WordPress Vulnerability Report: November 2021, Part 2

by | Nov 11, 2021 | Security

Written by Michael Moore of Ithemes on November 10, 2021

Last Updated on November 10, 2021

Vulnerable plugins and themes are the #1 reason WordPress websites get hacked. This post covers recent WordPress plugin, theme, and core vulnerabilities and what to do if you run one of the vulnerable plugins or themes on your website.

Each vulnerability will have a severity rating of Low, Medium, High, or Critical. Responsible disclosure and reporting of vulnerabilities is an integral part of keeping the WordPress community safe. Please share this post with your friends to help get the word out and make WordPress safer for everyone.


Is Your WordPress Website Secure?

DID YOU KNOW – A staggering 83% of WordPress websites are not upgraded or updated, is your website one of these?

Hacks happen due to lack of website upkeep and protection, like updating WordPress or plugins, plus using weak passwords. Contrary to popular belief, web designers and website hosting companies are not responsible for the security of your WordPress website; you are. It’s like using your computer without Anti-virus!


WordPress Core Vulnerabilities
The latest version of WordPress core is 5.8.1 was released as a security and maintenance release. As a best practice, always be sure to run the latest version of WordPress core!

WordPress Plugin Vulnerabilities

1. Contest Gallery
2. Check & Log Email
3. BSK PDF Manager
4. Stylish Cost Calculator
5. Shop Page WP
6. Ibtana – Ecommerce Product Addons
7. WP RSS Aggregator
8. GenerateBlocks
9. Email Before Download
10. myCred
11. Google Maps Easy
12. My Calendar
13. ARForms Form Builder
14. WP DSGVO Tools
15. WP All Import
16. WPS Hide Login
17. WP Google Fonts
18. Event Manager for WooCommerce
19. AutomatorWP
20. Logo Slider and Showcase
21. Stylish Price List
22. WP Debugging
23. Hotel Listing
24. Email Tracker
25. Contact Form by Supsystic
26. Restaurant Menu by MotoPress
27. SEO Redirection
28. Tutor LMS
29. Ninja Forms
30. Registrations for The Events Calendar


WordPress Plugin Vulnerabilities

1. Contest Gallery


Plugin: Contest Gallery
Vulnerability: Subscriber+ Email Address Disclosure
Patched in Version: 13.1.0.7
Severity: Medium

Plugin: Contest Gallery
Vulnerability: Missing Access Controls to Unauthenticated SQL injection / Email Address Disclosure
Patched in Version: 13.1.0.6
Severity: High

2. Check & Log Email

Plugin: Check & Log Email
Vulnerability: Reflected Cross-Site Scripting
Patched in Version: 1.0.4
Severity: High

3. BSK PDF Manager

Plugin: BSK PDF Manager
Vulnerability: Admin+ SQL Injection
Patched in Version: 3.1.2
Severity: Medium

4. Stylish Cost Calculator


Plugin: Stylish Cost Calculator
Vulnerability: Subscriber+ Unauthorised AJAX Calls to Stored XSS
Patched in Version: 7.0.4
Severity: High

5. Shop Page WP


Plugin: Shop Page WP
Vulnerability: Admin+ Stored Cross-Site Scripting
Patched in Version: 1.2.8
Severity: Medium

6. Ibtana – Ecommerce Products Addon


Plugin: Ibtana – Ecommerce Product Addons
Vulnerability: Reflected Cross-Site Scripting
Patched in Version: 0.2.4
Severity: High

7. WP RSS Aggregator


Plugin: WP RSS Aggregator
Vulnerability: Admin+ Stored Cross-Site Scripting
Patched in Version: 4.19.2
Severity: Low

8. GenerateBlocks


Plugin: GenerateBlocks 
Vulnerability: Contributor+ Stored Cross-Site Scripting
Patched in Version: 1.4.0
Severity: Medium

9. Email Before Download


Plugin: Email Before Download
Vulnerability: Admin+ SQL Injection
Patched in Version: 6.8
Severity: Medium

10. myCred


Plugin: myCred
Vulnerability: Subscriber+ SQL Injection
Patched in Version: 2.3
Severity: High

11. Google Maps Easy


Plugin: Google Maps Easy
Vulnerability: Admin+ Stored Cross-Site Scripting
Patched in Version: 1.10.1
Severity: Low

12. My Calendar


Plugin: My Calendar
Vulnerability: Subscriber+ Reflected Cross-Site Scripting
Patched in Version: 3.2.18
Severity: Medium

13. ARForms Form Builder


Plugin: ARForms Form Builder
Vulnerability: Admin+ Stored Cross-Site Scripting
Patched in Version: 1.5
Severity: Low

14. WP DSGVO Tools


Plugin: WP DSGVO Tools
Vulnerability: Unauthenticated Arbitrary Post Deletion
Patched in Version: 3.1.24
Severity: High

15. WP All Import


Plugin: WP All Import
Vulnerability: Admin+ Stored Cross-Site Scripting
Patched in Version: 3.6.3
Severity: Low

16. WPS Hide Login


Plugin: WPS Hide Login
Vulnerability: Protection Bypass with Referer-Header
Patched in Version: 1.9.1
Severity: Medium

17. WP Google Fonts


Plugin: WP Google Fonts
Vulnerability: Reflected Cross-Site Scripting
Patched in Version: 3.1.5
Severity: Medium

18. Event Manager for WooCommerce


Plugin: Event Manager for WooCommerce
Vulnerability: Unauthenticated Arbitrary Elementor Template Import
Patched in Version: 3.5.3
Severity: Medium

Plugin: Event Manager for WooCommerce
Vulnerability: Unauthenticated Arbitrary Options Reset
Patched in Version: 3.5.3
Severity: High

19. Automator WP


Plugin: AutomatorWP
Vulnerability: Missing Authorization and Privilege Escalation
Patched in Version: 1.7.6
Severity: Medium

20. Logo Slider and Showcase


Plugin: Logo Slider and Showcase
Vulnerability: Editor Plugin’s Settings Update
Patched in Version: 1.3.37
Severity: Low

21. Stylish Price List


Plugin: Stylish Price List 
Vulnerability: Unauthenticated Arbitrary Image Upload
Patched in Version: 6.9.0
Severity: Medium

Plugin: Stylish Price List 
Vulnerability: Subscriber+ Arbitrary Image Upload
Patched in Version: 6.9.1
Severity: Medium

22. WP Debugging


Plugin: WP Debugging
Vulnerability: Unauthenticated Plugin’s Settings Update
Patched in Version: 2.11.0
Severity: Medium

23. Hotel Listing

Plugin: Hotel Listing
Vulnerability: Authenticated Stored Cross-Site Scripting
Patched in Version: 1.3.3
Severity: Medium

24. Email Tracker

Plugin: Email Tracker
Vulnerability: Reflected Cross-Site Scripting
Patched in Version: 5.2.6
Severity: High

25. Contact Form by Supsystic


Plugin: Contact Form by Supsystic
Vulnerability: Admin+ Stored Cross-Site Scripting
Patched in Version: 1.7.20
Severity: Low

26. Restaurant Menu by MotoPress


Plugin: Restaurant Menu by MotoPress
Vulnerability: Admin+ Stored Cross Site Scripting
Patched in Version: 2.4.2
Severity: Low

27. SEO Redirection


Plugin: SEO Redirection
Vulnerability: Subscriber+ SQL Injection
Patched in Version: 8.2
Severity: Medium

28. Tutor LMS


Plugin: Tutor LMS
Vulnerability: Reflected Cross-Site Scripting
Patched in Version: 1.9.11
Severity: Medium

29. Ninja Forms


Plugin: Ninja Forms
Vulnerability: Admin+ SQL Injection
Patched in Version: 3.6.4
Severity: Medium

30. Registrations For The Events Calendar


Plugin: Registrations for The Events Calendar
Vulnerability: Reflected Cross-Site Scripting
Patched in Version: 2.7.5
Severity: High


Protect Your WordPress Website Today With Website Guardian

Join hundreds of businesses like yours who trust InterwebDEFENCE to protect their websites and livelihood. Using our proven website security analysis and best-in-class AI ‘Website Guardian” software, we are able to protect, monitor and backup your WordPress website.

Go ahead, keep the good guys In and the bad guys out – Click HERE to see our Website Guardian security plans NOW
PLUS
Find out about our unconditional ‘Double Protection’ Guarantee. This guarantee is better than risk free!

We’ll have you scanned, protected and secure in no time, giving you total peace of mind that your website is safe, leaving you to focus on your business success.

Click to access the login or register cheese