WordPress Vulnerability Report: August 2021, Part 2

by | Aug 11, 2021 | Security

Written by Michael Moore of Ithemes on August 11, 2021

Last Updated on August 11, 2021

Vulnerable plugins and themes are the #1 reason WordPress websites get hacked. This post covers recent WordPress plugin, theme, and core vulnerabilities and what to do if you run one of the vulnerable plugins or themes on your website.

Each vulnerability will have a severity rating of Low, Medium, High, or Critical. Responsible disclosure and reporting of vulnerabilities is an integral part of keeping the WordPress community safe. Please share this post with your friends to help get the word out and make WordPress safer for everyone.


Is Your WordPress Website Secure?

DID YOU KNOW – A staggering 83% of WordPress websites are not upgraded or updated, is your website one of these?

Hacks happen due to lack of website upkeep and protection, like updating WordPress or plugins, plus using weak passwords. Contrary to popular belief, web designers and website hosting companies are not responsible for the security of your WordPress website; you are. It’s like using your computer without Anti-virus!


WordPress Core Vulnerabilities
No new WordPress core vulnerabilities have been disclosed so far in June 2021.

WordPress Theme Vulnerabilities

WordPress Plugin Vulnerabilities

1. Sitewide Notice WP
2. Business Hours Indicator
3. Bold Page Builder
4. ShareThis Dashboard for Google Analytics
5. StoryChief
6. WP LMS
7. VDZ Google Analytics or Google Tag Manager / GTM
8. Cooked
9. Email Encoder – Protect Email Addresses
10. SMS Alert Order Notifications – WooCommerce
11. HM Multiple Roles
12. WP Customise Login
13. User Rights Access Manager
14. JiangQie Official Website Mini Program
15. Welcart e-Commerce
16. Highlight
17. Cookie Notice & Consent Banner for GDPR & CCPA Compliance
18. Pods


WordPress Plugin Vulnerabilities

1. Sitenote Notice WP


Plugin: Sitewide Notice WP
Vulnerability: Authenticated Stored XSS
Patched in Version: 2.3
Severity: Low

2. Business Hours Indicator


Plugin: Business Hours Indicator
Vulnerability: Authenticated Stored XSS
Patched in Version: 2.3.5
Severity: Low

3. Bold Page Builder


Plugin: Bold Page Builder
Vulnerability: PHP Object Injection
Patched in Version: 3.1.6
Severity: Medium

4. ShareThis Dashboard for Google Analytics


Plugin: ShareThis Dashboard for Google Analytics
Vulnerability: Authenticated Stored (XSS)
Patched in Version: 2.5.2
Severity: High

5. StoryChief


Plugin: StoryChief
Vulnerability: Reflected Cross-Site Scripting (XSS)
Patched in Version: 1.0.31
Severity: High

6. WP LMS


Plugin: WP LMS
Vulnerability: Unauthenticated Arbitrary User Field Edition/Creation
Patched in Version: 1.1.5
Severity: Medium

7. VDZ Google Analytics or Google Tag Manager / GTM


Plugin: VDZ Google Analytics or Google Tag Manager / GTM
Vulnerability: Authenticated Stored XSS
Patched in Version: 1.6.0
Severity: Low

Plugin: VDZ Google Analytics or Google Tag Manager / GTM
Vulnerability: Authenticated Stored XSS
Patched in Version: 1.4.9
Severity: Low

8. Cooked


Plugin: Cooked
Vulnerability: Unauthenticated Reflected Cross-Site Scripting (XSS)
Patched in Version: 1.7.9.1
Severity: Medium

9. Email Encoder – Protect Email Addresses


Plugin: Email Encoder – Protect Email Addresses
Vulnerability: Reflected Cross Site Scripting
Patched in Version: 2.1.2
Severity: Medium

10. SMS Alert Order Notifcations – WooCommerce


Plugin: SMS Alert Order Notifications – WooCommerce
Vulnerability: Authenticated Cross Site Scripting
Patched in Version: 3.4.7
Severity: Low

11. HM Multiple Roles


Plugin: HM Multiple Roles
Vulnerability: Arbitrary Role Change
Patched in Version: 1.3
Severity: Critical

12. WP Customize Login


Plugin: WP Customize Login
Vulnerability: Authenticated Stored Cross-Site Scripting (XSS)
Patched in Version: No known fix
Severity: Low

13. User Rights Access Manager


Plugin: User Rights Access Manager
Vulnerability: Access Restriction Bypass
Patched in Version: No known fix
Severity: Medium

14. JiangQie Official Website Mini Program


Plugin: JiangQie Official Website Mini Program
Vulnerability: Authenticated SQL Injection
Patched in Version: 1.1.1
Severity: Critical

15. Welcart e-Commerce


Plugin: Welcart e-Commerce
Vulnerability: Unauthenticated Information Disclosure
Patched in Version: 2.2.8
Severity: High

Plugin: Welcart e-Commerce
Vulnerability: Authenticated System Information Disclosure
Patched in Version: 2.2.8
Severity: Medium

16. Highlight


Plugin: Highlight
Vulnerability: Authenticated Stored Cross-Site Scripting
Patched in Version: 0.9.3
Severity: Critical

17. Cookie Notice & Consent Banner for GDPR & CCPA Compliance


Plugin: Cookie Notice & Consent Banner for GDPR & CCPA Compliance
Vulnerability: Authenticated Stored XSS
Patched in Version: 1.7.2
Severity: Low

18. Pods


Plugin: Pods
Vulnerability: Multiple Authenticated Stored Cross-Site Scripting (XSS)
Patched in Version: 2.7.29
Severity: Low


Protect Your WordPress Website Today With Website Guardian

Join hundreds of businesses like yours who trust InterwebDEFENCE to protect their websites and livelihood. Using our proven website security analysis and best-in-class AI ‘Website Guardian” software, we are able to protect, monitor and backup your WordPress website.

Go ahead, keep the good guys In and the bad guys out – Click HERE to see our Website Guardian security plans NOW
PLUS
Find out about our unconditional ‘Double Protection’ Guarantee. This guarantee is better than risk free!

We’ll have you scanned, protected and secure in no time, giving you total peace of mind that your website is safe, leaving you to focus on your business success.

Click to access the login or register cheese