WordPress Vulnerability Report: November 2021, Part 3
Written by Michael Moore of Ithemes on November 10, 2021
Last Updated on November 10, 2021
Vulnerable plugins and themes are the #1 reason WordPress websites get hacked. This post covers recent WordPress plugin, theme, and core vulnerabilities and what to do if you run one of the vulnerable plugins or themes on your website.
Each vulnerability will have a severity rating of Low, Medium, High, or Critical. Responsible disclosure and reporting of vulnerabilities is an integral part of keeping the WordPress community safe. Please share this post with your friends to help get the word out and make WordPress safer for everyone.
Is Your WordPress Website Secure?
DID YOU KNOW – A staggering 83% of WordPress websites are not upgraded or updated, is your website one of these?
Hacks happen due to lack of website upkeep and protection, like updating WordPress or plugins, plus using weak passwords. Contrary to popular belief, web designers and website hosting companies are not responsible for the security of your WordPress website; you are. It’s like using your computer without Anti-virus!
WordPress Core Vulnerabilities
The latest version of WordPress core is 5.8.1 was released as a security and maintenance release. As a best practice, always be sure to run the latest version of WordPress core!
WordPress Plugin Vulnerabilities
1. Registrations for the Events Calendar
2. LoginWP
3. WooCommerce Currency Switcher
4. Secure Copy Content Protection and Content Locking
5. Bookly
6. Email Log
7. Tawk.to Live Chat
8. WP Data Access
9. PDF.js Viewer
10. Backup and Restore
11. LearnPress
12. Get Custom Field Values
13. Booking Package
14. Like Button Rating
15. Caldera Forms
16. Starter Templates
17. Contact Form Email
18. Video Gallery – Vimeo and YouTube Gallery
19. WordPress Popular Posts
WordPress Plugin Vulnerabilities
1. Registrations for the Events Calendar

Plugin: Registrations for the Events Calendar
Vulnerability: Unauthenticated SQL Injection
Patched in Version: 2.7.6
Severity: High
2. LoginWP

Plugin: LoginWP
Vulnerability: Reflected Cross-Site Scripting
Patched in Version: 3.0.0.5
Severity: High
3. WooCommerce Currency Switcher

Plugin: WooCommerce Currency Switcher
Vulnerability: Reflected Cross-Site Scripting
Patched in Version: 1.3.7.1
Severity: Medium
4. Secure Copy Content Protection and Content Locking

Plugin: Secure Copy Content Protection and Content Locking
Vulnerability: Subscriber+ Email Address Disclosure
Patched in Version: 2.8.2
Severity: High
5. Bookly

Plugin: Bookly
Vulnerability: Staff Member Stored Cross-Site Scripting
Patched in Version: 20.3.1
Severity: Medium
6. Email Log

Plugin: Email Log
Vulnerability: Reflected Cross-Site Scripting
Patched in Version: 2.4.8
Severity: High
7. Tawk.to Live Chat

Plugin: Tawk.to Live Chat
Vulnerability: Subscriber+ Visitor Monitoring & Chat Removal
Patched in Version: 0.6.0
Severity: High
8. WP Data Access
Plugin: WP Data Access
Vulnerability: Admin+ SQL Injection
Patched in Version: 5.0.0
Severity: High
9. PDF.js Viewer

Plugin: PDF.js Viewer
Vulnerability: Contributor+ Stored Cross-Site Scripting
Patched in Version: 2.0.2
Severity: Medium
10. Backup and Restore

Plugin: Backup and Restore
Vulnerability: Admin+ Arbitrary File Deletion
Patched in Version: No known fix
Severity: Medium
11. LearnPress

Plugin: LearnPress
Vulnerability: Admin+ SQL Injection
Patched in Version: 4.1.4
Severity: Medium
12. Get Custom Field Values

Plugin: Get Custom Field Values
Vulnerability: Contributor+ Stored Cross-Site Scripting
Patched in Version: 4.0.1
Severity: Medium
13. Booking Package

Plugin: Booking Package
Vulnerability: Reflected Cross-Site Scripting
Patched in Version: 1.5.11
Severity: Medium
14. Like Button Rating

Plugin: Like Button Rating
Vulnerability: Unauthorised Vote Export to Email & IP Addresses Disclosure
Patched in Version: 2.6.38
Severity: High
15. Caldera Forms

Plugin: Caldera Forms
Vulnerability: Admin+ Stored Cross-Site Scripting
Patched in Version: 1.9.5
Severity: Low
16. Starter Templates

Plugin: Starter Templates
Vulnerability: Contributor+ Block Import to Stored XSS
Patched in Version: 2.7.1
Severity: High
17. Contact Form Email

Plugin: Contact Form Email
Vulnerability: Admin+ Stored Cross-Site Scripting
Patched in Version: 1.3.21
Severity: Low
18. Video Gallery – Vimeo and Youtube Gallery

Plugin: Video Gallery – Vimeo and YouTube Gallery
Vulnerability: Admin+ Stored Cross-Site Scripting
Patched in Version: 1.1.5
Severity: Low
19. WordPress Popular Posts

Plugin: WordPress Popular Posts
Vulnerability: Admin+ Stored Cross-Site Scripting
Patched in Version: 5.3.4
Severity: Low
Protect Your WordPress Website Today With Website Guardian
Join hundreds of businesses like yours who trust InterwebDEFENCE to protect their websites and livelihood. Using our proven website security analysis and best-in-class AI ‘Website Guardian” software, we are able to protect, monitor and backup your WordPress website.
Go ahead, keep the good guys In and the bad guys out – Click HERE to see our Website Guardian security plans NOW
PLUS
Find out about our unconditional ‘Double Protection’ Guarantee. This guarantee is better than risk free!
We’ll have you scanned, protected and secure in no time, giving you total peace of mind that your website is safe, leaving you to focus on your business success.