WordPress Vulnerability Report: May 2021, Part 3

by | May 19, 2021 | Security

Written by Michael Moore of Ithemes on May 19, 2021

Last Updated on May 19, 2021

Vulnerable plugins and themes are the #1 reason WordPress websites get hacked. The Weekly WordPress Vulnerability Report powered by WPScan covers recent WordPress plugin, theme, and core vulnerabilities, and what to do if you run one of the vulnerable plugins or themes on your website.

Each vulnerability will have a severity rating of Low, Medium, High, or Critical. Responsible disclosure and reporting of vulnerabilities is an integral part of keeping the WordPress community safe. Please share this post with your friends to help get the word out and make WordPress safer for everyone.


Is Your WordPress Website Secure?

DID YOU KNOW – A staggering 83% of WordPress websites are not upgraded or updated, is your website one of these?

Hacks happen due to lack of website upkeep and protection, like updating WordPress or plugins, plus using weak passwords. Contrary to popular belief, web designers and website hosting companies are not responsible for the security of your WordPress website; you are. It’s like using your computer without Anti-virus!


WordPress Core Vulnerabilities
No new WordPress core vulnerabilities have been disclosed so far in May 2021.

This week, we saw a WordPress 5.7.2 security release with one security issue affecting WordPress versions between 3.7 and 5.7. If you haven’t yet updated to 5.7, all WordPress versions since 3.7 have also been updated to fix an Object Injection in PHPMailer security issue.

WordPress Theme Vulnerabilities
1. Mediumish
2. Listeo
3. Bello

WordPress Plugin Vulnerabilities
1. Photo Gallery
2. Weekly Schedule
3. External Media
4. WP Super Cache
5. Database Backup for WordPress


WordPress Plugin Vulnerabilities

1. Photo Gallery

Plugin: Photo Gallery
Vulnerability: Authenticated Stored Cross-Site Scripting via Gallery Title

Patched in Version: 1.5.67
Severity: Medium

2. Weekly Schedule

Plugin: Weekly Schedule
Vulnerability: Authenticated Stored Cross-Site Scripting
Patched in Version: 3.4.3
Severity: Medium

3. External Media

Plugin: External Media
Vulnerability: Authenticated Arbitrary File Upload
Patched in Version: 1.0.34
Severity: Critical

4. WP Super Cache

Plugin: WP Super Cache
Vulnerability: Authenticated Remote Code Execution

Patched in Version: 1.7.3
Severity: High

5. Database Backup for WordPress

Plugin: Database Backup for WordPress
Vulnerability: Authenticated Persistent Cross-Site Scripting

Patched in Version: 2.4
Severity: Medium

WordPress Theme Vulnerabilities

1. Mediumish

Theme: Mediumish
Vulnerability: Unauthenticated Reflected Cross-Site Scripting
Patched in Version: No known fix
Severity: Medium

2. Listeo

Theme: Listeo
Vulnerability: Multiple XSS & XFS vulnerabilities
Patched in Version: 1.6.11
Severity: Medium

Vulnerability: Multiple Authenticated IDOR Vulnerabilities
Patched in Version: 1.6.11
Severity: Medium

3. Bello

Theme: Bello
Vulnerability: Authenticated XSS & XFS
Patched in Version: 1.6.0
Severity: Medium

Vulnerability: Unauthenticated XSS & XFS
Patched in Version: 1.6.0
Severity: Medium

Vulnerability: Unauthenticated Blind SQL Injection
Patched in Version: 1.6.0
Severity: Critical


Protect Your WordPress Website Today With Website Guardian

Join hundreds of businesses like yours who trust InterwebDEFENCE to protect their websites and livelihood. Using our proven website security analysis and best-in-class AI ‘Website Guardian” software, we are able to protect, monitor and backup your WordPress website.

Go ahead, keep the good guys In and the bad guys out – Click HERE to see our Website Guardian security plans NOW
PLUS
Find out about our unconditional ‘Double Protection’ Guarantee. This guarantee is better than risk free!

We’ll have you scanned, protected and secure in no time, giving you total peace of mind that your website is safe, leaving you to focus on your business success.

Click to access the login or register cheese