WordPress Vulnerability Report – August 30, 2023

by | Aug 30, 2023 | Security

DETAILS FROM DAN KNAUSS OF ITHEMES ON AUGUST 30, 2023

original available here

Last Updated on August 30, 2023

 

Since last week, 56 total vulnerabilities emerged in public disclosure. They may affect over two million WordPress sites. There are 28 plugin vulnerabilities with security patches, so run those updates!

Additionally, there are 28 plugin vulnerabilities with no patch available yet. If you use an unpatched plugin or theme, check their vendors’ intentions and progress on a security release. Suppose no patch is forthcoming or the vulnerable software has been marked “closed” and dropped from the official WordPress theme and plugin repositories. In that case, you should consider deactivation and removal in favor of alternative solutions.

Is Your WordPress Website Secure?

DID YOU KNOW – A staggering 83% of WordPress websites are not upgraded or updated, is your website one of these?

Hacks happen due to lack of website upkeep and protection, like updating WordPress or plugins, plus using weak passwords. Contrary to popular belief, web designers and website hosting companies are not responsible for the security of your WordPress website; you are. It’s like using your computer without Anti-virus!

WordPress Core Vulnerabilities

No new WordPress core vulnerabilities were disclosed this week. 

WordPress Theme Vulnerabilities

Jump to section

These are vulnerabilities that have occoured in themes for wordpress. If there is a patch for the issue you should update the theme immediately, if there is no fix you should change your site to a different theme.

There were no new theme vulnerabilities this week

WordPress Plugin Vulnerabilities – Patched

ElementsKit Elementor addons

1 - ElementsKit Elementor addons

Plugin -

ElementsKit Elementor addons


Plugin Slug -

elementskit-lite


Installations -

1,000,000+


Vulnerability -

Broken Access Control


Patched In Version -

2.9.1


Severity -

Medium


CVE Code -

2023-39993


Hide My WP Ghost – Security Plugin

2 - Hide My WP Ghost – Security Plugin

Plugin -

Hide My WP Ghost – Security Plugin


Plugin Slug -

hide-my-wp


Installations -

200,000+


Vulnerability -

Bypass Vulnerability


Patched In Version -

5.0.26


Severity -

Medium


CVE Code -

2023-34001


Slimstat Analytics

3 - Slimstat Analytics

Plugin -

Slimstat Analytics


Plugin Slug -

wp-slimstat


Installations -

100,000+


Vulnerability -

Broken Access Control


Patched In Version -

5.0.6


Severity -

Medium


CVE Code -

2023-33994


Slimstat Analytics

4 - Slimstat Analytics

Plugin -

Slimstat Analytics


Plugin Slug -

wp-slimstat


Installations -

100,000+


Vulnerability -

Cross Site Scripting (XSS)


Patched In Version -

5.0.9


Severity -

Medium


CVE Code -

2023-40676


Folders – Unlimited Folders to Organize Media Library Folder, Pages, Posts, File Manager

5 - Folders – Unlimited Folders to Organize Media Library Folder, Pages, Posts, File Manager

Plugin -

Folders – Unlimited Folders to Organize Media Library Folder, Pages, Posts, File Manager


Plugin Slug -

folders


Installations -

60,000+


Vulnerability -

Arbitrary File Upload


Patched In Version -

2.9.3


Severity -

Critical


CVE Code -

2023-40204


iThemes Sync

6 - iThemes Sync

Plugin -

iThemes Sync


Plugin Slug -

ithemes-sync


Installations -

50,000+


Vulnerability -

Broken Access Control


Patched In Version -

2.1.14


Severity -

Medium


CVE Code -

2023-40001


FV Flowplayer Video Player

7 - FV Flowplayer Video Player

Plugin -

FV Flowplayer Video Player


Plugin Slug -

fv-wordpress-flowplayer


Installations -

30,000+


Vulnerability -

Cross Site Scripting (XSS)


Patched In Version -

7.5.39.7212


Severity -

High


CVE Code -

2023-4520


Donation Forms by Charitable – Donations Plugin & Fundraising Platform for WordPress

8 - Donation Forms by Charitable – Donations Plugin & Fundraising Platform for WordPress

Plugin -

Donation Forms by Charitable – Donations Plugin & Fundraising Platform for WordPress


Plugin Slug -

charitable


Installations -

10,000+


Vulnerability -

Privilege Escalation


Patched In Version -

1.7.0.13


Severity -

Critical


CVE Code -

2023-4404


ReviewX – Multi-criteria Rating & Reviews for WooCommerce

9 - ReviewX – Multi-criteria Rating & Reviews for WooCommerce

Plugin -

ReviewX – Multi-criteria Rating & Reviews for WooCommerce


Plugin Slug -

reviewx


Installations -

10,000+


Vulnerability -

Broken Access Control


Patched In Version -

1.6.18


Severity -

Medium


CVE Code -

2023-40670


URL Shortify – Simple, Powerful and Easy URL Shortener Plugin For WordPress

10 - URL Shortify – Simple, Powerful and Easy URL Shortener Plugin For WordPress

Plugin -

URL Shortify – Simple, Powerful and Easy URL Shortener Plugin For WordPress


Plugin Slug -

url-shortify


Installations -

10,000+


Vulnerability -

Cross Site Scripting (XSS)


Patched In Version -

1.7.6


Severity -

High


CVE Code -

2023-4294


Min Max Control – Min Max Quantity & Step Control for WooCommerce

11 - Min Max Control – Min Max Quantity & Step Control for WooCommerce

Plugin -

Min Max Control – Min Max Quantity & Step Control for WooCommerce


Plugin Slug -

woo-min-max-quantity-step-control-single


Installations -

10,000+


Vulnerability -

Cross Site Scripting (XSS)


Patched In Version -

4.6


Severity -

High


CVE Code -

2023-4270


Category Slider for WooCommerce

12 - Category Slider for WooCommerce

Plugin -

Category Slider for WooCommerce


Plugin Slug -

woo-category-slider-grid


Installations -

9,000+


Vulnerability -

Broken Access Control


Patched In Version -

1.4.16


Severity -

Medium


CVE Code -

2023-41132


Herd Effects – fake notifications and social proof plugin

13 - Herd Effects – fake notifications and social proof plugin

Plugin -

Herd Effects – fake notifications and social proof plugin


Plugin Slug -

mwp-herd-effect


Installations -

5,000+


Vulnerability -

Cross Site Request Forgery (CSRF)


Patched In Version -

5.2.4


Severity -

Medium


CVE Code -

2023-4318


Order Tracking – WordPress Status Tracking Plugin

14 - Order Tracking – WordPress Status Tracking Plugin

Plugin -

Order Tracking – WordPress Status Tracking Plugin


Plugin Slug -

order-tracking


Installations -

4,000+


Vulnerability -

Cross Site Scripting (XSS)


Patched In Version -

3.3.7


Severity -

Medium


CVE Code -

2023-4500


Order Tracking – WordPress Status Tracking Plugin

15 - Order Tracking – WordPress Status Tracking Plugin

Plugin -

Order Tracking – WordPress Status Tracking Plugin


Plugin Slug -

order-tracking


Installations -

4,000+


Vulnerability -

Cross Site Scripting (XSS)


Patched In Version -

3.3.7


Severity -

High


CVE Code -

2023-4471


16 - DoLogin Security

Plugin -

DoLogin Security


Plugin Slug -

dologin


Installations -

3,000+


Vulnerability -

Bypass Vulnerability


Patched In Version -

3.7


Severity -

Medium


WooCommerce PDF Invoice Builder, Create invoices, packing slips and more

17 - WooCommerce PDF Invoice Builder, Create invoices, packing slips and more

Plugin -

WooCommerce PDF Invoice Builder, Create invoices, packing slips and more


Plugin Slug -

woo-pdf-invoice-builder


Installations -

3,000+


Vulnerability -

Broken Access Control


Patched In Version -

1.2.92


Severity -

Medium


CVE Code -

2023-4245


WooCommerce PDF Invoice Builder, Create invoices, packing slips and more

18 - WooCommerce PDF Invoice Builder, Create invoices, packing slips and more

Plugin -

WooCommerce PDF Invoice Builder, Create invoices, packing slips and more


Plugin Slug -

woo-pdf-invoice-builder


Installations -

3,000+


Vulnerability -

Cross Site Scripting (XSS)


Patched In Version -

1.2.91


Severity -

Medium


CVE Code -

2023-4160


WP Adminify – WordPress Dashboard Customization | Custom Login | Admin Columns | Dashboard Widget | Media Library Folders

19 - WP Adminify – WordPress Dashboard Customization | Custom Login | Admin Columns | Dashboard Widget | Media Library Folders

Plugin -

WP Adminify – WordPress Dashboard Customization | Custom Login | Admin Columns | Dashboard Widget | Media Library Folders


Plugin Slug -

adminify


Installations -

1,000+


Vulnerability -

Cross Site Scripting (XSS)


Patched In Version -

3.1.6


Severity -

Medium


CVE Code -

2023-4060


Premmerce User Roles

20 - Premmerce User Roles

Plugin -

Premmerce User Roles


Plugin Slug -

premmerce-user-roles


Installations -

1,000+


Vulnerability -

Broken Access Control


Patched In Version -

1.0.13


Severity -

High


CVE Code -

2023-41130


21 - Save as PDF plugin by Pdfcrowd

Plugin -

Save as PDF plugin by Pdfcrowd


Plugin Slug -

save-as-pdf-by-pdfcrowd


Installations -

1,000+


Vulnerability -

Cross Site Scripting (XSS)


Patched In Version -

2.16.1


Severity -

Medium


CVE Code -

2023-40668


Event Tickets with Ticket Scanner

22 - Event Tickets with Ticket Scanner

Plugin -

Event Tickets with Ticket Scanner


Plugin Slug -

event-tickets-with-ticket-scanner


Installations -

600+


Vulnerability -

Cross Site Scripting (XSS)


Patched In Version -

1.5.5


Severity -

Medium


23 - Push Notification for Post and BuddyPress

Plugin -

Push Notification for Post and BuddyPress


Plugin Slug -

push-notification-for-post-and-buddypress


Installations -

200+


Vulnerability -

Broken Access Control


Patched In Version -

1.64


Severity -

Medium


WP VK-???????????/??/?????????

24 - WP VK-???????????/??/?????????

Plugin -

WP VK-???????????/??/?????????


Plugin Slug -

wp-vk


Installations -

100+


Vulnerability -

Cross Site Request Forgery (CSRF)


Patched In Version -

1.3.4


Severity -

Medium


25 - Save as Image plugin by Pdfcrowd

Plugin -

Save as Image plugin by Pdfcrowd


Plugin Slug -

save-as-image-by-pdfcrowd


Installations -

30+


Vulnerability -

Cross Site Scripting (XSS)


Patched In Version -

2.16.1


Severity -

Medium


CVE Code -

2023-40665


26 - gAppointments

Plugin -

gAppointments


Plugin Slug -

gAppointments


Vulnerability -

Cross Site Scripting (XSS)


Patched In Version -

1.10.0


Severity -

High


CVE Code -

2023-2705


27 - JupiterX Core

Plugin -

JupiterX Core


Plugin Slug -

jupiterx-core


Vulnerability -

Arbitrary File Upload


Patched In Version -

3.3.8


Severity -

Critical


CVE Code -

2023-38388


28 - JupiterX Core

Plugin -

JupiterX Core


Plugin Slug -

jupiterx-core


Vulnerability -

Privilege Escalation


Patched In Version -

3.4.3


Severity -

Critical


CVE Code -

2023-38389


Protect Your WordPress Website Today With Website Guardian

Join hundreds of businesses like yours who trust InterwebDEFENCE to protect their websites and livelihood. Using our proven website security analysis and best-in-class AI ‘Website Guardian” software, we are able to protect, monitor and backup your WordPress website.

Go ahead, keep the good guys In and the bad guys out – Click HERE to see our Website Guardian security plans NOW
PLUS
Find out about our unconditional ‘Double Protection’ Guarantee. This guarantee is better than risk free!

We’ll have you scanned, protected and secure in no time, giving you total peace of mind that your website is safe, leaving you to focus on your business success.

WordPress Plugin Vulnerabilities – Unpatched

Royal Elementor Addons and Templates

1 - Royal Elementor Addons and Templates

Plugin -

Royal Elementor Addons and Templates


Plugin Slug -

royal-elementor-addons


Installations -

200,000+


Vulnerability -

Cross Site Request Forgery (CSRF)


Patched In Version -

No Fix


Severity -

Medium


CVE Code -

2022-47175


Post and Page Builder by BoldGrid – Visual Drag and Drop Editor

2 - Post and Page Builder by BoldGrid – Visual Drag and Drop Editor

Plugin -

Post and Page Builder by BoldGrid – Visual Drag and Drop Editor


Plugin Slug -

post-and-page-builder


Installations -

100,000+


Vulnerability -

Cross Site Request Forgery (CSRF)


Patched In Version -

No Fix


Severity -

Medium


CVE Code -

2023-25480


Collapse-O-Matic

3 - Collapse-O-Matic

Plugin -

Collapse-O-Matic


Plugin Slug -

jquery-collapse-o-matic


Installations -

60,000+


Vulnerability -

Cross Site Scripting (XSS)


Patched In Version -

No Fix


Severity -

Medium


CVE Code -

2023-40669


Master Addons for Elementor

4 - Master Addons for Elementor

Plugin -

Master Addons for Elementor


Plugin Slug -

master-addons


Installations -

40,000+


Vulnerability -

Broken Access Control


Patched In Version -

No Fix


Severity -

Medium


CVE Code -

2023-40679


Ultimate Addons for Contact Form 7

5 - Ultimate Addons for Contact Form 7

Plugin -

Ultimate Addons for Contact Form 7


Plugin Slug -

ultimate-addons-for-contact-form-7


Installations -

20,000+


Vulnerability -

Cross Site Scripting (XSS)


Patched In Version -

No Fix


Severity -

High


CVE Code -

2023-30493


URL Shortener by MyThemeShop

6 - URL Shortener by MyThemeShop

Plugin -

URL Shortener by MyThemeShop


Plugin Slug -

mts-url-shortener


Installations -

10,000+


Vulnerability -

Cross Site Scripting (XSS)


Patched In Version -

No Fix


Severity -

High


CVE Code -

2023-30472


Landing Page Builder – Lead Page – Optin Page – Squeeze Page – WordPress Landing Pages

7 - Landing Page Builder – Lead Page – Optin Page – Squeeze Page – WordPress Landing Pages

Plugin -

Landing Page Builder – Lead Page – Optin Page – Squeeze Page – WordPress Landing Pages


Plugin Slug -

page-builder-add


Installations -

10,000+


Vulnerability -

Cross Site Scripting (XSS)


Patched In Version -

No Fix


Severity -

Medium


CVE Code -

2023-40675


WP Super Minify

8 - WP Super Minify

Plugin -

WP Super Minify


Plugin Slug -

wp-super-minify


Installations -

10,000+


Vulnerability -

Cross Site Request Forgery (CSRF)


Patched In Version -

No Fix


Severity -

Medium


CVE Code -

2023-27615


Easy Coming Soon

9 - Easy Coming Soon

Plugin -

Easy Coming Soon


Plugin Slug -

easy-coming-soon


Installations -

7,000+


Vulnerability -

Cross Site Scripting (XSS)


Patched In Version -

No Fix


Severity -

Medium


CVE Code -

2023-25483


LuckyWP Scripts Control

10 - LuckyWP Scripts Control

Plugin -

LuckyWP Scripts Control


Plugin Slug -

luckywp-scripts-control


Installations -

6,000+


Vulnerability -

Broken Access Control


Patched In Version -

No Fix


Severity -

Medium


CVE Code -

2023-29239


11 - Social Share Boost

Plugin -

Social Share Boost


Plugin Slug -

social-share-boost


Installations -

6,000+


Vulnerability -

Cross Site Request Forgery (CSRF)


Patched In Version -

No Fix


Severity -

Medium


CVE Code -

2023-25033


MakeStories (for Google Web Stories)

12 - MakeStories (for Google Web Stories)

Plugin -

MakeStories (for Google Web Stories)


Plugin Slug -

makestories-helper


Installations -

5,000+


Vulnerability -

Cross Site Request Forgery (CSRF)


Patched In Version -

No Fix


Severity -

Medium


CVE Code -

2023-27448


Simple URLs – Link Cloaking, Product Displays, and Affiliate Link Management

13 - Simple URLs – Link Cloaking, Product Displays, and Affiliate Link Management

Plugin -

Simple URLs – Link Cloaking, Product Displays, and Affiliate Link Management


Plugin Slug -

simple-urls


Installations -

5,000+


Vulnerability -

Broken Access Control


Patched In Version -

No Fix


Severity -

Medium


CVE Code -

2023-40678


Simple URLs – Link Cloaking, Product Displays, and Affiliate Link Management

14 - Simple URLs – Link Cloaking, Product Displays, and Affiliate Link Management

Plugin -

Simple URLs – Link Cloaking, Product Displays, and Affiliate Link Management


Plugin Slug -

simple-urls


Installations -

5,000+


Vulnerability -

Cross Site Scripting (XSS)


Patched In Version -

No Fix


Severity -

Medium


CVE Code -

2023-40674


Simple URLs – Link Cloaking, Product Displays, and Affiliate Link Management

15 - Simple URLs – Link Cloaking, Product Displays, and Affiliate Link Management

Plugin -

Simple URLs – Link Cloaking, Product Displays, and Affiliate Link Management


Plugin Slug -

simple-urls


Installations -

5,000+


Vulnerability -

Cross Site Scripting (XSS)


Patched In Version -

No Fix


Severity -

High


CVE Code -

2023-40667


Vertical marquee plugin

16 - Vertical marquee plugin

Plugin -

Vertical marquee plugin


Plugin Slug -

vertical-marquee-plugin


Installations -

4,000+


Vulnerability -

Cross Site Scripting (XSS)


Patched In Version -

No Fix


Severity -

Medium


CVE Code -

2023-40677


17 - WP Users Media

Plugin -

WP Users Media


Plugin Slug -

wp-users-media


Installations -

4,000+


Vulnerability -

Broken Access Control


Patched In Version -

No Fix


Severity -

Medium


CVE Code -

2023-27428


WP Search Analytics

18 - WP Search Analytics

Plugin -

WP Search Analytics


Plugin Slug -

search-analytics


Installations -

2,000+


Vulnerability -

Cross Site Scripting (XSS)


Patched In Version -

No Fix


Severity -

High


CVE Code -

2023-30471


Sitekit

19 - Sitekit

Plugin -

Sitekit


Plugin Slug -

sitekit


Installations -

2,000+


Vulnerability -

Cross Site Scripting (XSS)


Patched In Version -

No Fix


Severity -

Medium


CVE Code -

2023-27628


Olive One Click Demo Import

20 - Olive One Click Demo Import

Plugin -

Olive One Click Demo Import


Plugin Slug -

olive-one-click-demo-import


Installations -

1,000+


Vulnerability -

Arbitrary File Upload


Patched In Version -

No Fix


Severity -

Critical


CVE Code -

2023-29102


Secure Admin IP

21 - Secure Admin IP

Plugin -

Secure Admin IP


Plugin Slug -

secure-admin-ip


Installations -

1,000+


Vulnerability -

Broken Access Control


Patched In Version -

No Fix


Severity -

Medium


CVE Code -

2023-41133


22 - Cartpauj Register Captcha

Plugin -

Cartpauj Register Captcha


Plugin Slug -

cartpauj-register-captcha


Vulnerability -

Bypass Vulnerability


Patched In Version -

No Fix


Severity -

Medium


CVE Code -

2023-40673


23 - DX-auto-save-images

Plugin -

DX-auto-save-images


Plugin Slug -

dx-auto-save-images


Vulnerability -

Cross Site Request Forgery (CSRF)


Patched In Version -

No Fix


Severity -

Medium


CVE Code -

2023-40671


24 - FTP Access

Plugin -

FTP Access


Plugin Slug -

ftp-access


Vulnerability -

Cross Site Scripting (XSS)


Patched In Version -

No Fix


Severity -

Medium


CVE Code -

2023-3510


25 - GuruWalk Affiliates

Plugin -

GuruWalk Affiliates


Plugin Slug -

guruwalk-affiliates


Vulnerability -

Cross Site Scripting (XSS)


Patched In Version -

No Fix


Severity -

Medium


CVE Code -

2023-27622


26 - Lock User Account

Plugin -

Lock User Account


Plugin Slug -

lock-user-account


Vulnerability -

Cross Site Request Forgery (CSRF)


Patched In Version -

No Fix


Severity -

Medium


CVE Code -

2023-4307


27 - Maintenance Switch

Plugin -

Maintenance Switch


Plugin Slug -

maintenance-switch


Vulnerability -

Cross Site Request Forgery (CSRF)


Patched In Version -

No Fix


Severity -

Medium


CVE Code -

2023-29235


28 - Sticky Social Media Icons

Plugin -

Sticky Social Media Icons


Plugin Slug -

sticky-social-media-icons


Vulnerability -

Broken Access Control


Patched In Version -

No Fix


Severity -

Medium


CVE Code -

2023-40672


Protect Your WordPress Website Today With Website Guardian

Join hundreds of businesses like yours who trust InterwebDEFENCE to protect their websites and livelihood. Using our proven website security analysis and best-in-class AI ‘Website Guardian” software, we are able to protect, monitor and backup your WordPress website.

Go ahead, keep the good guys In and the bad guys out – Click HERE to see our Website Guardian security plans NOW
PLUS
Find out about our unconditional ‘Double Protection’ Guarantee. This guarantee is better than risk free!

We’ll have you scanned, protected and secure in no time, giving you total peace of mind that your website is safe, leaving you to focus on your business success.

WordPress Theme Vulnerabilities

There were no new theme vulnerabilties this week

Protect Your WordPress Website Today With Website Guardian

Join hundreds of businesses like yours who trust InterwebDEFENCE to protect their websites and livelihood. Using our proven website security analysis and best-in-class AI ‘Website Guardian” software, we are able to protect, monitor and backup your WordPress website.

Go ahead, keep the good guys In and the bad guys out – Click HERE to see our Website Guardian security plans NOW
PLUS
Find out about our unconditional ‘Double Protection’ Guarantee. This guarantee is better than risk free!

We’ll have you scanned, protected and secure in no time, giving you total peace of mind that your website is safe, leaving you to focus on your business success.

Click to access the login or register cheese