WordPress Vulnerability Report – August 9, 2023
DETAILS FROM DAN KNAUSS OF ITHEMES ON AUGUST 9, 2023
Last Updated on August 9, 2023
Since last week, only 30 total vulnerabilities emerged in public disclosure, but they include the popular Advanced Custom Fields (ACF) plugin. ACF is used on over two million active WordPress sites. Fortunately, a patch is available immediately for ACF and 27 other plugin vulnerabilities, so run those updates if you’re affected!
Additionally, there are two plugin vulnerabilities with no patch available yet. If you use an unpatched plugin or theme, check their vendors’ intentions and progress on a security release. Suppose no patch is forthcoming or the vulnerable software has been marked “closed” and dropped from the official WordPress theme and plugin repositories. In that case, you should consider deactivation and removal in favor of alternative solutions.
Is Your WordPress Website Secure?
DID YOU KNOW – A staggering 83% of WordPress websites are not upgraded or updated, is your website one of these?
Hacks happen due to lack of website upkeep and protection, like updating WordPress or plugins, plus using weak passwords. Contrary to popular belief, web designers and website hosting companies are not responsible for the security of your WordPress website; you are. It’s like using your computer without Anti-virus!
WordPress Core Vulnerabilities
No new WordPress core vulnerabilities were disclosed this week.
WordPress Plugin Vulnerabilities – Patched
These are plugin vulnerabilities that have been fixed with the most recent updates, it’s recomended to update all plugins to the newest version to improve site safety.
Jump to section
WordPress Plugin Vulnerabilities – Unpatched
These are plugin vulnerabilities that have NOT been fixed with the most recent updates, it’s recomended you deactivate or remove these plugins from your site until they are fixed.
Jump to section
WordPress Theme Vulnerabilities
Jump to section
These are vulnerabilities that have occoured in themes for wordpress. If there is a patch for the issue you should update the theme immediately, if there is no fix you should change your site to a different theme.
WordPress Plugin Vulnerabilities – Patched

1 - Advanced Custom Fields (ACF)
Plugin -
Plugin Slug -
advanced-custom-fields
Installations -
2,000,000+
Vulnerability -
Authenticated Cross Site Scripting (XSS)
Patched In Version -
6.1.8
Severity -
Medium

2 - Duplicate Post
Plugin -
Plugin Slug -
copy-delete-posts
Installations -
200,000+
Vulnerability -
Cross Site Request Forgery (CSRF) via AJAX action
Patched In Version -
1.4.2
Severity -
Medium

3 - TI WooCommerce Wishlist
Plugin -
Plugin Slug -
ti-woocommerce-wishlist
Installations -
100,000+
Vulnerability -
Unauthenticated Blind SQL Injection via Rest API
Patched In Version -
2.7.4
Severity -
Critical

4 - Change WP Admin Login
Plugin -
Plugin Slug -
change-wp-admin-login
Installations -
90,000+
Vulnerability -
Secret Login Page Disclosure
Patched In Version -
1.1.4
Severity -
Medium
CVE Code -

5 - The Post Grid – Shortcode, Gutenberg Blocks and Elementor Addon for Post Grid
Plugin -
The Post Grid – Shortcode, Gutenberg Blocks and Elementor Addon for Post Grid
Plugin Slug -
the-post-grid
Installations -
60,000+
Vulnerability -
Cross Site Request Forgery (CSRF) Leading To CSS Change
Patched In Version -
7.2.8
Severity -
Medium
CVE Code -

6 - PostX – Gutenberg Post Grid Blocks
Plugin -
PostX – Gutenberg Post Grid Blocks
Plugin Slug -
ultimate-post
Installations -
30,000+
Vulnerability -
Reflected Cross Site Scripting (XSS)
Patched In Version -
3.0.6
Severity -
High
CVE Code -

7 - Media from FTP
Plugin -
Plugin Slug -
media-from-ftp
Installations -
20,000+
Vulnerability -
Improper Privilege Management
Patched In Version -
11.16
Severity -
Medium

8 - Themesflat Addons For Elementor
Plugin -
Themesflat Addons For Elementor
Plugin Slug -
themesflat-addons-for-elementor
Installations -
20,000+
Vulnerability -
Unauthenticated PHP Object Injection
Patched In Version -
2.0.1
Severity -
High
CVE Code -

9 - Import All Pages, Post types, Products, Orders, and Users as XML & CSV
Plugin -
Import All Pages, Post types, Products, Orders, and Users as XML & CSV
Plugin Slug -
wp-ultimate-csv-importer
Installations -
20,000+
Vulnerability -
Authenticated Arbitrary Usermeta Update to Privilege Escalation
Patched In Version -
7.9.9
Severity -
Medium
CVE Code -

10 - Import All Pages, Post types, Products, Orders, and Users as XML & CSV
Plugin -
Import All Pages, Post types, Products, Orders, and Users as XML & CSV
Plugin Slug -
wp-ultimate-csv-importer
Installations -
20,000+
Vulnerability -
Sensitive Information Exposure via Directory Listing
Patched In Version -
7.9.9
Severity -
High
CVE Code -

11 - Import All Pages, Post types, Products, Orders, and Users as XML & CSV
Plugin -
Import All Pages, Post types, Products, Orders, and Users as XML & CSV
Plugin Slug -
wp-ultimate-csv-importer
Installations -
20,000+
Vulnerability -
Authenticated PHP file upload to Remote Code Execution (RCE)
Patched In Version -
7.9.9
Severity -
High
CVE Code -

12 - Import All Pages, Post types, Products, Orders, and Users as XML & CSV
Plugin -
Import All Pages, Post types, Products, Orders, and Users as XML & CSV
Plugin Slug -
wp-ultimate-csv-importer
Installations -
20,000+
Vulnerability -
Authenticated Remote Code Execution (RCE)
Patched In Version -
7.9.9
Severity -
High
CVE Code -

13 - Booking Package
Plugin -
Plugin Slug -
booking-package
Installations -
10,000+
Vulnerability -
Reflected Cross Site Scripting (XSS)
Patched In Version -
1.6.02
Severity -
High
CVE Code -

14 - Stripe Payment Plugin for WooCommerce
Plugin -
Stripe Payment Plugin for WooCommerce
Plugin Slug -
payment-gateway-stripe-and-woocommerce-integration
Installations -
10,000+
Vulnerability -
Authentication Bypass
Patched In Version -
3.7.8
Severity -
Critical
CVE Code -
15 - Simple Blog Card
Plugin -
Plugin Slug -
simple-blog-card
Installations -
3,000+
Vulnerability -
Sensitive Data Exposure
Patched In Version -
1.32
Severity -
Medium
16 - Simple Blog Card
Plugin -
Plugin Slug -
simple-blog-card
Installations -
3,000+
Vulnerability -
Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode
Patched In Version -
1.31
Severity -
Medium

17 - Leyka
Plugin -
Plugin Slug -
leyka
Installations -
2,000+
Vulnerability -
Reflected Cross Site Scripting (XSS)
Patched In Version -
3.30.3
Severity -
High
CVE Code -

18 - Photo Gallery by Ays – Responsive Image Gallery
Plugin -
Photo Gallery by Ays – Responsive Image Gallery
Plugin Slug -
gallery-photo-gallery
Installations -
1,000+
Vulnerability -
Cross Site Request Forgery (CSRF)
Patched In Version -
5.2.7
Severity -
Medium
CVE Code -

19 - Sign-up Sheets
Plugin -
Plugin Slug -
sign-up-sheets
Installations -
1,000+
Vulnerability -
Cross Site Request Forgery (CSRF)
Patched In Version -
2.2.9
Severity -
Medium
CVE Code -
20 - Upload Media By URL
Plugin -
Plugin Slug -
upload-media-by-url
Installations -
1,000+
Vulnerability -
Cross Site Request Forgery (CSRF)
Patched In Version -
1.0.8
Severity -
Medium
CVE Code -

21 - Bus Ticket Booking with Seat Reservation
Plugin -
Bus Ticket Booking with Seat Reservation
Plugin Slug -
bus-ticket-booking-with-seat-reservation
Installations -
900+
Vulnerability -
Reflected Cross Site Scripting (XSS)
Patched In Version -
5.2.4
Severity -
High
CVE Code -
22 - Simple Ticker
Plugin -
Plugin Slug -
simple-ticker
Installations -
400+
Vulnerability -
Authenticated (Contributor+) Stored Cross Site Scripting (XSS)
Patched In Version -
3.06
Severity -
Medium

23 - WordPress Job Board and Recruitment Plugin – JobWP
Plugin -
WordPress Job Board and Recruitment Plugin – JobWP
Plugin Slug -
jobwp
Installations -
300+
Vulnerability -
Arbitrary File Upload
Patched In Version -
2.1
Severity -
Critical
CVE Code -
24 - wpShopGermany – Protected Shops
Plugin -
wpShopGermany – Protected Shops
Plugin Slug -
wpshopgermany-protectedshops
Installations -
40+
Vulnerability -
Cross Site Scripting (XSS)
Patched In Version -
2.1
Severity -
Medium
CVE Code -
25 - JetElements For Elementor
Plugin -
Plugin Slug -
jet-elements
Vulnerability -
Authenticated Remote Code Execution (RCE)
Patched In Version -
2.6.11
Severity -
Critical
CVE Code -
26 - Shop as a Customer for WooCommerce
Plugin -
Shop as a Customer for WooCommerce
Plugin Slug -
shop-as-a-customer-for-woocommerce
Vulnerability -
Shop Manager+ Privilege Escalation
Patched In Version -
1.2.4
Severity -
High
27 - Shop as a Customer for WooCommerce
Plugin -
Shop as a Customer for WooCommerce
Plugin Slug -
shop-as-a-customer-for-woocommerce
Vulnerability -
Subscriber+ Privilege Escalation
Patched In Version -
1.1.8
Severity -
High
28 - Simple Share Follow Button
Plugin -
Plugin Slug -
simple-share-follow-button
Vulnerability -
Authenticated (Contributor+) Stored Cross Site Scripting (XSS) via Shortcode
Patched In Version -
1.04
Severity -
Medium
Protect Your WordPress Website Today With Website Guardian
Join hundreds of businesses like yours who trust InterwebDEFENCE to protect their websites and livelihood. Using our proven website security analysis and best-in-class AI ‘Website Guardian” software, we are able to protect, monitor and backup your WordPress website.
Go ahead, keep the good guys In and the bad guys out – Click HERE to see our Website Guardian security plans NOW
PLUS
Find out about our unconditional ‘Double Protection’ Guarantee. This guarantee is better than risk free!
We’ll have you scanned, protected and secure in no time, giving you total peace of mind that your website is safe, leaving you to focus on your business success.
WordPress Plugin Vulnerabilities – Unpatched

1 - Booster for WooCommerce
Plugin -
Plugin Slug -
woocommerce-jetpack
Installations -
60,000+
Vulnerability -
Shop Manager+ Arbitrary Option Update
Patched In Version -
No Fix
Severity -
High

2 - Guest posting / Frontend Posting wordpress plugin – WP Front User Submit / Front Editor
Plugin -
Guest posting / Frontend Posting wordpress plugin – WP Front User Submit / Front Editor
Plugin Slug -
front-editor
Installations -
200+
Vulnerability -
Authenticated Stored Cross Site Scripting (XSS)
Patched In Version -
No Fix
Severity -
Medium
CVE Code -
Protect Your WordPress Website Today With Website Guardian
Join hundreds of businesses like yours who trust InterwebDEFENCE to protect their websites and livelihood. Using our proven website security analysis and best-in-class AI ‘Website Guardian” software, we are able to protect, monitor and backup your WordPress website.
Go ahead, keep the good guys In and the bad guys out – Click HERE to see our Website Guardian security plans NOW
PLUS
Find out about our unconditional ‘Double Protection’ Guarantee. This guarantee is better than risk free!
We’ll have you scanned, protected and secure in no time, giving you total peace of mind that your website is safe, leaving you to focus on your business success.
WordPress Theme Vulnerabilities
There were no new theme vulnerabilities this week.
Protect Your WordPress Website Today With Website Guardian
Join hundreds of businesses like yours who trust InterwebDEFENCE to protect their websites and livelihood. Using our proven website security analysis and best-in-class AI ‘Website Guardian” software, we are able to protect, monitor and backup your WordPress website.
Go ahead, keep the good guys In and the bad guys out – Click HERE to see our Website Guardian security plans NOW
PLUS
Find out about our unconditional ‘Double Protection’ Guarantee. This guarantee is better than risk free!
We’ll have you scanned, protected and secure in no time, giving you total peace of mind that your website is safe, leaving you to focus on your business success.