WordPress Vulnerability Roundup: Jan 2021, Part 2
Written by Michael Moore of iThemes on January 27, 2021
Last Updated on February 9, 2021
New WordPress plugin and theme vulnerabilities were disclosed during the second half of January. This post covers the recent WordPress plugin, theme, and core vulnerabilities and what to do if you run one of the vulnerable plugins or themes on your website.
This weeks WordPress Vulnerability Roundup is divided into four different categories: WordPress core, WordPress plugins, WordPress themes, and Server.
Each vulnerability will have a severity rating of Low, Medium, High, or Critical. The severity ratings are based on the Common Vulnerability Scoring System.
Is Your WordPress Website Secure?
DID YOU KNOW – A staggering 83% of WordPress websites are not upgraded or updated, is your website one of these?
Hacks happen due to lack of website upkeep and protection, like updating WordPress or plugins, plus using weak passwords. Contrary to popular belief, web designers and website hosting companies are not responsible for the security of your WordPress website; you are. It’s like using your computer without Anti-virus!
WordPress Core Vulnerabilities
No new WordPress core vulnerabilities have been disclosed this month.
WordPress Theme Vulnerabilities
WordPress Plugin Vulnerabilities
1. Easy Contact Form Pro – Critical
2. FV Flowplayer Video Player – Medium
3. Simple Job Board – High
4. Easy Media Gallery Pro – Medium
5. Contact Form Submissions – Medium
6. 301 Redirects – Critical
7.WP Shieldon – Medium
8. Contact Form 7 Database Addon – Critical
9. WP24 Domain Check – Medium
WordPress Plugin Vulnerabilities
1. Easy Contact Form Pro – Critical

Easy Contact Form Pro versions below 1.1.1.9 have an Authenticated Stored Cross-Site Scripting vulnerability.
The vulnerability is patched, and you should update to version 1.1.1.9.
2. FV Flowplayer Video Player – Medium

FV Flowplayer Video Player versions below 7.4.38.727 have an Authenticated Stored Cross-Site Scripting vulnerability.
The vulnerability is patched, and you should update to version 7.4.38.727.
3. Simple Job Board – High

Simple Job Board versions below 2.9.4 have an Authenticated Path Traversal Leading to Arbitrary File Download vulnerability.
The vulnerability is patched, and you should update to version 2.9.4.
4. Easy Media Gallery Pro – Medium

Easy Media Gallery Pro versions below 1.3.0 have CSRF and XSS vulnerabilities.
The vulnerability is patched, and you should update to version 1.3.0.
5. Contact Form Submissions – Medium

All versions of Contact Form Submissions have an Authenticated SQL Injection vulnerability.
Remove the plugin until a security fix is released.
6. 301 Redirects – Critical

301 Redirects versions below 2.51 have an Authenticated SQL Injection vulnerability.
The vulnerability is patched, and you should update to version 2.51.
7.WP Shieldon – Medium

All versions of WP Shieldon have an Unauthenticated Cross-Site Scripting vulnerability.
Remove the plugin until a security fix is released.
8. Contact Form 7 Database Addon – Critical

Contact Form 7 Database Addon versions below 1.2.5.6 have an CSV Injection and Authenticated SQL Injections vulnerabilities.
The vulnerability is patched, and you should update to version 1.2.5.6.
9. WP24 Domain Check – Medium

WP24 Domain Check versions below 1.6.3 have an Authenticated Cross-Site Scripting vulnerability.
The vulnerability is patched, and you should update to version 1.6.3.
Severe Vulnerabilities
Security researchers at Qualys discovered a Privilege Escalation vulnerability in the Linux program sudo. An attacker could exploit the vulnerability to increase the privileges and take over the server.
For more information, check out our post covering this new Linux vulnerability.
Protect Your WordPress Website Today With Website Guardian
Join hundreds of businesses like yours who trust InterwebDEFENCE to protect their websites and livelihood. Using our proven website security analysis and best-in-class AI ‘Website Guardian” software, we are able to protect, monitor and backup your WordPress website.
Go ahead, keep the good guys In and the bad guys out – Click HERE to see our Website Guardian security plans NOW
PLUS
Find out about our unconditional ‘Double Protection’ Guarantee. This guarantee is better than risk free!
We’ll have you scanned, protected and secure in no time, giving you total peace of mind that your website is safe, leaving you to focus on your business success.