WordPress Vulnerability Roundup: Nov 2020, Part 2
Written by Michael Moore of iThemes on November 25, 2020
Last Updated on March 9, 2021
New WordPress plugin and theme vulnerabilities were disclosed during the second half of November. This post covers the recent WordPress plugin, theme, and core vulnerabilities and what to do if you run one of the vulnerable plugins or themes on your website.
The WordPress Vulnerability Roundup is divided into three different categories: WordPress core, WordPress plugins, and WordPress themes.
Is Your WordPress Website Secure?
DID YOU KNOW – A staggering 83% of WordPress websites are not upgraded or updated, is your website one of these?
Hacks happen due to lack of website upkeep and protection, like updating WordPress or plugins, plus using weak passwords. Contrary to popular belief, web designers and website hosting companies are not responsible for the security of your WordPress website; you are. It’s like using your computer without Anti-virus!
WordPress Core Vulnerabilities
Good news! No new WordPress core vulnerabilities disclosed in November.
WordPress Theme Vulnerabilities
1. Love Travel
WordPress Plugin Vulnerabilities
1. Good LMS
2. BA Book Everything
3. AIT CSV Import / Export
4. Fancy Product Designer
5. Contextual Related Posts
6. Import and export users and customers
7. Easy Registration Forms
8. Spam protection, AntiSpam, FireWall by CleanTalk
9. Secure File Manager
10. Media Library Assistant
11. WooCommerce Anti-Fraud
WordPress Plugin Vulnerabilities
1. Good LMS

Good LMS versions below 2.1.5 have an Unauthenticated SQL Injection vulnerability.
The vulnerability is patched, and you should update to version 2.1.5.
2. BA Book Everything

BA Book Everything versions below 1.3.25 have Unauthenticated Reflected XSS & XFS vulnerabilities.
The vulnerability is patched, and you should update to version 1.3.25.
3. AIT CSV Import / Export
All versions of AIT CSV Import / Export have an Unauthenticated Arbitrary File Upload vulnerability.
Remove the plugin until a security fix is released.
4. Fancy Product Designer
Fancy Product Designer versions below 4.5.1 have an Unauthenticated Stored Cross-Site Scripting vulnerability.
The vulnerability is patched, and you should update to version 4.5.1.
5. Contextual Related Posts

Contextual Related Posts versions below 2.9.4 have an CSRF Nonce Validation Bypass vulnerability.
The vulnerability is patched, and you should update to version 2.9.4.
6. Import and export users and customers

Import and export users and customers versions below 1.16.3.6 have a CSV Injection vulnerability.
The vulnerability is patched, and you should update to version 1.16.3.6.
7. Easy Registration Forms

Easy Registration Forms versions below 2.0.6 have an CSV Injection vulnerability.
The vulnerability is patched, and you should update to version 2.0.6.
8. Spam protection, AntiSpam, FireWall by CleanTalk

Spam protection, AntiSpam, FireWall by CleanTalk versions below 5.149 have Multiple Authenticated SQL Injections vulnerabilities.
The vulnerability is patched, and you should update to version 5.149.
9. Secure File Manager

All version of Secure File Manager have an Authenticated Remote Command Execution vulnerability.
Remove the plugin until a security fix is released.
10. Media Library Assistant

Media Library Assistant versions below 2.90 have an Authenticated Blind SQL Injection vulnerability.
The vulnerability is patched, and you should update to version 2.90.
11. WooCommerce Anti-Fraud

WooCommerce Anti-Fraud versions below 3.3 have an Unauthenticated Order Status Manipulation vulnerability.
The vulnerability is patched, and you should update to version 3,3.
WordPress Theme Vulnerabilities
1. Love Travel

Love Travel versions below 3.8 have Unauthenticated Reflected XSS & XFS vulnerabilities.
The vulnerability is patched, and you should update to version 3.8.
Protect Your WordPress Website Today With Website Guardian
Join hundreds of businesses like yours who trust InterwebDEFENCE to protect their websites and livelihood. Using our proven website security analysis and best-in-class AI ‘Website Guardian” software, we are able to protect, monitor and backup your WordPress website.
Go ahead, keep the good guys In and the bad guys out – Click HERE to see our Website Guardian security plans NOW
PLUS
Find out about our unconditional ‘Double Protection’ Guarantee. This guarantee is better than risk free!
We’ll have you scanned, protected and secure in no time, giving you total peace of mind that your website is safe, leaving you to focus on your business success.