WordPress Vulnerability Report: December 2021, Part 1

by | Dec 2, 2021 | Security

Written by Michael Moore of Ithemes on November 10, 2021

Last Updated on November 10, 2021

Vulnerable plugins and themes are the #1 reason WordPress websites get hacked. This post covers recent WordPress plugin, theme, and core vulnerabilities and what to do if you run one of the vulnerable plugins or themes on your website.

Each vulnerability will have a severity rating of Low, Medium, High, or Critical. Responsible disclosure and reporting of vulnerabilities is an integral part of keeping the WordPress community safe. Please share this post with your friends to help get the word out and make WordPress safer for everyone.


Is Your WordPress Website Secure?

DID YOU KNOW – A staggering 83% of WordPress websites are not upgraded or updated, is your website one of these?

Hacks happen due to lack of website upkeep and protection, like updating WordPress or plugins, plus using weak passwords. Contrary to popular belief, web designers and website hosting companies are not responsible for the security of your WordPress website; you are. It’s like using your computer without Anti-virus!


WordPress Core Vulnerabilities
The latest version of WordPress core is 5.8.1 was released as a security and maintenance release. As a best practice, always be sure to run the latest version of WordPress core!

WordPress Plugin Vulnerabilities

1. Logo Carousel
2. Ni WooCommerce Custom Order Status
3. WCFM
4. Everest Forms
5. WP Visitor Statistics (Real Time Traffic)
6. Kudos Donations
7. Icegram
8. Blog2Social
9. Paid Memberships Pro
10. WPFront User Role Editor
11. Tickera
12. WP Guppy
13. Simple JWT Login
14. myCRED
15. Hide My WP
16. Awesome Support – WordPress HelpDesk & Support Plugin
17. Display Post Metadata
18. Floating Social Media Icon
19. Gwolle Guestbook


WordPress Plugin Vulnerabilities

1. Logo Carousel


Plugin: Logo Carousel
Vulnerability: Contributor+ Stored Cross-Site Scripting
Patched in Version: 3.4.2
Severity: Medium

Plugin: Logo Carousel
Vulnerability: Unauthorised Private Post Access
Patched in Version: 3.4.2
Severity: Medium

2. Ni WooCommerce Custom Order Status


Plugin: Ni WooCommerce Custom Order Status
Vulnerability: Subscriber+ SQL Injection
Patched in Version: 1.9.7
Severity: High

3. WCFM


Plugin: WCFM
Vulnerability: Unauthenticated SQL Injection
Patched in Version: 3.4.12
Severity: High

4. Everest Forms


Plugin: Everest Forms
Vulnerability: Reflected Cross-Site Scripting
Patched in Version: 1.8.0
Severity: Medium

5. WP Visitor Statistics (Real Time Traffic)


Plugin: WP Visitor Statistics (Real Time Traffic)
Vulnerability: Subscriber+ SQL Injection
Patched in Version: 4.8
Severity: High

6. Kudos Donations


Plugin: Kudos Donations
Vulnerability: Arbitrary Items Deletion via CSRF
Patched in Version: 3.1.2
Severity: High

7. Icegram


Plugin: Icegram
Vulnerability: Reflected Cross-Site Scripting
Patched in Version: 2.0.5
Severity: Medium

8. Blog2Social


Plugin: Blog2Social
Vulnerability: Reflected Cross-Site Scripting
Patched in Version: 6.8.7
Severity: High

9. Paid Memberships Pro


Plugin: Paid Memberships Pro
Vulnerability: Reflected Cross-Site Scripting
Patched in Version: 2.6.6
Severity: High

10. WPFront User Role Editor


Plugin: WPFront User Role Editor
Vulnerability: Reflected Cross-Site Scripting
Patched in Version: 3.2.1.11184
Severity: Medium

11. Tickera


Plugin: Tickera
Vulnerability: Unauthenticated Stored Cross-Site Scripting
Patched in Version: 3.4.8.3
Severity: High

12. WP Guppy

Plugin: WP Guppy
Vulnerability: Sensitive Information Disclosure
Patched in Version: 1.3
Severity: High

13. Simple JWT Login


Plugin: Simple JWT Login
Vulnerability: Insecure Password Creation
Patched in Version: 3.3.0
Severity: Low

14. myCRED


Plugin: myCRED
Vulnerability: Reflected Cross-Site Scripting
Patched in Version: 1.7.8
Severity: High

15. Hide my WP

Plugin: Hide My WP
Vulnerability: Unauthenticated Plugin Deactivation
Patched in Version: 6.2.4
Severity: Medium

Plugin: Hide My WP
Vulnerability: Unauthenticated SQL Injection
Patched in Version: 6.2.4
Severity: High

16. Awesome Support – WordPress HelpDesk & Support Plugin


Plugin: Awesome Support – WordPress HelpDesk & Support Plugin
Vulnerability: Reflected Cross-Site Scripting
Patched in Version: 6.0.7
Severity: High

17. Display Post Metadata


Plugin: Display Post Metadata
Vulnerability: Contributor+ Stored Cross-Site Scripting
Patched in Version: 1.5.0
Severity: Medium

18. Floating Social Media Icon

Plugin: Floating Social Media Icon
Vulnerability: Admin+ Stored Cross-Site Scripting
Patched in Version: No known fix – plugin closed
Severity: Low

19. Gwolle Guestbook


Plugin: Gwolle Guestbook
Vulnerability: Reflected Cross-Site Scripting
Patched in Version: 4.2.0
Severity: Medium


Protect Your WordPress Website Today With Website Guardian

Join hundreds of businesses like yours who trust InterwebDEFENCE to protect their websites and livelihood. Using our proven website security analysis and best-in-class AI ‘Website Guardian” software, we are able to protect, monitor and backup your WordPress website.

Go ahead, keep the good guys In and the bad guys out – Click HERE to see our Website Guardian security plans NOW
PLUS
Find out about our unconditional ‘Double Protection’ Guarantee. This guarantee is better than risk free!

We’ll have you scanned, protected and secure in no time, giving you total peace of mind that your website is safe, leaving you to focus on your business success.

Click to access the login or register cheese