WordPress Vulnerability Report – August 9, 2023

by | Aug 9, 2023 | Security

DETAILS FROM DAN KNAUSS OF ITHEMES ON AUGUST 9, 2023

original available here

Last Updated on August 9, 2023

 

Since last week, only 30 total vulnerabilities emerged in public disclosure, but they include the popular Advanced Custom Fields (ACF) plugin. ACF is used on over two million active WordPress sites. Fortunately, a patch is available immediately for ACF and 27 other plugin vulnerabilities, so run those updates if you’re affected!

Additionally, there are two plugin vulnerabilities with no patch available yet. If you use an unpatched plugin or theme, check their vendors’ intentions and progress on a security release. Suppose no patch is forthcoming or the vulnerable software has been marked “closed” and dropped from the official WordPress theme and plugin repositories. In that case, you should consider deactivation and removal in favor of alternative solutions.

Is Your WordPress Website Secure?

DID YOU KNOW – A staggering 83% of WordPress websites are not upgraded or updated, is your website one of these?

Hacks happen due to lack of website upkeep and protection, like updating WordPress or plugins, plus using weak passwords. Contrary to popular belief, web designers and website hosting companies are not responsible for the security of your WordPress website; you are. It’s like using your computer without Anti-virus!

WordPress Core Vulnerabilities

No new WordPress core vulnerabilities were disclosed this week. 

WordPress Plugin Vulnerabilities – Patched

These are plugin vulnerabilities that have been fixed with the most recent updates, it’s recomended to update all plugins to the newest version to improve site safety.

Jump to section

WordPress Plugin Vulnerabilities – Unpatched

These are plugin vulnerabilities that have NOT been fixed with the most recent updates, it’s recomended you deactivate or remove these plugins from your site until they are fixed.

Jump to section

WordPress Theme Vulnerabilities

Jump to section

These are vulnerabilities that have occoured in themes for wordpress. If there is a patch for the issue you should update the theme immediately, if there is no fix you should change your site to a different theme.

WordPress Plugin Vulnerabilities – Patched

Advanced Custom Fields (ACF)

1 - Advanced Custom Fields (ACF)

Plugin -

Advanced Custom Fields (ACF)


Plugin Slug -

advanced-custom-fields


Installations -

2,000,000+


Vulnerability -

Authenticated Cross Site Scripting (XSS)


Patched In Version -

6.1.8


Severity -

Medium


Duplicate Post

2 - Duplicate Post

Plugin -

Duplicate Post


Plugin Slug -

copy-delete-posts


Installations -

200,000+


Vulnerability -

Cross Site Request Forgery (CSRF) via AJAX action


Patched In Version -

1.4.2


Severity -

Medium


TI WooCommerce Wishlist

3 - TI WooCommerce Wishlist

Plugin -

TI WooCommerce Wishlist


Plugin Slug -

ti-woocommerce-wishlist


Installations -

100,000+


Vulnerability -

Unauthenticated Blind SQL Injection via Rest API


Patched In Version -

2.7.4


Severity -

Critical


Change WP Admin Login

4 - Change WP Admin Login

Plugin -

Change WP Admin Login


Plugin Slug -

change-wp-admin-login


Installations -

90,000+


Vulnerability -

Secret Login Page Disclosure


Patched In Version -

1.1.4


Severity -

Medium


CVE Code -

2023-3604


The Post Grid – Shortcode, Gutenberg Blocks and Elementor Addon for Post Grid

5 - The Post Grid – Shortcode, Gutenberg Blocks and Elementor Addon for Post Grid

Plugin -

The Post Grid – Shortcode, Gutenberg Blocks and Elementor Addon for Post Grid


Plugin Slug -

the-post-grid


Installations -

60,000+


Vulnerability -

Cross Site Request Forgery (CSRF) Leading To CSS Change


Patched In Version -

7.2.8


Severity -

Medium


CVE Code -

2023-39923


PostX – Gutenberg Post Grid Blocks

6 - PostX – Gutenberg Post Grid Blocks

Plugin -

PostX – Gutenberg Post Grid Blocks


Plugin Slug -

ultimate-post


Installations -

30,000+


Vulnerability -

Reflected Cross Site Scripting (XSS)


Patched In Version -

3.0.6


Severity -

High


CVE Code -

2023-3992


Media from FTP

7 - Media from FTP

Plugin -

Media from FTP


Plugin Slug -

media-from-ftp


Installations -

20,000+


Vulnerability -

Improper Privilege Management


Patched In Version -

11.16


Severity -

Medium


Themesflat Addons For Elementor

8 - Themesflat Addons For Elementor

Plugin -

Themesflat Addons For Elementor


Plugin Slug -

themesflat-addons-for-elementor


Installations -

20,000+


Vulnerability -

Unauthenticated PHP Object Injection


Patched In Version -

2.0.1


Severity -

High


CVE Code -

2023-37390


Import All Pages, Post types, Products, Orders, and Users as XML & CSV

9 - Import All Pages, Post types, Products, Orders, and Users as XML & CSV

Plugin -

Import All Pages, Post types, Products, Orders, and Users as XML & CSV


Plugin Slug -

wp-ultimate-csv-importer


Installations -

20,000+


Vulnerability -

Authenticated Arbitrary Usermeta Update to Privilege Escalation


Patched In Version -

7.9.9


Severity -

Medium


CVE Code -

2023-4140


Import All Pages, Post types, Products, Orders, and Users as XML & CSV

10 - Import All Pages, Post types, Products, Orders, and Users as XML & CSV

Plugin -

Import All Pages, Post types, Products, Orders, and Users as XML & CSV


Plugin Slug -

wp-ultimate-csv-importer


Installations -

20,000+


Vulnerability -

Sensitive Information Exposure via Directory Listing


Patched In Version -

7.9.9


Severity -

High


CVE Code -

2023-4139


Import All Pages, Post types, Products, Orders, and Users as XML & CSV

11 - Import All Pages, Post types, Products, Orders, and Users as XML & CSV

Plugin -

Import All Pages, Post types, Products, Orders, and Users as XML & CSV


Plugin Slug -

wp-ultimate-csv-importer


Installations -

20,000+


Vulnerability -

Authenticated PHP file upload to Remote Code Execution (RCE)


Patched In Version -

7.9.9


Severity -

High


CVE Code -

2023-4141


Import All Pages, Post types, Products, Orders, and Users as XML & CSV

12 - Import All Pages, Post types, Products, Orders, and Users as XML & CSV

Plugin -

Import All Pages, Post types, Products, Orders, and Users as XML & CSV


Plugin Slug -

wp-ultimate-csv-importer


Installations -

20,000+


Vulnerability -

Authenticated Remote Code Execution (RCE)


Patched In Version -

7.9.9


Severity -

High


CVE Code -

2023-4142


Booking Package

13 - Booking Package

Plugin -

Booking Package


Plugin Slug -

booking-package


Installations -

10,000+


Vulnerability -

Reflected Cross Site Scripting (XSS)


Patched In Version -

1.6.02


Severity -

High


CVE Code -

2023-39918


Stripe Payment Plugin for WooCommerce

14 - Stripe Payment Plugin for WooCommerce

Plugin -

Stripe Payment Plugin for WooCommerce


Plugin Slug -

payment-gateway-stripe-and-woocommerce-integration


Installations -

10,000+


Vulnerability -

Authentication Bypass


Patched In Version -

3.7.8


Severity -

Critical


CVE Code -

2023-3162


15 - Simple Blog Card

Plugin -

Simple Blog Card


Plugin Slug -

simple-blog-card


Installations -

3,000+


Vulnerability -

Sensitive Data Exposure


Patched In Version -

1.32


Severity -

Medium


16 - Simple Blog Card

Plugin -

Simple Blog Card


Plugin Slug -

simple-blog-card


Installations -

3,000+


Vulnerability -

Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode


Patched In Version -

1.31


Severity -

Medium


Leyka

17 - Leyka

Plugin -

Leyka


Plugin Slug -

leyka


Installations -

2,000+


Vulnerability -

Reflected Cross Site Scripting (XSS)


Patched In Version -

3.30.3


Severity -

High


CVE Code -

2023-39314


Photo Gallery by Ays – Responsive Image Gallery

18 - Photo Gallery by Ays – Responsive Image Gallery

Plugin -

Photo Gallery by Ays – Responsive Image Gallery


Plugin Slug -

gallery-photo-gallery


Installations -

1,000+


Vulnerability -

Cross Site Request Forgery (CSRF)


Patched In Version -

5.2.7


Severity -

Medium


CVE Code -

2023-39917


Sign-up Sheets

19 - Sign-up Sheets

Plugin -

Sign-up Sheets


Plugin Slug -

sign-up-sheets


Installations -

1,000+


Vulnerability -

Cross Site Request Forgery (CSRF)


Patched In Version -

2.2.9


Severity -

Medium


CVE Code -

2023-39165


20 - Upload Media By URL

Plugin -

Upload Media By URL


Plugin Slug -

upload-media-by-url


Installations -

1,000+


Vulnerability -

Cross Site Request Forgery (CSRF)


Patched In Version -

1.0.8


Severity -

Medium


CVE Code -

2023-3720


Bus Ticket Booking with Seat Reservation

21 - Bus Ticket Booking with Seat Reservation

Plugin -

Bus Ticket Booking with Seat Reservation


Plugin Slug -

bus-ticket-booking-with-seat-reservation


Installations -

900+


Vulnerability -

Reflected Cross Site Scripting (XSS)


Patched In Version -

5.2.4


Severity -

High


CVE Code -

2023-4067


22 - Simple Ticker

Plugin -

Simple Ticker


Plugin Slug -

simple-ticker


Installations -

400+


Vulnerability -

Authenticated (Contributor+) Stored Cross Site Scripting (XSS)


Patched In Version -

3.06


Severity -

Medium


WordPress Job Board and Recruitment Plugin – JobWP

23 - WordPress Job Board and Recruitment Plugin – JobWP

Plugin -

WordPress Job Board and Recruitment Plugin – JobWP


Plugin Slug -

jobwp


Installations -

300+


Vulnerability -

Arbitrary File Upload


Patched In Version -

2.1


Severity -

Critical


CVE Code -

2023-29384


24 - wpShopGermany – Protected Shops

Plugin -

wpShopGermany – Protected Shops


Plugin Slug -

wpshopgermany-protectedshops


Installations -

40+


Vulnerability -

Cross Site Scripting (XSS)


Patched In Version -

2.1


Severity -

Medium


CVE Code -

2023-39919


25 - JetElements For Elementor

Plugin -

JetElements For Elementor


Plugin Slug -

jet-elements


Vulnerability -

Authenticated Remote Code Execution (RCE)


Patched In Version -

2.6.11


Severity -

Critical


CVE Code -

2023-39157


26 - Shop as a Customer for WooCommerce

Plugin -

Shop as a Customer for WooCommerce


Plugin Slug -

shop-as-a-customer-for-woocommerce


Vulnerability -

Shop Manager+ Privilege Escalation


Patched In Version -

1.2.4


Severity -

High


27 - Shop as a Customer for WooCommerce

Plugin -

Shop as a Customer for WooCommerce


Plugin Slug -

shop-as-a-customer-for-woocommerce


Vulnerability -

Subscriber+ Privilege Escalation


Patched In Version -

1.1.8


Severity -

High


28 - Simple Share Follow Button

Plugin -

Simple Share Follow Button


Plugin Slug -

simple-share-follow-button


Vulnerability -

Authenticated (Contributor+) Stored Cross Site Scripting (XSS) via Shortcode


Patched In Version -

1.04


Severity -

Medium


Protect Your WordPress Website Today With Website Guardian

Join hundreds of businesses like yours who trust InterwebDEFENCE to protect their websites and livelihood. Using our proven website security analysis and best-in-class AI ‘Website Guardian” software, we are able to protect, monitor and backup your WordPress website.

Go ahead, keep the good guys In and the bad guys out – Click HERE to see our Website Guardian security plans NOW
PLUS
Find out about our unconditional ‘Double Protection’ Guarantee. This guarantee is better than risk free!

We’ll have you scanned, protected and secure in no time, giving you total peace of mind that your website is safe, leaving you to focus on your business success.

WordPress Plugin Vulnerabilities – Unpatched

Booster for WooCommerce

1 - Booster for WooCommerce

Plugin -

Booster for WooCommerce


Plugin Slug -

woocommerce-jetpack


Installations -

60,000+


Vulnerability -

Shop Manager+ Arbitrary Option Update


Patched In Version -

No Fix


Severity -

High


Guest posting / Frontend Posting wordpress plugin – WP Front User Submit / Front Editor

2 - Guest posting / Frontend Posting wordpress plugin – WP Front User Submit / Front Editor

Plugin -

Guest posting / Frontend Posting wordpress plugin – WP Front User Submit / Front Editor


Plugin Slug -

front-editor


Installations -

200+


Vulnerability -

Authenticated Stored Cross Site Scripting (XSS)


Patched In Version -

No Fix


Severity -

Medium


CVE Code -

2023-1982


Protect Your WordPress Website Today With Website Guardian

Join hundreds of businesses like yours who trust InterwebDEFENCE to protect their websites and livelihood. Using our proven website security analysis and best-in-class AI ‘Website Guardian” software, we are able to protect, monitor and backup your WordPress website.

Go ahead, keep the good guys In and the bad guys out – Click HERE to see our Website Guardian security plans NOW
PLUS
Find out about our unconditional ‘Double Protection’ Guarantee. This guarantee is better than risk free!

We’ll have you scanned, protected and secure in no time, giving you total peace of mind that your website is safe, leaving you to focus on your business success.

WordPress Theme Vulnerabilities

There were no new theme vulnerabilities this week.

Protect Your WordPress Website Today With Website Guardian

Join hundreds of businesses like yours who trust InterwebDEFENCE to protect their websites and livelihood. Using our proven website security analysis and best-in-class AI ‘Website Guardian” software, we are able to protect, monitor and backup your WordPress website.

Go ahead, keep the good guys In and the bad guys out – Click HERE to see our Website Guardian security plans NOW
PLUS
Find out about our unconditional ‘Double Protection’ Guarantee. This guarantee is better than risk free!

We’ll have you scanned, protected and secure in no time, giving you total peace of mind that your website is safe, leaving you to focus on your business success.

Click to access the login or register cheese