WordPress Vulnerability Report: January 2022, Part 1

by | Jan 5, 2022 | Security

Written by Michael Moore of Ithemes on January 5, 2022

Last Updated on January 5, 2022

Vulnerable plugins and themes are the #1 reason WordPress websites get hacked. This post covers recent WordPress plugin, theme, and core vulnerabilities and what to do if you run one of the vulnerable plugins or themes on your website.

Each vulnerability will have a severity rating of Low, Medium, High, or Critical. Responsible disclosure and reporting of vulnerabilities is an integral part of keeping the WordPress community safe. Please share this post with your friends to help get the word out and make WordPress safer for everyone.


Is Your WordPress Website Secure?

DID YOU KNOW – A staggering 83% of WordPress websites are not upgraded or updated, is your website one of these?

Hacks happen due to lack of website upkeep and protection, like updating WordPress or plugins, plus using weak passwords. Contrary to popular belief, web designers and website hosting companies are not responsible for the security of your WordPress website; you are. It’s like using your computer without Anti-virus!


WordPress Core Vulnerabilities
The latest version of WordPress core is 5.8.2. As a best practice, always be sure to run the latest version of WordPress core!

WordPress Plugin Vulnerabilities

1. UpdraftPlus
2. WebP Converter for Media
3. WOOF – Products Filter for WooCommerce
4. LearnPress
5. WP Post Page Clone
6. WP Extra File Types
7. Tutor LMS
8. Custom Dashboard & Login Page
9. Ultimate FAQ
10. WP User Frontend
11.  myCred
12. Image Hover Effects Ultimate
13. Qubely
14. Registration Magic
15. Orders Tracking for WooCommerce
16. Link Library
17. AF Companion
18. KNR Author List Widget
19. WP Cookie User Info

WordPress Plugin Vulnerabilities: Plugin Closed

20. LabTools
21. Domain Check
22. Error Log Viewer
23. WP Visited Countries Reloaded
24. Learning Courses
25. Perfect Survey

WordPress Plugin Vulnerabilities: No known Fix

26. Mediamatic


WordPress Plugin Vulnerabilities

1.UpdraftPlus


Plugin: UpdraftPlus
Vulnerability: Reflected Cross-Site Scripting
Active Installation: 3+ Million
Patched in Version: 1.16.569
Severity: High

Plugin: UpdraftPlus
Vulnerability: Admin+ Stored Cross-Site Scripting
Active Installation: 3+ Million
Patched in Version: 1.6.59
Severity: Low

Plugin: UpdraftPlus
Vulnerability: Admin+ Local File Inclusion
Active Installation: 3+ Million
Patched in Version: 1.16.59
Severity: Medium

2. WebP Converter for Media


Plugin: WebP Converter for Media
Vulnerability: Unauthenticated Open redirect
Active Installation: 100,000+
Patched in Version: 4.0.3
Severity: Medium

3. WOOF – Products Filter for WooCommerce


Plugin: WOOF – Products Filter for WooCommerce
Vulnerability: Reflected Cross-Site Scripting
Active Installation: 100,000+
Patched in Version: 1.2.6.3
Severity: High

4. LearnPress


Plugin: LearnPress
Vulnerability: Admin+ Stored Cross-Site Scripting
Active Installation: 100,000+
Patched in Version: 4.1.3.2
Severity: Medium

5. WP Post Page Clone


Plugin: WP Post Page Clone
Vulnerability: Unauthorised Post Access
Active Installation: 80,000+
Patched in Version: 1.2
Severity: Medium

6. WP Extra File Types

Plugin: WP Extra File Types
Vulnerability: CSRF to Stored Cross-Site Scripting
Active Installation: 50,000+
Patched in Version: 0.5.1
Severity: High

7. Tutor LMS


Plugin: Tutor LMS
Vulnerability: Subscriber+ Stored Cross-Site Scripting
Active Installation: 40,000+
Patched in Version: 1.9.12
Severity: High

Plugin: Tutor LMS
Vulnerability: Reflected Cross-Site Scripting
Active Installation: 40,000+
Patched in Version: 1.9.12
Severity: High

8. Custom Dashboard & Login Page


Plugin: Custom Dashboard & Login Page
Vulnerability: Admin+ Stored Cross-Site Scripting
Active Installation: 40,000+
Patched in Version: 7.0
Severity: Medium

9. Ultimate FAQ


Plugin: Ultimate FAQ
Vulnerability: Subscriber+ Arbitrary FAQ Creation
Active Installation: 30,000+
Patched in Version: 2.1.2
Severity: Medium

10. WP User Frontend


Plugin: WP User Frontend
Vulnerability: SQL Injection to Reflected Cross-Site Scripting
Active Installation: 30,000+
Patched in Version: 3.5.26
Severity: High

11. myCred


Plugin: myCred
Vulnerability: Reflected Cross-Site Scripting
Active Installation: 20,000+
Patched in Version: 2.4
Severity: High

12. Image Hover Effects Ultimate


Plugin: Image Hover Effects Ultimate
Vulnerability: Reflected Cross-Site Scripting
Active Installation: 20,000+
Patched in Version: 9.7.1
Severity: High

13. Qubely


Plugin: Qubely
Vulnerability: Subscriber+ Arbitrary FAQ Creation
Active Installation: 10,000+
Patched in Version: 1.7.8
Severity: Medium

14. Registration Magic


Plugin: Registration Magic
Vulnerability: Reflected Cross-Site Scripting
Active Installation: 10,000+
Patched in Version: 5.0.1.9
Severity: High

15. Orders Tracking for WooCommerce


Plugin: Orders Tracking for WooCommerce
Vulnerability: Reflected Cross-Site Scripting
Active Installation: 10,000+
Patched in Version: 1.1.10
Severity: High

16. Link Library


Plugin: Link Library
Vulnerability: Reflected Cross-Site Scripting
Active Installation: 10,000+
Patched in Version: 7.2.8
Severity: Medium

Plugin: Link Library
Vulnerability: Library Settings Reset via CSRF
Active Installation: 10,000+
Patched in Version: 7.2.8
Severity: Medium

Plugin: Link Library
Vulnerability: Unauthenticated Arbitrary Links Deletion
Active Installation: 10,000+
Patched in Version: 7.2.8
Severity: Medium

17. AF Companion


Plugin: AF Companion
Vulnerability: Arbitrary Plugin Installation & Activation via CSRF
Active Installation: 9,000+
Patched in Version: 1.2.0
Severity: High

18. KNR Author List Widget


Plugin: KNR Author List Widget
Vulnerability: Unauthenticated SQL Injection
Active Installation: 200+

Patched in Version: 3.0.0
Severity: Critical

19. WP Cookie User Info


Plugin: WP Cookie User Info
Vulnerability: Admin+ SQL Injection
Active Installation: 200+
Patched in Version: 1.0.9
Severity: Medium

WordPress Plugin Vulnerabilities: Plugin Closed

20. LabTools

Plugin: LabTools
Vulnerability: Subscriber+ Arbitrary Publication Deletion
Patched in Version: No known fix – plugin closed
Severity: Medium

21. Domain Check

Plugin: Domain Check
Vulnerability: Reflected Cross-Site Scripting
Patched in Version: No known fix – plugin closed
Severity: High

22. Error Log Viewer

Plugin: Error Log Viewer
Vulnerability: Arbitrary Text File Deletion via CSRF
Patched in Version: No known fix – plugin closed
Severity: Low

23. WP Visited Countries Reloaded

Plugin: WP Visited Countries Reloaded
Vulnerability: Reflected Cross-Site Scripting
Patched in Version: 3.1.1- plugin closed
Severity: High

24. Learning Courses

Plugin: Learning Courses
Vulnerability: Admin+ Stored Cross-Site Scripting
Patched in Version: 5.0 – plugin closed
Severity: Low

25. Perfect Survey

Plugin: Perfect Survey
Vulnerability: Unauthorised AJAX Call to Stored XSS / Survey Settings Update
Patched in Version: 1.5.2 – plugin closed
Severity: High

Plugin: Perfect Survey
Vulnerability: Unauthorised AJAX Call to Stored XSS / Survey Settings Update
Patched in Version: 1.5.2 – plugin closed
Severity: High

Plugin: Perfect Survey
Vulnerability: Unauthorised AJAX Call to Stored XSS / Survey Settings Update
Patched in Version: 1.5.2 – plugin closed
Severity: High

Plugin: Perfect Survey
Vulnerability: Unauthorised AJAX Call to Stored XSS / Survey Settings Update
Patched in Version: 1.5.2 – plugin closed
Severity: High

Plugin: Perfect Survey
Vulnerability: Unauthorised AJAX Call to Stored XSS / Survey Settings Update
Patched in Version: 1.5.2 – plugin closed
Severity: High

WordPress Plugin Vulnerabilities: No Known Fix

26. Mediamatic


Plugin: Mediamatic
Vulnerability: Subscriber+ SQL Injection
Active Installation: 3000+
Patched in Version: No Known Fix
Severity: High



Protect Your WordPress Website Today With Website Guardian

Join hundreds of businesses like yours who trust InterwebDEFENCE to protect their websites and livelihood. Using our proven website security analysis and best-in-class AI ‘Website Guardian” software, we are able to protect, monitor and backup your WordPress website.

Go ahead, keep the good guys In and the bad guys out – Click HERE to see our Website Guardian security plans NOW
PLUS
Find out about our unconditional ‘Double Protection’ Guarantee. This guarantee is better than risk free!

We’ll have you scanned, protected and secure in no time, giving you total peace of mind that your website is safe, leaving you to focus on your business success.

Click to access the login or register cheese