WordPress Vulnerability Roundup: Oct 2020, Part 2
Written by Michael Moore of iThemes on October 28, 2020
Last Updated on March 9, 2021
Quite a few new WordPress plugin vulnerabilities were disclosed during the second half of October. In this post, we cover recent WordPress plugin, theme, and core vulnerabilities and what to do if you are running one of the vulnerable plugins or themes on your website.
The WordPress Vulnerability Roundup is divided into three different categories: WordPress core, WordPress plugins, and WordPress themes.
Is Your WordPress Website Secure?
DID YOU KNOW – A staggering 83% of WordPress websites are not upgraded or updated, is your website one of these?
Hacks happen due to lack of website upkeep and protection, like updating WordPress or plugins, plus using weak passwords. Contrary to popular belief, web designers and website hosting companies are not responsible for the security of your WordPress website; you are. It’s like using your computer without Anti-virus!
WordPress Core Vulnerabilities
WordPress 5.5.2 was released on October 29th and included 10 WordPress core security fixes.
Here is the list of security fixes mentioned in the WordPress 5.5.2 release post.
Hardened deserialization requests.
Fix to disable spam embeds from disabled sites on a multisite network.
Fixed a security issue that could lead to an XSS from global variables.
Fixed a privilege escalation issue in XML-RPC.
Fixed an issue around privilege escalation around post commenting via XML-RPC.
Fixed a security issue where a DoS attack could lead to RCE.
Removed a method to store XSS in post slugs.
Removed method to bypass protected meta that could lead to arbitrary file deletion.
Removed a method that could lead to CSRF.
The vulnerabilities have been patched, so update WordPress to version 5.5.2.
WordPress Theme Vulnerabilities
WordPress Plugin Vulnerabilities
1. Live Chat – Live support
2. Quick Chat
3. Child Theme Creator by Orbisius
4. Realia
5. Comment Press
6. Super Store Finder for WordPress
7. Super Interactive Maps for WordPress
8. Super Logos Showcase for WordPress
9. Simple Download Monitor
10. Loginizer
11. Helios Solutions Brand Logo Slider
12. CM Download Manager
13. Advanced Booking Calendar
WordPress Plugin Vulnerabilities
1. Live Chat – Live support

Live Chat – Live support versions below 3.2.0 have a Cross-Site Request Forgery vulnerability.
The vulnerability is patched, and you should update to version 3.2.0.
2. Quick Chat

All versions of Quick Chat have an Unauthenticated Stored Cross-Site Scripting vulnerability.
Remove the plugin until a security fix is released.
3. Child Theme Creator by Orbisius

Child Theme Creator by Orbisius versions below 1.5.2 have an CSRF to Arbitrary File Modification/Creation vulnerability.
The vulnerability is patched, and you should update to version 1.5.2.
4. Realia

All versions of Realia have an Unauthenticated IDOR leading to Arbitrary Post Deletion vulnerability.
Remove the plugin until a security fix is released.
5. Comment Press

Comment Press versions below 2.7.2 have an Unauthenticated Cross-Frame Scripting vulnerability.
The vulnerability is patched, and you should update to version 2.7.2.
6. Super Store Finder for WordPress

Super Store Finder for WordPress versions below 6.2 have an Unauthenticated Arbitrary File Upload vulnerability.
The vulnerability is patched, and you should update to version 6.2.
7. Super Interactive Maps for WordPress

Super Interactive Maps for WordPress versions below 2.0 have an Unauthenticated Arbitrary File Upload vulnerability.
The vulnerability is patched, and you should update to version 2.0.
8. Super Logos Showcase for WordPress

Super Logos Showcase for WordPress versions below 2.3 have an Unauthenticated Arbitrary File Upload vulnerability.
The vulnerability is patched, and you should update to version 2.3.
9. Simple Download Monitor

Simple Download Monitor versions below 3.8.9 have an Unauthenticated Cross-Site Scripting and a SQL Injection vulnerabilities.
The vulnerability is patched, and you should update to version 3.8.9.
10. Loginizer

Loginizer versions below 1.6.4 have an Unauthenticated SQL Injection vulnerability.
The vulnerability is patched, and you should update to version 1.6.4.
11. Helios Solutions Brand Logo Slider

All versions Helios Solutions Brand Logo Slider have an Authenticated Arbitrary File Upload vulnerability.
Remove the plugin until a security fix is released.
12. CM Download Manager

CM Download Manager versions below 2.8.0 have an Authenticated Cross-Site Scripting vulnerability.
The vulnerability is patched, and you should update to version 2.8.0.
13. Advanced Booking Calendar

Advanced Booking Calendar versions below 1.6.2 have an Unauthenticated SQL Injection vulnerability.
The vulnerability is patched, and you should update to version 1.6.2.
Protect Your WordPress Website Today With Website Guardian
Join hundreds of businesses like yours who trust InterwebDEFENCE to protect their websites and livelihood. Using our proven website security analysis and best-in-class AI ‘Website Guardian” software, we are able to protect, monitor and backup your WordPress website.
Go ahead, keep the good guys In and the bad guys out – Click HERE to see our Website Guardian security plans NOW
PLUS
Find out about our unconditional ‘Double Protection’ Guarantee. This guarantee is better than risk free!
We’ll have you scanned, protected and secure in no time, giving you total peace of mind that your website is safe, leaving you to focus on your business success.