Dec 2020 WordPress Plugin Vulnerabilities

 

WordPress Plugin Vulnerabilities

 

1. WPJobBoard

WPJobBoard versions below 5.7.0 have Unauthenticated SQL Injection, Reflected XSS, & XFS vulnerabilities.

The vulnerability is patched, and you should update to version 5.7.0.

 

2. WP Google Map Plugin

WP Google Map Plugin versions below 4.1.4 have an Authenticated SQL Injection vulnerability.

The vulnerability is patched, and you should update to version 4.1.4.

 

3. BuddyPress

BuddyPress versions below 6.4.0 Lack of Capability Check vulnerability.

The vulnerability is patched, and you should update to version 6.4.0.

 

4. Events Manager

Events Manager versions below 5.9.8 have a Cross-Site Scripting & an SQL Injection vulnerability.

The vulnerability is patched, and you should update to version 5.9.8.

 

5. Age Gate

Age Gate versions below 2.13.5 have an Unauthenticated Open Redirect vulnerability.

The vulnerability is patched, and you should update to version 2.13.5.

 

6. Canto

All versions of Canto have an Unauthenticated Blind SSRF vulnerability.

Remove the plugin until a security fix is released.

 

7. Profile Builder

Profile Builder versions below 3.3.3 have an Authenticated Blind SQL Injection vulnerability.

The vulnerability is patched, and you should update to version 2.2.9.

 

8. Paid Memberships Pro

Paid Memberships Pro versions below 2.5.1 have an Authenticated Cross-Site Scripting vulnerability.

The vulnerability is patched, and you should update to version 2.5.1.

 

9. Themify Portfolio Post

Themify Portfolio Post versions below 1.1.6 an Authenticated Stored Cross-Site Scripting vulnerability.

The vulnerability is patched, and you should update to version 1.1.6.

 

10. Easy WP SMTP

Easy WP SMTP versions below 1.4.3 have a Debug Log Disclosure vulnerability.

The vulnerability is patched, and you should update to version 1.4.3.

 

WordPress Theme Vulnerabilities

1. Wibar

Wibar versions below 1.2.1 has an Authenticated Stored Cross-Site Scripting vulnerability.

The vulnerability is patched, and you should update to version 1.2.1.

Need Security Help? Get WooSecured

We take security seriously. While security measures are built into WordPress and WooCommerce out of the box, there are things store owners should be doing to keep their customers, team, and data safe in the event of those worst-case scenarios. Our security services make your life easier by making your data and your customer data safe.

Share This Post

Subscribe To Our Newsletter

Get updates and learn from the best

More To Explore

Plugins

eboov.com

From the desk of Joel Otterstrom President of WpConcierges Since the middle of November my mind has been focused on a project. The project is

Plugins

Plugin Vulnerabilities for March 2022

Is your site up to date? Outdate plugins & themes are the #1 reason sites get hacked. Don’t leave your WooCommerce store vulnerable! MC4WP Vulnerability:

Do You Want To Boost Your Business?

drop us a line and keep in touch