WordPress Vulnerability Report – July 19, 2023

by | Jul 19, 2023 | Security

DETAILS FROM DAN KNAUSS OF ITHEMES ON JULY 19, 2023

original available here

Last Updated on July 19, 2023

 

Since last week, 80 total vulnerabilities emerged in public disclosure. They may affect over 5 million WordPress sites. There are 55 plugin vulnerabilities with security patches available, so run those updates!

Additionally, there are 23 plugin vulnerabilities and two theme vulnerabilities with no patch available yet. If you discover you are using an unpatched plugin or theme, check their vendors’ intentions and progress on a security release. If no patch is forthcoming or the vulnerable software has been marked “closed” and dropped from the official WordPress theme and plugin repositories, you should consider deactivation and removal in favor of alternative solutions.

Is Your WordPress Website Secure?

DID YOU KNOW – A staggering 83% of WordPress websites are not upgraded or updated, is your website one of these?

Hacks happen due to lack of website upkeep and protection, like updating WordPress or plugins, plus using weak passwords. Contrary to popular belief, web designers and website hosting companies are not responsible for the security of your WordPress website; you are. It’s like using your computer without Anti-virus!

WordPress Core Vulnerabilities

No new WordPress core vulnerabilities were disclosed this week. 

WordPress Theme Vulnerabilities

Jump to section

These are vulnerabilities that have occoured in themes for wordpress. If there is a patch for the issue you should update the theme immediately, if there is no fix you should change your site to a different theme.

WordPress Plugin Vulnerabilities – Patched

Rank Math SEO

1 - Rank Math SEO

Plugin -

Rank Math SEO


Plugin Slug -

seo-by-rank-math


Installations -

2,000,000+


Vulnerability -

Cross Site Scripting (XSS)


Patched In Version -

1.0.119.1


Severity -

Medium


CVE Code -

2023-32600


All-In-One Security (AIOS) – Security and Firewall

2 - All-In-One Security (AIOS) – Security and Firewall

Plugin -

All-In-One Security (AIOS) – Security and Firewall


Plugin Slug -

all-in-one-wp-security-and-firewall


Installations -

1,000,000+


Vulnerability -

Sensitive Data Exposure of Plaintext Credentials


Patched In Version -

5.2.0


Severity -

Medium


Spectra – WordPress Gutenberg Blocks

3 - Spectra – WordPress Gutenberg Blocks

Plugin -

Spectra – WordPress Gutenberg Blocks


Plugin Slug -

ultimate-addons-for-gutenberg


Installations -

500,000+


Vulnerability -

Server Side Request Forgery (SSRF)


Patched In Version -

2.6.7


Severity -

High


CVE Code -

2023-36679


Spectra – WordPress Gutenberg Blocks

4 - Spectra – WordPress Gutenberg Blocks

Plugin -

Spectra – WordPress Gutenberg Blocks


Plugin Slug -

ultimate-addons-for-gutenberg


Installations -

500,000+


Vulnerability -

Broken Access Control


Patched In Version -

2.6.7


Severity -

Medium


CVE Code -

2023-36676


Contact Form Plugin – Fastest Contact Form Builder Plugin for WordPress by Fluent Forms

5 - Contact Form Plugin – Fastest Contact Form Builder Plugin for WordPress by Fluent Forms

Plugin -

Contact Form Plugin – Fastest Contact Form Builder Plugin for WordPress by Fluent Forms


Plugin Slug -

fluentform


Installations -

300,000+


Vulnerability -

SQL Injection


Patched In Version -

5.0.0


Severity -

Medium


CVE Code -

2023-24410


POST SMTP Mailer – Email log, Delivery Failure Notifications and Best Mail SMTP for WordPress

6 - POST SMTP Mailer – Email log, Delivery Failure Notifications and Best Mail SMTP for WordPress

Plugin -

POST SMTP Mailer – Email log, Delivery Failure Notifications and Best Mail SMTP for WordPress


Plugin Slug -

post-smtp


Installations -

300,000+


Vulnerability -

Unauthenticated Stored Cross-Site Scripting via Email


Patched In Version -

2.5.8


Severity -

High


CVE Code -

2023-3082


HT Mega – Absolute Addons For Elementor

7 - HT Mega – Absolute Addons For Elementor

Plugin -

HT Mega – Absolute Addons For Elementor


Plugin Slug -

ht-mega-for-elementor


Installations -

100,000+


Vulnerability -

Unauthenticated Privilege Escalation


Patched In Version -

2.2.1


Severity -

Critical


CVE Code -

2023-37999


YARPP – Yet Another Related Posts Plugin

8 - YARPP – Yet Another Related Posts Plugin

Plugin -

YARPP – Yet Another Related Posts Plugin


Plugin Slug -

yet-another-related-posts-plugin


Installations -

100,000+


Vulnerability -

Authenticated (Contributor+) Stored Cross Site Scripting (XSS)


Patched In Version -

5.30.4


Severity -

Medium


CVE Code -

2023-2433


kk Star Ratings

9 - kk Star Ratings

Plugin -

kk Star Ratings


Plugin Slug -

kk-star-ratings


Installations -

90,000+


Vulnerability -

Rate Manipulation due to IP Spoofing


Patched In Version -

5.4.4


Severity -

Medium


CVE Code -

2023-36528


Media Library Assistant

10 - Media Library Assistant

Plugin -

Media Library Assistant


Plugin Slug -

media-library-assistant


Installations -

70,000+


Vulnerability -

Reflected Cross Site Scripting (XSS)


Patched In Version -

3.0.8


Severity -

Medium


CVE Code -

2023-34010


Advanced AJAX Product Filters

11 - Advanced AJAX Product Filters

Plugin -

Advanced AJAX Product Filters


Plugin Slug -

woocommerce-ajax-filters


Installations -

60,000+


Vulnerability -

Broken Access Control


Patched In Version -

1.6.3.4


Severity -

Medium


CVE Code -

2022-45813


HTTP Headers

12 - HTTP Headers

Plugin -

HTTP Headers


Plugin Slug -

http-headers


Installations -

40,000+


Vulnerability -

Server Side Request Forgery (SSRF)


Patched In Version -

1.19.0


Severity -

Medium


CVE Code -

2023-37978


HTTP Headers

13 - HTTP Headers

Plugin -

HTTP Headers


Plugin Slug -

http-headers


Installations -

40,000+


Vulnerability -

Cross Site Scripting (XSS)


Patched In Version -

1.19.0


Severity -

Medium


CVE Code -

2023-37874


Quiz And Survey Master – Best Quiz, Exam and Survey Plugin for WordPress

14 - Quiz And Survey Master – Best Quiz, Exam and Survey Plugin for WordPress

Plugin -

Quiz And Survey Master – Best Quiz, Exam and Survey Plugin for WordPress


Plugin Slug -

quiz-master-next


Installations -

40,000+


Vulnerability -

Broken Access Control


Patched In Version -

8.1.11


Severity -

Medium


CVE Code -

2023-37984


Social Share, Social Login and Social Comments Plugin – Super Socializer

15 - Social Share, Social Login and Social Comments Plugin – Super Socializer

Plugin -

Social Share, Social Login and Social Comments Plugin – Super Socializer


Plugin Slug -

super-socializer


Installations -

40,000+


Vulnerability -

Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode


Patched In Version -

7.13.54


Severity -

Medium


JetFormBuilder — Dynamic Blocks Form Builder

16 - JetFormBuilder — Dynamic Blocks Form Builder

Plugin -

JetFormBuilder — Dynamic Blocks Form Builder


Plugin Slug -

jetformbuilder


Installations -

30,000+


Vulnerability -

Authenticated Privilege Escalation


Patched In Version -

3.0.9


Severity -

High


CVE Code -

2023-37866


IP2Location Country Blocker

17 - IP2Location Country Blocker

Plugin -

IP2Location Country Blocker


Plugin Slug -

ip2location-country-blocker


Installations -

20,000+


Vulnerability -

IP Bypass Vulnerability


Patched In Version -

2.29.2


Severity -

Medium


CVE Code -

2023-37865


Yasr – Yet Another Stars Rating

18 - Yasr – Yet Another Stars Rating

Plugin -

Yasr – Yet Another Stars Rating


Plugin Slug -

yet-another-stars-rating


Installations -

20,000+


Vulnerability -

Race Condition


Patched In Version -

3.3.9


Severity -

Low


CVE Code -

2023-37867


Booking Package

19 - Booking Package

Plugin -

Booking Package


Plugin Slug -

booking-package


Installations -

10,000+


Vulnerability -

Unathenticated Privilege Escalation


Patched In Version -

1.5.99


Severity -

High


CVE Code -

2023-37389


User Activity Log

20 - User Activity Log

Plugin -

User Activity Log


Plugin Slug -

user-activity-log


Installations -

10,000+


Vulnerability -

SQL Injection


Patched In Version -

1.6.3


Severity -

High


CVE Code -

2023-37966


Variation Swatches for WooCommerce

21 - Variation Swatches for WooCommerce

Plugin -

Variation Swatches for WooCommerce


Plugin Slug -

woo-product-variation-swatches


Installations -

10,000+


Vulnerability -

Reflected Cross Site Scripting (XSS)


Patched In Version -

2.3.8


Severity -

High


CVE Code -

2023-37975


Zippy

22 - Zippy

Plugin -

Zippy


Plugin Slug -

zippy


Installations -

10,000+


Vulnerability -

Broken Access Control


Patched In Version -

1.6.3


Severity -

Medium


CVE Code -

2023-34381


Restaurant Menu and Food Ordering by Five Star Plugins

23 - Restaurant Menu and Food Ordering by Five Star Plugins

Plugin -

Restaurant Menu and Food Ordering by Five Star Plugins


Plugin Slug -

food-and-drink-menu


Installations -

8,000+


Vulnerability -

Cross Site Request Forgery (CSRF)


Patched In Version -

2.4.7


Severity -

Medium


CVE Code -

2023-37985


Variation Images Gallery for WooCommerce

24 - Variation Images Gallery for WooCommerce

Plugin -

Variation Images Gallery for WooCommerce


Plugin Slug -

woo-product-variation-gallery


Installations -

8,000+


Vulnerability -

Reflected Cross Site Scripting (XSS)


Patched In Version -

2.3.4


Severity -

High


CVE Code -

2023-37894


BookingPress – Appointment Booking Calendar Plugin and Online Scheduling Plugin

25 - BookingPress – Appointment Booking Calendar Plugin and Online Scheduling Plugin

Plugin -

BookingPress – Appointment Booking Calendar Plugin and Online Scheduling Plugin


Plugin Slug -

bookingpress-appointment-booking


Installations -

7,000+


Vulnerability -

Unauth. Server Information Disclosure


Patched In Version -

1.0.65


Severity -

Medium


CVE Code -

2023-36507


Buy Me a Coffee – Button and Widget Plugin

26 - Buy Me a Coffee – Button and Widget Plugin

Plugin -

Buy Me a Coffee – Button and Widget Plugin


Plugin Slug -

buymeacoffee


Installations -

6,000+


Vulnerability -

Cross Site Request Forgery (CSRF)


Patched In Version -

3.8


Severity -

Medium


CVE Code -

2023-2079


Buy Me a Coffee – Button and Widget Plugin

27 - Buy Me a Coffee – Button and Widget Plugin

Plugin -

Buy Me a Coffee – Button and Widget Plugin


Plugin Slug -

buymeacoffee


Installations -

6,000+


Vulnerability -

Broken Access Control


Patched In Version -

3.8


Severity -

Medium


CVE Code -

2023-2078


WooCommerce Product Stock Alert

28 - WooCommerce Product Stock Alert

Plugin -

WooCommerce Product Stock Alert


Plugin Slug -

woocommerce-product-stock-alert


Installations -

6,000+


Vulnerability -

Sensitive Data Exposure


Patched In Version -

2.0.2


Severity -

Medium


CVE Code -

2023-37972


WooCommerce Product Stock Alert

29 - WooCommerce Product Stock Alert

Plugin -

WooCommerce Product Stock Alert


Plugin Slug -

woocommerce-product-stock-alert


Installations -

6,000+


Vulnerability -

Settings Change


Patched In Version -

2.0.2


Severity -

Medium


CVE Code -

2023-37971


AnsPress – Question and answer

30 - AnsPress – Question and answer

Plugin -

AnsPress – Question and answer


Plugin Slug -

anspress-question-answer


Installations -

5,000+


Vulnerability -

Cross Site Scripting (XSS)


Patched In Version -

4.3.2


Severity -

Medium


CVE Code -

2023-34374


Drag & Drop Sales Funnel Builder for WordPress – WPFunnels

31 - Drag & Drop Sales Funnel Builder for WordPress – WPFunnels

Plugin -

Drag & Drop Sales Funnel Builder for WordPress – WPFunnels


Plugin Slug -

wpfunnels


Installations -

5,000+


Vulnerability -

Reflected Cross Site Scripting (XSS)


Patched In Version -

2.7.17


Severity -

High


CVE Code -

2023-37977


Drag & Drop Sales Funnel Builder for WordPress – WPFunnels

32 - Drag & Drop Sales Funnel Builder for WordPress – WPFunnels

Plugin -

Drag & Drop Sales Funnel Builder for WordPress – WPFunnels


Plugin Slug -

wpfunnels


Installations -

5,000+


Vulnerability -

Insecure Direct Object References (IDOR)


Patched In Version -

2.7.16


Severity -

Medium


Integrate Google Drive – Browse, Upload, Download, Embed, Play, Share, Gallery, and Manage Your Google Drive Files Into Your WordPress Site

33 - Integrate Google Drive – Browse, Upload, Download, Embed, Play, Share, Gallery, and Manage Your Google Drive Files Into Your WordPress Site

Plugin -

Integrate Google Drive – Browse, Upload, Download, Embed, Play, Share, Gallery, and Manage Your Google Drive Files Into Your WordPress Site


Plugin Slug -

integrate-google-drive


Installations -

3,000+


Vulnerability -

Unauthenticated Broken Access Control


Patched In Version -

1.2.0


Severity -

Critical


CVE Code -

2023-32117


ARMember – Membership Plugin, Content Restriction, Member Levels, User Profile & User signup

34 - ARMember – Membership Plugin, Content Restriction, Member Levels, User Profile & User signup

Plugin -

ARMember – Membership Plugin, Content Restriction, Member Levels, User Profile & User signup


Plugin Slug -

armember-membership


Installations -

2,000+


Vulnerability -

Cross Site Request Forgery (CSRF)


Patched In Version -

4.0.6


Severity -

Medium


CVE Code -

2022-47424


Authors List

35 - Authors List

Plugin -

Authors List


Plugin Slug -

authors-list


Installations -

2,000+


Vulnerability -

Cross Site Scripting (XSS)


Patched In Version -

2.0.3


Severity -

High


CVE Code -

2023-37981


Integration for Contact Form 7 and Salesforce

36 - Integration for Contact Form 7 and Salesforce

Plugin -

Integration for Contact Form 7 and Salesforce


Plugin Slug -

cf7-salesforce


Installations -

2,000+


Vulnerability -

Open Redirection


Patched In Version -

1.3.4


Severity -

Medium


CVE Code -

2023-37982


Gift Cards (Gift Vouchers and Packages) (WooCommerce Supported)

37 - Gift Cards (Gift Vouchers and Packages) (WooCommerce Supported)

Plugin -

Gift Cards (Gift Vouchers and Packages) (WooCommerce Supported)


Plugin Slug -

gift-voucher


Installations -

2,000+


Vulnerability -

Cross-Site Request Forgery in new_voucher_template.php


Patched In Version -

4.3.6


Severity -

Medium


KB Support – WordPress Help Desk

38 - KB Support – WordPress Help Desk

Plugin -

KB Support – WordPress Help Desk


Plugin Slug -

kb-support


Installations -

2,000+


Vulnerability -

Broken Access Control


Patched In Version -

1.5.89


Severity -

Medium


CVE Code -

2023-37890


Short URL

39 - Short URL

Plugin -

Short URL


Plugin Slug -

shorten-url


Installations -

2,000+


Vulnerability -

Cross Site Scripting (XSS)


Patched In Version -

1.6.5


Severity -

Medium


CVE Code -

2023-3130


BuddyPress Builder for Elementor – BuddyBuilder

40 - BuddyPress Builder for Elementor – BuddyBuilder

Plugin -

BuddyPress Builder for Elementor – BuddyBuilder


Plugin Slug -

stax-buddy-builder


Installations -

2,000+


Vulnerability -

Cross Site Request Forgery (CSRF)


Patched In Version -

1.7.4


Severity -

Medium


Checkout with Zelle on Woocommerce

41 - Checkout with Zelle on Woocommerce

Plugin -

Checkout with Zelle on Woocommerce


Plugin Slug -

wc-zelle


Installations -

2,000+


Vulnerability -

Broken Access Control


Patched In Version -

3.1.1


Severity -

Medium


CVE Code -

2023-37969


Custom Field For WP Job Manager

42 - Custom Field For WP Job Manager

Plugin -

Custom Field For WP Job Manager


Plugin Slug -

custom-field-for-wp-job-manager


Installations -

1,000+


Vulnerability -

Cross Site Scripting (XSS)


Patched In Version -

1.2


Severity -

Medium


CVE Code -

2023-37980


DirectoryPress – Business Directory And Classified Ad Listing

43 - DirectoryPress – Business Directory And Classified Ad Listing

Plugin -

DirectoryPress – Business Directory And Classified Ad Listing


Plugin Slug -

directorypress


Installations -

1,000+


Vulnerability -

Broken Access Control


Patched In Version -

3.6.3


Severity -

Medium


CVE Code -

2023-37967


Falang multilanguage for WordPress

44 - Falang multilanguage for WordPress

Plugin -

Falang multilanguage for WordPress


Plugin Slug -

falang


Installations -

1,000+


Vulnerability -

Cross Site Request Forgery (CSRF)


Patched In Version -

1.3.40


Severity -

Medium


CVE Code -

2023-37968


45 - MF Gig Calendar

Plugin -

MF Gig Calendar


Plugin Slug -

mf-gig-calendar


Installations -

1,000+


Vulnerability -

Cross Site Scripting (XSS)


Patched In Version -

1.2.1


Severity -

Medium


CVE Code -

2023-37970


46 - WP Social AutoConnect

Plugin -

WP Social AutoConnect


Plugin Slug -

wp-fb-autoconnect


Installations -

1,000+


Vulnerability -

Cross Site Request Forgery (CSRF)


Patched In Version -

4.6.2


Severity -

Medium


CVE Code -

2023-37974


47 - MailArchiver

Plugin -

MailArchiver


Plugin Slug -

mailarchiver


Installations -

100+


Vulnerability -

Unauthenticated Stored Cross-Site Scripting via Email Subject


Patched In Version -

2.11.0


Severity -

High


CVE Code -

2023-3136


48 - CartFlows Pro

Plugin -

CartFlows Pro


Plugin Slug -

cartflows-pro


Vulnerability -

Reflected Cross Site Scripting (XSS)


Patched In Version -

1.11.12


Severity -

High


CVE Code -

2023-36686


49 - Grid Kit Premium

Plugin -

Grid Kit Premium


Plugin Slug -

grid-kit-premium


Vulnerability -

Multiple Reflected Cross Site Scripting (XSS)


Patched In Version -

2.2.0


Severity -

High


CVE Code -

2023-3292


50 - Premium Addons PRO

Plugin -

Premium Addons PRO


Plugin Slug -

premium-addons-pro


Vulnerability -

Broken Access Control


Patched In Version -

2.9.1


Severity -

Medium


CVE Code -

2023-37869


51 - Premium Addons PRO

Plugin -

Premium Addons PRO


Plugin Slug -

premium-addons-pro


Vulnerability -

Sensitive Data Exposure


Patched In Version -

2.9.1


Severity -

Medium


CVE Code -

2023-37868


52 - WooCommerce GoCardless Gateway

Plugin -

WooCommerce GoCardless Gateway


Plugin Slug -

woocommerce-gateway-gocardless


Vulnerability -

Unauth. Insecure Direct Object References (IDOR)


Patched In Version -

2.5.7


Severity -

High


CVE Code -

2023-37871


53 - WooCommerce Ship to Multiple Addresses

Plugin -

WooCommerce Ship to Multiple Addresses


Plugin Slug -

woocommerce-shipping-multiple-addresses


Vulnerability -

Reflected Cross Site Scripting (XSS)


Patched In Version -

3.8.6


Severity -

High


CVE Code -

2023-37873


54 - WooCommerce Ship to Multiple Addresses

Plugin -

WooCommerce Ship to Multiple Addresses


Plugin Slug -

woocommerce-shipping-multiple-addresses


Vulnerability -

Broken Access Control


Patched In Version -

3.8.6


Severity -

Medium


CVE Code -

2023-37872


55 - WooCommerce Warranty Requests

Plugin -

WooCommerce Warranty Requests


Plugin Slug -

woocommerce-warranty


Vulnerability -

Broken Access Control


Patched In Version -

2.2.0


Severity -

High


CVE Code -

2023-37870


Protect Your WordPress Website Today With Website Guardian

Join hundreds of businesses like yours who trust InterwebDEFENCE to protect their websites and livelihood. Using our proven website security analysis and best-in-class AI ‘Website Guardian” software, we are able to protect, monitor and backup your WordPress website.

Go ahead, keep the good guys In and the bad guys out – Click HERE to see our Website Guardian security plans NOW
PLUS
Find out about our unconditional ‘Double Protection’ Guarantee. This guarantee is better than risk free!

We’ll have you scanned, protected and secure in no time, giving you total peace of mind that your website is safe, leaving you to focus on your business success.

WordPress Plugin Vulnerabilities – Unpatched

Chat Button by GetButton.io

1 - Chat Button by GetButton.io

Plugin -

Chat Button by GetButton.io


Plugin Slug -

whatshelp-chat-button


Installations -

50,000+


Vulnerability -

Cross Site Scripting (XSS)


Patched In Version -

No Fix


Severity -

Medium


CVE Code -

2023-32292


Coming Soon Chop Chop

2 - Coming Soon Chop Chop

Plugin -

Coming Soon Chop Chop


Plugin Slug -

cc-coming-soon


Installations -

4,000+


Vulnerability -

Reflected Cross Site Scripting (XSS)


Patched In Version -

No Fix


Severity -

High


CVE Code -

2023-37893


Slider a SlidersPack – Image Slider, Post Slider, ACF Gallery Slider

3 - Slider a SlidersPack – Image Slider, Post Slider, ACF Gallery Slider

Plugin -

Slider a SlidersPack – Image Slider, Post Slider, ACF Gallery Slider


Plugin Slug -

sliderspack-all-in-one-image-sliders


Installations -

4,000+


Vulnerability -

Broken Access Control


Patched In Version -

No Fix


Severity -

Medium


CVE Code -

2022-46845


OptiMonk: Popups, Personalization & A/B Testing

4 - OptiMonk: Popups, Personalization & A/B Testing

Plugin -

OptiMonk: Popups, Personalization & A/B Testing


Plugin Slug -

exit-intent-popups-by-optimonk


Installations -

3,000+


Vulnerability -

Cross Site Request Forgery (CSRF)


Patched In Version -

No Fix


Severity -

Medium


CVE Code -

2023-37891


5 - Social Media Icons Widget

Plugin -

Social Media Icons Widget


Plugin Slug -

spoontalk-social-media-icons-widget


Installations -

3,000+


Vulnerability -

Cross Site Request Forgery (CSRF)


Patched In Version -

No Fix


Severity -

Medium


CVE Code -

2023-25036


Easyship WooCommerce Shipping Rates

6 - Easyship WooCommerce Shipping Rates

Plugin -

Easyship WooCommerce Shipping Rates


Plugin Slug -

easyship-woocommerce-shipping-rates


Installations -

2,000+


Vulnerability -

Broken Access Control


Patched In Version -

No Fix


Severity -

Medium


CVE Code -

2023-37989


School Management System – WPSchoolPress

7 - School Management System – WPSchoolPress

Plugin -

School Management System – WPSchoolPress


Plugin Slug -

wpschoolpress


Installations -

2,000+


Vulnerability -

Broken Access Control


Patched In Version -

No Fix


Severity -

Medium


CVE Code -

2023-37887


WPAdmin AWS CDN

8 - WPAdmin AWS CDN

Plugin -

WPAdmin AWS CDN


Plugin Slug -

aws-cdn-by-wpadmin


Installations -

1,000+


Vulnerability -

Cross Site Request Forgery (CSRF)


Patched In Version -

No Fix


Severity -

Medium


CVE Code -

2023-37889


Contact Form Generator : Creative form builder for WordPress

9 - Contact Form Generator : Creative form builder for WordPress

Plugin -

Contact Form Generator : Creative form builder for WordPress


Plugin Slug -

contact-form-generator


Installations -

1,000+


Vulnerability -

Reflected Cross Site Scripting (XSS)


Patched In Version -

No Fix


Severity -

High


CVE Code -

2023-37988


Contact Form to Any API

10 - Contact Form to Any API

Plugin -

Contact Form to Any API


Plugin Slug -

contact-form-to-any-api


Installations -

1,000+


Vulnerability -

SQL Injection


Patched In Version -

No Fix


Severity -

High


CVE Code -

2023-32741


Shortcode IMDB

11 - Shortcode IMDB

Plugin -

Shortcode IMDB


Plugin Slug -

shortcode-imdb


Installations -

1,000+


Vulnerability -

Cross Site Request Forgery (CSRF)


Patched In Version -

No Fix


Severity -

Medium


CVE Code -

2023-37892


Radio Forge Muses Player with Skins

12 - Radio Forge Muses Player with Skins

Plugin -

Radio Forge Muses Player with Skins


Plugin Slug -

radio-forge


Installations -

900+


Vulnerability -

Cross Site Scripting (XSS)


Patched In Version -

No Fix


Severity -

High


CVE Code -

2023-37976


Replace Word

13 - Replace Word

Plugin -

Replace Word


Plugin Slug -

replace-word


Installations -

900+


Vulnerability -

Cross Site Request Forgery (CSRF)


Patched In Version -

No Fix


Severity -

Medium


CVE Code -

2023-37973


14 - Art Direction

Plugin -

Art Direction


Plugin Slug -

art-direction


Installations -

800+


Vulnerability -

Cross Site Scripting (XSS)


Patched In Version -

No Fix


Severity -

Medium


CVE Code -

2023-37983


WPBulky – WordPress Bulk Edit Post Types

15 - WPBulky – WordPress Bulk Edit Post Types

Plugin -

WPBulky – WordPress Bulk Edit Post Types


Plugin Slug -

wpbulky-wp-bulk-edit-post-types


Installations -

200+


Vulnerability -

Cross Site Scripting (XSS)


Patched In Version -

No Fix


Severity -

Medium


CVE Code -

2023-30482


ShopConstruct – Product Catalog, Shopping Cart and eCommerce solution for Store

16 - ShopConstruct – Product Catalog, Shopping Cart and eCommerce solution for Store

Plugin -

ShopConstruct – Product Catalog, Shopping Cart and eCommerce solution for Store


Plugin Slug -

shopconstruct


Installations -

60+


Vulnerability -

Reflected Cross Site Scripting (XSS)


Patched In Version -

No Fix


Severity -

High


CVE Code -

2023-34011


17 - Dovetail

Plugin -

Dovetail


Plugin Slug -

dovetail


Installations -

10+


Vulnerability -

Cross Site Scripting (XSS)


Patched In Version -

No Fix


Severity -

Medium


CVE Code -

2023-25984


18 - YourMembership Single Sign On – YM SSO Login

Plugin -

YourMembership Single Sign On – YM SSO Login


Plugin Slug -

login-with-yourmembership


Installations -

10+


Vulnerability -

Broken Access Control


Patched In Version -

No Fix


Severity -

Medium


CVE Code -

2023-37987


19 - YourMembership Single Sign On – YM SSO Login

Plugin -

YourMembership Single Sign On – YM SSO Login


Plugin Slug -

login-with-yourmembership


Installations -

10+


Vulnerability -

Cross Site Scripting (XSS)


Patched In Version -

No Fix


Severity -

Medium


CVE Code -

2023-37986


Twittee Text Tweet

20 - Twittee Text Tweet

Plugin -

Twittee Text Tweet


Plugin Slug -

twittee-text-tweet


Installations -

10+


Vulnerability -

Reflected Cross Site Scripting (XSS)


Patched In Version -

No Fix


Severity -

High


CVE Code -

2023-0602


21 - Mail Control

Plugin -

Mail Control


Plugin Slug -

mail-control


Vulnerability -

Unauthenticated Stored Cross Site Scripting (XSS) via Email Subject


Patched In Version -

No Fix


Severity -

High


CVE Code -

2023-3158


PDQ CSV

22 - PDQ CSV

Plugin -

PDQ CSV


Plugin Slug -

pdq-csv


Vulnerability -

Cross Site Scripting (XSS)


Patched In Version -

No Fix


Severity -

Medium


CVE Code -

2023-31221


WP Default Feature Image

23 - WP Default Feature Image

Plugin -

WP Default Feature Image


Plugin Slug -

wp-default-feature-image


Vulnerability -

Cross Site Scripting (XSS)


Patched In Version -

No Fix


Severity -

Medium


CVE Code -

2023-25488


Protect Your WordPress Website Today With Website Guardian

Join hundreds of businesses like yours who trust InterwebDEFENCE to protect their websites and livelihood. Using our proven website security analysis and best-in-class AI ‘Website Guardian” software, we are able to protect, monitor and backup your WordPress website.

Go ahead, keep the good guys In and the bad guys out – Click HERE to see our Website Guardian security plans NOW
PLUS
Find out about our unconditional ‘Double Protection’ Guarantee. This guarantee is better than risk free!

We’ll have you scanned, protected and secure in no time, giving you total peace of mind that your website is safe, leaving you to focus on your business success.

WordPress Theme Vulnerabilities

1 - RealHomes

Theme -

RealHomes


Theme Slug -

realhomes


Vulnerability -

Broken Access Control


Patched In Version -

No Fix


Severity -

Medium


CVE Code -

2023-37886


2 - RealHomes

Theme -

RealHomes


Theme Slug -

realhomes


Vulnerability -

Broken Access Control


Patched In Version -

No Fix


Severity -

Medium


CVE Code -

2023-37885


Protect Your WordPress Website Today With Website Guardian

Join hundreds of businesses like yours who trust InterwebDEFENCE to protect their websites and livelihood. Using our proven website security analysis and best-in-class AI ‘Website Guardian” software, we are able to protect, monitor and backup your WordPress website.

Go ahead, keep the good guys In and the bad guys out – Click HERE to see our Website Guardian security plans NOW
PLUS
Find out about our unconditional ‘Double Protection’ Guarantee. This guarantee is better than risk free!

We’ll have you scanned, protected and secure in no time, giving you total peace of mind that your website is safe, leaving you to focus on your business success.

Click to access the login or register cheese