WordPress Vulnerability Report: December 2021, Part 3

by | Dec 17, 2021 | Security

Written by Michael Moore of Ithemes on November 10, 2021

Last Updated on November 10, 2021

Vulnerable plugins and themes are the #1 reason WordPress websites get hacked. This post covers recent WordPress plugin, theme, and core vulnerabilities and what to do if you run one of the vulnerable plugins or themes on your website.

Each vulnerability will have a severity rating of Low, Medium, High, or Critical. Responsible disclosure and reporting of vulnerabilities is an integral part of keeping the WordPress community safe. Please share this post with your friends to help get the word out and make WordPress safer for everyone.


Is Your WordPress Website Secure?

DID YOU KNOW – A staggering 83% of WordPress websites are not upgraded or updated, is your website one of these?

Hacks happen due to lack of website upkeep and protection, like updating WordPress or plugins, plus using weak passwords. Contrary to popular belief, web designers and website hosting companies are not responsible for the security of your WordPress website; you are. It’s like using your computer without Anti-virus!


WordPress Core Vulnerabilities
The latest version of WordPress core is 5.8.1 was released as a security and maintenance release. As a best practice, always be sure to run the latest version of WordPress core!

WordPress News
As the busiest online shopping time of the year is in full swing, cybercriminals have been busy with attempts to “hack the planet.” Wordfence recently reported a massive wave of attacks that targeted 1.6 million WordPress sites over the course of just 36 hours!

Finally, BleepingComputer recently reported that hackers have been installing skimmer code into random plugins. To tighten security for e-commerce sites, we recommend requiring two-factor authentication for all admin users, activating trusted devices, file change detection, and that WordPress security logs be read and reviewed regularly.

WordPress Plugin Vulnerabilities

1. Elementor
2. UpdraftPlus
3. WooCommerce PDF Invoices & Packing Slips
4. PublishPress Capabilities
5. Chaty Free
6. PowerPack Addons for Elementor
7. Booking Calendar
8. 10Web Social Photo Feed
9. Site Reviews
10. Speed Booster Pack
11. Multivendor Marketplace Solution for WooCommerce
12. Modal Window
13. WP Coder
14. RegistrationMagic
15. Events Made Easy
16. Button Generator
17. Tab – Accordion, FAQ
18. Stars Rating
19. WPCalc


WordPress Plugin Vulnerabilities

1. Elementor


Plugin: Elementor
Vulnerability: Admin+ SQL Injection
Active Installation: 5+ Million
Patched in Version: 3.4.8
Severity: High

2. UpdraftPlus


Plugin: UpdraftPlus
Vulnerability: Reflected Cross-Site Scripting
Active Installation: 3+ Million
Patched in Version: 1.16.66
Severity: High

3. WooCommerce PDF Invoices & Packing Slips


Plugin: WooCommerce PDF Invoices & Packing Slips
Vulnerability: Reflected Cross-Site Scripting
Active Installation: 300,000+
Patched in Version: 2.10.5
Severity: High

4. PublishPress Capabilities


Plugin: PublishPress Capabilities
Vulnerability: Unauthenticated Arbitrary Options Update to Blog Compromise
Active Installation: 100,000+
Patched in Version: 2.3.1
Severity: Critical

Plugin: PublishPress Capabilities Pro
Vulnerability: Unauthenticated Arbitrary Options Update to Blog Compromise
Patched in Version: 2.3.1
Severity: Critical

5. Chaty Free


Plugin: Chaty Free
Vulnerability: Reflected Cross-Site Scripting
Active Installation: 100,000+
Patched in Version: 2.8.3
Severity: High

Plugin: Chaty Pro
Vulnerability: Reflected Cross-Site Scripting
Patched in Version: 2.8.2
Severity: High

6. PowerPack Addons for Elementor


Plugin: PowerPack Addons for Elementor
Vulnerability: Reflected Cross-Site Scripting
Active Installation: 60,000+
Patched in Version: 2.6.2
Severity: High

7. Booking Calendar


Plugin: Booking Calendar
Vulnerability: Reflected Cross-Site Scripting
Active Installation: 60,000+
Patched in Version: 8.9.2
Severity: High

8. 10Web Social Photo Feed


Plugin: 10Web Social Photo Feed 
Vulnerability: Reflected Cross-Site Scripting (XSS)
Active Installation: 60,000+
Patched in Version: 1.4.29
Severity: High

9. Site Reviews


Plugin: Site Reviews
Vulnerability: Unauthenticated Stored Cross-Site Scripting
Active Installation: 40,000+
Patched in Version: 5.17.3
Severity: High

10. Speed Booster Pack


Plugin: Speed Booster Pack
Vulnerability: Admin+ SQL Injection
Active Installation: 30,000+
Patched in Version: 4.3.3.1
Severity: Medium

11. Multivendor Marketplace Solution for WooCommerce


Plugin: Multivendor Marketplace Solution for WooCommerce
Vulnerability: Unauthenticated AJAX Calls
Active Installation: 10,000+
Patched in Version: 3.8.4
Severity: High

12. Modal Window


Plugin: Modal Window
Vulnerability: RFI leading to RCE via CSRF
Active Installation: 10,000+
Patched in Version: 5.2.2
Severity: High

13. WP Coder


Plugin: WP Coder
Vulnerability: RFI leading to RCE via CSRF
Active Installation: 10,000+
Patched in Version: 2.5.2
Severity: High

14. RegistrationMagic


Plugin: RegistrationMagic
Vulnerability: Admin+ SQL Injection
Active Installation: 10,000+
Patched in Version: 5.0.1.6
Severity: Medium

Plugin: RegistrationMagic
Vulnerability: Authentication Bypass
Active Installation: 10,000+
Patched in Version: 5.0.1.8
Severity: Critical

15. Events Made Easy


Plugin: Events Made Easy
Vulnerability: Subscriber+ SQL Injection
Activate Installation: 6,000+
Patched in Version: 2.2.36
Severity: High

16. Button Generator


Plugin: Button Generator
Vulnerability: RFI leading to RCE via CSRF
Activate Installation: 5,000+
Patched in Version: 2.3.3
Severity: High

17. Tab – Accordion, FAQ


Plugin: Tab – Accordion, FAQ
Vulnerability: Unauthenticated AJAX Calls
Activate Installation: 2000+
Patched in Version: 1.3.2
Severity: Critical

18. Stars Rating


Plugin: Stars Rating
Vulnerability: Comments Denial of Service
Activate Installation: 800+
Patched in Version: 3.5.1
Severity: Medium

19. WPcalc

Plugin: WPCalc
Vulnerability: Authenticated SQL Injection
Patched in Version: No known fix – plugin closed
Severity: Medium


Protect Your WordPress Website Today With Website Guardian

Join hundreds of businesses like yours who trust InterwebDEFENCE to protect their websites and livelihood. Using our proven website security analysis and best-in-class AI ‘Website Guardian” software, we are able to protect, monitor and backup your WordPress website.

Go ahead, keep the good guys In and the bad guys out – Click HERE to see our Website Guardian security plans NOW
PLUS
Find out about our unconditional ‘Double Protection’ Guarantee. This guarantee is better than risk free!

We’ll have you scanned, protected and secure in no time, giving you total peace of mind that your website is safe, leaving you to focus on your business success.

Click to access the login or register cheese