Watch Out Wednesday – June 23, 2021

Understanding Vulnerabilities in WordPress Plugins

Every week, we highlight known vulnerabilities in WordPress plugins. This information helps you stay informed about potential risks and take appropriate action to protect your website. By addressing these vulnerabilities, you ensure the safety and integrity of your WordPress site and its data.

Plugin: Request a Quote

Vulnerability: Authenticated Stored Cross-Site Scripting
Patched Version: 2.3.4
Recommended Action: Update to version 2.3.4, or a newer patched version

Plugin: 404 to 301 – Redirect, Log and Notify 404 Errors

Vulnerability: Missing Authorization to Redirect Creation
Patched Version: 3.0.8
Recommended Action: Update to version 3.0.8, or a newer patched version

Plugin: Salon Booking System

Vulnerability: Stored Cross-Site Scripting
Patched Version: 6.3.1
Recommended Action: Update to version 6.3.1, or a newer patched version

Plugin: Poll, Survey, Questionnaire and Voting system

Vulnerability: Unauthenticated Blind SQL Injection
Patched Version: 1.5.3
Recommended Action: Update to version 1.5.3, or a newer patched version

Plugin: FileBird – WordPress Media Library Folders & File Manager

Vulnerability: Unauthenticated SQL Injection
Patched Version: 4.7.4
Recommended Action: Update to version 4.7.4, or a newer patched version

Plugin: Contact Form 7 Style

Vulnerability: Cross-Site Request Forgery Bypass
Patched Version: No patched version available
Recommended Action: No known patch available. Please review the vulnerability’s details in depth and employ mitigations based on your organization’s risk tolerance. It may be best to uninstall the affected software and find a replacement.

Plugin: Ultimate Gift Cards for WooCommerce – Create WooCommerce Gift Cards, Gift Vouchers, Redeem & Manage Digital Gift Coupons. Offer Gift Certificates, Schedule Gift Cards, and Use Advance Coupons With Personalized Templates

Vulnerability: Cross-Site Request Forgery Bypass
Patched Version: 2.1.2
Recommended Action: Update to version 2.1.2, or a newer patched version

Plugin: Sign-up Sheets

Vulnerability: Authenticated CSV Injection
Patched Version: 1.0.14
Recommended Action: Update to version 1.0.14, or a newer patched version

Plugin: Cooked – Recipe Management

Vulnerability: Reflected Cross-Site Scripting
Patched Version: 1.7.9.1
Recommended Action: Update to version 1.7.9.1, or a newer patched version

Plugin: Glass

Vulnerability: Cross-Site Request Forgery to Stored Cross-Site Scripting
Patched Version: No patched version available
Recommended Action: No known patch available. Please review the vulnerability’s details in depth and employ mitigations based on your organization’s risk tolerance. It may be best to uninstall the affected software and find a replacement.

Plugin: Fudousan Plugin

Vulnerability: Cross-Site Scripting
Patched Version: No patched version available
Recommended Action: No known patch available. Please review the vulnerability’s details in depth and employ mitigations based on your organization’s risk tolerance. It may be best to uninstall the affected software and find a replacement.

Plugin: Prismatic

Vulnerability: Reflected Cross-Site Scripting
Patched Version: 2.8
Recommended Action: Update to version 2.8, or a newer patched version

Plugin: Staff Directory Plugin: Company Directory

Vulnerability: Cross-Site Request Forgery Bypass
Patched Version: 4.0
Recommended Action: Update to version 4.0, or a newer patched version

Plugin: Floating Notification Bar, Sticky Menu on Scroll, Announcement Banner, and Sticky Header for Any Theme – My Sticky Bar (formerly myStickymenu)

Vulnerability: Authenticated Stored Cross-Site Scripting
Patched Version: 2.5.2
Recommended Action: Update to version 2.5.2, or a newer patched version

Plugin: YOP Poll

Vulnerability: Unauthenticated Stored Cross-Site Scripting
Patched Version: 6.2.8
Recommended Action: Update to version 6.2.8, or a newer patched version

Plugin: Export Users With Meta

Vulnerability: Authenticated (Admin+) SQL Injection
Patched Version: 0.6.5
Recommended Action: Update to version 0.6.5, or a newer patched version

Plugin: Admin Columns

Vulnerability: No subtitle
Patched Version: 4.3.2
Recommended Action: Update to version 4.3.2, or a newer patched version

Plugin: CiviCRM for WordPress

Vulnerability: Cross-Site Request Forgery to Cross-Site Scripting
Patched Version: 5.28.1
Recommended Action: Update to version 5.28.1, or a newer patched version

Plugin: Remove Schema

Vulnerability: Cross-Site Request Forgery Bypass
Patched Version: 1.6
Recommended Action: Update to version 1.6, or a newer patched version

Plugin: Fluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder

Vulnerability: Stored Cross-Site Scripting
Patched Version: 3.6.67
Recommended Action: Update to version 3.6.67, or a newer patched version

Plugin: DW Question & Answer

Vulnerability: Cross-Site Request Forgery Bypass
Patched Version: No patched version available
Recommended Action: No known patch available. Please review the vulnerability’s details in depth and employ mitigations based on your organization’s risk tolerance. It may be best to uninstall the affected software and find a replacement.

Plugin: W3 Total Cache

Vulnerability: No subtitle
Patched Version: 2.1.3
Recommended Action: Update to version 2.1.3, or a newer patched version

Plugin: simple sort&search

Vulnerability: Authenticated (Contributor+) Stored Cross-Site Scripting
Patched Version: No patched version available
Recommended Action: No known patch available. Please review the vulnerability’s details in depth and employ mitigations based on your organization’s risk tolerance. It may be best to uninstall the affected software and find a replacement.

Plugin: Browser Screenshots

Vulnerability: Stored Cross-Site Scripting
Patched Version: 1.7.6
Recommended Action: Update to version 1.7.6, or a newer patched version

Plugin: Sunshine Photo Cart: Free Client Photo Galleries for Photographers

Vulnerability: Cross-Site Request Forgery Bypass
Patched Version: 2.8.29
Recommended Action: Update to version 2.8.29, or a newer patched version

Plugin: wp-mpdf

Vulnerability: Cross-Site Request Forgery Bypass
Patched Version: 3.5.2
Recommended Action: Update to version 3.5.2, or a newer patched version

Plugin: Backup by 10Web – Backup and Restore Plugin

Vulnerability: Reflected Cross-Site Scripting
Patched Version: No patched version available
Recommended Action: No known patch available. Please review the vulnerability’s details in depth and employ mitigations based on your organization’s risk tolerance. It may be best to uninstall the affected software and find a replacement.

Plugin: Prismatic

Vulnerability: Stored Cross-Site Scripting
Patched Version: 2.8
Recommended Action: Update to version 2.8, or a newer patched version

Plugin: Absolute Reviews

Vulnerability: Cross-Site Request Forgery Bypass
Patched Version: 1.0.9
Recommended Action: Update to version 1.0.9, or a newer patched version

Plugin: Sign-up Sheets

Vulnerability: Stored Cross-Site Scripting
Patched Version: 1.0.14
Recommended Action: Update to version 1.0.14, or a newer patched version

***

Check out the Watch Out Wednesday Archive for past Watch Out Wednesday posts.

About the Author

Recent Posts

WordPress