WordPress Vulnerability Report – August 23, 2023

by | Aug 23, 2023 | Security

DETAILS FROM DAN KNAUSS OF ITHEMES ON AUGUST 23, 2023

original available here

Last Updated on August 23, 2023

 

Since last week, 89 total vulnerabilities emerged in public disclosure. They may affect over one million WordPress sites. There are 43 plugin vulnerabilities and five theme vulnerabilities with security patches, so run those updates!

Additionally, there are 37 plugin vulnerabilities and four theme vulnerabilities with no patch available yet. If you use an unpatched plugin or theme, check their vendors’ intentions and progress on a security release. Suppose no patch is forthcoming or the vulnerable software has been marked “closed” and dropped from the official WordPress theme and plugin repositories. In that case, you should consider deactivation and removal in favor of alternative solutions.

Is Your WordPress Website Secure?

DID YOU KNOW – A staggering 83% of WordPress websites are not upgraded or updated, is your website one of these?

Hacks happen due to lack of website upkeep and protection, like updating WordPress or plugins, plus using weak passwords. Contrary to popular belief, web designers and website hosting companies are not responsible for the security of your WordPress website; you are. It’s like using your computer without Anti-virus!

WordPress Core Vulnerabilities

No new WordPress core vulnerabilities were disclosed this week. 

WordPress Theme Vulnerabilities

Jump to section

These are vulnerabilities that have occoured in themes for wordpress. If there is a patch for the issue you should update the theme immediately, if there is no fix you should change your site to a different theme.

WordPress Plugin Vulnerabilities – Patched

InfiniteWP Client

1 - InfiniteWP Client

Plugin -

InfiniteWP Client


Plugin Slug -

iwp-client


Installations -

300,000+


Vulnerability -

Sensitive Data Exposure


Patched In Version -

1.12.1


Severity -

High


CVE Code -

2023-2916


Advanced File Manager

2 - Advanced File Manager

Plugin -

Advanced File Manager


Plugin Slug -

file-manager-advanced


Installations -

100,000+


Vulnerability -

Sensitive Data Exposure


Patched In Version -

5.1.1


Severity -

Medium


CVE Code -

2023-3814


Blog2Social: Social Media Auto Post & Scheduler

3 - Blog2Social: Social Media Auto Post & Scheduler

Plugin -

Blog2Social: Social Media Auto Post & Scheduler


Plugin Slug -

blog2social


Installations -

70,000+


Vulnerability -

Cross Site Scripting (XSS)


Patched In Version -

7.2.1


Severity -

High


CVE Code -

2023-40554


wpDataTables – WordPress Data Table, Dynamic Tables & Table Charts Plugin

4 - wpDataTables – WordPress Data Table, Dynamic Tables & Table Charts Plugin

Plugin -

wpDataTables – WordPress Data Table, Dynamic Tables & Table Charts Plugin


Plugin Slug -

wpdatatables


Installations -

70,000+


Vulnerability -

PHP Object Injection


Patched In Version -

2.1.66


Severity -

Medium


WP-PostRatings

5 - WP-PostRatings

Plugin -

WP-PostRatings


Plugin Slug -

wp-postratings


Installations -

50,000+


Vulnerability -

Bypass Vulnerability


Patched In Version -

1.91.1


Severity -

Medium


CVE Code -

2023-40332


Cost Calculator Builder

6 - Cost Calculator Builder

Plugin -

Cost Calculator Builder


Plugin Slug -

cost-calculator-builder


Installations -

30,000+


Vulnerability -

Broken Access Control


Patched In Version -

3.1.43


Severity -

Medium


CVE Code -

2023-40011


Countdown Timer Ultimate

7 - Countdown Timer Ultimate

Plugin -

Countdown Timer Ultimate


Plugin Slug -

countdown-timer-ultimate


Installations -

20,000+


Vulnerability -

Broken Access Control


Patched In Version -

2.4.1


Severity -

Medium


CVE Code -

2023-40200


Media from FTP

8 - Media from FTP

Plugin -

Media from FTP


Plugin Slug -

media-from-ftp


Installations -

20,000+


Vulnerability -

Settings Change


Patched In Version -

11.17


Severity -

Low


CVE Code -

2023-4019


User Submitted Posts – Enable Users to Submit Posts from the Front End

9 - User Submitted Posts – Enable Users to Submit Posts from the Front End

Plugin -

User Submitted Posts – Enable Users to Submit Posts from the Front End


Plugin Slug -

user-submitted-posts


Installations -

20,000+


Vulnerability -

Cross Site Scripting (XSS)


Patched In Version -

20230811


Severity -

High


CVE Code -

2023-4308


Album and Image Gallery plus Lightbox

10 - Album and Image Gallery plus Lightbox

Plugin -

Album and Image Gallery plus Lightbox


Plugin Slug -

album-and-image-gallery-plus-lightbox


Installations -

10,000+


Vulnerability -

Broken Access Control


Patched In Version -

1.7.1


Severity -

Medium


CVE Code -

2023-40200


Cookies and Content Security Policy

11 - Cookies and Content Security Policy

Plugin -

Cookies and Content Security Policy


Plugin Slug -

cookies-and-content-security-policy


Installations -

10,000+


Vulnerability -

Sensitive Data Exposure


Patched In Version -

2.16


Severity -

Medium


CVE Code -

2023-40662


Stripe Payment Plugin for WooCommerce

12 - Stripe Payment Plugin for WooCommerce

Plugin -

Stripe Payment Plugin for WooCommerce


Plugin Slug -

payment-gateway-stripe-and-woocommerce-integration


Installations -

10,000+


Vulnerability -

Broken Access Control


Patched In Version -

3.8.0


Severity -

Medium


CVE Code -

2023-4040


Smart SEO Tool – SEO

13 - Smart SEO Tool – SEO

Plugin -

Smart SEO Tool – SEO


Plugin Slug -

smart-seo-tool


Installations -

10,000+


Vulnerability -

Cross Site Request Forgery (CSRF)


Patched In Version -

4.0.2


Severity -

Medium


Orders Tracking for WooCommerce

14 - Orders Tracking for WooCommerce

Plugin -

Orders Tracking for WooCommerce


Plugin Slug -

woo-orders-tracking


Installations -

10,000+


Vulnerability -

Directory Traversal


Patched In Version -

1.2.6


Severity -

Low


CVE Code -

2023-4216


Testimonial Grid and Testimonial Slider plus Carousel with Rotator Widget

15 - Testimonial Grid and Testimonial Slider plus Carousel with Rotator Widget

Plugin -

Testimonial Grid and Testimonial Slider plus Carousel with Rotator Widget


Plugin Slug -

wp-testimonial-with-widget


Installations -

10,000+


Vulnerability -

Broken Access Control


Patched In Version -

3.3.1


Severity -

Medium


CVE Code -

2023-40200


WP VR – 360 Panorama and Virtual Tour Builder For WordPress

16 - WP VR – 360 Panorama and Virtual Tour Builder For WordPress

Plugin -

WP VR – 360 Panorama and Virtual Tour Builder For WordPress


Plugin Slug -

wpvr


Installations -

10,000+


Vulnerability -

Cross Site Scripting (XSS)


Patched In Version -

8.3.5


Severity -

High


CVE Code -

2023-40663


Blog Designer – Post and Widget

17 - Blog Designer – Post and Widget

Plugin -

Blog Designer – Post and Widget


Plugin Slug -

blog-designer-for-post-and-widget


Installations -

8,000+


Vulnerability -

Broken Access Control


Patched In Version -

2.5.2


Severity -

Medium


CVE Code -

2023-40200


WP Remote Users Sync

18 - WP Remote Users Sync

Plugin -

WP Remote Users Sync


Plugin Slug -

wp-remote-users-sync


Installations -

8,000+


Vulnerability -

Broken Access Control


Patched In Version -

1.2.12


Severity -

Medium


CVE Code -

2023-4374


WP Remote Users Sync

19 - WP Remote Users Sync

Plugin -

WP Remote Users Sync


Plugin Slug -

wp-remote-users-sync


Installations -

8,000+


Vulnerability -

Server Side Request Forgery (SSRF)


Patched In Version -

1.2.13


Severity -

High


CVE Code -

2023-3958


Meta Slider and Carousel with Lightbox

20 - Meta Slider and Carousel with Lightbox

Plugin -

Meta Slider and Carousel with Lightbox


Plugin Slug -

meta-slider-and-carousel-with-lightbox


Installations -

7,000+


Vulnerability -

Broken Access Control


Patched In Version -

1.8.3


Severity -

Medium


CVE Code -

2023-40200


Plausible Analytics

21 - Plausible Analytics

Plugin -

Plausible Analytics


Plugin Slug -

plausible-analytics


Installations -

7,000+


Vulnerability -

Cross Site Scripting (XSS)


Patched In Version -

1.3.4


Severity -

Medium


CVE Code -

2023-40553


Post grid and filter ultimate

22 - Post grid and filter ultimate

Plugin -

Post grid and filter ultimate


Plugin Slug -

post-grid-and-filter-ultimate


Installations -

7,000+


Vulnerability -

Broken Access Control


Patched In Version -

1.5.3


Severity -

Medium


CVE Code -

2023-40200


Timeline and History slider

23 - Timeline and History slider

Plugin -

Timeline and History slider


Plugin Slug -

timeline-and-history-slider


Installations -

6,000+


Vulnerability -

Broken Access Control


Patched In Version -

2.1.1


Severity -

Medium


CVE Code -

2023-40200


JS Help Desk – Best Help Desk & Support Plugin

24 - JS Help Desk – Best Help Desk & Support Plugin

Plugin -

JS Help Desk – Best Help Desk & Support Plugin


Plugin Slug -

js-support-ticket


Installations -

5,000+


Vulnerability -

Arbitrary File Upload


Patched In Version -

2.7.8


Severity -

Critical


CVE Code -

2023-25444


Team Slider and Team Grid Showcase plus Team Carousel

25 - Team Slider and Team Grid Showcase plus Team Carousel

Plugin -

Team Slider and Team Grid Showcase plus Team Carousel


Plugin Slug -

wp-team-showcase-and-slider


Installations -

4,000+


Vulnerability -

Broken Access Control


Patched In Version -

2.6.1


Severity -

Medium


CVE Code -

2023-40200


Trending/Popular Post Slider and Widget

26 - Trending/Popular Post Slider and Widget

Plugin -

Trending/Popular Post Slider and Widget


Plugin Slug -

wp-trending-post-slider-and-widget


Installations -

4,000+


Vulnerability -

Broken Access Control


Patched In Version -

1.6.1


Severity -

Medium


CVE Code -

2023-40200


Video Gallery for YouTube Videos and WordPress

27 - Video Gallery for YouTube Videos and WordPress

Plugin -

Video Gallery for YouTube Videos and WordPress


Plugin Slug -

youtube-showcase


Installations -

4,000+


Vulnerability -

Cross Site Request Forgery (CSRF)


Patched In Version -

3.3.6


Severity -

Medium


CVE Code -

2023-40558


Accordion and Accordion Slider

28 - Accordion and Accordion Slider

Plugin -

Accordion and Accordion Slider


Plugin Slug -

accordion-and-accordion-slider


Installations -

3,000+


Vulnerability -

Broken Access Control


Patched In Version -

1.2.5


Severity -

Medium


CVE Code -

2023-40200


29 - DoLogin Security

Plugin -

DoLogin Security


Plugin Slug -

dologin


Installations -

3,000+


Vulnerability -

Bypass Vulnerability


Patched In Version -

3.7


Severity -

Medium


Video gallery and Player

30 - Video gallery and Player

Plugin -

Video gallery and Player


Plugin Slug -

html5-videogallery-plus-player


Installations -

3,000+


Vulnerability -

Broken Access Control


Patched In Version -

2.6.6


Severity -

Medium


CVE Code -

2023-40200


WooCommerce PDF Invoice Builder, Create invoices, packing slips and more

31 - WooCommerce PDF Invoice Builder, Create invoices, packing slips and more

Plugin -

WooCommerce PDF Invoice Builder, Create invoices, packing slips and more


Plugin Slug -

woo-pdf-invoice-builder


Installations -

3,000+


Vulnerability -

Broken Access Control


Patched In Version -

1.2.92


Severity -

Medium


CVE Code -

2023-4245


WooCommerce PDF Invoice Builder, Create invoices, packing slips and more

32 - WooCommerce PDF Invoice Builder, Create invoices, packing slips and more

Plugin -

WooCommerce PDF Invoice Builder, Create invoices, packing slips and more


Plugin Slug -

woo-pdf-invoice-builder


Installations -

3,000+


Vulnerability -

Cross Site Scripting (XSS)


Patched In Version -

1.2.91


Severity -

Medium


CVE Code -

2023-4160


WooCommerce PDF Invoice Builder, Create invoices, packing slips and more

33 - WooCommerce PDF Invoice Builder, Create invoices, packing slips and more

Plugin -

WooCommerce PDF Invoice Builder, Create invoices, packing slips and more


Plugin Slug -

woo-pdf-invoice-builder


Installations -

3,000+


Vulnerability -

Cross Site Request Forgery (CSRF)


Patched In Version -

1.2.91


Severity -

Medium


CVE Code -

2023-4161


Accordion Slider

34 - Accordion Slider

Plugin -

Accordion Slider


Plugin Slug -

accordion-slider


Installations -

2,000+


Vulnerability -

Broken Access Control


Patched In Version -

1.9.7


Severity -

Medium


CVE Code -

2023-40331


35 - Doofinder WP & WooCommerce Search

Plugin -

Doofinder WP & WooCommerce Search


Plugin Slug -

doofinder-for-woocommerce


Installations -

2,000+


Vulnerability -

Open Redirection


Patched In Version -

2.0.0


Severity -

Medium


CVE Code -

2023-40602


Portfolio and Projects

36 - Portfolio and Projects

Plugin -

Portfolio and Projects


Plugin Slug -

portfolio-and-projects


Installations -

2,000+


Vulnerability -

Broken Access Control


Patched In Version -

1.3.8


Severity -

Medium


CVE Code -

2023-40200


Post Ticker Ultimate

37 - Post Ticker Ultimate

Plugin -

Post Ticker Ultimate


Plugin Slug -

ticker-ultimate


Installations -

2,000+


Vulnerability -

Broken Access Control


Patched In Version -

1.5.6


Severity -

Medium


CVE Code -

2023-40200


CLUEVO LMS, E-Learning Platform

38 - CLUEVO LMS, E-Learning Platform

Plugin -

CLUEVO LMS, E-Learning Platform


Plugin Slug -

cluevo-lms


Installations -

700+


Vulnerability -

Cross Site Request Forgery (CSRF)


Patched In Version -

1.11.0


Severity -

Medium


CVE Code -

2023-40607


Serial Codes Generator and Validator with WooCommerce Support

39 - Serial Codes Generator and Validator with WooCommerce Support

Plugin -

Serial Codes Generator and Validator with WooCommerce Support


Plugin Slug -

serial-codes-generator-and-validator


Installations -

600+


Vulnerability -

Cross Site Scripting (XSS)


Patched In Version -

2.4.15


Severity -

Medium


Event Tickets with Ticket Scanner

40 - Event Tickets with Ticket Scanner

Plugin -

Event Tickets with Ticket Scanner


Plugin Slug -

event-tickets-with-ticket-scanner


Installations -

500+


Vulnerability -

Cross Site Scripting (XSS)


Patched In Version -

1.5.5


Severity -

Medium


Products Quick View for WooCommerce

41 - Products Quick View for WooCommerce

Plugin -

Products Quick View for WooCommerce


Plugin Slug -

woocommerce-products-quick-view


Installations -

100+


Vulnerability -

Broken Access Control


Patched In Version -

2.3.0


Severity -

Medium


123.chat – 1:1 Live Video Chat Tool Plugin

42 - 123.chat – 1:1 Live Video Chat Tool Plugin

Plugin -

123.chat – 1:1 Live Video Chat Tool Plugin


Plugin Slug -

123-chat-videochat


Installations -

40+


Vulnerability -

Cross Site Scripting (XSS)


Patched In Version -

1.3.1


Severity -

Medium


CVE Code -

2023-4298


43 - Paid Memberships Pro CCBill Gateway

Plugin -

Paid Memberships Pro CCBill Gateway


Plugin Slug -

pmpro-ccbill


Vulnerability -

Broken Access Control


Patched In Version -

0.4


Severity -

High


CVE Code -

2023-40608


Protect Your WordPress Website Today With Website Guardian

Join hundreds of businesses like yours who trust InterwebDEFENCE to protect their websites and livelihood. Using our proven website security analysis and best-in-class AI ‘Website Guardian” software, we are able to protect, monitor and backup your WordPress website.

Go ahead, keep the good guys In and the bad guys out – Click HERE to see our Website Guardian security plans NOW
PLUS
Find out about our unconditional ‘Double Protection’ Guarantee. This guarantee is better than risk free!

We’ll have you scanned, protected and secure in no time, giving you total peace of mind that your website is safe, leaving you to focus on your business success.

WordPress Plugin Vulnerabilities – Unpatched

Simple URLs – Link Cloaking, Product Displays, and Affiliate Link Management

1 - Simple URLs – Link Cloaking, Product Displays, and Affiliate Link Management

Plugin -

Simple URLs – Link Cloaking, Product Displays, and Affiliate Link Management


Plugin Slug -

simple-urls


Installations -

5,000+


Vulnerability -

Broken Access Control


Patched In Version -

No Fix


Severity -

Medium


CVE Code -

2023-40678


Simple URLs – Link Cloaking, Product Displays, and Affiliate Link Management

2 - Simple URLs – Link Cloaking, Product Displays, and Affiliate Link Management

Plugin -

Simple URLs – Link Cloaking, Product Displays, and Affiliate Link Management


Plugin Slug -

simple-urls


Installations -

5,000+


Vulnerability -

Cross Site Scripting (XSS)


Patched In Version -

No Fix


Severity -

Medium


CVE Code -

2023-40674


Simple URLs – Link Cloaking, Product Displays, and Affiliate Link Management

3 - Simple URLs – Link Cloaking, Product Displays, and Affiliate Link Management

Plugin -

Simple URLs – Link Cloaking, Product Displays, and Affiliate Link Management


Plugin Slug -

simple-urls


Installations -

5,000+


Vulnerability -

Cross Site Scripting (XSS)


Patched In Version -

No Fix


Severity -

High


CVE Code -

2023-40667


Enhanced Ecommerce Google Analytics for WooCommerce

4 - Enhanced Ecommerce Google Analytics for WooCommerce

Plugin -

Enhanced Ecommerce Google Analytics for WooCommerce


Plugin Slug -

woo-ecommerce-tracking-for-google-and-facebook


Installations -

3,000+


Vulnerability -

Cross Site Request Forgery (CSRF)


Patched In Version -

No Fix


Severity -

Medium


CVE Code -

2023-40561


GD Security Headers

5 - GD Security Headers

Plugin -

GD Security Headers


Plugin Slug -

gd-security-headers


Installations -

2,000+


Vulnerability -

Cross Site Scripting (XSS)


Patched In Version -

No Fix


Severity -

High


CVE Code -

2023-40330


6 - WP LINE Notify

Plugin -

WP LINE Notify


Plugin Slug -

wp-line-notify


Installations -

2,000+


Vulnerability -

Cross Site Scripting (XSS)


Patched In Version -

No Fix


Severity -

High


CVE Code -

2023-30497


fitness calculators plugin

7 - fitness calculators plugin

Plugin -

fitness calculators plugin


Plugin Slug -

fitness-calculators


Installations -

1,000+


Vulnerability -

Cross Site Scripting (XSS)


Patched In Version -

No Fix


Severity -

Medium


CVE Code -

2023-40552


Kanban Boards for WordPress

8 - Kanban Boards for WordPress

Plugin -

Kanban Boards for WordPress


Plugin Slug -

kanban


Installations -

1,000+


Vulnerability -

Arbitrary Code Execution


Patched In Version -

No Fix


Severity -

Critical


CVE Code -

2023-40606


9 - Save as PDF plugin by Pdfcrowd

Plugin -

Save as PDF plugin by Pdfcrowd


Plugin Slug -

save-as-pdf-by-pdfcrowd


Installations -

1,000+


Vulnerability -

Cross Site Scripting (XSS)


Patched In Version -

No Fix


Severity -

Medium


CVE Code -

2023-40668


Schedule Posts Calendar

10 - Schedule Posts Calendar

Plugin -

Schedule Posts Calendar


Plugin Slug -

schedule-posts-calendar


Installations -

1,000+


Vulnerability -

Cross Site Request Forgery (CSRF)


Patched In Version -

No Fix


Severity -

Medium


CVE Code -

2023-40556


Schedule Posts Calendar

11 - Schedule Posts Calendar

Plugin -

Schedule Posts Calendar


Plugin Slug -

schedule-posts-calendar


Installations -

1,000+


Vulnerability -

Cross Site Scripting (XSS)


Patched In Version -

No Fix


Severity -

Medium


CVE Code -

2023-40560


Tabs & Accordion

12 - Tabs & Accordion

Plugin -

Tabs & Accordion


Plugin Slug -

tabs


Installations -

1,000+


Vulnerability -

Content Injection


Patched In Version -

No Fix


Severity -

Medium


CVE Code -

2023-40557


Dynamic Pricing and Discount Rules for WooCommerce

13 - Dynamic Pricing and Discount Rules for WooCommerce

Plugin -

Dynamic Pricing and Discount Rules for WooCommerce


Plugin Slug -

woo-conditional-discount-rules-for-checkout


Installations -

1,000+


Vulnerability -

Cross Site Request Forgery (CSRF)


Patched In Version -

No Fix


Severity -

Medium


CVE Code -

2023-40559


RSVPMaker

14 - RSVPMaker

Plugin -

RSVPMaker


Plugin Slug -

rsvpmaker


Installations -

400+


Vulnerability -

Cross Site Scripting (XSS)


Patched In Version -

No Fix


Severity -

High


CVE Code -

2023-27616


RSVPMaker

15 - RSVPMaker

Plugin -

RSVPMaker


Plugin Slug -

rsvpmaker


Installations -

400+


Vulnerability -

Cross Site Scripting (XSS)


Patched In Version -

No Fix


Severity -

Medium


CVE Code -

2023-27617


16 - Save as Image plugin by Pdfcrowd

Plugin -

Save as Image plugin by Pdfcrowd


Plugin Slug -

save-as-image-by-pdfcrowd


Installations -

50+


Vulnerability -

Cross Site Scripting (XSS)


Patched In Version -

No Fix


Severity -

Medium


CVE Code -

2023-40665


17 - Typing Effect

Plugin -

Typing Effect


Plugin Slug -

animated-typing-effect


Vulnerability -

Cross Site Scripting (XSS)


Patched In Version -

No Fix


Severity -

Medium


CVE Code -

2023-40605


18 - Password Reset with Code for WordPress REST API

Plugin -

Password Reset with Code for WordPress REST API


Plugin Slug -

bdvs-password-reset


Vulnerability -

Broken Authentication


Patched In Version -

No Fix


Severity -

Critical


CVE Code -

2023-35039


19 - BigBlueButton

Plugin -

BigBlueButton


Plugin Slug -

bigbluebutton


Vulnerability -

Cross Site Scripting (XSS)


Patched In Version -

No Fix


Severity -

Medium


20 - Carrot

Plugin -

Carrot


Plugin Slug -

carrrot


Vulnerability -

Cross Site Scripting (XSS)


Patched In Version -

No Fix


Severity -

Medium


CVE Code -

2023-40328


21 - Cartpauj Register Captcha

Plugin -

Cartpauj Register Captcha


Plugin Slug -

cartpauj-register-captcha


Vulnerability -

Bypass Vulnerability


Patched In Version -

No Fix


Severity -

Medium


CVE Code -

2023-40673


22 - Contact form 7 Custom validation

Plugin -

Contact form 7 Custom validation


Plugin Slug -

cf7-field-validation


Vulnerability -

SQL Injection


Patched In Version -

No Fix


Severity -

High


CVE Code -

2023-40609


23 - Cleverwise Daily Quotes

Plugin -

Cleverwise Daily Quotes


Plugin Slug -

cleverwise-daily-quotes


Vulnerability -

Cross Site Scripting (XSS)


Patched In Version -

No Fix


Severity -

High


CVE Code -

2023-40335


24 - Cookies by JM

Plugin -

Cookies by JM


Plugin Slug -

cookies-by-jm


Vulnerability -

Cross Site Scripting (XSS)


Patched In Version -

No Fix


Severity -

Medium


CVE Code -

2023-40604


25 - CT Commerce

Plugin -

CT Commerce


Plugin Slug -

ct-commerce


Vulnerability -

Cross Site Scripting (XSS)


Patched In Version -

No Fix


Severity -

Medium


CVE Code -

2023-40007


26 - Custom Admin Login Page | WPZest

Plugin -

Custom Admin Login Page | WPZest


Plugin Slug -

custom-admin-login-styler-wpzest


Vulnerability -

Cross Site Scripting (XSS)


Patched In Version -

No Fix


Severity -

Medium


CVE Code -

2023-40329


27 - DX-auto-save-images

Plugin -

DX-auto-save-images


Plugin Slug -

dx-auto-save-images


Vulnerability -

Cross Site Request Forgery (CSRF)


Patched In Version -

No Fix


Severity -

Medium


CVE Code -

2023-40671


28 - Mortgage Calculator Estatik

Plugin -

Mortgage Calculator Estatik


Plugin Slug -

estatik-mortgage-calculator


Vulnerability -

Cross Site Scripting (XSS)


Patched In Version -

No Fix


Severity -

High


CVE Code -

2023-40601


29 - Make Paths Relative

Plugin -

Make Paths Relative


Plugin Slug -

make-paths-relative


Vulnerability -

Cross Site Request Forgery (CSRF)


Patched In Version -

No Fix


Severity -

Medium


CVE Code -

2023-27433


30 - Simple Org Chart

Plugin -

Simple Org Chart


Plugin Slug -

simple-org-chart


Vulnerability -

Broken Access Control


Patched In Version -

No Fix


Severity -

Medium


CVE Code -

2023-40603


31 - Simple Org Chart

Plugin -

Simple Org Chart


Plugin Slug -

simple-org-chart


Vulnerability -

Cross Site Request Forgery (CSRF)


Patched In Version -

No Fix


Severity -

Medium


CVE Code -

2023-28791


32 - Simple Staff List

Plugin -

Simple Staff List


Plugin Slug -

simple-staff-list


Vulnerability -

Cross Site Scripting (XSS)


Patched In Version -

No Fix


Severity -

Medium


CVE Code -

2023-28790


33 - Donations Made Easy – Smart Donations

Plugin -

Donations Made Easy – Smart Donations


Plugin Slug -

smart-donations


Vulnerability -

Cross Site Scripting (XSS)


Patched In Version -

No Fix


Severity -

High


CVE Code -

2023-40664


34 - Sticky Social Media Icons

Plugin -

Sticky Social Media Icons


Plugin Slug -

sticky-social-media-icons


Vulnerability -

Broken Access Control


Patched In Version -

No Fix


Severity -

Medium


CVE Code -

2023-40672


35 - WebLibrarian

Plugin -

WebLibrarian


Plugin Slug -

weblibrarian


Vulnerability -

Cross Site Scripting (XSS)


Patched In Version -

No Fix


Severity -

High


CVE Code -

2023-29441


36 - Putler Connector for WooCommerce

Plugin -

Putler Connector for WooCommerce


Plugin Slug -

woocommerce-putler-connector


Vulnerability -

Broken Access Control


Patched In Version -

No Fix


Severity -

Medium


CVE Code -

2023-40326


37 - Putler Connector for WooCommerce

Plugin -

Putler Connector for WooCommerce


Plugin Slug -

woocommerce-putler-connector


Vulnerability -

Broken Access Control


Patched In Version -

No Fix


Severity -

Medium


CVE Code -

2023-40327


Protect Your WordPress Website Today With Website Guardian

Join hundreds of businesses like yours who trust InterwebDEFENCE to protect their websites and livelihood. Using our proven website security analysis and best-in-class AI ‘Website Guardian” software, we are able to protect, monitor and backup your WordPress website.

Go ahead, keep the good guys In and the bad guys out – Click HERE to see our Website Guardian security plans NOW
PLUS
Find out about our unconditional ‘Double Protection’ Guarantee. This guarantee is better than risk free!

We’ll have you scanned, protected and secure in no time, giving you total peace of mind that your website is safe, leaving you to focus on your business success.

WordPress Theme Vulnerabilities

1 - Bazaar Lite

Theme -

Bazaar Lite


Theme Slug -

bazaar-lite


Vulnerability -

Cross Site Scripting (XSS)


Patched In Version -

1.8.6


Severity -

High


CVE Code -

2023-2813


2 - Aapna

Theme -

Aapna


Theme Slug -

aapna


Vulnerability -

Cross Site Scripting (XSS)


Patched In Version -

No Fix


Severity -

High


CVE Code -

2023-2813


3 - College

Theme -

College


Theme Slug -

college


Vulnerability -

Cross Site Scripting (XSS)


Patched In Version -

1.5.1


Severity -

High


CVE Code -

2023-2813


4 - BunnyPressLite

Theme -

BunnyPressLite


Theme Slug -

bunnypresslite


Vulnerability -

Cross Site Scripting (XSS)


Patched In Version -

2.1


Severity -

High


CVE Code -

2023-2813


5 - Anfaust

Theme -

Anfaust


Theme Slug -

anfaust


Vulnerability -

Cross Site Scripting (XSS)


Patched In Version -

No Fix


Severity -

High


CVE Code -

2023-2813


6 - Brain Power

Theme -

Brain Power


Theme Slug -

brain-power


Vulnerability -

Cross Site Scripting (XSS)


Patched In Version -

No Fix


Severity -

High


CVE Code -

2023-2813


7 - Cafe Bistro

Theme -

Cafe Bistro


Theme Slug -

cafe-bistro


Vulnerability -

Cross Site Scripting (XSS)


Patched In Version -

1.1.4


Severity -

High


CVE Code -

2023-2813


8 - Anand

Theme -

Anand


Theme Slug -

anand


Vulnerability -

Cross Site Scripting (XSS)


Patched In Version -

No Fix


Severity -

High


CVE Code -

2023-2813


9 - Arendelle

Theme -

Arendelle


Theme Slug -

arendelle


Vulnerability -

Cross Site Scripting (XSS)


Patched In Version -

1.1.3


Severity -

High


CVE Code -

2023-2813


Protect Your WordPress Website Today With Website Guardian

Join hundreds of businesses like yours who trust InterwebDEFENCE to protect their websites and livelihood. Using our proven website security analysis and best-in-class AI ‘Website Guardian” software, we are able to protect, monitor and backup your WordPress website.

Go ahead, keep the good guys In and the bad guys out – Click HERE to see our Website Guardian security plans NOW
PLUS
Find out about our unconditional ‘Double Protection’ Guarantee. This guarantee is better than risk free!

We’ll have you scanned, protected and secure in no time, giving you total peace of mind that your website is safe, leaving you to focus on your business success.

Click to access the login or register cheese