WordPress Vulnerability Roundup: Nov 2020, Part 1
Written by Michael Moore of iThemes on November 11, 2020
Last Updated on March 9, 2021
Quite a few new WordPress plugin and theme vulnerabilities were disclosed during the first half of November. This post covers the recent WordPress plugin, theme, and core vulnerabilities and what to do if you run one of the vulnerable plugins or themes on your website.
The WordPress Vulnerability Roundup is divided into three different categories: WordPress core, WordPress plugins, and WordPress themes.
Is Your WordPress Website Secure?
DID YOU KNOW – A staggering 83% of WordPress websites are not upgraded or updated, is your website one of these?
Hacks happen due to lack of website upkeep and protection, like updating WordPress or plugins, plus using weak passwords. Contrary to popular belief, web designers and website hosting companies are not responsible for the security of your WordPress website; you are. It’s like using your computer without Anti-virus!
WordPress Core Vulnerabilities
Here is the list of security fixes mentioned in the WordPress 5.5.2 release post
Hardened deserialization requests.
Fix to disable spam embeds from disabled sites on a multisite network.
Fixed a security issue that could lead to an XSS from global variables.
Fixed a privilege escalation issue in XML-RPC.
Fixed an issue around privilege escalation around post commenting via XML-RPC.
Fixed a security issue where a DoS attack could lead to RCE.
Removed a method to store XSS in post slugs.
Removed method to bypass protected meta that could lead to arbitrary file deletion.
Removed a method that could lead to CSRF.
The vulnerabilities have been patched, so update WordPress to version 5.5.2.
WordPress Theme Vulnerabilities
1.GreenMart
WordPress Plugin Vulnerabilities
1. SW Ajax WooCommerce Search
2. AccessPress Social Icons
3. GDPR CCPA Compliance Support
4. Augmented Reality
5. Welcart e-Commerce
6. WooCommerce
7. WooCommerce Blocks
8. Abandoned Cart Lite for WooCommerce
9. WP Activity Log
10. Ultimate Member
11. Ultimate Reviews
WordPress Plugin Vulnerabilities
1. SW Ajax WooCommerce Search

SW Ajax WooCommerce Search versions below 1.2.8 have an Unauthenticated Reflected XSS & XFS vulnerabilities.
The vulnerability is patched, and you should update to version 1.2.8.
2. AccessPress Social Icons
![]()
AccessPress Social Icons versions below 1.8.1 have an Authenticated SQL Injection vulnerability.
The vulnerability is patched, and you should update to version 1.8.1.
3. GDPR CCPA Compliance Support

GDPR CCPA Compliance Support versions below 2.4 have an Unauthenticated PHP Object Injection vulnerability.
The vulnerability is patched, and you should update to version 2.4.
4. Augmented Reality

All versions of Augmented Reality have an Unauthenticated PHP File Upload leading to RCE vulnerability.
Remove the plugin until a security fix is released.
5. Welcart e-Commerce

Welcart e-Commerce versions below 1.9.36 have Authenticated PHP Object Injection vulnerability.
The vulnerability is patched, and you should update to version 1.9.36.
6. WooCommerce

WooCommerce versions below 4.6.2 have a Guest Account Creation vulnerability.
The vulnerability is patched, and you should update to version 4.6.2.
7. WooCommerce Blocks

WooCommerce Blocks versions below 3.7.1 have a Guest Account Creation vulnerability.
The vulnerability is patched, and you should update to version 3.7.1.
8. Abandoned Cart Lite for WooCommerce

Abandoned Cart Lite for WooCommerce versions below 5.8.3 have an Unauthenticated SQL Injection vulnerability.
The vulnerability is patched, and you should update to version 5.8.3.
9. WP Activity Log

WP Activity Log versions below 4.1.5 have an SQL Injection in External Database Module vulnerability.
The vulnerability is patched, and you should update to version 4.1.5.
10. Ultimate Member

Ultimate Member versions below 2.1.12 have an Unauthenticated Privilege Escalation via User Roles, Profile Update & User Meta vulnerabilities.
The vulnerability is patched, and you should update to version 2.1.12.
11. Ultimate Reviews

Ultimate Reviews versions below 2.1.33 have an Unauthenticated PHP Object Injection vulnerability.
The vulnerability is patched, and you should update to version 2.1.33.
WordPress Theme Vulnerabilities
1. GreenMart

GreenMart versions below 2.4.3 have a Reflected Cross-Site Scripting vulnerability.
The vulnerability is patched, and you should update to version 2.4.3.
Protect Your WordPress Website Today With Website Guardian
Join hundreds of businesses like yours who trust InterwebDEFENCE to protect their websites and livelihood. Using our proven website security analysis and best-in-class AI ‘Website Guardian” software, we are able to protect, monitor and backup your WordPress website.
Go ahead, keep the good guys In and the bad guys out – Click HERE to see our Website Guardian security plans NOW
PLUS
Find out about our unconditional ‘Double Protection’ Guarantee. This guarantee is better than risk free!
We’ll have you scanned, protected and secure in no time, giving you total peace of mind that your website is safe, leaving you to focus on your business success.