WordPress Vulnerability Roundup: March 2021, Part 3
Written by Michael Moore of Ithemes on March 23, 2021
Last Updated on March 23, 2021
New WordPress plugin and theme vulnerabilities were disclosed during the third week of March. This post covers the recent WordPress plugin, theme, and core vulnerabilities and what to do if you run one of the vulnerable plugins or themes on your website.
The WordPress Vulnerability Roundup is divided into three different categories: WordPress core, WordPress plugins, and WordPress themes.
Each vulnerability will have a severity rating of Low, Medium, High, or Critical. The severity ratings are based on the Common WordPress Vulnerability Scoring System.
Is Your WordPress Website Secure?
DID YOU KNOW – A staggering 83% of WordPress websites are not upgraded or updated, is your website one of these?
Hacks happen due to lack of website upkeep and protection, like updating WordPress or plugins, plus using weak passwords. Contrary to popular belief, web designers and website hosting companies are not responsible for the security of your WordPress website; you are. It’s like using your computer without Anti-virus!
WordPress Core Vulnerabilities
No new WordPress core vulnerabilities have been disclosed this month.
WordPress Theme Vulnerabilities
WordPress Plugin Vulnerabilities
1. Tutor LMS
2. WP Super Cache
3. SEO Redirection
4. Flo Forms
5. Social Slider Widget
6. Paid Membership Pro
7. BuddyPress
8. Elementor
9. WordPress Related Posts
10. WP Page Builder
11. PhastPress
12. WordPress Related Posts
13. WooCommerce Help Scout
14. Controlled Admin Access
WordPress Plugin Vulnerabilities
1. Tutor LMS

Vulnerability: Multiple SQL Injection & Unprotected AJAX including Privilege Escalation
Patched in Version: 1.7.7
Severity: High – CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
2. WP Super Cache

Vulnerability: Authenticated RCE
Patched in Version: 1.7.2
Severity: Critical – CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H
3. SEO Redirection
Vulnerability: Authenticated Reflected Cross-Site Scripting
Patched in Version: No Known Fix
Severity: Medium – CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
4. Flo Forms

Vulnerability: Authenticated Options Change to Stored XSS
Patched in Version: 1.0.36
Severity: Critical – CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
5. Social Slider Widget

Vulnerability: Authenticated Reflected Cross-Site Scripting
Patched in Version: 1.8.5
Severity: Critical – CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:L
6. Paid Membership Pro

Vulnerability: Authenticated SQL Injection
Patched in Version: 2.5.6
Severity: Medium – CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L
7. BuddyPress

Vulnerability: Multiple Vulnerabilities, including REST API Privilege Escalation
Patched in Version: 7.2.1
Severity: High – CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:L
8. Elementor

Vulnerability: Multiple Authenticated Stored Cross-Site Scripting
Patched in Version: 3.1.2
Severity: Medium – CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N
9. WordPress Related Posts
Vulnerability: Authenticated Stored Cross-Site Scripting
Patched in Version: No Known Fix
Severity: Medium – CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:L/I:L/A:N
10. WP Page Builder

Vulnerability: Insecure default configuration Allows Subscribers Editing Access to Posts
Patched in Version: 1.2.4
Severity: Medium – CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N
11. PhastPress
Vulnerability: Open Redirect
Patched in Version: 1.111
Severity: Medium – CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N
12. WordPress Related Posts
Vulnerability: Authenticated Stored Cross-Site Scripting
Patched in Version: No Known Fix
Severity: Medium – CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:L/I:L/A:N
13. WooCommerce Help Scout
Vulnerability: Unauthenticated Arbitrary File Upload leading to RCE
Patched in Version: No Known Fix (Actively Being Exploited Remove Now)
Severity: Critical – CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
14. Controlled Admin Access

Vulnerability: Improper Access Control & Privilege Escalation
Patched in Version: 1.5.2
Severity: High – CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Protect Your WordPress Website Today With Website Guardian
Join hundreds of businesses like yours who trust InterwebDEFENCE to protect their websites and livelihood. Using our proven website security analysis and best-in-class AI ‘Website Guardian” software, we are able to protect, monitor and backup your WordPress website.
Go ahead, keep the good guys In and the bad guys out – Click HERE to see our Website Guardian security plans NOW
PLUS
Find out about our unconditional ‘Double Protection’ Guarantee. This guarantee is better than risk free!
We’ll have you scanned, protected and secure in no time, giving you total peace of mind that your website is safe, leaving you to focus on your business success.