WordPress Vulnerability Report: December 2021, Part 4

by | Dec 22, 2021 | Security

Written by Michael Moore of Ithemes on November 10, 2021

Last Updated on November 10, 2021

Vulnerable plugins and themes are the #1 reason WordPress websites get hacked. This post covers recent WordPress plugin, theme, and core vulnerabilities and what to do if you run one of the vulnerable plugins or themes on your website.

Each vulnerability will have a severity rating of Low, Medium, High, or Critical. Responsible disclosure and reporting of vulnerabilities is an integral part of keeping the WordPress community safe. Please share this post with your friends to help get the word out and make WordPress safer for everyone.


Is Your WordPress Website Secure?

DID YOU KNOW – A staggering 83% of WordPress websites are not upgraded or updated, is your website one of these?

Hacks happen due to lack of website upkeep and protection, like updating WordPress or plugins, plus using weak passwords. Contrary to popular belief, web designers and website hosting companies are not responsible for the security of your WordPress website; you are. It’s like using your computer without Anti-virus!


WordPress Core Vulnerabilities
The latest version of WordPress core is 5.8.2. As a best practice, always be sure to run the latest version of WordPress core!

WordPress Plugin Vulnerabilities

1. All In One SEO
2. Smash Balloon Social Post Feed
3. Modern Events Calendar Lite
4. WOOCS
5. Crisp Live Chat
6. Image Hover Effects Ultimate
7. WP Booking System – Booking Calendar
8. Landing Page Builder
9. Fathom Analytics
10. True Ranker

WordPress Plugin: Plugin Closed:

11. Comment Engine Pro
12. .htaccess Redirect
13. Parsian Bank Gateway for Woocommerce
14. Real WYSIWYG
15. Link List Manager
16. Simple Image Gallery
17. WooCommerce EnvioPack
18. Magic Post Voice
19. H5P CSS Editor
20. duoFAQ
21. Magic Post Voice
22. WooCommerce myghpay Payment Gateway

Premium Plugin Vulnerabilities

23. The Plus Addons for Elementor Pro
24. Lets Box
25. Share One Drive
26. Out of the Box
27. Use Your Drive


WordPress Plugin Vulnerabilities

1. All In One SEO


Plugin: All In One SEO
Vulnerability: Authenticated SQL Injection
Active Installation: 3+ Million
Patched in Version: 4.1.5.3
Severity: High

Plugin: All In One SEO
Vulnerability: Authenticated Privilege Escalation
Active Installation: 3+ Million
Patched in Version: 4.1.5.3
Severity: Critical

2. Smash Balloon Social Post Feed


Plugin: Smash Balloon Social Post Feed
Vulnerability: Authenticated Reflected Cross-Site Scripting (XSS)
Active Installation: 200,000+
Patched in Version: 4.1.1
Severity: Medium

3. Modern Events Calendar Lite


Plugin: Modern Events Calendar Lite
Vulnerability: Subscriber+ Category Add Leading to Stored XSS
Active Installation: 100,000+
Patched in Version: 6.2.0
Severity: Medium

4. WOOCS


Plugin: WOOCS
Vulnerability: Reflected Cross-Site Scripting
Active Installation: 60,000+
Patched in Version: 1.3.7.3
Severity: High

5. Crispy Live Chat


Plugin: Crisp Live Chat
Vulnerability: CSRF to Stored Cross-Site Scripting
Active Installation: 60,000+
Patched in Version: 0.32
Severity: High

6. Image Hover Effects Ultimate


Plugin: Image Hover Effects Ultimate
Vulnerability: Unauthenticated Arbitrary Option Update
Active Installation: 20,000+
Patched in Version: 9.7.0
Severity: Critical

7. WP Booking System – Booking Calendar


Plugin: WP Booking System – Booking Calendar
Vulnerability: Authenticated Reflected Cross-Site Scripting (XSS)
Active Installation: 10,000+
Patched in Version: 2.0.15
Severity: Medium

8. Landing Page Builder


Plugin: Landing Page Builder
Vulnerability: Authenticated Reflected Cross-Site Scripting (XSS)
Active Installation: 10,000+
Patched in Version: 1.4.9.6
Severity: Medium

9. Fathom Analytics


Plugin: Fathom Analytics
Vulnerability: Admin+ Stored Cross-Site Scripting
Active Installation: 2000+
Patched in Version: 3.0.5
Severity: Low

10. True Ranker

Plugin: True Ranker
Vulnerability: Unauthenticated Arbitrary File Access via Path Traversal
Active Installation: 200+
Patched in Version: 2.2.4
Severity: Low

WordPress Plugin Vulnerabilities: Plugin Closed

11. Comment Engine Pro

Plugin: Comment Engine Pro 
Vulnerability: Editor+ Stored Cross-Site Scripting
Patched in Version: No known fix – plugin closed
Severity: Low

12. .htaccess Redirect

Plugin: .htaccess Redirect 
Vulnerability: Reflected Cross-Site Scripting
Patched in Version: No known fix – plugin closed
Severity: High

13. Parsian Bank Gateway for Woocommerce

Plugin: Parsian Bank Gateway for Woocommerce
Vulnerability: Reflected Cross-Site Scripting
Patched in Version: No known fix – plugin closed
Severity: High

14. Real WYSIWYG

Plugin: Real WYSIWYG
Vulnerability: Reflected Cross-Site Scripting
Patched in Version: No known fix – plugin closed
Severity: High

15. Link List Manager

Plugin: Link List Manager 
Vulnerability: Reflected Cross-Site Scripting
Patched in Version: No known fix – plugin closed
Severity: High

16. Simple Image Gallery

Plugin: Simple Image Gallery
Vulnerability: Reflected Cross-Site Scripting
Patched in Version: No known fix – plugin closed
Severity: High

17. WooCommerce EnvioPack


Plugin: WooCommerce EnvioPack 
Vulnerability: Reflected Cross-Site Scripting
Patched in Version: No known fix – plugin closed
Severity: High

18. Magic Post Voice

Plugin: Magic Post Voice
Vulnerability: Reflected Cross-Site Scripting
Patched in Version: No known fix – plugin closed
Severity: High

19. H5P CSS Editor

Plugin: H5P CSS Editor
Vulnerability: Reflected Cross-Site Scripting
Patched in Version: No known fix – plugin closed
Severity: High

20. duoFAQ

Plugin: duoFAQ
Vulnerability: Reflected Cross-Site Scripting
Patched in Version: No known fix – plugin closed
Severity: High

21. Magic Post Voice

Plugin: Magic Post Voice
Vulnerability: Reflected Cross-Site Scripting
Patched in Version: No known fix – plugin closed
Severity: High

22. WooCommerce myghpay Payment Gateway

Plugin: WooCommerce myghpay Payment Gateway
Vulnerability: Reflected Cross-Site Scripting
Patched in Version: No known fix – plugin closed
Severity: High

Premium Plugin Vulnerabilities

23. The Plus Addons for Elementor Pro

Plugin: The Plus Addons for Elementor Pro
Vulnerability: Sensitive Data Disclosure
Patched in Version: 5.0.7
Severity: Medium

Plugin: The Plus Addons for Elementor Pro
Vulnerability: Unauthenticated SQL Injection
Patched in Version: 5.0.7
Severity: Medium

24. Lets Box

Plugin: Lets Box
Vulnerability: Reflected Cross-Site Scripting
Patched in Version: 1.13.3
Severity: Medium

25. Share One Drive

Plugin: Share One Drive
Vulnerability: Reflected Cross-Site Scripting
Patched in Version: 1.15.3
Severity: Medium

26. Out of the Box

Plugin: Out of the Box
Vulnerability: Reflected Cross-Site Scripting
Patched in Version: 1.20.3
Severity: Medium

27. Use your Drive

Plugin: Use your Drive
Vulnerability: Reflected Cross-Site Scripting
Patched in Version: 1.18.3
Severity: Medium


Protect Your WordPress Website Today With Website Guardian

Join hundreds of businesses like yours who trust InterwebDEFENCE to protect their websites and livelihood. Using our proven website security analysis and best-in-class AI ‘Website Guardian” software, we are able to protect, monitor and backup your WordPress website.

Go ahead, keep the good guys In and the bad guys out – Click HERE to see our Website Guardian security plans NOW
PLUS
Find out about our unconditional ‘Double Protection’ Guarantee. This guarantee is better than risk free!

We’ll have you scanned, protected and secure in no time, giving you total peace of mind that your website is safe, leaving you to focus on your business success.

Click to access the login or register cheese