WordPress Vulnerability Report: November 2021, Part 2
Last Updated on November 10, 2021
Vulnerable plugins and themes are the #1 reason WordPress websites get hacked. This post covers recent WordPress plugin, theme, and core vulnerabilities and what to do if you run one of the vulnerable plugins or themes on your website.
Each vulnerability will have a severity rating of Low, Medium, High, or Critical. Responsible disclosure and reporting of vulnerabilities is an integral part of keeping the WordPress community safe. Please share this post with your friends to help get the word out and make WordPress safer for everyone.
Is Your WordPress Website Secure?
DID YOU KNOW – A staggering 83% of WordPress websites are not upgraded or updated, is your website one of these?
Hacks happen due to lack of website upkeep and protection, like updating WordPress or plugins, plus using weak passwords. Contrary to popular belief, web designers and website hosting companies are not responsible for the security of your WordPress website; you are. It’s like using your computer without Anti-virus!
WordPress Core Vulnerabilities
The latest version of WordPress core is 5.8.1 was released as a security and maintenance release. As a best practice, always be sure to run the latest version of WordPress core!
WordPress Plugin Vulnerabilities
1. Contest Gallery
2. Check & Log Email
3. BSK PDF Manager
4. Stylish Cost Calculator
5. Shop Page WP
6. Ibtana – Ecommerce Product Addons
7. WP RSS Aggregator
8. GenerateBlocks
9. Email Before Download
10. myCred
11. Google Maps Easy
12. My Calendar
13. ARForms Form Builder
14. WP DSGVO Tools
15. WP All Import
16. WPS Hide Login
17. WP Google Fonts
18. Event Manager for WooCommerce
19. AutomatorWP
20. Logo Slider and Showcase
21. Stylish Price List
22. WP Debugging
23. Hotel Listing
24. Email Tracker
25. Contact Form by Supsystic
26. Restaurant Menu by MotoPress
27. SEO Redirection
28. Tutor LMS
29. Ninja Forms
30. Registrations for The Events Calendar
WordPress Plugin Vulnerabilities
1. Contest Gallery

Plugin: Contest Gallery
Vulnerability: Subscriber+ Email Address Disclosure
Patched in Version: 13.1.0.7
Severity: Medium
Plugin: Contest Gallery
Vulnerability: Missing Access Controls to Unauthenticated SQL injection / Email Address Disclosure
Patched in Version: 13.1.0.6
Severity: High
2. Check & Log Email
Plugin: Check & Log Email
Vulnerability: Reflected Cross-Site Scripting
Patched in Version: 1.0.4
Severity: High
3. BSK PDF Manager
Plugin: BSK PDF Manager
Vulnerability: Admin+ SQL Injection
Patched in Version: 3.1.2
Severity: Medium
4. Stylish Cost Calculator

Plugin: Stylish Cost Calculator
Vulnerability: Subscriber+ Unauthorised AJAX Calls to Stored XSS
Patched in Version: 7.0.4
Severity: High
5. Shop Page WP

Plugin: Shop Page WP
Vulnerability: Admin+ Stored Cross-Site Scripting
Patched in Version: 1.2.8
Severity: Medium
6. Ibtana – Ecommerce Products Addon

Plugin: Ibtana – Ecommerce Product Addons
Vulnerability: Reflected Cross-Site Scripting
Patched in Version: 0.2.4
Severity: High
7. WP RSS Aggregator

Plugin: WP RSS Aggregator
Vulnerability: Admin+ Stored Cross-Site Scripting
Patched in Version: 4.19.2
Severity: Low
8. GenerateBlocks

Plugin: GenerateBlocks
Vulnerability: Contributor+ Stored Cross-Site Scripting
Patched in Version: 1.4.0
Severity: Medium
9. Email Before Download

Plugin: Email Before Download
Vulnerability: Admin+ SQL Injection
Patched in Version: 6.8
Severity: Medium
10. myCred

Plugin: myCred
Vulnerability: Subscriber+ SQL Injection
Patched in Version: 2.3
Severity: High
11. Google Maps Easy

Plugin: Google Maps Easy
Vulnerability: Admin+ Stored Cross-Site Scripting
Patched in Version: 1.10.1
Severity: Low
12. My Calendar

Plugin: My Calendar
Vulnerability: Subscriber+ Reflected Cross-Site Scripting
Patched in Version: 3.2.18
Severity: Medium
13. ARForms Form Builder

Plugin: ARForms Form Builder
Vulnerability: Admin+ Stored Cross-Site Scripting
Patched in Version: 1.5
Severity: Low
14. WP DSGVO Tools

Plugin: WP DSGVO Tools
Vulnerability: Unauthenticated Arbitrary Post Deletion
Patched in Version: 3.1.24
Severity: High
15. WP All Import

Plugin: WP All Import
Vulnerability: Admin+ Stored Cross-Site Scripting
Patched in Version: 3.6.3
Severity: Low
16. WPS Hide Login

Plugin: WPS Hide Login
Vulnerability: Protection Bypass with Referer-Header
Patched in Version: 1.9.1
Severity: Medium
17. WP Google Fonts

Plugin: WP Google Fonts
Vulnerability: Reflected Cross-Site Scripting
Patched in Version: 3.1.5
Severity: Medium
18. Event Manager for WooCommerce

Plugin: Event Manager for WooCommerce
Vulnerability: Unauthenticated Arbitrary Elementor Template Import
Patched in Version: 3.5.3
Severity: Medium
Plugin: Event Manager for WooCommerce
Vulnerability: Unauthenticated Arbitrary Options Reset
Patched in Version: 3.5.3
Severity: High
19. Automator WP

Plugin: AutomatorWP
Vulnerability: Missing Authorization and Privilege Escalation
Patched in Version: 1.7.6
Severity: Medium
20. Logo Slider and Showcase

Plugin: Logo Slider and Showcase
Vulnerability: Editor Plugin’s Settings Update
Patched in Version: 1.3.37
Severity: Low
21. Stylish Price List

Plugin: Stylish Price List
Vulnerability: Unauthenticated Arbitrary Image Upload
Patched in Version: 6.9.0
Severity: Medium
Plugin: Stylish Price List
Vulnerability: Subscriber+ Arbitrary Image Upload
Patched in Version: 6.9.1
Severity: Medium
22. WP Debugging

Plugin: WP Debugging
Vulnerability: Unauthenticated Plugin’s Settings Update
Patched in Version: 2.11.0
Severity: Medium
23. Hotel Listing
Plugin: Hotel Listing
Vulnerability: Authenticated Stored Cross-Site Scripting
Patched in Version: 1.3.3
Severity: Medium
24. Email Tracker
Plugin: Email Tracker
Vulnerability: Reflected Cross-Site Scripting
Patched in Version: 5.2.6
Severity: High
25. Contact Form by Supsystic

Plugin: Contact Form by Supsystic
Vulnerability: Admin+ Stored Cross-Site Scripting
Patched in Version: 1.7.20
Severity: Low
26. Restaurant Menu by MotoPress

Plugin: Restaurant Menu by MotoPress
Vulnerability: Admin+ Stored Cross Site Scripting
Patched in Version: 2.4.2
Severity: Low
27. SEO Redirection

Plugin: SEO Redirection
Vulnerability: Subscriber+ SQL Injection
Patched in Version: 8.2
Severity: Medium
28. Tutor LMS

Plugin: Tutor LMS
Vulnerability: Reflected Cross-Site Scripting
Patched in Version: 1.9.11
Severity: Medium
29. Ninja Forms

Plugin: Ninja Forms
Vulnerability: Admin+ SQL Injection
Patched in Version: 3.6.4
Severity: Medium
30. Registrations For The Events Calendar

Plugin: Registrations for The Events Calendar
Vulnerability: Reflected Cross-Site Scripting
Patched in Version: 2.7.5
Severity: High
Protect Your WordPress Website Today With Website Guardian
Join hundreds of businesses like yours who trust InterwebDEFENCE to protect their websites and livelihood. Using our proven website security analysis and best-in-class AI ‘Website Guardian” software, we are able to protect, monitor and backup your WordPress website.
Go ahead, keep the good guys In and the bad guys out – Click HERE to see our Website Guardian security plans NOW
PLUS
Find out about our unconditional ‘Double Protection’ Guarantee. This guarantee is better than risk free!
We’ll have you scanned, protected and secure in no time, giving you total peace of mind that your website is safe, leaving you to focus on your business success.