WordPress Vulnerability Roundup: Sep 2020, Part 1

by | Sep 9, 2020 | Security

Written by Michael Moore of iThemes on September 9, 2020

Last Updated on September 22, 2020

New WordPress plugin and theme vulnerabilities were disclosed during the first half of September, so we want to keep you aware. In this post, we cover recent WordPress plugin, theme, and core vulnerabilities and what to do if you are running one of the vulnerable plugins or themes on your website.

The WordPress Vulnerability Roundup is divided into three different categories: WordPress core, WordPress plugins, and WordPress themes.


Is Your WordPress Website Secure?

DID YOU KNOW – A staggering 83% of WordPress websites are not upgraded or updated, is your website one of these?

Hacks happen due to lack of website upkeep and protection, like updating WordPress or plugins, plus using weak passwords. Contrary to popular belief, web designers and website hosting companies are not responsible for the security of your WordPress website; you are. It’s like using your computer without Anti-virus!


WordPress Core Vulnerabilities
No new WordPress core vulnerabilities have been disclosed this month.

WordPress Theme Vulnerabilities

WordPress Plugin Vulnerabilities
1. FooGallery Image Gallery
2. Quiz and Survey Master
3. WP smart CRM & Invoices FREE
4. WP Floating Menu
5. Subscribe Sidebar
6. Recall Products
7. File Manager
8. Ceceppa Multilingua
9. Bulk Change
10. NextScripts: Social Networks Auto-Poster
11. Constant Contact Forms
12. Advanced Database Cleaner
13. ActiveCampaign


WordPress Plugin Vulnerabilities

1. FooGallery Image Gallery

FooGallery Image Gallery versions below 1.9.25 have an Authenticated Cross-Site Scripting vulnerability.

The vulnerability is patched, and you should update to version 1.9.25.

2. Quiz and Survey Master

Quiz and Survey Master versions below 7.0.2 have an Unauthenticated Arbitrary File Upload vulnerability.

The vulnerability is patched, and you should update to version 7.0.2.

3. WP smart CRM & Invoices FREE

All version of WP smart CRM & Invoices FREE have an Authenticated Stored Cross-Site Scripting vulnerability.

Remove the plugin until a security fix is released.

4. WP Floating Menu

WP Floating Menu versions below 1.4.1 have an Authenticated Reflected Cross-Site Scripting vulnerability.

The vulnerability is patched, and you should update to version 1.4.1.

5. Subscribe Sidebar

All versions of Subscribe Sidebar plugin by Blubrry have an Authenticated Reflected Cross-Site Scripting vulnerability.

Remove the plugin until a security fix is released.

6. Recall Products

All versions of Recall Products have an Authenticated SQL Injection vulnerability.

Remove the plugin until a security fix is released.

7. File Manager

File Manager versions below 6.9 have an Arbitrary File Upload vulnerability leading to a Remote Code Execution vulnerability.

The vulnerability is patched, and you should update to version 6.9.

8. Ceceppa Multilingua

All versions of Ceceppa Multilingua have an Authenticated Reflected Cross-Site Scripting vulnerability.

Remove the plugin until a security fix is released.

9. Bulk Change

All versions of Bulk Change have an Authenticated Reflected Cross-Site Scripting vulnerability.

Remove the plugin until a security fix is released.

10. NextScripts: Social Networks Auto-Poster

NextScripts: Social Networks Auto-Poster versions below 4.3.18 have Insufficient Privilege Validation.

The vulnerability is patched, and you should update to version 4.3.18.

11. Constant Contact Forms

Constant Contact Forms versions below 1.8.8 have Multiple Authenticated Stored XSS vulnerabilities.

The vulnerabilities are patched, and you should update to version 1.8.8.

12. Advanced Database Cleaner

Advanced Database Cleaner versions below 3.0.2 have Authenticated SQL injection vulnerability.

The vulnerability is patched, and you should update to version 3.0.2.

13. ActiveCampaign

ActiveCampaign versions below 8.0.2 have a Cross-Site Request Forgery vulnerability.

The vulnerability is patched, and you should update to version 8.0.2.


Protect Your WordPress Website Today With Website Guardian

Join hundreds of businesses like yours who trust InterwebDEFENCE to protect their websites and livelihood. Using our proven website security analysis and best-in-class AI ‘Website Guardian” software, we are able to protect, monitor and backup your WordPress website.

Go ahead, keep the good guys In and the bad guys out – Click HERE to see our Website Guardian security plans NOW
PLUS
Find out about our unconditional ‘Double Protection’ Guarantee. This guarantee is better than risk free!

We’ll have you scanned, protected and secure in no time, giving you total peace of mind that your website is safe, leaving you to focus on your business success.

Click to access the login or register cheese