-media-icons

Installations – 200,000+

Vulnerability – CAuthenticated Stored Cross-Site Scripting

Severity – Medium 

Patched in version – 2.8.2

CVE code2023-1166

The vulnerability has been patched, so you should update to version 2.8.2.

11 – WP Mail Logging

PluginWP Mail Logging

Plugin slug – wp-mail-logging

Installations – 200,000+

Vulnerability – Unauthenticated Stored Cross-Site Scripting via Email

Severity – High 

Patched in version – 1.11.1

CVE code2023-3081

The vulnerability has been patched, so you should update to version 1.11.1.

12 – FiboSearch – AJAX Search for WooCommerce

PluginFiboSearch – Ajax Search for WooCommerce

Plugin slug – ajax-search-for-woocommerce

Installations – 100,000+

Vulnerability – Authenticated (Admin+) Stored Cross-Site Scripting

Severity – Medium

Patched in version – 1.24.0

CVE code2023-2450

The vulnerability has been patched, so you should update to version 1.24.0

13 – Visual Composer

Vulnerability – Multiple Cross-Site Scripting (XSS)

Severity – Medium

Patched in version – 27.0

CVE code2020-36722

The vulnerability has been patched, so you should update to version 27.0

14 – VK Blocks

PluginVK Blocks

Plugin slugvk-blocks

Installations – 70,000+

Vulnerability – Auth. Settings Update

Severity – Medium

Patched in version – 1.57.1.2

CVE code2023-0583

The vulnerability has been patched, so you should update to version 1.57.1.2

15 – Easy Digital Downloads

PluginEasy Digital Downloads – Simple eCommerce for Selling Digital Files

Plugin slug – easy-digital-downloads

Installations – 50,000+

Vulnerability – Cross-Site Request Forgery Leading To Plugin Upgrade

Severity – Medium

Patched in version – 3.1.2

The vulnerability has been patched, so you should update to version 3.1.2

16 to 17 – Getwid – Gutenberg Blocks

PluginGetwid – Gutenberg Blocks

Plugin slug – getwid

Installations – 50,000+

Vulnerability – Authenticated(Subscriber+) Server Side Request Forgery

Severity – Medium

Patched in version – 1.8.4

CVE code2023-1895

Vulnerability – Improper Authorization via get_remote_templates REST endpoint

Severity – Medium

Patched in version – 1.8.4

CVE code2023-1910

The vulnerabilites have been patched, so you should update to version 1.8.4

18 – PowerPress

PluginPowerPress Podcasting plugin by Blubrry

Plugin slug – powerpress

Installations – 40,000+

Vulnerability – Authenticated Stored Cross-Site Scripting

Severity – Medium

Patched in version – 10.2.4

The vulnerability has been patched, so you should update to version 10.2.4

19 – Abandoned Cart Lite for WooCommerce

PluginAbandoned Cart Lite for WooCommerce

Plugin slug – woocommerce-abandoned-cart

Installations – 30,000+

Vulnerability – Authentication Bypass

Severity – Critical

Patched in version – 5.15.0

CVE code2023-2986

The vulnerability has been patched, so you should update to version 5.15.0

20 to 21 – Directorist

PluginDirectorist – WordPress Business Directory Plugin with Classified Ads Listings

Plugin slug – directorist

Installations – 10,000+

Vulnerability – Authenticated Arbitrary Post Deletion

Severity – High

Patched in version – 7.5.5

CVE code2023-1889

Vulnerability – Authenticated Privilege Escalation

Severity – High

Patched in version – 7.5.5

CVE code2023-1888

The vulnerabilities have been patched, so you should update to version 7.5.5

22 – WP Mail Catcher

PluginMail logging – WP Mail Catcher

Plugin slug – wp-mail-catcher

Installations – 10,000+

Vulnerability – Unauthenticated Stored Cross-Site Scripting via Email Subject

Severity – High

Patched in version – 2.1.3

CVE code2023-3080

The vulnerability has been patched, so you should update to version 2.1.3

23 – Ultimate Product Catalogue

PluginUltimate Product Catalog

Plugin slug – ultimate-product-catalogue

Installations – 8,000+

Vulnerability – Authenticated SQL Injection

Severity – High

Patched in version – 5.2.6

CVE code2023-2711

The vulnerability has been patched, so you should update to version 5.2.6

24 to 25 – B2BKing

PluginB2BKing — Ultimate WooCommerce Wholesale and B2B Solution — Wholesale Order Form, Catalog Mode, Dynamic Pricing & More

Plugin slug – b2bking-wholesale-for-woocommerce

Installations – 6,000+

Vulnerability – Information Disclosure

Severity – Medium

Patched in version – 4.6.20

CVE code2023-3126

Vulnerability – Price Modification

Severity – Medium

Patched in version – 4.6.20

CVE code2023-3125

The vulnerabilities have been patched, so you should update to version 4.6.20

26 – WP EasyCart

PluginShopping Cart & eCommerce Store

Plugin slug – wp-easycart

Installations – 6,000+

Vulnerability – Authenticated (Administrator+) SQL Injection via ‘orderby’

Severity – High

Patched in version – 5.4.11

CVE code2023-3023

The vulnerability has been patched, so you should update to version 5.4.11

27 – Online Booking & Scheduling Calendar for WordPress by vcita

PluginOnline Booking & Scheduling Calendar for WordPress by vcita

Plugin slug – meeting-scheduler-by-vcita

Installations – 3,000+

Vulnerability – Missing Authorization to Account Logout

Severity – Medium

Patched in version – 4.3.0

CVE code2023-2415

The vulnerability has been patched, so you should update to version 4.3.0

28 – CodeColorer

PluginCodeColorer

Plugin slug – codecolorer

Installations – 2,000+

Vulnerability – Admin+ Cross-Site Scripting

Severity – Medium

Patched in version – 0.10.1

CVE code2023-2795

The vulnerability has been patched, so you should update to version 0.10.1

29 – GD Mail Queue

PluginGD Mail Queue

Plugin slug – gd-mail-queue

Installations – 700+

Vulnerability – Unauthenticated Stored Cross-Site Scripting via Email

Severity – High

Patched in version – 4.0

CVE code2023-3122

The vulnerability has been patched, so you should update to version 4.0

30 – Gravity Forms Google Sheet Connector

PluginGravity Forms Google Sheet Connector

Plugin slug – gsheetconnector-gravity-forms

Installations – 500+

Vulnerability – Cross Site Request Forgery (CSRF)

Severity – Medium

Patched in version – 1.3.5

CVE code2023-2326

The vulnerability has been patched, so you should update to version 1.3.5

31 – Aajoda Testimonials

PluginAajoda Testimonials

Plugin slug – aajoda-testimonials

Installations – 50+

Vulnerability – Admin+ Cross Site Scripting (XSS)

Severity – Medium

Patched in version – 2.2.2

CVE code2023-2178

The vulnerability has been patched, so you should update to version 2.2.2

32 – Catalyst Connect Zoho CRM Client Portal

PluginCatalyst Connect Zoho CRM Client Portal

Plugin slug – catalyst-connect-client-portal

Installations – 10+

Vulnerability – Reflected Cross Site Scripting (XSS)

Severity – High

Patched in version – 2.1.0

CVE code2023-0588

The vulnerability has been patched, so you should update to version 2.1.0

33 – Lana Email Logger

PluginLana Email Logger

Plugin slug – lana-email-logger

Vulnerability – Unauthenticated Stored Cross-Site Scripting via Email Subject

Severity – High

Patched in version – 1.1.0

CVE code2023-3166

The vulnerability has been patched, so you should update to version 1.1.0

34 – WP-Members Membership

PluginMembers

Plugin slug – wp-members1

Vulnerability – Missing Authorization to Settings Update

Severity – Medium

Patched in version – 3.4.8

CVE code2023-2869

The vulnerability has been patched, so you should update to version 3.4.8

35 to 36 – WP Brutal AI

PluginWP Brutal AI

Plugin slug – wpbrutalai

Vulnerability – Admin+ Cross Site Scripting (XSS)

Severity – Medium

Patched in version – 2.0.1

CVE code2023-2605

Vulnerability – Admin+ SQL Injection

Severity – High

Patched in version – 2.0.0

CVE code2023-2601

The vulnerabilities have been patched, so you should update to version 2.0.1

Protect Your WordPress Website Today With Website Guardian

Join hundreds of businesses like yours who trust InterwebDEFENCE to protect their websites and livelihood. Using our proven website security analysis and best-in-class AI ‘Website Guardian” software, we are able to protect, monitor and backup your WordPress website.

Go ahead, keep the good guys In and the bad guys out – Click HERE to see our Website Guardian security plans NOW
PLUS
Find out about our unconditional ‘Double Protection’ Guarantee. This guarantee is better than risk free!

We’ll have you scanned, protected and secure in no time, giving you total peace of mind that your website is safe, leaving you to focus on your business success.

WordPress Plugin Vulnerabilities – Unpatched

1 – VK Blocks

PluginVK Blocks

Plugin slug – vk-blocks

Installations – 70,000+

Vulnerability – Auth. Settings Update

Severity – Medium

CVE code2023-0584

The vulnerability has not been patched, it is strongly recomended you deactivate it and find an alternative

2 to 4 – Online Booking & Scheduling Calendar for WordPress by vcita

PluginOnline Booking & Scheduling Calendar for WordPress by vcita

Plugin slug – meeting-scheduler-by-vcita

Installations – 3,000+

Vulnerability – Unauth. Stored Cross-Site Scripting (XSS)

Severity – High

CVE code2023-2298

Vulnerability – Missing Authorization on REST-API

Severity – Medium

CVE code2023-2299

Vulnerability – Missing Authorization to Settings Update and Media Upload

Severity – Medium

CVE code2023-2414

The vulnerabilities have not been patched, it is strongly recomended you deactivate it and find an alternative

5 – WordPress Tables

PluginWordPress Tables

Plugin slug – wptables

Installations – 2,000+

Vulnerability – Cross Site Scripting (XSS)

Severity – High

CVE code2023-25453

The vulnerability has not been patched, it is strongly recomended you deactivate it and find an alternative

6 to 7 – Contact Form Builder by vcita

PluginContact Form Builder by vcita

Plugin slug – contact-form-with-a-meeting-scheduler-by-vcita

Installations – 1,000+

Vulnerability – Cross-Site Request Forgery to Stored Cross-Site Scripting

Severity – Medium

CVE code2023-2301

Vulnerability – Auth. Stored Cross Site Scripting (XSS)

Severity – Medium

CVE code2023-2300

The vulnerabilities have not been patched, it is strongly recomended you deactivate it and find an alternative

8 – Responsive CSS EDITOR

PluginResponsive CSS EDITOR

Plugin slug – responsive-css-editor

Installations – 600+

Vulnerability – Admin+ SQL Injection

Severity – High

CVE code2023-2482

The vulnerability has not been patched, it is strongly recomended you deactivate it and find an alternative

9 to 10 – Contact Form and Calls To Action by vcita

PluginContact Form and Calls To Action by vcita

Plugin slug – lead-capturing-call-to-actions-by-vcita

Installations – 400+

Vulnerability – Auth. Stored Cross Site Scripting (XSS)

Severity – Medium

CVE code2023-2302

Vulnerability – Cross-Site Request Forgery to Stored Cross-Site Scripting

Severity – Medium

CVE code2023-2303

The vulnerabilities have not been patched, it is strongly recomended you deactivate it and find an alternative

11 to 12 – CRM and Lead Management by vcita

PluginCRM and Lead Management by vcita

Plugin slug – crm-customer-relationship-management-by-vcita

Installations – 200+

Vulnerability – Auth. Stored Cross Site Scripting (XSS)

Severity – Medium

CVE code2023-2302

Vulnerability – Cross-Site Request Forgery to Stored Cross-Site Scripting

Severity – Medium

CVE code2023-2405

The vulnerabilities have not been patched, it is strongly recomended you deactivate it and find an alternative

13 to 16 – Page Builder by AZEXO

PluginPage Builder with Image Map by AZEXO

Plugin slug – page-builder-by-azexo

Vulnerability – Cross Site Request Forgery (CSRF)

Severity – Medium

CVE code2023-3052

Vulnerability – Auth. Stored Cross-Site Scripting (XSS)

Severity – Medium

CVE code2023-3051

Vulnerability – Missing Authorization to Post Creation

Severity – Medium

CVE code2023-3053

Vulnerability – Cross-Site Request Forgery to Stored Cross-Site Scripting (XSS)

Severity – Medium

CVE code2023-3055

Vulnerability – Cross-Site Request Forgery to Stored Cross-Site Scripting (XSS)

Severity – Medium

CVE code2023-3055

The vulnerabilities have not been patched, it is strongly recomended you deactivate it and find an alternative

This plugin is also closed and so should be uninstalled and removed from your website.

Protect Your WordPress Website Today With Website Guardian

Join hundreds of businesses like yours who trust InterwebDEFENCE to protect their websites and livelihood. Using our proven website security analysis and best-in-class AI ‘Website Guardian” software, we are able to protect, monitor and backup your WordPress website.

Go ahead, keep the good guys In and the bad guys out – Click HERE to see our Website Guardian security plans NOW
PLUS
Find out about our unconditional ‘Double Protection’ Guarantee. This guarantee is better than risk free!

We’ll have you scanned, protected and secure in no time, giving you total peace of mind that your website is safe, leaving you to focus on your business success.

WordPress Theme Vulnerabilities

1 – Activello

PluginActivello

Plugin slug – activello

Downloads – 704,000+

Vulnerability – Unauthenticated Plugin Activation/Deactivation

Severity – Medium

Patched in version – 1.4.2

CVE code2020-36721

The vulnerability has been patched, so you should update to version 1.4.2

2 – Newspaper X

PluginNewspaper X

Plugin slug – newspaper-x

Downloads – 171,600+

Vulnerability – Unauthenticated Plugin Activation/Deactivation

Severity – Medium

Patched in version – 1.3.2

CVE code2020-36721

The vulnerability has been patched, so you should update to version 1.3.2

3 – Brilliance

PluginBrilliance

Plugin slug – brilliance

Downloads – 139,800+

Vulnerability – Unauthenticated Plugin Activation/Deactivation

Severity – Medium

Patched in version – 1.3.0

CVE code2020-36721

The vulnerability has been patched, so you should update to version 1.3.0

Protect Your WordPress Website Today With Website Guardian

Join hundreds of businesses like yours who trust InterwebDEFENCE to protect their websites and livelihood. Using our proven website security analysis and best-in-class AI ‘Website Guardian” software, we are able to protect, monitor and backup your WordPress website.

Go ahead, keep the good guys In and the bad guys out – Click HERE to see our Website Guardian security plans NOW
PLUS
Find out about our unconditional ‘Double Protection’ Guarantee. This guarantee is better than risk free!

We’ll have you scanned, protected and secure in no time, giving you total peace of mind that your website is safe, leaving you to focus on your business success.

Click to access the login or register cheese