WordPress Vulnerability Report – August 30, 2023
DETAILS FROM DAN KNAUSS OF ITHEMES ON AUGUST 30, 2023
Last Updated on August 30, 2023
Since last week, 56 total vulnerabilities emerged in public disclosure. They may affect over two million WordPress sites. There are 28 plugin vulnerabilities with security patches, so run those updates!
Additionally, there are 28 plugin vulnerabilities with no patch available yet. If you use an unpatched plugin or theme, check their vendors’ intentions and progress on a security release. Suppose no patch is forthcoming or the vulnerable software has been marked “closed” and dropped from the official WordPress theme and plugin repositories. In that case, you should consider deactivation and removal in favor of alternative solutions.
Is Your WordPress Website Secure?
DID YOU KNOW – A staggering 83% of WordPress websites are not upgraded or updated, is your website one of these?
Hacks happen due to lack of website upkeep and protection, like updating WordPress or plugins, plus using weak passwords. Contrary to popular belief, web designers and website hosting companies are not responsible for the security of your WordPress website; you are. It’s like using your computer without Anti-virus!
WordPress Core Vulnerabilities
No new WordPress core vulnerabilities were disclosed this week.
WordPress Plugin Vulnerabilities – Patched
These are plugin vulnerabilities that have been fixed with the most recent updates, it’s recomended to update all plugins to the newest version to improve site safety.
Jump to section
- ElementsKit Lite
- Hide My WP Ghost – Security Plugin
- Slimstat Analytics
- Slimstat Analytics
- Folders
- iThemes Sync
- FV Flowplayer Video Player
- Donation Forms by Charitable
- ReviewX
- URL Shortify
- Min Max Control
- Category Slider for WooCommerce
- Herd Effects
- Order Tracking Pro
- Order Tracking Pro
- DoLogin Security
- WooCommerce PDF Invoice Builder
- WooCommerce PDF Invoice Builder
- WP Adminify
- Premmerce User Roles
- Save as PDF plugin by Pdfcrowd
- Event Tickets with Ticket Scanner
- Push Notification for Post and BuddyPress
- WP VK-??????
- Save as Image plugin by Pdfcrowd
- Appointment booking addon for Gravity Forms
- Jupiter X Core
- Jupiter X Core
WordPress Plugin Vulnerabilities – Unpatched
These are plugin vulnerabilities that have NOT been fixed with the most recent updates, it’s recomended you deactivate or remove these plugins from your site until they are fixed.
Jump to section
- Royal Elementor Addons
- Post and Page Builder by BoldGrid
- Collapse-O-Matic
- Master Elementor Addons
- Ultimate Addons for Contact Form 7
- URL Shortener by MyThemeShop
- Landing Page Builder
- WP Super Minify
- Easy Coming Soon
- LuckyWP Scripts Control
- Social Share Boost
- MakeStories (for Google Web Stories)
- Simple URLs
- Simple URLs
- Simple URLs
- Vertical Marquee Plugin
- WP users media
- WP Search Analytics
- Sitekit
- Olive One Click Demo Import
- Secure Admin IP
- Cartpauj Register Captcha
- DX-auto-save-images
- FTP Access
- GuruWalk Affiliates
- Lock User Account
- Maintenance Switch
- Sticky Social Media Icons
WordPress Theme Vulnerabilities
Jump to section
These are vulnerabilities that have occoured in themes for wordpress. If there is a patch for the issue you should update the theme immediately, if there is no fix you should change your site to a different theme.
There were no new theme vulnerabilities this week
WordPress Plugin Vulnerabilities – Patched

1 - ElementsKit Elementor addons
Plugin -
Plugin Slug -
elementskit-lite
Installations -
1,000,000+
Vulnerability -
Broken Access Control
Patched In Version -
2.9.1
Severity -
Medium
CVE Code -

2 - Hide My WP Ghost – Security Plugin
Plugin -
Hide My WP Ghost – Security Plugin
Plugin Slug -
hide-my-wp
Installations -
200,000+
Vulnerability -
Bypass Vulnerability
Patched In Version -
5.0.26
Severity -
Medium
CVE Code -

3 - Slimstat Analytics
Plugin -
Plugin Slug -
wp-slimstat
Installations -
100,000+
Vulnerability -
Broken Access Control
Patched In Version -
5.0.6
Severity -
Medium
CVE Code -

4 - Slimstat Analytics
Plugin -
Plugin Slug -
wp-slimstat
Installations -
100,000+
Vulnerability -
Cross Site Scripting (XSS)
Patched In Version -
5.0.9
Severity -
Medium
CVE Code -

5 - Folders – Unlimited Folders to Organize Media Library Folder, Pages, Posts, File Manager
Plugin -
Folders – Unlimited Folders to Organize Media Library Folder, Pages, Posts, File Manager
Plugin Slug -
folders
Installations -
60,000+
Vulnerability -
Arbitrary File Upload
Patched In Version -
2.9.3
Severity -
Critical
CVE Code -

6 - iThemes Sync
Plugin -
Plugin Slug -
ithemes-sync
Installations -
50,000+
Vulnerability -
Broken Access Control
Patched In Version -
2.1.14
Severity -
Medium
CVE Code -

7 - FV Flowplayer Video Player
Plugin -
Plugin Slug -
fv-wordpress-flowplayer
Installations -
30,000+
Vulnerability -
Cross Site Scripting (XSS)
Patched In Version -
7.5.39.7212
Severity -
High
CVE Code -

8 - Donation Forms by Charitable – Donations Plugin & Fundraising Platform for WordPress
Plugin -
Donation Forms by Charitable – Donations Plugin & Fundraising Platform for WordPress
Plugin Slug -
charitable
Installations -
10,000+
Vulnerability -
Privilege Escalation
Patched In Version -
1.7.0.13
Severity -
Critical
CVE Code -

9 - ReviewX – Multi-criteria Rating & Reviews for WooCommerce
Plugin -
ReviewX – Multi-criteria Rating & Reviews for WooCommerce
Plugin Slug -
reviewx
Installations -
10,000+
Vulnerability -
Broken Access Control
Patched In Version -
1.6.18
Severity -
Medium
CVE Code -

10 - URL Shortify – Simple, Powerful and Easy URL Shortener Plugin For WordPress
Plugin -
URL Shortify – Simple, Powerful and Easy URL Shortener Plugin For WordPress
Plugin Slug -
url-shortify
Installations -
10,000+
Vulnerability -
Cross Site Scripting (XSS)
Patched In Version -
1.7.6
Severity -
High
CVE Code -

11 - Min Max Control – Min Max Quantity & Step Control for WooCommerce
Plugin -
Min Max Control – Min Max Quantity & Step Control for WooCommerce
Plugin Slug -
woo-min-max-quantity-step-control-single
Installations -
10,000+
Vulnerability -
Cross Site Scripting (XSS)
Patched In Version -
4.6
Severity -
High
CVE Code -

12 - Category Slider for WooCommerce
Plugin -
Category Slider for WooCommerce
Plugin Slug -
woo-category-slider-grid
Installations -
9,000+
Vulnerability -
Broken Access Control
Patched In Version -
1.4.16
Severity -
Medium
CVE Code -

13 - Herd Effects – fake notifications and social proof plugin
Plugin -
Herd Effects – fake notifications and social proof plugin
Plugin Slug -
mwp-herd-effect
Installations -
5,000+
Vulnerability -
Cross Site Request Forgery (CSRF)
Patched In Version -
5.2.4
Severity -
Medium
CVE Code -
14 - Order Tracking – WordPress Status Tracking Plugin
Plugin -
Order Tracking – WordPress Status Tracking Plugin
Plugin Slug -
order-tracking
Installations -
4,000+
Vulnerability -
Cross Site Scripting (XSS)
Patched In Version -
3.3.7
Severity -
Medium
CVE Code -
15 - Order Tracking – WordPress Status Tracking Plugin
Plugin -
Order Tracking – WordPress Status Tracking Plugin
Plugin Slug -
order-tracking
Installations -
4,000+
Vulnerability -
Cross Site Scripting (XSS)
Patched In Version -
3.3.7
Severity -
High
CVE Code -
16 - DoLogin Security
Plugin -
Plugin Slug -
dologin
Installations -
3,000+
Vulnerability -
Bypass Vulnerability
Patched In Version -
3.7
Severity -
Medium

17 - WooCommerce PDF Invoice Builder, Create invoices, packing slips and more
Plugin -
WooCommerce PDF Invoice Builder, Create invoices, packing slips and more
Plugin Slug -
woo-pdf-invoice-builder
Installations -
3,000+
Vulnerability -
Broken Access Control
Patched In Version -
1.2.92
Severity -
Medium
CVE Code -

18 - WooCommerce PDF Invoice Builder, Create invoices, packing slips and more
Plugin -
WooCommerce PDF Invoice Builder, Create invoices, packing slips and more
Plugin Slug -
woo-pdf-invoice-builder
Installations -
3,000+
Vulnerability -
Cross Site Scripting (XSS)
Patched In Version -
1.2.91
Severity -
Medium
CVE Code -

19 - WP Adminify – WordPress Dashboard Customization | Custom Login | Admin Columns | Dashboard Widget | Media Library Folders
Plugin -
Plugin Slug -
adminify
Installations -
1,000+
Vulnerability -
Cross Site Scripting (XSS)
Patched In Version -
3.1.6
Severity -
Medium
CVE Code -

20 - Premmerce User Roles
Plugin -
Plugin Slug -
premmerce-user-roles
Installations -
1,000+
Vulnerability -
Broken Access Control
Patched In Version -
1.0.13
Severity -
High
CVE Code -
21 - Save as PDF plugin by Pdfcrowd
Plugin -
Save as PDF plugin by Pdfcrowd
Plugin Slug -
save-as-pdf-by-pdfcrowd
Installations -
1,000+
Vulnerability -
Cross Site Scripting (XSS)
Patched In Version -
2.16.1
Severity -
Medium
CVE Code -

22 - Event Tickets with Ticket Scanner
Plugin -
Event Tickets with Ticket Scanner
Plugin Slug -
event-tickets-with-ticket-scanner
Installations -
600+
Vulnerability -
Cross Site Scripting (XSS)
Patched In Version -
1.5.5
Severity -
Medium
23 - Push Notification for Post and BuddyPress
Plugin -
Push Notification for Post and BuddyPress
Plugin Slug -
push-notification-for-post-and-buddypress
Installations -
200+
Vulnerability -
Broken Access Control
Patched In Version -
1.64
Severity -
Medium

24 - WP VK-???????????/??/?????????
Plugin -
WP VK-???????????/??/?????????
Plugin Slug -
wp-vk
Installations -
100+
Vulnerability -
Cross Site Request Forgery (CSRF)
Patched In Version -
1.3.4
Severity -
Medium
25 - Save as Image plugin by Pdfcrowd
Plugin -
Save as Image plugin by Pdfcrowd
Plugin Slug -
save-as-image-by-pdfcrowd
Installations -
30+
Vulnerability -
Cross Site Scripting (XSS)
Patched In Version -
2.16.1
Severity -
Medium
CVE Code -
26 - gAppointments
Plugin -
Plugin Slug -
gAppointments
Vulnerability -
Cross Site Scripting (XSS)
Patched In Version -
1.10.0
Severity -
High
CVE Code -
27 - JupiterX Core
Plugin -
Plugin Slug -
jupiterx-core
Vulnerability -
Arbitrary File Upload
Patched In Version -
3.3.8
Severity -
Critical
CVE Code -
28 - JupiterX Core
Plugin -
Plugin Slug -
jupiterx-core
Vulnerability -
Privilege Escalation
Patched In Version -
3.4.3
Severity -
Critical
CVE Code -
Protect Your WordPress Website Today With Website Guardian
Join hundreds of businesses like yours who trust InterwebDEFENCE to protect their websites and livelihood. Using our proven website security analysis and best-in-class AI ‘Website Guardian” software, we are able to protect, monitor and backup your WordPress website.
Go ahead, keep the good guys In and the bad guys out – Click HERE to see our Website Guardian security plans NOW
PLUS
Find out about our unconditional ‘Double Protection’ Guarantee. This guarantee is better than risk free!
We’ll have you scanned, protected and secure in no time, giving you total peace of mind that your website is safe, leaving you to focus on your business success.
WordPress Plugin Vulnerabilities – Unpatched

1 - Royal Elementor Addons and Templates
Plugin -
Royal Elementor Addons and Templates
Plugin Slug -
royal-elementor-addons
Installations -
200,000+
Vulnerability -
Cross Site Request Forgery (CSRF)
Patched In Version -
No Fix
Severity -
Medium
CVE Code -

2 - Post and Page Builder by BoldGrid – Visual Drag and Drop Editor
Plugin -
Post and Page Builder by BoldGrid – Visual Drag and Drop Editor
Plugin Slug -
post-and-page-builder
Installations -
100,000+
Vulnerability -
Cross Site Request Forgery (CSRF)
Patched In Version -
No Fix
Severity -
Medium
CVE Code -

3 - Collapse-O-Matic
Plugin -
Plugin Slug -
jquery-collapse-o-matic
Installations -
60,000+
Vulnerability -
Cross Site Scripting (XSS)
Patched In Version -
No Fix
Severity -
Medium
CVE Code -

4 - Master Addons for Elementor
Plugin -
Plugin Slug -
master-addons
Installations -
40,000+
Vulnerability -
Broken Access Control
Patched In Version -
No Fix
Severity -
Medium
CVE Code -

5 - Ultimate Addons for Contact Form 7
Plugin -
Ultimate Addons for Contact Form 7
Plugin Slug -
ultimate-addons-for-contact-form-7
Installations -
20,000+
Vulnerability -
Cross Site Scripting (XSS)
Patched In Version -
No Fix
Severity -
High
CVE Code -

6 - URL Shortener by MyThemeShop
Plugin -
Plugin Slug -
mts-url-shortener
Installations -
10,000+
Vulnerability -
Cross Site Scripting (XSS)
Patched In Version -
No Fix
Severity -
High
CVE Code -

7 - Landing Page Builder – Lead Page – Optin Page – Squeeze Page – WordPress Landing Pages
Plugin -
Landing Page Builder – Lead Page – Optin Page – Squeeze Page – WordPress Landing Pages
Plugin Slug -
page-builder-add
Installations -
10,000+
Vulnerability -
Cross Site Scripting (XSS)
Patched In Version -
No Fix
Severity -
Medium
CVE Code -

8 - WP Super Minify
Plugin -
Plugin Slug -
wp-super-minify
Installations -
10,000+
Vulnerability -
Cross Site Request Forgery (CSRF)
Patched In Version -
No Fix
Severity -
Medium
CVE Code -

9 - Easy Coming Soon
Plugin -
Plugin Slug -
easy-coming-soon
Installations -
7,000+
Vulnerability -
Cross Site Scripting (XSS)
Patched In Version -
No Fix
Severity -
Medium
CVE Code -

10 - LuckyWP Scripts Control
Plugin -
Plugin Slug -
luckywp-scripts-control
Installations -
6,000+
Vulnerability -
Broken Access Control
Patched In Version -
No Fix
Severity -
Medium
CVE Code -
11 - Social Share Boost
Plugin -
Plugin Slug -
social-share-boost
Installations -
6,000+
Vulnerability -
Cross Site Request Forgery (CSRF)
Patched In Version -
No Fix
Severity -
Medium
CVE Code -

12 - MakeStories (for Google Web Stories)
Plugin -
MakeStories (for Google Web Stories)
Plugin Slug -
makestories-helper
Installations -
5,000+
Vulnerability -
Cross Site Request Forgery (CSRF)
Patched In Version -
No Fix
Severity -
Medium
CVE Code -

13 - Simple URLs – Link Cloaking, Product Displays, and Affiliate Link Management
Plugin -
Simple URLs – Link Cloaking, Product Displays, and Affiliate Link Management
Plugin Slug -
simple-urls
Installations -
5,000+
Vulnerability -
Broken Access Control
Patched In Version -
No Fix
Severity -
Medium
CVE Code -

14 - Simple URLs – Link Cloaking, Product Displays, and Affiliate Link Management
Plugin -
Simple URLs – Link Cloaking, Product Displays, and Affiliate Link Management
Plugin Slug -
simple-urls
Installations -
5,000+
Vulnerability -
Cross Site Scripting (XSS)
Patched In Version -
No Fix
Severity -
Medium
CVE Code -

15 - Simple URLs – Link Cloaking, Product Displays, and Affiliate Link Management
Plugin -
Simple URLs – Link Cloaking, Product Displays, and Affiliate Link Management
Plugin Slug -
simple-urls
Installations -
5,000+
Vulnerability -
Cross Site Scripting (XSS)
Patched In Version -
No Fix
Severity -
High
CVE Code -

16 - Vertical marquee plugin
Plugin -
Plugin Slug -
vertical-marquee-plugin
Installations -
4,000+
Vulnerability -
Cross Site Scripting (XSS)
Patched In Version -
No Fix
Severity -
Medium
CVE Code -
17 - WP Users Media
Plugin -
Plugin Slug -
wp-users-media
Installations -
4,000+
Vulnerability -
Broken Access Control
Patched In Version -
No Fix
Severity -
Medium
CVE Code -

18 - WP Search Analytics
Plugin -
Plugin Slug -
search-analytics
Installations -
2,000+
Vulnerability -
Cross Site Scripting (XSS)
Patched In Version -
No Fix
Severity -
High
CVE Code -

19 - Sitekit
Plugin -
Plugin Slug -
sitekit
Installations -
2,000+
Vulnerability -
Cross Site Scripting (XSS)
Patched In Version -
No Fix
Severity -
Medium
CVE Code -

20 - Olive One Click Demo Import
Plugin -
Plugin Slug -
olive-one-click-demo-import
Installations -
1,000+
Vulnerability -
Arbitrary File Upload
Patched In Version -
No Fix
Severity -
Critical
CVE Code -

21 - Secure Admin IP
Plugin -
Plugin Slug -
secure-admin-ip
Installations -
1,000+
Vulnerability -
Broken Access Control
Patched In Version -
No Fix
Severity -
Medium
CVE Code -
22 - Cartpauj Register Captcha
Plugin -
Plugin Slug -
cartpauj-register-captcha
Vulnerability -
Bypass Vulnerability
Patched In Version -
No Fix
Severity -
Medium
CVE Code -
23 - DX-auto-save-images
Plugin -
Plugin Slug -
dx-auto-save-images
Vulnerability -
Cross Site Request Forgery (CSRF)
Patched In Version -
No Fix
Severity -
Medium
CVE Code -
24 - FTP Access
Plugin -
Plugin Slug -
ftp-access
Vulnerability -
Cross Site Scripting (XSS)
Patched In Version -
No Fix
Severity -
Medium
CVE Code -
25 - GuruWalk Affiliates
Plugin -
Plugin Slug -
guruwalk-affiliates
Vulnerability -
Cross Site Scripting (XSS)
Patched In Version -
No Fix
Severity -
Medium
CVE Code -
26 - Lock User Account
Plugin -
Plugin Slug -
lock-user-account
Vulnerability -
Cross Site Request Forgery (CSRF)
Patched In Version -
No Fix
Severity -
Medium
CVE Code -
27 - Maintenance Switch
Plugin -
Plugin Slug -
maintenance-switch
Vulnerability -
Cross Site Request Forgery (CSRF)
Patched In Version -
No Fix
Severity -
Medium
CVE Code -
28 - Sticky Social Media Icons
Plugin -
Plugin Slug -
sticky-social-media-icons
Vulnerability -
Broken Access Control
Patched In Version -
No Fix
Severity -
Medium
CVE Code -
Protect Your WordPress Website Today With Website Guardian
Join hundreds of businesses like yours who trust InterwebDEFENCE to protect their websites and livelihood. Using our proven website security analysis and best-in-class AI ‘Website Guardian” software, we are able to protect, monitor and backup your WordPress website.
Go ahead, keep the good guys In and the bad guys out – Click HERE to see our Website Guardian security plans NOW
PLUS
Find out about our unconditional ‘Double Protection’ Guarantee. This guarantee is better than risk free!
We’ll have you scanned, protected and secure in no time, giving you total peace of mind that your website is safe, leaving you to focus on your business success.
WordPress Theme Vulnerabilities
There were no new theme vulnerabilties this week
Protect Your WordPress Website Today With Website Guardian
Join hundreds of businesses like yours who trust InterwebDEFENCE to protect their websites and livelihood. Using our proven website security analysis and best-in-class AI ‘Website Guardian” software, we are able to protect, monitor and backup your WordPress website.
Go ahead, keep the good guys In and the bad guys out – Click HERE to see our Website Guardian security plans NOW
PLUS
Find out about our unconditional ‘Double Protection’ Guarantee. This guarantee is better than risk free!
We’ll have you scanned, protected and secure in no time, giving you total peace of mind that your website is safe, leaving you to focus on your business success.