WordPress Vulnerability Report – July 12, 2023

by | Jul 12, 2023 | Security

DETAILS FROM DAN KNAUSS OF ITHEMES ON JUly 12, 2023

original available here

Last Updated on July 12, 2023

 

Since last week, 82 total vulnerabilities emerged in public disclosure. They may affect over 4 million WordPress sites. There are 46 plugin vulnerabilities and one theme vulnerability with security patches available, so run those updates!

Additionally, there are 34 plugin vulnerabilities and one theme vulnerability with no patch available yet. If you discover you are using an unpatched plugin or theme, check their vendors’ intentions and progress on a security release. If no patch is forthcoming or the vulnerable software has been marked “closed” and dropped from the official WordPress theme and plugin repositories, you should consider deactivation and removal in favor of alternative solutions.

Is Your WordPress Website Secure?

DID YOU KNOW – A staggering 83% of WordPress websites are not upgraded or updated, is your website one of these?

Hacks happen due to lack of website upkeep and protection, like updating WordPress or plugins, plus using weak passwords. Contrary to popular belief, web designers and website hosting companies are not responsible for the security of your WordPress website; you are. It’s like using your computer without Anti-virus!

WordPress Core Vulnerabilities

No new WordPress core vulnerabilities were disclosed this week. 

WordPress Theme Vulnerabilities

Jump to section

These are vulnerabilities that have occoured in themes for wordpress. If there is a patch for the issue you should update the theme immediately, if there is no fix you should change your site to a different theme.

WordPress Plugin Vulnerabilities – Patched

WP-Optimize – Cache, Clean, Compress.

1 - WP-Optimize – Cache, Clean, Compress.

Plugin -

WP-Optimize – Cache, Clean, Compress.


Plugin Slug -

wp-optimize


Installations -

1,000,000+


Vulnerability -

Reflected Cross Site Scripting (XSS)


Patched In Version -

3.2.13


Severity -

High


CVE Code -

2023-1119


Ninja Forms Contact Form – The Drag and Drop Form Builder for WordPress

2 - Ninja Forms Contact Form – The Drag and Drop Form Builder for WordPress

Plugin -

Ninja Forms Contact Form – The Drag and Drop Form Builder for WordPress


Plugin Slug -

ninja-forms


Installations -

900,000+


Vulnerability -

Denial of Service Attack


Patched In Version -

3.6.26


Severity -

Medium


CVE Code -

2023-35909


Forminator – Contact Form, Payment Form & Custom Form Builder

3 - Forminator – Contact Form, Payment Form & Custom Form Builder

Plugin -

Forminator – Contact Form, Payment Form & Custom Form Builder


Plugin Slug -

forminator


Installations -

400,000+


Vulnerability -

Unauth. Race Condition


Patched In Version -

1.24.1


Severity -

Low


CVE Code -

2023-2010


POST SMTP Mailer – Email log, Delivery Failure Notifications and Best Mail SMTP for WordPress

4 - POST SMTP Mailer – Email log, Delivery Failure Notifications and Best Mail SMTP for WordPress

Plugin -

POST SMTP Mailer – Email log, Delivery Failure Notifications and Best Mail SMTP for WordPress


Plugin Slug -

post-smtp


Installations -

300,000+


Vulnerability -

Account Takeover via Cross Site Request Forgery (CSRF)


Patched In Version -

2.5.7


Severity -

High


CVE Code -

2023-3179


POST SMTP Mailer – Email log, Delivery Failure Notifications and Best Mail SMTP for WordPress

5 - POST SMTP Mailer – Email log, Delivery Failure Notifications and Best Mail SMTP for WordPress

Plugin -

POST SMTP Mailer – Email log, Delivery Failure Notifications and Best Mail SMTP for WordPress


Plugin Slug -

post-smtp


Installations -

300,000+


Vulnerability -

Arbitrary Log Deletion via Cross Site Request Forgery (CSRF)


Patched In Version -

2.5.7


Severity -

Medium


CVE Code -

2023-3178


ShopLentor – WooCommerce Builder for Elementor & Gutenberg +10 Modules – All in One Solution (formerly WooLentor)

6 - ShopLentor – WooCommerce Builder for Elementor & Gutenberg +10 Modules – All in One Solution (formerly WooLentor)

Plugin -

ShopLentor – WooCommerce Builder for Elementor & Gutenberg +10 Modules – All in One Solution (formerly WooLentor)


Plugin Slug -

woolentor-addons


Installations -

100,000+


Vulnerability -

Cross Site Request Forgery (CSRF)


Patched In Version -

2.6.3


Severity -

Medium


CVE Code -

2022-47172


WP Content Copy Protection & No Right Click

7 - WP Content Copy Protection & No Right Click

Plugin -

WP Content Copy Protection & No Right Click


Plugin Slug -

wp-content-copy-protector


Installations -

100,000+


Vulnerability -

Cross Site Scripting (XSS)


Patched In Version -

3.5.6


Severity -

Medium


CVE Code -

2023-36678


LearnPress – WordPress LMS Plugin

8 - LearnPress – WordPress LMS Plugin

Plugin -

LearnPress – WordPress LMS Plugin


Plugin Slug -

learnpress


Installations -

90,000+


Vulnerability -

Authenticated Broken Access Control


Patched In Version -

4.2.3.1


Severity -

High


CVE Code -

2023-36516


LearnPress – WordPress LMS Plugin

9 - LearnPress – WordPress LMS Plugin

Plugin -

LearnPress – WordPress LMS Plugin


Plugin Slug -

learnpress


Installations -

90,000+


Vulnerability -

Unauthenticated Broken Access Control


Patched In Version -

4.2.3.1


Severity -

High


CVE Code -

2023-36515


HTTP Headers

10 - HTTP Headers

Plugin -

HTTP Headers


Plugin Slug -

http-headers


Installations -

40,000+


Vulnerability -

Cross Site Scripting (XSS)


Patched In Version -

1.19.0


Severity -

Medium


CVE Code -

2023-37874


HTTP Headers

11 - HTTP Headers

Plugin -

HTTP Headers


Plugin Slug -

http-headers


Installations -

40,000+


Vulnerability -

Admin+ Remote Code Execution (RCE)


Patched In Version -

1.18.11


Severity -

High


CVE Code -

2023-1208


All-in-one Floating Contact Form, Call, Chat, and 50+ Social Icon Tabs – My Sticky Elements

12 - All-in-one Floating Contact Form, Call, Chat, and 50+ Social Icon Tabs – My Sticky Elements

Plugin -

All-in-one Floating Contact Form, Call, Chat, and 50+ Social Icon Tabs – My Sticky Elements


Plugin Slug -

mystickyelements


Installations -

40,000+


Vulnerability -

Admin+ Stored Cross Site Scripting (XSS)


Patched In Version -

2.1.2


Severity -

Medium


CVE Code -

2023-3248


JetFormBuilder — Dynamic Blocks Form Builder

13 - JetFormBuilder — Dynamic Blocks Form Builder

Plugin -

JetFormBuilder — Dynamic Blocks Form Builder


Plugin Slug -

jetformbuilder


Installations -

30,000+


Vulnerability -

Authenticated Privilege Escalation


Patched In Version -

3.0.9


Severity -

High


CVE Code -

2023-37866


Visibility Logic for Elementor

14 - Visibility Logic for Elementor

Plugin -

Visibility Logic for Elementor


Plugin Slug -

visibility-logic-elementor


Installations -

30,000+


Vulnerability -

Cross Site Request Forgery (CSRF)


Patched In Version -

2.3.5


Severity -

Medium


CVE Code -

2022-47169


IP2Location Country Blocker

15 - IP2Location Country Blocker

Plugin -

IP2Location Country Blocker


Plugin Slug -

ip2location-country-blocker


Installations -

20,000+


Vulnerability -

IP Bypass Vulnerability


Patched In Version -

2.29.2


Severity -

Medium


CVE Code -

2023-37865


ND Shortcodes

16 - ND Shortcodes

Plugin -

ND Shortcodes


Plugin Slug -

nd-shortcodes


Installations -

20,000+


Vulnerability -

Auth. Cross Site Scripting (XSS)


Patched In Version -

7.0


Severity -

Medium


CVE Code -

2022-4623


wpForo Forum

17 - wpForo Forum

Plugin -

wpForo Forum


Plugin Slug -

wpforo


Installations -

20,000+


Vulnerability -

Reflected Cross Site Scripting (XSS)


Patched In Version -

2.1.9


Severity -

High


CVE Code -

2023-2309


Yasr – Yet Another Stars Rating

18 - Yasr – Yet Another Stars Rating

Plugin -

Yasr – Yet Another Stars Rating


Plugin Slug -

yet-another-stars-rating


Installations -

20,000+


Vulnerability -

Race Condition


Patched In Version -

3.3.9


Severity -

Low


CVE Code -

2023-37867


Booking Package

19 - Booking Package

Plugin -

Booking Package


Plugin Slug -

booking-package


Installations -

10,000+


Vulnerability -

Unauthenticated Privilege Escalation


Patched In Version -

1.5.99


Severity -

High


CVE Code -

2023-37389


Cryptocurrency Widgets – Price Ticker & Coins List

20 - Cryptocurrency Widgets – Price Ticker & Coins List

Plugin -

Cryptocurrency Widgets – Price Ticker & Coins List


Plugin Slug -

cryptocurrency-price-ticker-widget


Installations -

10,000+


Vulnerability -

Broken Access Control


Patched In Version -

2.6.3


Severity -

Medium


CVE Code -

2023-36681


Image Regenerate & Select Crop

21 - Image Regenerate & Select Crop

Plugin -

Image Regenerate & Select Crop


Plugin Slug -

image-regenerate-select-crop


Installations -

10,000+


Vulnerability -

Broken Access Control


Patched In Version -

7.2.0


Severity -

Medium


CVE Code -

2023-36680


WP Mail Log

22 - WP Mail Log

Plugin -

WP Mail Log


Plugin Slug -

wp-mail-log


Installations -

10,000+


Vulnerability -

Unauthenticated Stored Cross Site Scripting (XSS) via Email


Patched In Version -

1.1.2


Severity -

High


CVE Code -

2023-3088


Companion Sitemap Generator – HTML & XML

23 - Companion Sitemap Generator – HTML & XML

Plugin -

Companion Sitemap Generator – HTML & XML


Plugin Slug -

companion-sitemap-generator


Installations -

9,000+


Vulnerability -

Reflected Cross Site Scripting (XSS)


Patched In Version -

4.5.3


Severity -

High


CVE Code -

2023-1780


Buy Me a Coffee – Button and Widget Plugin

24 - Buy Me a Coffee – Button and Widget Plugin

Plugin -

Buy Me a Coffee – Button and Widget Plugin


Plugin Slug -

buymeacoffee


Installations -

6,000+


Vulnerability -

Cross Site Request Forgery (CSRF)


Patched In Version -

3.8


Severity -

Medium


CVE Code -

2023-2079


Buy Me a Coffee – Button and Widget Plugin

25 - Buy Me a Coffee – Button and Widget Plugin

Plugin -

Buy Me a Coffee – Button and Widget Plugin


Plugin Slug -

buymeacoffee


Installations -

6,000+


Vulnerability -

Missing Authorization


Patched In Version -

3.8


Severity -

Medium


CVE Code -

2023-2078


Buy Me a Coffee – Button and Widget Plugin

26 - Buy Me a Coffee – Button and Widget Plugin

Plugin -

Buy Me a Coffee – Button and Widget Plugin


Plugin Slug -

buymeacoffee


Installations -

6,000+


Vulnerability -

Broken Access Control


Patched In Version -

3.8


Severity -

Medium


CVE Code -

2023-25030


WP Dummy Content Generator

27 - WP Dummy Content Generator

Plugin -

WP Dummy Content Generator


Plugin Slug -

wp-dummy-content-generator


Installations -

4,000+


Vulnerability -

Broken Access Control


Patched In Version -

3.0.0


Severity -

Medium


CVE Code -

2023-37394


WP Dummy Content Generator

28 - WP Dummy Content Generator

Plugin -

WP Dummy Content Generator


Plugin Slug -

wp-dummy-content-generator


Installations -

4,000+


Vulnerability -

Cross Site Request Forgery (CSRF)


Patched In Version -

3.0.0


Severity -

Medium


CVE Code -

2023-37392


29 - WebwinkelKeur: Webshop keurmerk & reviews for WordPress

Plugin -

WebwinkelKeur: Webshop keurmerk & reviews for WordPress


Plugin Slug -

webwinkelkeur


Installations -

3,000+


Vulnerability -

Cross Site Request Forgery (CSRF)


Patched In Version -

3.25


Severity -

Medium


CVE Code -

2023-36691


ARMember – Membership Plugin, Content Restriction, Member Levels, User Profile & User signup

30 - ARMember – Membership Plugin, Content Restriction, Member Levels, User Profile & User signup

Plugin -

ARMember – Membership Plugin, Content Restriction, Member Levels, User Profile & User signup


Plugin Slug -

armember-membership


Installations -

2,000+


Vulnerability -

Cross Site Request Forgery (CSRF)


Patched In Version -

4.0.6


Severity -

Medium


CVE Code -

2022-47424


Gift Cards (Gift Vouchers and Packages) (WooCommerce Supported)

31 - Gift Cards (Gift Vouchers and Packages) (WooCommerce Supported)

Plugin -

Gift Cards (Gift Vouchers and Packages) (WooCommerce Supported)


Plugin Slug -

gift-voucher


Installations -

2,000+


Vulnerability -

Cross Site Request Forgery (CSRF) in new_voucher_template.php


Patched In Version -

4.3.6


Severity -

Medium


LMS by Masteriyo – WordPress Learning Management System, eLearning Platform, Online Education System & Online Course Builder

32 - LMS by Masteriyo – WordPress Learning Management System, eLearning Platform, Online Education System & Online Course Builder

Plugin -

LMS by Masteriyo – WordPress Learning Management System, eLearning Platform, Online Education System & Online Course Builder


Plugin Slug -

learning-management-system


Installations -

2,000+


Vulnerability -

Sensitive Data Exposure


Patched In Version -

1.6.8


Severity -

Medium


BuddyPress Builder for Elementor – BuddyBuilder

33 - BuddyPress Builder for Elementor – BuddyBuilder

Plugin -

BuddyPress Builder for Elementor – BuddyBuilder


Plugin Slug -

stax-buddy-builder


Installations -

2,000+


Vulnerability -

Cross Site Request Forgery (CSRF)


Patched In Version -

1.7.4


Severity -

Medium


Terms descriptions

34 - Terms descriptions

Plugin -

Terms descriptions


Plugin Slug -

terms-descriptions


Installations -

2,000+


Vulnerability -

Reflected Cross Site Scripting (XSS)


Patched In Version -

3.4.5


Severity -

High


CVE Code -

2023-28779


Sublanguage

35 - Sublanguage

Plugin -

Sublanguage


Plugin Slug -

sublanguage


Installations -

1,000+


Vulnerability -

Broken Access Control


Patched In Version -

2.10


Severity -

Medium


CVE Code -

2023-36695


WP Reroute Email

36 - WP Reroute Email

Plugin -

WP Reroute Email


Plugin Slug -

wp-reroute-email


Installations -

1,000+


Vulnerability -

Unauthenticated Stored Cross Site Scripting (XSS) via Email Subject


Patched In Version -

1.5.0


Severity -

High


CVE Code -

2023-3168


WPFactory Helper

37 - WPFactory Helper

Plugin -

WPFactory Helper


Plugin Slug -

wpcodefactory-helper


Installations -

1,000+


Vulnerability -

Reflected Cross Site Scripting (XSS)


Patched In Version -

1.5.3


Severity -

High


CVE Code -

2023-36689


RSVPMaker

38 - RSVPMaker

Plugin -

RSVPMaker


Plugin Slug -

rsvpmaker


Installations -

400+


Vulnerability -

SQL Injection


Patched In Version -

10.5.5


Severity -

High


CVE Code -

2023-29095


Getnet Argentina para Woocommerce

39 - Getnet Argentina para Woocommerce

Plugin -

Getnet Argentina para Woocommerce


Plugin Slug -

integrar-getnet-con-woo


Installations -

200+


Vulnerability -

Authorization Bypass via webhook


Patched In Version -

0.0.5


Severity -

High


CVE Code -

2023-3525


My Content Management

40 - My Content Management

Plugin -

My Content Management


Plugin Slug -

my-content-management


Installations -

200+


Vulnerability -

Cross Site Scripting (XSS)


Patched In Version -

1.7.7


Severity -

Medium


CVE Code -

2023-34377


41 - Auto Location for WP Job Manager via Google

Plugin -

Auto Location for WP Job Manager via Google


Plugin Slug -

auto-location-for-wp-job-manager


Installations -

100+


Vulnerability -

Admin+ Cross Site Scripting (XSS)


Patched In Version -

1.1


Severity -

Medium


CVE Code -

2023-3344


42 - tagDiv Cloud Library

Plugin -

tagDiv Cloud Library


Plugin Slug -

td-cloud-library


Vulnerability -

Unauthenticated Arbitrary User Metadata Update to Privilege Escalation


Patched In Version -

2.7


Severity -

Critical


CVE Code -

2023-1597


43 - WooCommerce GoCardless Gateway

Plugin -

WooCommerce GoCardless Gateway


Plugin Slug -

woocommerce-gateway-gocardless


Vulnerability -

Unauth. Insecure Direct Object References (IDOR)


Patched In Version -

2.5.7


Severity -

High


CVE Code -

2023-37871


44 - WooCommerce Ship to Multiple Addresses

Plugin -

WooCommerce Ship to Multiple Addresses


Plugin Slug -

woocommerce-shipping-multiple-addresses


Vulnerability -

Reflected Cross Site Scripting (XSS)


Patched In Version -

3.8.6


Severity -

High


CVE Code -

2023-37873


45 - WooCommerce Ship to Multiple Addresses

Plugin -

WooCommerce Ship to Multiple Addresses


Plugin Slug -

woocommerce-shipping-multiple-addresses


Vulnerability -

Broken Access Control


Patched In Version -

3.8.6


Severity -

Medium


CVE Code -

2023-37872


46 - WooCommerce Warranty Requests

Plugin -

WooCommerce Warranty Requests


Plugin Slug -

woocommerce-warranty


Vulnerability -

Broken Access Control


Patched In Version -

2.2.0


Severity -

High


CVE Code -

2023-37870


Protect Your WordPress Website Today With Website Guardian

Join hundreds of businesses like yours who trust InterwebDEFENCE to protect their websites and livelihood. Using our proven website security analysis and best-in-class AI ‘Website Guardian” software, we are able to protect, monitor and backup your WordPress website.

Go ahead, keep the good guys In and the bad guys out – Click HERE to see our Website Guardian security plans NOW
PLUS
Find out about our unconditional ‘Double Protection’ Guarantee. This guarantee is better than risk free!

We’ll have you scanned, protected and secure in no time, giving you total peace of mind that your website is safe, leaving you to focus on your business success.

WordPress Plugin Vulnerabilities – Unpatched

1 - oAuth Twitter Feed for Developers

Plugin -

oAuth Twitter Feed for Developers


Plugin Slug -

oauth-twitter-feed-for-developers


Installations -

60,000+


Vulnerability -

Cross Site Scripting (XSS)


Patched In Version -

No Fix


Severity -

Medium


CVE Code -

2023-25042


Video Gallery – YouTube Playlist, Channel Gallery by YotuWP

2 - Video Gallery – YouTube Playlist, Channel Gallery by YotuWP

Plugin -

Video Gallery – YouTube Playlist, Channel Gallery by YotuWP


Plugin Slug -

yotuwp-easy-youtube-embed


Installations -

30,000+


Vulnerability -

Cross Site Scripting (XSS)


Patched In Version -

No Fix


Severity -

Medium


CVE Code -

2023-25477


Bulk edit image alt tag, caption & description – WordPress Media Library Helper by Codexin

3 - Bulk edit image alt tag, caption & description – WordPress Media Library Helper by Codexin

Plugin -

Bulk edit image alt tag, caption & description – WordPress Media Library Helper by Codexin


Plugin Slug -

media-library-helper


Installations -

10,000+


Vulnerability -

Cross Site Request Forgery (CSRF)


Patched In Version -

No Fix


Severity -

Medium


CVE Code -

2023-37386


Secondary Title

4 - Secondary Title

Plugin -

Secondary Title


Plugin Slug -

secondary-title


Installations -

10,000+


Vulnerability -

Cross Site Scripting (XSS)


Patched In Version -

No Fix


Severity -

Medium


CVE Code -

2023-28773


Classified Listing – Classified ads & Business Directory Plugin

5 - Classified Listing – Classified ads & Business Directory Plugin

Plugin -

Classified Listing – Classified ads & Business Directory Plugin


Plugin Slug -

classified-listing


Installations -

9,000+


Vulnerability -

Cross Site Request Forgery (CSRF) Leading To Thumbnail Removal


Patched In Version -

No Fix


Severity -

Medium


CVE Code -

2023-37387


Mobile Call Now & Map Buttons

6 - Mobile Call Now & Map Buttons

Plugin -

Mobile Call Now & Map Buttons


Plugin Slug -

mobile-call-now-map-buttons


Installations -

9,000+


Vulnerability -

Cross Site Scripting (XSS)


Patched In Version -

No Fix


Severity -

Medium


CVE Code -

2023-24401


7 - Social Share Boost

Plugin -

Social Share Boost


Plugin Slug -

social-share-boost


Installations -

6,000+


Vulnerability -

Cross Site Scripting (XSS)


Patched In Version -

No Fix


Severity -

Medium


CVE Code -

2023-25044


Simple Light Weight Social Share (Tweet, Like, Share and Linkedin)

8 - Simple Light Weight Social Share (Tweet, Like, Share and Linkedin)

Plugin -

Simple Light Weight Social Share (Tweet, Like, Share and Linkedin)


Plugin Slug -

only-tweet-like-share-and-google-1


Installations -

5,000+


Vulnerability -

Cross Site Scripting (XSS)


Patched In Version -

No Fix


Severity -

Medium


CVE Code -

2023-37388


Drag & Drop Sales Funnel Builder for WordPress – WPFunnels

9 - Drag & Drop Sales Funnel Builder for WordPress – WPFunnels

Plugin -

Drag & Drop Sales Funnel Builder for WordPress – WPFunnels


Plugin Slug -

wpfunnels


Installations -

5,000+


Vulnerability -

Insecure Direct Object References (IDOR)


Patched In Version -

No Fix


Severity -

Medium


Animated Number Counters

10 - Animated Number Counters

Plugin -

Animated Number Counters


Plugin Slug -

animated-number-counters


Installations -

3,000+


Vulnerability -

Cross Site Scripting (XSS)


Patched In Version -

No Fix


Severity -

Medium


CVE Code -

2023-24393


11 - Social Media Icons Widget

Plugin -

Social Media Icons Widget


Plugin Slug -

spoontalk-social-media-icons-widget


Installations -

3,000+


Vulnerability -

Cross Site Request Forgery (CSRF)


Patched In Version -

No Fix


Severity -

Medium


CVE Code -

2023-25036


Kingkong Board

12 - Kingkong Board

Plugin -

Kingkong Board


Plugin Slug -

kingkong-board


Installations -

2,000+


Vulnerability -

Broken Access Control


Patched In Version -

No Fix


Severity -

Medium


CVE Code -

2023-36694


13 - Menubar

Plugin -

Menubar


Plugin Slug -

menubar


Installations -

2,000+


Vulnerability -

Cross Site Request Forgery (CSRF)


Patched In Version -

No Fix


Severity -

Medium


CVE Code -

2023-36687


Product Category Tree

14 - Product Category Tree

Plugin -

Product Category Tree


Plugin Slug -

product-category-tree


Installations -

2,000+


Vulnerability -

Broken Access Control


Patched In Version -

No Fix


Severity -

Medium


CVE Code -

2023-29173


15 - WP RSS Images

Plugin -

WP RSS Images


Plugin Slug -

wp-rss-images


Installations -

2,000+


Vulnerability -

Cross Site Request Forgery (CSRF)


Patched In Version -

No Fix


Severity -

Medium


CVE Code -

2023-36693


Image Social Feed Plugin

16 - Image Social Feed Plugin

Plugin -

Image Social Feed Plugin


Plugin Slug -

add-instagram


Installations -

1,000+


Vulnerability -

Cross Site Scripting (XSS)


Patched In Version -

No Fix


Severity -

Medium


CVE Code -

2023-24412


Simple Giveaways – Grow your business, email lists and traffic with contests

17 - Simple Giveaways – Grow your business, email lists and traffic with contests

Plugin -

Simple Giveaways – Grow your business, email lists and traffic with contests


Plugin Slug -

giveasap


Installations -

1,000+


Vulnerability -

Broken Access Control


Patched In Version -

No Fix


Severity -

Medium


CVE Code -

2023-23893


Coming Soon Page – Responsive Coming Soon & Maintenance Mode

18 - Coming Soon Page – Responsive Coming Soon & Maintenance Mode

Plugin -

Coming Soon Page – Responsive Coming Soon & Maintenance Mode


Plugin Slug -

responsive-coming-soon-page


Installations -

1,000+


Vulnerability -

SQL Injection


Patched In Version -

No Fix


Severity -

High


CVE Code -

2022-46849


Simple Site Verify

19 - Simple Site Verify

Plugin -

Simple Site Verify


Plugin Slug -

simple-site-verify


Installations -

1,000+


Vulnerability -

Cross Site Scripting (XSS)


Patched In Version -

No Fix


Severity -

Medium


CVE Code -

2023-36688


20 - WP-Cirrus

Plugin -

WP-Cirrus


Plugin Slug -

wp-cirrus


Installations -

1,000+


Vulnerability -

Cross Site Scripting (XSS)


Patched In Version -

No Fix


Severity -

Medium


CVE Code -

2023-36692


WP Full Stripe Free

21 - WP Full Stripe Free

Plugin -

WP Full Stripe Free


Plugin Slug -

wp-full-stripe-free


Installations -

1,000+


Vulnerability -

Cross Site Scripting (XSS)


Patched In Version -

No Fix


Severity -

Medium


CVE Code -

2023-28934


22 - Baidu Tongji generator

Plugin -

Baidu Tongji generator


Plugin Slug -

baidu-tongji-generator


Installations -

100+


Vulnerability -

Cross Site Request Forgery (CSRF)


Patched In Version -

No Fix


Severity -

Medium


CVE Code -

2023-31230


23 - Querlo Chatbot

Plugin -

Querlo Chatbot


Plugin Slug -

querlo-chatbots


Installations -

10+


Vulnerability -

Cross Site Scripting (XSS)


Patched In Version -

No Fix


Severity -

Medium


CVE Code -

2023-3418


24 - BadgeOS

Plugin -

BadgeOS


Plugin Slug -

badgeos


Vulnerability -

Authenticated (Subscriber+) Insecure Direct Object References (IDOR) to Arbitrary Post Title Overwrite


Patched In Version -

No Fix


Severity -

Medium


CVE Code -

2023-2172


25 - BadgeOS

Plugin -

BadgeOS


Plugin Slug -

badgeos


Vulnerability -

Authenticated (Subscriber+) Insecure Direct Object References (IDOR) to Arbitrary Post Deletion


Patched In Version -

No Fix


Severity -

Medium


CVE Code -

2023-2173


26 - BadgeOS

Plugin -

BadgeOS


Plugin Slug -

badgeos


Vulnerability -

Authenticated (Contributor+) Stored Cross Site Scripting (XSS) via Shortcode


Patched In Version -

No Fix


Severity -

Medium


CVE Code -

2023-2171


Livestream Notice

27 - Livestream Notice

Plugin -

Livestream Notice


Plugin Slug -

livestream-notice


Vulnerability -

Cross Site Scripting (XSS)


Patched In Version -

No Fix


Severity -

Medium


CVE Code -

2023-27621


28 - Mail Control

Plugin -

Mail Control


Plugin Slug -

mail-control


Vulnerability -

Unauthenticated Stored Cross Site Scripting (XSS) via Email Subject


Patched In Version -

No Fix


Severity -

High


CVE Code -

2023-3158


29 - Premium Addons PRO

Plugin -

Premium Addons PRO


Plugin Slug -

premium-addons-pro


Vulnerability -

Broken Access Control


Patched In Version -

No Fix


Severity -

Medium


CVE Code -

2023-37869


30 - Premium Addons PRO

Plugin -

Premium Addons PRO


Plugin Slug -

premium-addons-pro


Vulnerability -

Sensitive Data Exposure


Patched In Version -

No Fix


Severity -

Medium


CVE Code -

2023-37868


Reservation.Studio widget

31 - Reservation.Studio widget

Plugin -

Reservation.Studio widget


Plugin Slug -

reservation-studio-widget


Vulnerability -

Cross Site Scripting (XSS)


Patched In Version -

No Fix


Severity -

Medium


CVE Code -

2023-24397


32 - SMTP Mail

Plugin -

SMTP Mail


Plugin Slug -

smtp-mail


Vulnerability -

Unauthenticated Stored Cross Site Scripting (XSS) via Email Subject


Patched In Version -

No Fix


Severity -

High


CVE Code -

2023-3092


33 - WordPress Mobile Pack

Plugin -

WordPress Mobile Pack


Plugin Slug -

wordpress-mobile-pack


Vulnerability -

Cross Site Request Forgery (CSRF)


Patched In Version -

No Fix


Severity -

Medium


CVE Code -

2023-37391


WP Default Feature Image

34 - WP Default Feature Image

Plugin -

WP Default Feature Image


Plugin Slug -

wp-default-feature-image


Vulnerability -

Cross Site Scripting (XSS)


Patched In Version -

No Fix


Severity -

Medium


CVE Code -

2023-25488


Protect Your WordPress Website Today With Website Guardian

Join hundreds of businesses like yours who trust InterwebDEFENCE to protect their websites and livelihood. Using our proven website security analysis and best-in-class AI ‘Website Guardian” software, we are able to protect, monitor and backup your WordPress website.

Go ahead, keep the good guys In and the bad guys out – Click HERE to see our Website Guardian security plans NOW
PLUS
Find out about our unconditional ‘Double Protection’ Guarantee. This guarantee is better than risk free!

We’ll have you scanned, protected and secure in no time, giving you total peace of mind that your website is safe, leaving you to focus on your business success.

WordPress Theme Vulnerabilities

1 - Consulting

Theme -

Consulting


Theme Slug -

consulting


Vulnerability -

Local File Inclusion


Patched In Version -

No Fix


Severity -

High


CVE Code -

2023-37385


2 - WPLMS

Theme -

WPLMS


Theme Slug -

wplms


Vulnerability -

Cross Site Request Forgery (CSRF)


Patched In Version -

4.900


Severity -

High


CVE Code -

2023-36690


Protect Your WordPress Website Today With Website Guardian

Join hundreds of businesses like yours who trust InterwebDEFENCE to protect their websites and livelihood. Using our proven website security analysis and best-in-class AI ‘Website Guardian” software, we are able to protect, monitor and backup your WordPress website.

Go ahead, keep the good guys In and the bad guys out – Click HERE to see our Website Guardian security plans NOW
PLUS
Find out about our unconditional ‘Double Protection’ Guarantee. This guarantee is better than risk free!

We’ll have you scanned, protected and secure in no time, giving you total peace of mind that your website is safe, leaving you to focus on your business success.

Click to access the login or register cheese