Understanding Vulnerabilities in WordPress Plugins
Every week, we highlight known vulnerabilities in WordPress plugins. This information helps you stay informed about potential risks and take appropriate action to protect your website. By addressing these vulnerabilities, you ensure the safety and integrity of your WordPress site and its data.
Plugin: Youtube Channel Gallery
Vulnerability: Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode
Patched Version: No patched version available
Recommended Action: No known patch available. Please review the vulnerability’s details in depth and employ mitigations based on your organization’s risk tolerance. It may be best to uninstall the affected software and find a replacement.
Plugin: Royal Elementor Addons and Templates
Vulnerability: Insufficient Access Control to Template Activation
Patched Version: 1.3.60
Recommended Action: Update to version 1.3.60, or a newer patched version
Plugin: Mega Main Menu
Vulnerability: Information Disclosure
Patched Version: No patched version available
Recommended Action: No known patch available. Please review the vulnerability’s details in depth and employ mitigations based on your organization’s risk tolerance. It may be best to uninstall the affected software and find a replacement.
Plugin: Show-Hide / Collapse-Expand
Vulnerability: Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode
Patched Version: 1.3.0
Recommended Action: Update to version 1.3.0, or a newer patched version
Plugin: SAML Single Sign On – SSO Login Standard
Vulnerability: Open Redirect
Patched Version: 16.0.8
Recommended Action: Update to version 16.0.8, or a newer patched version
Plugin: Smart Post Show – Post Grid, Post Carousel, Post Slider, Post Timeline, Post Table, and List Category Posts, Latest Posts, Recent Posts, Popular Posts and More
Vulnerability: Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode
Patched Version: 2.4.19
Recommended Action: Update to version 2.4.19, or a newer patched version
Plugin: Membership For WooCommerce – SIMPLE MEMBERSHIP PLANS, RECURRING REVENUE, USER PROFILES & SIGNUPS, CONTENT RESTRICTIONS, AND MEMBER LEVELS WITH WOOCOMMERCE MEMBERSHIP
Vulnerability: Unauthenticated Arbitrary File Upload
Patched Version: 2.1.7
Recommended Action: Update to version 2.1.7, or a newer patched version
Plugin: Embed PDF
Vulnerability: Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode
Patched Version: No patched version available
Recommended Action: No known patch available. Please review the vulnerability’s details in depth and employ mitigations based on your organization’s risk tolerance. It may be best to uninstall the affected software and find a replacement.
Plugin: GigPress
Vulnerability: Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode
Patched Version: 2.3.28
Recommended Action: Update to version 2.3.28, or a newer patched version
Plugin: My Tickets – Accessible Event Ticketing
Vulnerability: Cross-Site Request Forgery
Patched Version: 1.9.11
Recommended Action: Update to version 1.9.11, or a newer patched version
Plugin: CC Child Pages
Vulnerability: Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode
Patched Version: 1.43
Recommended Action: Update to version 1.43, or a newer patched version
Plugin: Easy Testimonials
Vulnerability: Authenticated (Contributor+) Stored Cross-Site Scripting
Patched Version: 3.9.3
Recommended Action: Update to version 3.9.3, or a newer patched version
Plugin: Strong Testimonials
Vulnerability: Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode
Patched Version: 3.0.3
Recommended Action: Update to version 3.0.3, or a newer patched version
Plugin: My YouTube Channel
Vulnerability: Missing Authorization
Patched Version: 3.23.0
Recommended Action: Update to version 3.23.0, or a newer patched version
Plugin: Clean Login
Vulnerability: Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode
Patched Version: 1.13.7
Recommended Action: Update to version 1.13.7, or a newer patched version
Plugin: WP Extended Search
Vulnerability: Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode
Patched Version: 2.1.2
Recommended Action: Update to version 2.1.2, or a newer patched version
Plugin: Social Sharing Plugin – Social Warfare
Vulnerability: Missing Authorization
Patched Version: 4.3.1
Recommended Action: Update to version 4.3.1, or a newer patched version
Plugin: PDF.js Viewer
Vulnerability: Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode
Patched Version: 2.1.8
Recommended Action: Update to version 2.1.8, or a newer patched version
Plugin: Themify Shortcodes
Vulnerability: Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode
Patched Version: 2.0.8
Recommended Action: Update to version 2.0.8, or a newer patched version
Plugin: Video Sidebar Widgets
Vulnerability: Authenticated (Contributor+) Stored Cross-Site Scripting
Patched Version: No patched version available
Recommended Action: No known patch available. Please review the vulnerability’s details in depth and employ mitigations based on your organization’s risk tolerance. It may be best to uninstall the affected software and find a replacement.
Plugin: ContentStudio
Vulnerability: Missing Authorization
Patched Version: 1.2.6
Recommended Action: Update to version 1.2.6, or a newer patched version
Plugin: Royal Elementor Addons and Templates
Vulnerability: Cross-Site Request Forgery to Menu Template creation
Patched Version: 1.3.60
Recommended Action: Update to version 1.3.60, or a newer patched version
Plugin: Royal Elementor Addons and Templates
Vulnerability: Insufficient Access Control to Plugin Activation
Patched Version: 1.3.60
Recommended Action: Update to version 1.3.60, or a newer patched version
Plugin: RSS Feed Retriever
Vulnerability: Cross-Site Request Forgery
Patched Version: 1.6.8
Recommended Action: Update to version 1.6.8, or a newer patched version
Plugin: Royal Elementor Addons and Templates
Vulnerability: Insufficient Access Control to Import Deletion
Patched Version: 1.3.60
Recommended Action: Update to version 1.3.60, or a newer patched version
Plugin: Revive Social – Social Media Auto Post and Scheduling Automation Plugin
Vulnerability: Authenticated (Admin+) PHP Object Injection
Patched Version: 9.0.11
Recommended Action: Update to version 9.0.11, or a newer patched version
Plugin: Logaster Logo Generator
Vulnerability: Missing Authorization to Arbitrary Media Deletion and Creation
Patched Version: No patched version available
Recommended Action: No known patch available. Please review the vulnerability’s details in depth and employ mitigations based on your organization’s risk tolerance. It may be best to uninstall the affected software and find a replacement.
Plugin: Blog Designer – Post and Widget
Vulnerability: Post and Widget <= 2.3
Patched Version: 2.4
Recommended Action: Update to version 2.4, or a newer patched version
Plugin: Exclusive Addons for Elementor
Vulnerability: Cross-Site Request Forgery
Patched Version: 2.6.2
Recommended Action: Update to version 2.6.2, or a newer patched version
Plugin: Royal Elementor Addons and Templates
Vulnerability: Insufficient Access Control to Template Import
Patched Version: 1.3.60
Recommended Action: Update to version 1.3.60, or a newer patched version
Plugin: Social Sharing Toolkit
Vulnerability: Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode
Patched Version: No patched version available
Recommended Action: No known patch available. Please review the vulnerability’s details in depth and employ mitigations based on your organization’s risk tolerance. It may be best to uninstall the affected software and find a replacement.
Plugin: Twitter Cards Meta – Best Twitter Card Plugin for WordPress
Vulnerability: Authenticated (Contributor+) Stored Cross-Site Scripting
Patched Version: No patched version available
Recommended Action: No known patch available. Please review the vulnerability’s details in depth and employ mitigations based on your organization’s risk tolerance. It may be best to uninstall the affected software and find a replacement.
Plugin: WooCommerce Chained Products
Vulnerability: Missing Authorization to Arbitrary Options Update
Patched Version: 2.12.0
Recommended Action: Update to version 2.12.0, or a newer patched version
Plugin: Blog Grid & Post Grid – Blog Post Slider, Blog Post Carousel, Blog Post Ticker, Blog Post Masonry, Category Post Grid By News & Blog Designer Pack
Vulnerability: Authenticated (Contributor+) Stored Cross-Site SQcripting via Shortcode
Patched Version: 3.3
Recommended Action: Update to version 3.3, or a newer patched version
Plugin: CPO Companion
Vulnerability: Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode
Patched Version: 1.1.0
Recommended Action: Update to version 1.1.0, or a newer patched version
Plugin: WPDating
Vulnerability: Arbitrary File Upload
Patched Version: 7.4.2
Recommended Action: Update to version 7.4.2, or a newer patched version
Plugin: MDTF – Meta Data and Taxonomies Filter
Vulnerability: Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode
Patched Version: 1.3.1
Recommended Action: Update to version 1.3.1, or a newer patched version
Plugin: FL3R FeelBox
Vulnerability: Cross-Site Request Forgery leading to Plugin Settings Reset
Patched Version: No patched version available
Recommended Action: No known patch available. Please review the vulnerability’s details in depth and employ mitigations based on your organization’s risk tolerance. It may be best to uninstall the affected software and find a replacement.
Plugin: RSS Feed Retriever
Vulnerability: Missing Authorization
Patched Version: 1.6.8
Recommended Action: Update to version 1.6.8, or a newer patched version
Plugin: Widgets for Google Reviews
Vulnerability: Authenticated (Contributor+) Stored XSS
Patched Version: 9.8
Recommended Action: Update to version 9.8, or a newer patched version
Plugin: Page View Count
Vulnerability: Authenticated (Contributor+) Stored Cross-Site Scripting
Patched Version: 2.6.1
Recommended Action: Update to version 2.6.1, or a newer patched version
Plugin: YourChannel: Everything you want in a YouTube plugin.
Vulnerability: No subtitle
Patched Version: 1.2.3
Recommended Action: Update to version 1.2.3, or a newer patched version
Plugin: JetWidgets For Elementor
Vulnerability: Cross-Site Request Forgery to Settings Update
Patched Version: 1.0.13
Recommended Action: Update to version 1.0.13, or a newer patched version
Plugin: CPO Companion
Vulnerability: Authenticated (Administrator+) Stored Cross-Site Scripting
Patched Version: 1.1.0
Recommended Action: Update to version 1.1.0, or a newer patched version
Plugin: Video.js – HTML5 Video Player for WordPress
Vulnerability: Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode
Patched Version: No patched version available
Recommended Action: No known patch available. Please review the vulnerability’s details in depth and employ mitigations based on your organization’s risk tolerance. It may be best to uninstall the affected software and find a replacement.
Plugin: Event Manager and Tickets Selling Plugin for WooCommerce – WpEvently – WordPress Plugin
Vulnerability: Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode
Patched Version: 3.8.0
Recommended Action: Update to version 3.8.0, or a newer patched version
Plugin: Simple File Downloader
Vulnerability: Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode
Patched Version: No patched version available
Recommended Action: No known patch available. Please review the vulnerability’s details in depth and employ mitigations based on your organization’s risk tolerance. It may be best to uninstall the affected software and find a replacement.
Plugin: Restaurant Menu – Food Ordering System – Table Reservation
Vulnerability: Authenticated (Contributor+) Cross-Site Scripting
Patched Version: 2.3.6
Recommended Action: Update to version 2.3.6, or a newer patched version
Plugin: Social Sharing Plugin – Social Warfare
Vulnerability: Cross-Site Request Forgery
Patched Version: 4.4.0
Recommended Action: Update to version 4.4.0, or a newer patched version
Plugin: List Pages Shortcode
Vulnerability: Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode
Patched Version: 1.7.6
Recommended Action: Update to version 1.7.6, or a newer patched version
Plugin: Royal Elementor Addons and Templates
Vulnerability: Reflected Cross-Site Scripting
Patched Version: 1.3.60
Recommended Action: Update to version 1.3.60, or a newer patched version
Plugin: FL3R FeelBox
Vulnerability: Cross-Site Request Forgery leading to Stored Cross-Site Scripting
Patched Version: No patched version available
Recommended Action: No known patch available. Please review the vulnerability’s details in depth and employ mitigations based on your organization’s risk tolerance. It may be best to uninstall the affected software and find a replacement.
Plugin: Post Category Image With Grid and Slider
Vulnerability: Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode
Patched Version: 1.4.8
Recommended Action: Update to version 1.4.8, or a newer patched version
Plugin: Royal Elementor Addons and Templates
Vulnerability: Insufficient Access Control to Template Conditions Modification
Patched Version: 1.3.60
Recommended Action: Update to version 1.3.60, or a newer patched version
Plugin: WooCommerce Eway Gateway
Vulnerability: Insecure Direct Object Reference
Patched Version: 3.5.1
Recommended Action: Update to version 3.5.1, or a newer patched version
Plugin: WP Social Widget
Vulnerability: Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode
Patched Version: 2.2.4
Recommended Action: Update to version 2.2.4, or a newer patched version
Plugin: Product Slider and Carousel with Category for WooCommerce
Vulnerability: Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode
Patched Version: 2.8
Recommended Action: Update to version 2.8, or a newer patched version
Plugin: WP Tabs – Responsive Tabs and Custom Product Tabs
Vulnerability: Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode
Patched Version: 2.1.17
Recommended Action: Update to version 2.1.17, or a newer patched version
Plugin: PPWP – Password Protect Pages
Vulnerability: Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode
Patched Version: 1.8.6
Recommended Action: Update to version 1.8.6, or a newer patched version
Plugin: Royal Elementor Addons and Templates
Vulnerability: Insufficient Access Control to Menu Settings Update
Patched Version: 1.3.60
Recommended Action: Update to version 1.3.60, or a newer patched version
Plugin: Royal Elementor Addons and Templates
Vulnerability: Insufficient Access Control to Plugin Deactivation
Patched Version: 1.3.60
Recommended Action: Update to version 1.3.60, or a newer patched version
Plugin: Royal Elementor Addons and Templates
Vulnerability: Insufficient Access Control to Theme Activation
Patched Version: 1.3.60
Recommended Action: Update to version 1.3.60, or a newer patched version
Plugin: Logaster Logo Generator
Vulnerability: Cross-Site Request Forgery to Arbitrary Media Deletion and Creation
Patched Version: No patched version available
Recommended Action: No known patch available. Please review the vulnerability’s details in depth and employ mitigations based on your organization’s risk tolerance. It may be best to uninstall the affected software and find a replacement.
Plugin: RSS Aggregator by Feedzy – Feed to Post, Autoblogging, News & YouTube Video Feeds Aggregator
Vulnerability: Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode
Patched Version: 4.1.1
Recommended Action: Update to version 4.1.1, or a newer patched version
Plugin: Lightbox Gallery
Vulnerability: Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode
Patched Version: 0.9.5
Recommended Action: Update to version 0.9.5, or a newer patched version
Plugin: My YouTube Channel
Vulnerability: Authenticated (Administrator+) Stored Cross-Site Scripting
Patched Version: 3.23.0
Recommended Action: Update to version 3.23.0, or a newer patched version
Plugin: Contextual Related Posts
Vulnerability: Authenticated (Contributor+) Stored Cross-Site Scripting via Block Attribute
Patched Version: 3.3.1
Recommended Action: Update to version 3.3.1, or a newer patched version
Plugin: User Meta Manager
Vulnerability: Cross Site Request Forgery
Patched Version: No patched version available
Recommended Action: No known patch available. Please review the vulnerability’s details in depth and employ mitigations based on your organization’s risk tolerance. It may be best to uninstall the affected software and find a replacement.
Plugin: Show-Hide / Collapse-Expand
Vulnerability: Missing Authorization
Patched Version: 1.3.0
Recommended Action: Update to version 1.3.0, or a newer patched version
Plugin: Post List Designer by Category – List Category Post Or Recent Post
Vulnerability: Authenticated (Contributor+) Stored Cross-Site Scriptiong via Shortcode
Patched Version: 3.2
Recommended Action: Update to version 3.2, or a newer patched version
Plugin: WP-ShowHide
Vulnerability: Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode
Patched Version: 1.05
Recommended Action: Update to version 1.05, or a newer patched version
Plugin: Amazon Affiliate
Vulnerability: Reflected File Download
Patched Version: 3.12.3
Recommended Action: Update to version 3.12.3, or a newer patched version
Plugin: Custom User Profile Fields for User Registration & Member Frontend Profiles with Paid Memberships Pro
Vulnerability: Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode
Patched Version: 1.8.1
Recommended Action: Update to version 1.8.1, or a newer patched version
Plugin: Pricing Tables WordPress Plugin – Easy Pricing Tables
Vulnerability: Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode
Patched Version: 3.2.3
Recommended Action: Update to version 3.2.3, or a newer patched version
Plugin: Royal Elementor Addons and Templates
Vulnerability: Insufficient Access Control to Template Kit Import
Patched Version: 1.3.60
Recommended Action: Update to version 1.3.60, or a newer patched version
***
Check out the Watch Out Wednesday Archive for past Watch Out Wednesday posts.