WordPress Vulnerability Roundup: Feb 2021, Part 1
Written by Michael Moore of iThemes on February 10, 2021
Last Updated on February 10, 2021
New WordPress plugin and theme vulnerabilities were disclosed during the first half of February. This post covers the recent WordPress plugin, theme, and core vulnerabilities and what to do if you run one of the vulnerable plugins or themes on your website.
The WordPress Vulnerability Roundup is divided into three different categories: WordPress core, WordPress plugins, and WordPress themes.
Each vulnerability will have a severity rating of Low, Medium, High, or Critical. The severity ratings are based on the Common Vulnerability Scoring System.
Is Your WordPress Website Secure?
DID YOU KNOW – A staggering 83% of WordPress websites are not upgraded or updated, is your website one of these?
Hacks happen due to lack of website upkeep and protection, like updating WordPress or plugins, plus using weak passwords. Contrary to popular belief, web designers and website hosting companies are not responsible for the security of your WordPress website; you are. It’s like using your computer without Anti-virus!
WordPress Core Vulnerabilities
No new WordPress core vulnerabilities have been disclosed this month.
WordPress Theme Vulnerabilities
1. Wyzi – Medium
2. Multiple Parallelus Themes – Medium
WordPress Plugin Vulnerabilities
1. uListing – Critical
2. Super Forms – Critical
3. Modern Events Calendar Lite – Critical
4. Ivory Search – Medium
5. WP Editor – Critical
6. MStore API – High
7. Popup Builder – Medium
8. Gift Voucher – Critical
9. Name Directory – Medium
10. Contact Form 7 Style – High
11. Ultimate GDPR & CCPA Compliance Toolkit – Critical
12. Like Button Rating ? LikeBtn – High
13. Paid Membership Pro – Medium
14. Backup by Supsystic – Critical
15. Contact Form by Supsystic – Critical
16. Data Tables Generator by Supsystic – Critical
17. Digital Publications by Supsystic – Medium
18. Membership by Supsystic – Critical
19. Newsletter by Supsystic – Critical
20. Pricing Table by Supsystic – Critical
21. Ultimate Maps by Supsystic – Critical
22. NextGen Gallery – Critical
23. Map Block for Google Maps – Medium
WordPress Plugin Vulnerabilities
1. uListing – Critical

uListing versions below 1.7 have multiple vulnerabilities, including Unauthenticated SQL Injections, Unauthenticated Arbitrary Account Creation, and Unauthenticated WordPress Options Change.
The vulnerability is patched, and you should update to version 1.7.
2. Super Forms – Critical

Super Forms versions below 4.9.703 have an Unauthenticated PHP File Upload to RCE vulnerability.
The vulnerability is patched, and you should update to version 4.9.703.
3. Modern Events Calendar Lite – Critical

Modern Events Calendar Lite versions below 5.16.5 have multiple issues, including an Authenticated Arbitrary File Upload leading to Remote Code Execution vulnerability.
The vulnerability is patched, and you should update to version 5.16.5.
4. Ivory Search – Medium

Ivory Search versions below 4.5.11 have an Authenticated Reflected Cross-Site Scripting vulnerability.
The vulnerability is patched, and you should update to version 4.5.11.
5. WP Editor – Critical

WP Editor versions below 1.2.7 have an Authenticated SQL Injection vulnerability.
The vulnerability is patched, and you should update to version 1.2.7.
6. MStore API – High

MStore API versions below 3.2.0 have an Authentication Bypass With Sign In With Apple vulnerability.
The vulnerability is patched, and you should update to version 3.2.0.
7. Popup Builder – Medium

Popup Builder versions below 3.74 have an Authenticated Reflected Cross-Site Scripting vulnerability.
The vulnerability is patched, and you should update to version 3.74.
8. Gift Voucher – Critical

All versions of Gift Voucher have an Unauthenticated Blind SQL Injection vulnerability.
Remove the plugin until a security fix is released.
9. Name Directory – Medium

Name Directory versions below 1.18 have a Cross-Site Request Forgery vulnerability.
The vulnerability is patched, and you should update to version 1.18.
10. Contact Form 7 Style – High

All versions of Contact Form 7 Style have Cross-Site Request Forgery to Stored Cross-Site Scripting vulnerability.
Remove the plugin until a security fix is released.
11. Ultimate GDPR & CCPA Compliance Toolkit – Critical

Ultimate GDPR & CCPA Compliance Toolkit versions below 2.5 Unauthenticated Plugin Settings Export and Import leading to a Malicious Redirect vulnerability.
The vulnerability is patched, and you should update to version 2.5.
12. Like Button Rating ? LikeBtn – High

Like Button Rating ? LikeBtn versions below 2.6.32 have an Unauthenticated Arbitrary Blog Settings Change and an Unauthenticated Full-Read SSRF vulnerabilities.
The vulnerability is patched, and you should update to version 2.6.32.
13. Paid Membership Pro – Medium

Paid Membership Pro versions below 2.5.3 have an Authentication Bypass vulnerability leading to Unauthorized Order Information Disclosure.
The vulnerability is patched, and you should update to version 2.5.3.
14. Backup by Supsystic – Critical

All versions of Backup by Supsystic have a Local File Inclusion vulnerability.
Remove the plugin until a security fix is released.
15. Contact Form by Supsystic – Critical

All versions of Contact Form by Supsystic have an Authenticated SQL Injection vulnerability.
Remove the plugin until a security fix is released.
16. Data Tables Generator by Supsystic – Critical

All versions of Data Tables Generator by Supsystic by Supsystic have an Authenticated SQL Injection vulnerability.
Remove the plugin until a security fix is released.
17. Digital Publications by Supsystic – Medium

All versions of Digital Publications by Supsystic have an Authenticated Stored Cross-Site Scripting vulnerability.
Remove the plugin until a security fix is released.
18. Membership by Supsystic – Critical

All versions of Membership by Supsystic have an Authenticated SQL Injection vulnerability.
Remove the plugin until a security fix is released.
19. Newsletter by Supsystic – Critical

All versions of Newsletter by Supsystic have an Authenticated SQL Injection vulnerability.
Remove the plugin until a security fix is released.
20. Pricing Table by Supsystic – Critical

All versions of Pricing Table by Supsystic have an Authenticated SQL Injection vulnerability.
Remove the plugin until a security fix is released.
21. Ultimate Maps by Supsystic – Critical

All versions of have an Ultimate Maps by Supsystic Authenticated SQL Injection vulnerability.
Remove the plugin until a security fix is released.
22. NextGen Gallery – Critical

NextGen Gallery versions below 3.5.0 have CSRF, File Upload, Stored XSS, and RCE vulnerabilities.
The vulnerability is patched, and you should update to version 3.5.0.
23. Map Block for Google Maps – Medium

Map Block for Google Maps versions below 1.32 have a Broken Access Control vulnerability leading to an Unauthorized Google API Key change.
The vulnerability is patched, and you should update to version 1.32.
WordPress Theme Vulnerabilities
1. Wyzi – Medium

Wyzi versions below 2.4.3 have Reflected Cross-Site Scripting vulnerability.
The vulnerability is patched, and you should update to version 2.4.3.
2. Multiple Parallelus Themes – Medium

Multiple Parallelus Themes versions below 2.0 have a Reflected Cross-Site Scripting vulnerability.
The vulnerability is patched, and you should update to version 2.0.
Protect Your WordPress Website Today With Website Guardian
Join hundreds of businesses like yours who trust InterwebDEFENCE to protect their websites and livelihood. Using our proven website security analysis and best-in-class AI ‘Website Guardian” software, we are able to protect, monitor and backup your WordPress website.
Go ahead, keep the good guys In and the bad guys out – Click HERE to see our Website Guardian security plans NOW
PLUS
Find out about our unconditional ‘Double Protection’ Guarantee. This guarantee is better than risk free!
We’ll have you scanned, protected and secure in no time, giving you total peace of mind that your website is safe, leaving you to focus on your business success.