WordPress Vulnerability Report – July 5, 2023
DETAILS FROM DAN KNAUSS OF ITHEMES ON July 5, 2023
Last Updated on July 5, 2023
This week, 70 total vulnerabilities emerged in public disclosure. They may affect over one million WordPress sites. There are 36 plugin vulnerabilities that have security patches available, so run those updates!
Additionally, there are 33 plugin vulnerabilities and one theme vulnerability with no patch available yet. If you are using any unpatched plugins or themes, check their vendors’ intentions and progress on a security release. If no patch is forthcoming or the vulnerable software has been closed and dropped from the official WordPress theme and plugin repositories, you should consider deactivation and removal in favor of alternative solutions.
Is Your WordPress Website Secure?
DID YOU KNOW – A staggering 83% of WordPress websites are not upgraded or updated, is your website one of these?
Hacks happen due to lack of website upkeep and protection, like updating WordPress or plugins, plus using weak passwords. Contrary to popular belief, web designers and website hosting companies are not responsible for the security of your WordPress website; you are. It’s like using your computer without Anti-virus!
WordPress Core Vulnerabilities
No new WordPress core vulnerabilities were disclosed this week.
WordPress Plugin Vulnerabilities – Patched
These are plugin vulnerabilities that have been fixed with the most recent updates, it’s recomended to update all plugins to the newest version to improve site safety.
Jump to section
- Formidable Forms
- Chaty
- Ultimate Member
- EmbedPress
- Login/Signup Popup
- Social Login and Register
- Subscribe2
- Subscribe2
- Contact Form & Lead Form Elementor Builder
- Supsystic Popup
- WPGraphQL
- WP ERP
- Active Directory Integration / LDAP Integration
- MStore API
- Poll Maker
- Th Product Compare
- Waitlist WooCommerce ( Back in stock notifier )
- Short URL
- Short URL
- WP Inventory Manager
- Kanban Boards for WordPress
- Request a Quote
- LiquidPoll
- Front User Submit / Front Editor
- TrustProfile
- Knowledge Center
- Catalyst Connect Zoho CRM Client Portal
- ARMember
- AutomateWoo
- AutomateWoo
- Houzez CRM
- Salon Booking System
- LearnDash LMS
- WooCommerce Order Barcodes
- WooCommerce Ship to Multiple Addresses
- WP Post Author
WordPress Plugin Vulnerabilities – Unpatched
These are plugin vulnerabilities that have NOT been fixed with the most recent updates, it’s recomended you deactivate or remove these plugins from your site until they are fixed.
Jump to section
- Side Cart Woocommerce
- Enhanced Text Widget
- Duplicate Post Page Menu & Custom Post Type
- Zippy
- Form Builder
- Enable SVG, WebP & ICO Upload
- SW Product Bundles
- ApplyOnline – Application Form Builder and Manager
- Email download link
- Post Hit Counter
- Layer Slider
- WooCommerce Google Sheet Connector
- WCP OpenWeather
- WP Abstracts
- WP Abstracts
- Post to CSV by BestWebSoft
- Caldera Forms Google Sheets Connector
- Autochat
- Quiz Expert
- AN_GradeBook
- Booked
- Editorial Calendar
- Editorial Calendar
- File Manager Advanced Shortcode
- Image Map Pro Lite
- Image Map Pro
- Noo Timetable
- Noo Timetable
- SP Project & Document Manager
- SP Project & Document Manager
- SP Project & Document Manager
- Web3
- WPJobBoard
WordPress Theme Vulnerabilities
Jump to section
These are vulnerabilities that have occoured in themes for wordpress. If there is a patch for the issue you should update the theme immediately, if there is no fix you should change your site to a different theme.
WordPress Plugin Vulnerabilities – Patched

1 - Formidable Forms – Contact Form, Survey, Quiz, Calculator & Custom Form Builder
Plugin -
Formidable Forms – Contact Form, Survey, Quiz, Calculator & Custom Form Builder
Plugin Slug -
formidable
Installations -
300,000+
Vulnerability -
Auth. Remote Code Execution (RCE)
Patched In Version -
6.3.1
Severity -
Critical
CVE Code -

2 - Floating Chat Widget: Contact Chat Icons, Telegram Chat, Line Messenger, WeChat, Email, SMS, Call Button – Chaty
Plugin -
Plugin Slug -
chaty
Installations -
200,000+
Vulnerability -
Authenticated Stored Cross Site Scripting (XSS)
Patched In Version -
3.1.2
Severity -
Medium
CVE Code -

3 - Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin
Plugin -
Plugin Slug -
ultimate-member
Installations -
200,000+
Vulnerability -
Unauthenticated Privilege Escalation
Patched In Version -
2.6.7
Severity -
Critical
CVE Code -

4 - EmbedPress – Embed PDF, YouTube, Google Docs, Vimeo, Wistia Videos, Audios, Maps & Any Documents in Gutenberg & Elementor
Plugin -
Plugin Slug -
embedpress
Installations -
80,000+
Vulnerability -
Sensitive Data Exposure
Patched In Version -
3.8.0
Severity -
Medium
CVE Code -

5 - Login/Signup Popup ( Inline Form + Woocommerce )
Plugin -
Login/Signup Popup ( Inline Form + Woocommerce )
Plugin Slug -
easy-login-woocommerce
Installations -
30,000+
Vulnerability -
Cross Site Request Forgery (CSRF)
Patched In Version -
2.4
Severity -
Medium

6 - WordPress Social Login and Register (Discord, Google, Twitter, LinkedIn)
Plugin -
WordPress Social Login and Register (Discord, Google, Twitter, LinkedIn)
Plugin Slug -
miniorange-login-openid
Installations -
30,000+
Vulnerability -
Authentication Broken Authentication
Patched In Version -
7.6.5
Severity -
Critical
CVE Code -

7 - Subscribe2 – Form, Email Subscribers & Newsletters
Plugin -
Subscribe2 – Form, Email Subscribers & Newsletters
Plugin Slug -
subscribe2
Installations -
30,000+
Vulnerability -
Broken Access Control
Patched In Version -
10.41
Severity -
Medium
CVE Code -

8 - Subscribe2 – Form, Email Subscribers & Newsletters
Plugin -
Subscribe2 – Form, Email Subscribers & Newsletters
Plugin Slug -
subscribe2
Installations -
30,000+
Vulnerability -
Cross Site Request Forgery (CSRF)
Patched In Version -
10.41
Severity -
Medium
CVE Code -

9 - Responsive Contact Form Builder & Lead Generation Plugin
Plugin -
Responsive Contact Form Builder & Lead Generation Plugin
Plugin Slug -
lead-form-builder
Installations -
20,000+
Vulnerability -
Broken Access Control
Patched In Version -
1.8.5
Severity -
Medium
CVE Code -

10 - Popup by Supsystic
Plugin -
Plugin Slug -
popup-by-supsystic
Installations -
20,000+
Vulnerability -
Prototype Pollution
Patched In Version -
1.10.19
Severity -
High
CVE Code -

11 - WPGraphQL
Plugin -
Plugin Slug -
wp-graphql
Installations -
20,000+
Vulnerability -
Server Side Request Forgery (SSRF)
Patched In Version -
1.14.6
Severity -
Medium
CVE Code -

12 - WP ERP | Complete HR solution with recruitment & job listings | WooCommerce CRM & Accounting
Plugin -
WP ERP | Complete HR solution with recruitment & job listings | WooCommerce CRM & Accounting
Plugin Slug -
erp
Installations -
9,000+
Vulnerability -
Reflected Cross Site Scripting (XSS)
Patched In Version -
1.12.4
Severity -
High
CVE Code -

13 - Active Directory Integration / LDAP Integration
Plugin -
Active Directory Integration / LDAP Integration
Plugin Slug -
ldap-login-for-intranet-sites
Installations -
5,000+
Vulnerability -
Unauthenticated LDAP Injection
Patched In Version -
4.1.6
Severity -
High
CVE Code -

14 - MStore API
Plugin -
Plugin Slug -
mstore-api
Installations -
5,000+
Vulnerability -
Unauth. SQL Injection
Patched In Version -
4.0.2
Severity -
Critical
CVE Code -

15 - Poll Maker – Best WordPress Poll Plugin
Plugin -
Poll Maker – Best WordPress Poll Plugin
Plugin Slug -
poll-maker
Installations -
5,000+
Vulnerability -
Server Side Request Forgery (SSRF)
Patched In Version -
4.6.3
Severity -
Medium
CVE Code -

16 - Product Compare for WooCommerce
Plugin -
Product Compare for WooCommerce
Plugin Slug -
th-product-compare
Installations -
5,000+
Vulnerability -
Broken Access Control
Patched In Version -
1.2.6
Severity -
Medium
CVE Code -

17 - Waitlist Woocommerce ( Back in stock notifier )
Plugin -
Waitlist Woocommerce ( Back in stock notifier )
Plugin Slug -
waitlist-woocommerce
Installations -
5,000+
Vulnerability -
Cross Site Request Forgery (CSRF)
Patched In Version -
2.5.3
Severity -
Medium


19 - Short URL
Plugin -
Plugin Slug -
shorten-url
Installations -
2,000+
Vulnerability -
SQL Injection
Patched In Version -
1.6.5
Severity -
High
CVE Code -

20 - WP Inventory Manager
Plugin -
Plugin Slug -
wp-inventory-manager
Installations -
2,000+
Vulnerability -
Inventory Items Deletion via Cross Site Request Forgery (CSRF)
Patched In Version -
2.1.0.14
Severity -
Medium
CVE Code -

21 - Kanban Boards for WordPress
Plugin -
Plugin Slug -
kanban
Installations -
1,000+
Vulnerability -
Auth. Stored Cross Site Scripting (XSS)
Patched In Version -
2.5.21
Severity -
Medium
CVE Code -

22 - Request a Quote
Plugin -
Plugin Slug -
request-a-quote
Installations -
1,000+
Vulnerability -
Cross Site Request Forgery (CSRF)
Patched In Version -
2.3.11
Severity -
Medium

23 - LiquidPoll – Advanced Polls for Creators and Brands
Plugin -
LiquidPoll – Advanced Polls for Creators and Brands
Plugin Slug -
wp-poll
Installations -
1,000+
Vulnerability -
Broken Access Control
Patched In Version -
3.3.69
Severity -
Medium
CVE Code -

24 - Guest posting / Frontend Posting wordpress plugin – WP Front User Submit / Front Editor
Plugin -
Guest posting / Frontend Posting wordpress plugin – WP Front User Submit / Front Editor
Plugin Slug -
front-editor
Installations -
200+
Vulnerability -
Auth. Stored Cross Site Scripting (XSS)
Patched In Version -
3.8.5
Severity -
Medium
25 - TrustProfile and reviews for WordPress
Plugin -
TrustProfile and reviews for WordPress
Plugin Slug -
trustprofile
Installations -
200+
Vulnerability -
Cross Site Request Forgery (CSRF)
Patched In Version -
3.25
Severity -
Medium

26 - Easy Accordion FAQ and Knowledge Base Software for WordPress
Plugin -
Easy Accordion FAQ and Knowledge Base Software for WordPress
Plugin Slug -
knowledge-center
Installations -
20+
Vulnerability -
Authenticated Cross Site Scripting (XSS)
Patched In Version -
2.8
Severity -
Medium

27 - Catalyst Connect Zoho CRM Client Portal
Plugin -
Catalyst Connect Zoho CRM Client Portal
Plugin Slug -
catalyst-connect-client-portal
Installations -
10+
Vulnerability -
Auth. Stored Cross Site Scripting (XSS)
Patched In Version -
2.1.0
Severity -
Medium
CVE Code -
28 - ARMember
Plugin -
Plugin Slug -
armember-membership
Vulnerability -
Stored Cross Site Scripting (XSS) on Common Messages Settings
Patched In Version -
4.0.5
Severity -
Medium
CVE Code -
29 - AutomateWoo
Plugin -
Plugin Slug -
automatewoo
Vulnerability -
Cross Site Request Forgery (CSRF)
Patched In Version -
5.7.6
Severity -
Medium
CVE Code -
30 - AutomateWoo
Plugin -
Plugin Slug -
automatewoo
Vulnerability -
Broken Access Control
Patched In Version -
5.7.6
Severity -
Medium
CVE Code -
31 - Houzez CRM
Plugin -
Plugin Slug -
houzez-crm
Vulnerability -
SQL Injection
Patched In Version -
1.3.5
Severity -
Critical
CVE Code -
32 - Salon booking system
Plugin -
Plugin Slug -
salon-booking-system
Vulnerability -
Cross Site Request Forgery (CSRF)
Patched In Version -
8.4.8
Severity -
Medium
CVE Code -
33 - LearnDash LMS
Plugin -
Plugin Slug -
sfwd-lms
Vulnerability -
Authenticated IDOR to Account Takeover
Patched In Version -
4.6.0.1
Severity -
High
CVE Code -
34 - WooCommerce Order Barcodes
Plugin -
Plugin Slug -
woocommerce-order-barcodes
Vulnerability -
Cross Site Request Forgery (CSRF)
Patched In Version -
1.6.5
Severity -
Medium
CVE Code -
35 - WooCommerce Ship to Multiple Addresses
Plugin -
WooCommerce Ship to Multiple Addresses
Plugin Slug -
woocommerce-shipping-multiple-addresses
Vulnerability -
Cross Site Request Forgery (CSRF)
Patched In Version -
3.8.6
Severity -
Medium
CVE Code -
36 - WP Post Author
Plugin -
Plugin Slug -
wp-post-author
Vulnerability -
Privilege Escalation
Patched In Version -
3.3.0
Severity -
Critical
Protect Your WordPress Website Today With Website Guardian
Join hundreds of businesses like yours who trust InterwebDEFENCE to protect their websites and livelihood. Using our proven website security analysis and best-in-class AI ‘Website Guardian” software, we are able to protect, monitor and backup your WordPress website.
Go ahead, keep the good guys In and the bad guys out – Click HERE to see our Website Guardian security plans NOW
PLUS
Find out about our unconditional ‘Double Protection’ Guarantee. This guarantee is better than risk free!
We’ll have you scanned, protected and secure in no time, giving you total peace of mind that your website is safe, leaving you to focus on your business success.
WordPress Plugin Vulnerabilities – Unpatched

1 - Side Cart Woocommerce (Ajax)
Plugin -
Plugin Slug -
side-cart-woocommerce
Installations -
60,000+
Vulnerability -
Cross Site Scripting (XSS)
Patched In Version -
No Fix
Severity -
Medium
CVE Code -

2 - Enhanced Text Widget
Plugin -
Plugin Slug -
enhanced-text-widget
Installations -
50,000+
Vulnerability -
Broken Access Control
Patched In Version -
No Fix
Severity -
Medium
CVE Code -

3 - Duplicate Post Page Menu & Custom Post Type
Plugin -
Duplicate Post Page Menu & Custom Post Type
Plugin Slug -
duplicate-post-page-menu-custom-post-type
Installations -
30,000+
Vulnerability -
Broken Access Control
Patched In Version -
No Fix
Severity -
Medium
CVE Code -

4 - Zippy
Plugin -
Plugin Slug -
zippy
Installations -
10,000+
Vulnerability -
PHP Object Injection
Patched In Version -
No Fix
Severity -
Medium
CVE Code -

5 - Form Builder | Create Responsive Contact Forms
Plugin -
Form Builder | Create Responsive Contact Forms
Plugin Slug -
contact-form-add
Installations -
6,000+
Vulnerability -
CSV Injection
Patched In Version -
No Fix
Severity -
Medium
CVE Code -

6 - Enable SVG, WebP & ICO Upload
Plugin -
Plugin Slug -
enable-svg-webp-ico-upload
Installations -
6,000+
Vulnerability -
Auth. Stored Cross Site Scripting (XSS)
Patched In Version -
No Fix
Severity -
Medium
CVE Code -

7 - SW Product Bundles
Plugin -
Plugin Slug -
sw-product-bundles
Installations -
6,000+
Vulnerability -
Broken Access Control
Patched In Version -
No Fix
Severity -
Medium
CVE Code -

8 - ApplyOnline – Application Form Builder and Manager
Plugin -
ApplyOnline – Application Form Builder and Manager
Plugin Slug -
apply-online
Installations -
5,000+
Vulnerability -
Cross Site Scripting (XSS)
Patched In Version -
No Fix
Severity -
Medium
CVE Code -

9 - Email download link
Plugin -
Plugin Slug -
email-download-link
Installations -
5,000+
Vulnerability -
Sensitive Data Exposure
Patched In Version -
No Fix
Severity -
Medium
CVE Code -

10 - Post Hit Counter
Plugin -
Plugin Slug -
post-hit-counter
Installations -
3,000+
Vulnerability -
Broken Access Control
Patched In Version -
No Fix
Severity -
Medium
CVE Code -

11 - Layer Slider
Plugin -
Plugin Slug -
slider-slideshow
Installations -
3,000+
Vulnerability -
Cross Site Scripting (XSS)
Patched In Version -
No Fix
Severity -
Medium
CVE Code -

12 - WooCommerce Google Sheet Connector
Plugin -
WooCommerce Google Sheet Connector
Plugin Slug -
wc-gsheetconnector
Installations -
1,000+
Vulnerability -
Cross Site Request Forgery (CSRF)
Patched In Version -
No Fix
Severity -
Medium
CVE Code -

13 - WCP OpenWeather
Plugin -
Plugin Slug -
wcp-openweather
Installations -
1,000+
Vulnerability -
Cross Site Scripting (XSS)
Patched In Version -
No Fix
Severity -
High
CVE Code -

14 - WP Abstracts
Plugin -
Plugin Slug -
wp-abstracts-manuscripts-manager
Installations -
400+
Vulnerability -
Cross Site Request Forgery (CSRF)
Patched In Version -
No Fix
Severity -
Medium
CVE Code -

15 - WP Abstracts
Plugin -
Plugin Slug -
wp-abstracts-manuscripts-manager
Installations -
400+
Vulnerability -
Cross Site Scripting (XSS)
Patched In Version -
No Fix
Severity -
Medium
CVE Code -

16 - Post to CSV by BestWebSoft
Plugin -
Plugin Slug -
post-to-csv
Installations -
300+
Vulnerability -
CSV Injection
Patched In Version -
No Fix
Severity -
Medium
CVE Code -

17 - Caldera Forms Google Sheets Connector
Plugin -
Caldera Forms Google Sheets Connector
Plugin Slug -
gsheetconnector-caldera-forms
Installations -
200+
Vulnerability -
Access Code Update via Cross Site Request Forgery (CSRF)
Patched In Version -
No Fix
Severity -
Medium
CVE Code -

18 - Autochat Automatic Conversation
Plugin -
Autochat Automatic Conversation
Plugin Slug -
auyautochat-for-wp
Installations -
70+
Vulnerability -
Unauth. Stored Cross Site Scripting (XSS)
Patched In Version -
No Fix
Severity -
High
CVE Code -

19 - Quiz Expert – Easy Quiz Maker, Exam and Test Manager
Plugin -
Quiz Expert – Easy Quiz Maker, Exam and Test Manager
Plugin Slug -
quiz-expert
Installations -
50+
Vulnerability -
Cross Site Request Forgery (CSRF)
Patched In Version -
No Fix
Severity -
Medium
CVE Code -
20 - AN_GradeBook
Plugin -
Plugin Slug -
an-gradebook
Vulnerability -
Authenticated SQL Injection
Patched In Version -
No Fix
Severity -
High
CVE Code -
21 - Booked
Plugin -
Plugin Slug -
booked
Vulnerability -
Unauth. Appointment Data Exposure
Patched In Version -
No Fix
Severity -
Medium
CVE Code -
22 - Editorial Calendar
Plugin -
Plugin Slug -
editorial-calendar
Vulnerability -
Auth. Stored Cross Site Scripting (XSS)
Patched In Version -
No Fix
Severity -
Medium
CVE Code -
23 - Editorial Calendar
Plugin -
Plugin Slug -
editorial-calendar
Vulnerability -
Insecure Direct Object References (IDOR)
Patched In Version -
No Fix
Severity -
Medium
CVE Code -
24 - File Manager Advanced Shortcode
Plugin -
File Manager Advanced Shortcode
Plugin Slug -
file-manager-advanced-shortcode
Vulnerability -
Unauth. Remote Code Execution (RCE)
Patched In Version -
No Fix
Severity -
Critical
CVE Code -
25 - Image Map Pro
Plugin -
Plugin Slug -
image-map-pro-lite
Vulnerability -
Cross-Site Request Forgery to Stored Cross-Site Scripting
Patched In Version -
No Fix
Severity -
High
CVE Code -
26 - Image Map Pro
Plugin -
Plugin Slug -
image-map-pro-lite
Vulnerability -
Missing Authorization to Stored Cross-Site Scripting
Patched In Version -
No Fix
Severity -
Medium
CVE Code -
27 - NOO Timetable
Plugin -
Plugin Slug -
noo-timetable
Vulnerability -
Cross Site Request Forgery (CSRF)
Patched In Version -
No Fix
Severity -
Medium
CVE Code -
28 - NOO Timetable
Plugin -
Plugin Slug -
noo-timetable
Vulnerability -
Cross Site Scripting (XSS)
Patched In Version -
No Fix
Severity -
Medium
CVE Code -
29 - SP Project & Document Manager
Plugin -
Plugin Slug -
sp-client-document-manager
Vulnerability -
Auth. Insecure Direct Object References (IDOR)
Patched In Version -
No Fix
Severity -
High
CVE Code -
30 - SP Project & Document Manager
Plugin -
Plugin Slug -
sp-client-document-manager
Vulnerability -
SQL Injection
Patched In Version -
No Fix
Severity -
High
CVE Code -
31 - SP Project & Document Manager
Plugin -
Plugin Slug -
sp-client-document-manager
Vulnerability -
Cross Site Scripting (XSS)
Patched In Version -
No Fix
Severity -
Medium
CVE Code -
32 - Web3 – Crypto wallet Login & NFT token gating
Plugin -
Web3 – Crypto wallet Login & NFT token gating
Plugin Slug -
web3-authentication
Vulnerability -
Authentication Bypass Vulnerability
Patched In Version -
No Fix
Severity -
Critical
CVE Code -
33 - WPJobBoard
Plugin -
Plugin Slug -
wpjobboard
Vulnerability -
Unauth. Blind SQL Injection
Patched In Version -
No Fix
Severity -
High
CVE Code -
Protect Your WordPress Website Today With Website Guardian
Join hundreds of businesses like yours who trust InterwebDEFENCE to protect their websites and livelihood. Using our proven website security analysis and best-in-class AI ‘Website Guardian” software, we are able to protect, monitor and backup your WordPress website.
Go ahead, keep the good guys In and the bad guys out – Click HERE to see our Website Guardian security plans NOW
PLUS
Find out about our unconditional ‘Double Protection’ Guarantee. This guarantee is better than risk free!
We’ll have you scanned, protected and secure in no time, giving you total peace of mind that your website is safe, leaving you to focus on your business success.
WordPress Theme Vulnerabilities
1 - The7
Theme -
The7
Theme Slug -
dt-the7
Vulnerability -
Cross Site Request Forgery (CSRF)
Patched In Version -
No Fix
Severity -
Medium
CVE Code -
Protect Your WordPress Website Today With Website Guardian
Join hundreds of businesses like yours who trust InterwebDEFENCE to protect their websites and livelihood. Using our proven website security analysis and best-in-class AI ‘Website Guardian” software, we are able to protect, monitor and backup your WordPress website.
Go ahead, keep the good guys In and the bad guys out – Click HERE to see our Website Guardian security plans NOW
PLUS
Find out about our unconditional ‘Double Protection’ Guarantee. This guarantee is better than risk free!
We’ll have you scanned, protected and secure in no time, giving you total peace of mind that your website is safe, leaving you to focus on your business success.