WordPress Vulnerability Roundup: Dec 2020, Part 1

by | Dec 9, 2020 | Security

Written by Michael Moore on December 9, 2020

Last Updated on December 9, 2020

New WordPress plugin and theme vulnerabilities were disclosed during the first half of December. This post covers recent WordPress plugin, theme, and core vulnerabilities and what to do if you run one of the vulnerable plugins or themes on your website.

The WordPress Vulnerability Roundup is divided into three different categories: WordPress core, WordPress plugins, and WordPress themes.


Is Your WordPress Website Secure?

DID YOU KNOW – A staggering 83% of WordPress websites are not upgraded or updated, is your website one of these?

Hacks happen due to lack of website upkeep and protection, like updating WordPress or plugins, plus using weak passwords. Contrary to popular belief, web designers and website hosting companies are not responsible for the security of your WordPress website; you are. It’s like using your computer without Anti-virus!


WordPress Core Vulnerabilities
No new WordPress core vulnerabilities have been disclosed this month.

However, a new major version of WordPress core was just released yesterday. WordPress 5.6 includes several new features and improvements, so be sure to update.

WordPress Theme Vulnerabilities

WordPress Plugin Vulnerabilities
1. WPJobBoard
2. WP Google Map Plugin
3. BuddyPress
4. Events Manager
5. Age Gate
6. Canto
7. Profile Builder
8. Paid Memberships Pro
9. Themify Portfolio Post
10. Easy WP SMTP


WordPress Plugin Vulnerabilities

1. WPJobBoard

WPJobBoard versions below 5.7.0 have Unauthenticated SQL Injection, Reflected XSS, & XFS vulnerabilities.

The vulnerability is patched, and you should update to version 5.7.0.

2. WP Google Map Plugin

WP Google Map Plugin versions below 4.1.4 have an Authenticated SQL Injection vulnerability.

The vulnerability is patched, and you should update to version 4.1.4.

3. BuddyPress

BuddyPress versions below 6.4.0 Lack of Capability Check vulnerability.

The vulnerability is patched, and you should update to version 6.4.0.

4. Events Manager

Events Manager versions below 5.9.8 have a Cross-Site Scripting & an SQL Injection vulnerability.

The vulnerability is patched, and you should update to version 5.9.8.

5. Age Gate

Age Gate versions below 2.13.5 have an Unauthenticated Open Redirect vulnerability.

The vulnerability is patched, and you should update to version 2.13.5.

6. Canto

All versions of Canto have an Unauthenticated Blind SSRF vulnerability.

Remove the plugin until a security fix is released.

7. Profile Builder

Profile Builder versions below 3.3.3 have an Authenticated Blind SQL Injection vulnerability.

The vulnerability is patched, and you should update to version 2.2.9.

8. Paid Memberships Pro

Paid Memberships Pro versions below 2.5.1 have an Authenticated Cross-Site Scripting vulnerability.

The vulnerability is patched, and you should update to version 2.5.1.

9. Themify Portfolio Post

Themify Portfolio Post versions below 1.1.6 an Authenticated Stored Cross-Site Scripting vulnerability.

The vulnerability is patched, and you should update to version 1.1.6.

10. Easy WP SMTP

Easy WP SMTP versions below 1.4.3 have a Debug Log Disclosure vulnerability.

The vulnerability is patched, and you should update to version 1.4.3.

WordPress Theme Vulnerabilities

1. Wibar

Wibar versions below 1.2.1 has an Authenticated Stored Cross-Site Scripting vulnerability.

The vulnerability is patched, and you should update to version 1.2.1.


Protect Your WordPress Website Today With Website Guardian

Join hundreds of businesses like yours who trust InterwebDEFENCE to protect their websites and livelihood. Using our proven website security analysis and best-in-class AI ‘Website Guardian” software, we are able to protect, monitor and backup your WordPress website.

Go ahead, keep the good guys In and the bad guys out – Click HERE to see our Website Guardian security plans NOW
PLUS
Find out about our unconditional ‘Double Protection’ Guarantee. This guarantee is better than risk free!

We’ll have you scanned, protected and secure in no time, giving you total peace of mind that your website is safe, leaving you to focus on your business success.

Click to access the login or register cheese