WordPress Vulnerability Report: November 2021, Part 3

by | Nov 17, 2021 | Security

Written by Michael Moore of Ithemes on November 10, 2021

Last Updated on November 10, 2021

Vulnerable plugins and themes are the #1 reason WordPress websites get hacked. This post covers recent WordPress plugin, theme, and core vulnerabilities and what to do if you run one of the vulnerable plugins or themes on your website.

Each vulnerability will have a severity rating of Low, Medium, High, or Critical. Responsible disclosure and reporting of vulnerabilities is an integral part of keeping the WordPress community safe. Please share this post with your friends to help get the word out and make WordPress safer for everyone.


Is Your WordPress Website Secure?

DID YOU KNOW – A staggering 83% of WordPress websites are not upgraded or updated, is your website one of these?

Hacks happen due to lack of website upkeep and protection, like updating WordPress or plugins, plus using weak passwords. Contrary to popular belief, web designers and website hosting companies are not responsible for the security of your WordPress website; you are. It’s like using your computer without Anti-virus!


WordPress Core Vulnerabilities
The latest version of WordPress core is 5.8.1 was released as a security and maintenance release. As a best practice, always be sure to run the latest version of WordPress core!

WordPress Plugin Vulnerabilities

1. Registrations for the Events Calendar
2. LoginWP
3. WooCommerce Currency Switcher
4. Secure Copy Content Protection and Content Locking
5. Bookly
6. Email Log
7. Tawk.to Live Chat
8. WP Data Access
9. PDF.js Viewer
10. Backup and Restore
11. LearnPress
12. Get Custom Field Values
13. Booking Package
14. Like Button Rating
15. Caldera Forms
16. Starter Templates
17. Contact Form Email
18. Video Gallery – Vimeo and YouTube Gallery
19. WordPress Popular Posts


WordPress Plugin Vulnerabilities

1. Registrations for the Events Calendar


Plugin: Registrations for the Events Calendar
Vulnerability: Unauthenticated SQL Injection
Patched in Version: 2.7.6
Severity: High

2. LoginWP


Plugin: LoginWP
Vulnerability: Reflected Cross-Site Scripting
Patched in Version: 3.0.0.5
Severity: High

3. WooCommerce Currency Switcher


Plugin: WooCommerce Currency Switcher
Vulnerability: Reflected Cross-Site Scripting
Patched in Version: 1.3.7.1
Severity: Medium

4. Secure Copy Content Protection and Content Locking


Plugin: Secure Copy Content Protection and Content Locking
Vulnerability: Subscriber+ Email Address Disclosure
Patched in Version: 2.8.2
Severity: High

5. Bookly


Plugin: Bookly
Vulnerability: Staff Member Stored Cross-Site Scripting
Patched in Version: 20.3.1
Severity: Medium

6. Email Log


Plugin: Email Log
Vulnerability: Reflected Cross-Site Scripting
Patched in Version: 2.4.8
Severity: High

7. Tawk.to Live Chat


Plugin: Tawk.to Live Chat
Vulnerability:  Subscriber+ Visitor Monitoring & Chat Removal
Patched in Version: 0.6.0
Severity: High

8. WP Data Access

Plugin: WP Data Access
Vulnerability: Admin+ SQL Injection
Patched in Version: 5.0.0
Severity: High

9. PDF.js Viewer


Plugin: PDF.js Viewer
Vulnerability: Contributor+ Stored Cross-Site Scripting
Patched in Version: 2.0.2
Severity: Medium

10. Backup and Restore


Plugin: Backup and Restore
Vulnerability: Admin+ Arbitrary File Deletion
Patched in Version: No known fix
Severity: Medium

11. LearnPress


Plugin: LearnPress 
Vulnerability: Admin+ SQL Injection
Patched in Version: 4.1.4
Severity: Medium

12. Get Custom Field Values


Plugin: Get Custom Field Values
Vulnerability: Contributor+ Stored Cross-Site Scripting
Patched in Version: 4.0.1
Severity: Medium

13. Booking Package


Plugin: Booking Package
Vulnerability: Reflected Cross-Site Scripting
Patched in Version: 1.5.11
Severity: Medium

14. Like Button Rating


Plugin: Like Button Rating
Vulnerability: Unauthorised Vote Export to Email & IP Addresses Disclosure
Patched in Version: 2.6.38
Severity: High

15. Caldera Forms


Plugin: Caldera Forms
Vulnerability: Admin+ Stored Cross-Site Scripting
Patched in Version: 1.9.5
Severity: Low

16. Starter Templates


Plugin: Starter Templates
Vulnerability: Contributor+ Block Import to Stored XSS
Patched in Version: 2.7.1
Severity: High

17. Contact Form Email


Plugin: Contact Form Email
Vulnerability: Admin+ Stored Cross-Site Scripting
Patched in Version: 1.3.21
Severity: Low

18. Video Gallery – Vimeo and Youtube Gallery


Plugin: Video Gallery – Vimeo and YouTube Gallery 
Vulnerability: Admin+ Stored Cross-Site Scripting
Patched in Version: 1.1.5
Severity: Low

19. WordPress Popular Posts


Plugin: WordPress Popular Posts
Vulnerability: Admin+ Stored Cross-Site Scripting
Patched in Version: 5.3.4
Severity: Low


Protect Your WordPress Website Today With Website Guardian

Join hundreds of businesses like yours who trust InterwebDEFENCE to protect their websites and livelihood. Using our proven website security analysis and best-in-class AI ‘Website Guardian” software, we are able to protect, monitor and backup your WordPress website.

Go ahead, keep the good guys In and the bad guys out – Click HERE to see our Website Guardian security plans NOW
PLUS
Find out about our unconditional ‘Double Protection’ Guarantee. This guarantee is better than risk free!

We’ll have you scanned, protected and secure in no time, giving you total peace of mind that your website is safe, leaving you to focus on your business success.

Click to access the login or register cheese