Watch Out Wednesday – October 13, 2021

Understanding Vulnerabilities in WordPress Plugins

Every week, we highlight known vulnerabilities in WordPress plugins. This information helps you stay informed about potential risks and take appropriate action to protect your website. By addressing these vulnerabilities, you ensure the safety and integrity of your WordPress site and its data.

Plugin: Header Footer Code Manager

Vulnerability: Authenticated SQL Injections
Patched Version: 1.1.14
Recommended Action: Update to version 1.1.14, or a newer patched version

Plugin: Registration Forms – User Registration Forms, Invitation-Based Registrations, Front-end User Profile, Login Form & Content Restriction

Vulnerability: Authentication Bypass
Patched Version: 3.7.1.6
Recommended Action: Update to version 3.7.1.6, or a newer patched version

Plugin: Asgaros Forum

Vulnerability: Unauthenticated SQL Injection
Patched Version: 1.15.13
Recommended Action: Update to version 1.15.13, or a newer patched version

Plugin: Age Gate

Vulnerability: Stored Cross-Site Scripting
Patched Version: 2.16.4
Recommended Action: Update to version 2.16.4, or a newer patched version

Plugin: ImageLinks Interactive Image Builder for WordPress

Vulnerability: Reflected Cross-Site Scripting
Patched Version: 1.5.3
Recommended Action: Update to version 1.5.3, or a newer patched version

Plugin: Visitor Traffic Real Time Statistics

Vulnerability: Subscriber+ SQL Injection
Patched Version: 3.9
Recommended Action: Update to version 3.9, or a newer patched version

Plugin: WordPress Easy Custom Js And Css Plugin

Vulnerability: Reflected Cross-Site Scripting
Patched Version: No patched version available
Recommended Action: No known patch available. Please review the vulnerability’s details in depth and employ mitigations based on your organization’s risk tolerance. It may be best to uninstall the affected software and find a replacement.

Plugin: Vision – Interactive Image Map Builder

Vulnerability: Reflected Cross-Site Scripting
Patched Version: 1.5.2
Recommended Action: Update to version 1.5.2, or a newer patched version

Plugin: Inline Related Posts

Vulnerability: Authenticated (Admin+) Cross-Site Scripting
Patched Version: 3.0.5
Recommended Action: Update to version 3.0.5, or a newer patched version

Plugin: Coupon Affiliates – Affiliate Plugin for WooCommerce

Vulnerability: Cross-Site Request Forgery
Patched Version: 4.11.3.4
Recommended Action: Update to version 4.11.3.4, or a newer patched version

Plugin: Export any WordPress data to XML/CSV

Vulnerability: Admin+ Stored Cross-Site Scripting
Patched Version: 1.3.1
Recommended Action: Update to version 1.3.1, or a newer patched version

Plugin: WP Header Images

Vulnerability: Reflected Cross-Site Scripting
Patched Version: 2.0.1
Recommended Action: Update to version 2.0.1, or a newer patched version

Plugin: MAZ Loader – Preloader Builder for WordPress

Vulnerability: SQL Injection
Patched Version: 1.3.3
Recommended Action: Update to version 1.3.3, or a newer patched version

Plugin: Loco Translate

Vulnerability: Authenticated PHP Code Injection
Patched Version: 2.5.4
Recommended Action: Update to version 2.5.4, or a newer patched version

Plugin: Quiz Tool Lite

Vulnerability: Authenticated (Admin+) Stored Cross-Site Scripting
Patched Version: No patched version available
Recommended Action: No known patch available. Please review the vulnerability’s details in depth and employ mitigations based on your organization’s risk tolerance. It may be best to uninstall the affected software and find a replacement.

Plugin: SpiderCatalog

Vulnerability: Authenticated (Admin+) SQL Injection
Patched Version: No patched version available
Recommended Action: No known patch available. Please review the vulnerability’s details in depth and employ mitigations based on your organization’s risk tolerance. It may be best to uninstall the affected software and find a replacement.

Plugin: WP SEO Redirect 301

Vulnerability: Cross-Site Request Forgery
Patched Version: 2.3.2
Recommended Action: Update to version 2.3.2, or a newer patched version

Plugin: School Management System – WPSchoolPress

Vulnerability: Reflected Cross-Site Scripting
Patched Version: 2.1.10
Recommended Action: Update to version 2.1.10, or a newer patched version

Plugin: iPanorama 360 – Advanced Virtual Tour Builder

Vulnerability: Reflected Cross-Site Scripting
Patched Version: 1.6.22
Recommended Action: Update to version 1.6.22, or a newer patched version

Plugin: Unlimited PopUps

Vulnerability: Authenticated (Admin+) SQL Injection
Patched Version: No patched version available
Recommended Action: No known patch available. Please review the vulnerability’s details in depth and employ mitigations based on your organization’s risk tolerance. It may be best to uninstall the affected software and find a replacement.

Plugin: Schreikasten

Vulnerability: Authenticated (Author+) SQL Injection
Patched Version: No patched version available
Recommended Action: No known patch available. Please review the vulnerability’s details in depth and employ mitigations based on your organization’s risk tolerance. It may be best to uninstall the affected software and find a replacement.

Plugin: G Auto-Hyperlink

Vulnerability: Authenticated (Admin+) SQL Injection
Patched Version: No patched version available
Recommended Action: No known patch available. Please review the vulnerability’s details in depth and employ mitigations based on your organization’s risk tolerance. It may be best to uninstall the affected software and find a replacement.

Plugin: WCFM – Frontend Manager for WooCommerce along with Bookings Subscription Listings Compatible

Vulnerability: Frontend Manager for WooCommerce <= 6.5.11
Patched Version: 6.5.12
Recommended Action: Update to version 6.5.12, or a newer patched version

Plugin: iPages Flipbook For WordPress

Vulnerability: Reflected Cross-Site Scripting
Patched Version: 1.4.3
Recommended Action: Update to version 1.4.3, or a newer patched version

Plugin: School Management System – WPSchoolPress

Vulnerability: SQL Injection
Patched Version: 2.1.10
Recommended Action: Update to version 2.1.10, or a newer patched version

Plugin: Print-O-Matic

Vulnerability: Admin+ Stored Cross-Site Scripting
Patched Version: 2.0.3
Recommended Action: Update to version 2.0.3, or a newer patched version

Plugin: School Management System – WPSchoolPress

Vulnerability: Stored Cross-Site Scripting
Patched Version: 2.1.17
Recommended Action: Update to version 2.1.17, or a newer patched version

Plugin: Wow Forms – create any form with custom style

Vulnerability: Authenticated (Admin+) SQL Injection
Patched Version: No patched version available
Recommended Action: No known patch available. Please review the vulnerability’s details in depth and employ mitigations based on your organization’s risk tolerance. It may be best to uninstall the affected software and find a replacement.

Plugin: Qwizcards | online quizzes and flashcards

Vulnerability: Stored Cross-Site Scripting
Patched Version: 3.62
Recommended Action: Update to version 3.62, or a newer patched version

Plugin: Affiliates Manager

Vulnerability: Admin+ SQL injection
Patched Version: 2.8.7
Recommended Action: Update to version 2.8.7, or a newer patched version

Plugin: Discounts Manager for Products

Vulnerability: Reflected Cross-Site Scripting
Patched Version: 3.4.5
Recommended Action: Update to version 3.4.5, or a newer patched version

Plugin: Support Board

Vulnerability: Agent+ Stored Cross-Site Scripting
Patched Version: 3.3.5
Recommended Action: Update to version 3.3.5, or a newer patched version

Plugin: Redirect 404 Error Page to Homepage or Custom Page with Logs

Vulnerability: Log Deletion via Cross-Site Request Forgery
Patched Version: 1.7.9
Recommended Action: Update to version 1.7.9, or a newer patched version

Plugin: Storefront Footer Text

Vulnerability: Authenticated (Admin+) Stored Cross-Site Scripting
Patched Version: No patched version available
Recommended Action: No known patch available. Please review the vulnerability’s details in depth and employ mitigations based on your organization’s risk tolerance. It may be best to uninstall the affected software and find a replacement.

Plugin: YITH WooCommerce Multi Vendor

Vulnerability: Reflected Cross-Site Scripting
Patched Version: 3.8.1
Recommended Action: Update to version 3.8.1, or a newer patched version

Plugin: Comment Engine Pro

Vulnerability: Authenticated (Editor+) Stored Cross-Site Scripting
Patched Version: No patched version available
Recommended Action: No known patch available. Please review the vulnerability’s details in depth and employ mitigations based on your organization’s risk tolerance. It may be best to uninstall the affected software and find a replacement.

Plugin: Chameleon CSS

Vulnerability: Cross-Site Request Forgery
Patched Version: No patched version available
Recommended Action: No known patch available. Please review the vulnerability’s details in depth and employ mitigations based on your organization’s risk tolerance. It may be best to uninstall the affected software and find a replacement.

Plugin: Phoenix Media Rename

Vulnerability: Author Arbitrary Media File Renaming
Patched Version: 3.4.4
Recommended Action: Update to version 3.4.4, or a newer patched version

Plugin: Formidable Forms – Contact Form Plugin, Survey, Quiz, Payment, Calculator Form & Custom Form Builder

Vulnerability: Admin+ Stored Cross-Site Scripting
Patched Version: 5.0.07
Recommended Action: Update to version 5.0.07, or a newer patched version

Plugin: Post Content XMLRPC

Vulnerability: Authenticated (Admin+) SQL Injection
Patched Version: No patched version available
Recommended Action: No known patch available. Please review the vulnerability’s details in depth and employ mitigations based on your organization’s risk tolerance. It may be best to uninstall the affected software and find a replacement.

Plugin: Similar Posts – Best Related Posts Plugin for WordPress

Vulnerability: Admin+ Arbitrary PHP Code Execution
Patched Version: 3.1.6
Recommended Action: Update to version 3.1.6, or a newer patched version

Plugin: 404 to 301 – Redirect, Log and Notify 404 Errors

Vulnerability: Logs Deletion via Cross-Site Request Forgery
Patched Version: 3.0.9
Recommended Action: Update to version 3.0.9, or a newer patched version

Plugin: Comments – wpDiscuz

Vulnerability: wpDiscuz <= 7.3.3
Patched Version: 7.3.4
Recommended Action: Update to version 7.3.4, or a newer patched version

Plugin: Registration Forms – User Registration Forms, Invitation-Based Registrations, Front-end User Profile, Login Form & Content Restriction

Vulnerability: Unauthenticated SQL Injection
Patched Version: 3.7.1.6
Recommended Action: Update to version 3.7.1.6, or a newer patched version

Plugin: WP Project Manager – Task, team, and project management plugin featuring kanban board and gantt charts

Vulnerability: Authenticated Stored Cross-Site Scripting
Patched Version: 2.4.14
Recommended Action: Update to version 2.4.14, or a newer patched version

Plugin: Schedule Post Changes With PublishPress Future: Unpublish, Delete, Change Status, Trash, Change Categories

Vulnerability: Contributor+ Arbitrary Post Schedule Deletion
Patched Version: 2.6.0
Recommended Action: Update to version 2.6.0, or a newer patched version

Plugin: Genie WP Favicon

Vulnerability: Cross-Site Request Forgery
Patched Version: No patched version available
Recommended Action: No known patch available. Please review the vulnerability’s details in depth and employ mitigations based on your organization’s risk tolerance. It may be best to uninstall the affected software and find a replacement.

***

Check out the Watch Out Wednesday Archive for past Watch Out Wednesday posts.

About the Author

Recent Posts

WordPress