WordPress Vulnerability Report: May 2021, Part 1
Written by Michael Moore of Ithemes on May 5, 2021
Last Updated on May 5, 2021
Vulnerable plugins and themes are the #1 reason WordPress websites get hacked. This post covers recent WordPress plugin, theme, and core vulnerabilities and what to do if you run one of the vulnerable plugins or themes on your website.
Each vulnerability will have a severity rating of Low, Medium, High, or Critical. Responsible disclosure and reporting of vulnerabilities is an integral part of keeping the WordPress community safe. Please share this post with your friends to help get the word out and make WordPress safer for everyone.
Is Your WordPress Website Secure?
DID YOU KNOW – A staggering 83% of WordPress websites are not upgraded or updated, is your website one of these?
Hacks happen due to lack of website upkeep and protection, like updating WordPress or plugins, plus using weak passwords. Contrary to popular belief, web designers and website hosting companies are not responsible for the security of your WordPress website; you are. It’s like using your computer without Anti-virus!
WordPress Core Vulnerabilities
No new WordPress core vulnerabilities have been disclosed so far in May 2021.
WordPress 5.7.1 is was released on April 15, 2021. This security and maintenance release features 26 bug fixes in addition to two security fixes. Because this is a security release of WordPress core, it is recommended that you update your sites immediately!
WordPress Theme Vulnerabilities
1. Goto
WordPress Plugin Vulnerabilities
1. AcyMailing
2. Give WP
3. Download Manager
4. Spam Protection, AntiSpam, FireWall by CleanTalk
5. WP Customer Reviews
A Note on Responsible Disclosure
WordPress Plugin Vulnerabilities
1. AcyMailing

Vulnerability: Open Redirect
Patched in Version: 7.5.0
Severity: Medium
2. Give WP

Vulnerability: Authenticated Stored Cross-Site Scripting
Patched in Version: 2.10.4
Severity: Medium
3. Download Manager

Vulnerability: Plugin Settings Change via CSRF
Patched in Version: 3.1.22
Severity: Medium
Vulnerability: Unauthorized Asset Manager Usage
Patched in Version: 3.1.22
Severity: High
Vulnerability: Authenticated PHP4 File Upload to RCE
Patched in Version: 3.1.19
Severity: Critical
4. Spam Protection, AntiSpam, FireWall by CleanTalk

Vulnerability: Unauthenticated Blind SQL Injection
Patched in Version: 5.153.4
Severity: High
5. WP Customer Reviews

Vulnerability: Authenticated Stored Cross-Site Scripting
Patched in Version: 3.5.6
Severity: Medium
WordPress Theme Vulnerabilities
1. Goto
Vulnerability: Unauthenticated Blind SQL Injection
Patched in Version: 2.1
Severity: Critical
Vulnerability: Reflected Cross-Site Scripting
Patched in Version: 2.1
Severity: High
Protect Your WordPress Website Today With Website Guardian
Join hundreds of businesses like yours who trust InterwebDEFENCE to protect their websites and livelihood. Using our proven website security analysis and best-in-class AI ‘Website Guardian” software, we are able to protect, monitor and backup your WordPress website.
Go ahead, keep the good guys In and the bad guys out – Click HERE to see our Website Guardian security plans NOW
PLUS
Find out about our unconditional ‘Double Protection’ Guarantee. This guarantee is better than risk free!
We’ll have you scanned, protected and secure in no time, giving you total peace of mind that your website is safe, leaving you to focus on your business success.