WordPress Vulnerability Report: June 2021, Part 1

by | Jun 2, 2021 | Security

Written by Michael Moore of Ithemes on June 2, 2021

Last Updated on June 2, 2021

Vulnerable plugins and themes are the #1 reason WordPress websites get hacked. This post covers recent WordPress plugin, theme, and core vulnerabilities and what to do if you run one of the vulnerable plugins or themes on your website.

Each vulnerability will have a severity rating of Low, Medium, High, or Critical. Responsible disclosure and reporting of vulnerabilities is an integral part of keeping the WordPress community safe. Please share this post with your friends to help get the word out and make WordPress safer for everyone.


Is Your WordPress Website Secure?

DID YOU KNOW – A staggering 83% of WordPress websites are not upgraded or updated, is your website one of these?

Hacks happen due to lack of website upkeep and protection, like updating WordPress or plugins, plus using weak passwords. Contrary to popular belief, web designers and website hosting companies are not responsible for the security of your WordPress website; you are. It’s like using your computer without Anti-virus!


WordPress Core Vulnerabilities
No new WordPress core vulnerabilities have been disclosed so far in June 2021.

WordPress Theme Vulnerabilities
1. JNews
2. CityBook

WordPress Plugin Vulnerabilities
1. iFlyChat
2. Easy Preloader
3. SP Project & Document Manager
4. Cookie Law Bar
5. Multivendor Marketplace Solution for WooCommerce
6. Gallery From Files
7. Simple 301 Redirects by BetterLinks
8. Visitors
9. Sendit WP Newsletter
10. Side Menu
11. Xllentech English Islamic Calendar
12. NinjaFirewall


WordPress Plugin Vulnerabilities

1. iFlyChat

Plugin: iFlyChat
Vulnerability: Authenticated Stored Cross-Site Scripting
Patched in Version: No known fix
Severity: Medium

2. Easy Preloader

Plugin: Easy Preloader
Vulnerability: Authenticated Stored Cross-Site Scripting
Patched in Version: No known fix
Severity: Medium

3. SP Project & Document Manager

Plugin: SP Project & Document Manager
Vulnerability: Authenticated Shell Upload
Patched in Version: No known fix
Severity: Medium

4. Cookie Law Bar

Plugin: Cookie Law Bar
Vulnerability: Authenticated Stored Cross-Site Scripting
Patched in Version: No known fix
Severity: Medium

5. Multivendor Marketplace Solution for WooCommerce

Plugin: Multivendor Marketplace Solution for WooCommerce
Vulnerability: Unauthenticated Arbitrary Product Comment
Patched in Version: 3.7.4
Severity: Medium

6. Gallery From Files

Plugin: Gallery From Files
Vulnerability: Unauthenticated RCE
Patched in Version: No known fix
Severity: Critical

Plugin: Gallery From Files
Vulnerability: Reflected Cross-Site Scripting
Patched in Version: No known fix
Severity: Medium

7. Simple 301 Redirects by BetterLinks

Plugin: Simple 301 Redirects by BetterLinks
Vulnerability: Unauthenticated Redirect Export
Patched in Version: 2.0.4
Severity: Critical

Plugin: Simple 301 Redirects by BetterLinks
Vulnerability: Unauthenticated Redirect Import
Patched in Version: 2.0.4
Severity: Critical

Plugin: Simple 301 Redirects by BetterLinks
Vulnerability: Arbitrary Plugin Installation
Patched in Version: 2.0.4
Severity: High

Plugin: Simple 301 Redirects by BetterLinks
Vulnerability: Update and Retrieve Wildcard Value
Patched in Version: 2.0.4
Severity: Medium

Plugin: Simple 301 Redirects by BetterLinks
Vulnerability: Arbitrary Plugin Activation
Patched in Version: 2.0.4
Severity: High

8. Visitors

Plugin: Visitors
Vulnerability: Unauthenticated Stored Cross-Site Scripting
Patched in Version: No known fix
Severity: High

9. Sendit WP Newsletter

Plugin: Sendit WP Newsletter
Vulnerability: Authenticated SQL Injection
Patched in Version: No known fix
Severity: Medium

10. Side Menu

Plugin: Side Menu
Vulnerability: Authenticated SQL Injection
Patched in Version: 3.1.5
Severity: High

11. Xllentech English Islamic Calendar

Plugin: Xllentech English Islamic Calendar
Vulnerability: Authenticated SQL Injection
Patched in Version: 2.6.8
Severity: Medium

12. NinjaFirewall

Plugin: NinjaFirewall
Vulnerability: Authenticated PHAR Deserialization
Patched in Version: 4.3.4
Severity: Low

WordPress Theme Vulnerabilities

1. J News


Theme: Unauthenticated Blind SQL Injection
Vulnerability: Reflected Cross-Site Scripting
Patched in Version: 8.0.6
Severity: Medium

2. CityBook

Theme: CityBook
Vulnerability: Unauthenticated Reflected Cross-Site Scripting (XSS)
Patched in Version: 2.4.4
Severity: High


Protect Your WordPress Website Today With Website Guardian

Join hundreds of businesses like yours who trust InterwebDEFENCE to protect their websites and livelihood. Using our proven website security analysis and best-in-class AI ‘Website Guardian” software, we are able to protect, monitor and backup your WordPress website.

Go ahead, keep the good guys In and the bad guys out – Click HERE to see our Website Guardian security plans NOW
PLUS
Find out about our unconditional ‘Double Protection’ Guarantee. This guarantee is better than risk free!

We’ll have you scanned, protected and secure in no time, giving you total peace of mind that your website is safe, leaving you to focus on your business success.

Click to access the login or register cheese