WordPress Vulnerability Roundup: Dec 2020, Part 2

by | Dec 23, 2020 | Security

Written by Michael Moore of iThemes on December 23, 2020

Last Updated on December 23, 2020

New WordPress plugin and theme vulnerabilities were disclosed during the second half of December. This post covers the recent WordPress plugin, theme, and core vulnerabilities and what to do if you run one of the vulnerable plugins or themes on your website. 

The WordPress Vulnerability Roundup is divided into three different categories: WordPress core, WordPress plugins, and WordPress themes.


Is Your WordPress Website Secure?

DID YOU KNOW – A staggering 83% of WordPress websites are not upgraded or updated, is your website one of these?

Hacks happen due to lack of website upkeep and protection, like updating WordPress or plugins, plus using weak passwords. Contrary to popular belief, web designers and website hosting companies are not responsible for the security of your WordPress website; you are. It’s like using your computer without Anti-virus!


WordPress Core Vulnerabilities
No new WordPress core vulnerabilities have been disclosed this month.

WordPress Theme Vulnerabilities
1. ListingPro

WordPress Plugin Vulnerabilities
1. DiveBook
2. Pagelayer
3. Ultimate Category Excluder
4. Directories Pro
5. Total Upkeep
6. Redux Framework
7. Contact Form 7
8. Simple Social Media Share Buttons
9. Envira Gallery Lite
10. Limit Login Attempts Reloaded


WordPress Plugin Vulnerabilities

1. DiveBook

DiveBook versions below 1.1.4 have an Improper Authorization Check, Unauthenticated SQL Injection, & Unauthenticated Reflected XSS vulnerabilities.

Remove the plugin until a security fix is released.

2. Pagelayer

Pagelayer versions below 1.3.5 have Multiple Reflected Cross-Site Scripting vulnerabilities.

The vulnerability is patched, and you should update to version 1.3.5.

3. Ultimate Category Excluder

Ultimate Category Excluder versions below 1.2 have a Cross-Site Request Forgery vulnerability.

The vulnerability is patched, and you should update to version 1.2.

4. Directories Pro

Directories Pro versions below 1.3.46 have Authenticated Reflected Cross-Site Scripting vulnerability.

The vulnerability is patched, and you should update to version 1.3.46.

5. Total Upkeep

Total Upkeep versions below 1.14.10 have a Sensitive Data Disclosure & Unauthenticated Backup Download vulnerabilities.

The vulnerability is patched, and you should update to version 1.14.10.

6. Redux Framework

Redux Framework versions below 4.1.21 have CSRF Nonce Validation Bypass vulnerability.

The vulnerability is patched, and you should update to version 4.1.21.

7. Contact Form 7

Contact Form 7 versions below 5.3.2 have an Unrestricted File Upload vulnerability.

The vulnerability is patched, and you should update to version 5.3.2.

8. Simple Social Media Share Buttons

Simple Social Media Share Buttons versions below 3.2.1 have an Unauthenticated Reflected Cross-Site Scripting vulnerability.

The vulnerability is patched, and you should update to version 3.2.1.

9. Envira Gallery Lite

Envira Gallery Lite versions below 1.8.3.3 have an Authenticated Stored Cross-Site Scripting vulnerability.

The vulnerability is patched, and you should update to version 1.8.3.3.

10. Limit Login Attempts Reloaded

Limit Login Attempts Reloaded versions below 2.16.0 have an Authenticated Reflected Cross-Site Scripting & Login Rate Limiting Bypass vulnerabilities.

The vulnerability is patched, and you should update to version 2.16.0.

WordPress Theme Vulnerabilities

1. ListingPro

ListingPro versions below 2.6.1 have an Unauthenticated Arbitrary Plugin Installation/Activation/Deactivation & Unauthenticated Sensitive Data Disclosure vulnerabilities.

The vulnerability is patched, and you should update to version 2.6.1.


Protect Your WordPress Website Today With Website Guardian

Join hundreds of businesses like yours who trust InterwebDEFENCE to protect their websites and livelihood. Using our proven website security analysis and best-in-class AI ‘Website Guardian” software, we are able to protect, monitor and backup your WordPress website.

Go ahead, keep the good guys In and the bad guys out – Click HERE to see our Website Guardian security plans NOW
PLUS
Find out about our unconditional ‘Double Protection’ Guarantee. This guarantee is better than risk free!

We’ll have you scanned, protected and secure in no time, giving you total peace of mind that your website is safe, leaving you to focus on your business success.

Click to access the login or register cheese