Vulnerable WordPress plugins keep piling up this week, spanning the full range from critical to medium risk, with a couple stuck without a fix. And if spam has been creeping into your forms lately, our guide breaks down exactly how to lock it out.
#1 – High Security Risks in Popular Plugins
These plugins are actively targeted, with the first one carrying the highest possible risk score. Review your sites and patch without delay.
Blocksy Companion Plugin
Arbitrary File Upload; 10/10; Update to v2.1.47+
Admin and Site Enhancements (ASE) Pro Plugin
XSS; 9.8/10; Update to v8.8.6+
BookingPress Appointment Booking Pro Plugin
SQL Injection; 9.3/10; Update to v5.7.2+
Editor Comment
It’s worth taking a few minutes each week to perform a sites review to catch issues early and wherever possible, use ShieldPRO’s auto-upgrade feature for vulnerable plugins.
#2 – Other Security Risks in Popular Plugins
The more sites a plugin runs on, the more attractive it becomes to attackers, regardless of how minor the flaw is. Stay ahead, and update.
LatePoint Plugin
Privilege Escalation; 8.8/10; Update to v5.6.4+
Perfmatters Plugin
Arbitrary File Download; 7.5/10; Update to v2.6.5+
Ninja Forms Plugin
Broken Access Control; 7.5/10; Update to v3.14.2+
HubSpot Plugin
Sensitive Data Exposure 7.4/10; No fix; Remove/or replace.
Image Optimizer by Elementor Plugin
Arbitrary File Deletion; 6.8/10; Update to v1.7.5+
GiveWP Plugin
XSS; 6.5/10; Update to v4.16.2+
Download Manager Plugin
XSS; 6.5/10; Update to v3.3.61+
Enable Media Replace Plugin
XSS; 5.9/10; Update to v4.2.2+
Contact Form by WPForms Plugin
Other Vulnerability Type; 5.3/10; Update to v1.10.2.1+
JetFormBuilder Plugin
Broken Access Control; 5.3/10; Update to v3.6.3.1+
Gutenberg Blocks by Kadence Blocks Plugin
IDOR; 4.3/10; Update to v3.7.8+
Ad Inserter Plugin
IDOR; 4.3/10; Update to v2.8.17+
Editor Comment
It’s worth taking a few minutes each week to perform a sites review to catch issues early and wherever possible, use ShieldPRO’s auto-upgrade feature for vulnerable plugins.
#3 – High Security Risks in Less Popular Plugins
Less popular doesn’t mean less dangerous. Watch these plugins closely, especially the ones with no patch available.
Divi Form Builder Plugin
Arbitrary File Upload; 10/10; Update to v5.1.9+
PrivateContent Plugin
Privilege Escalation; 9.8/10; No fix; Remove/or replace.
ProfileGrid Plugin
Privilege Escalation; 9.8/10; Update to v5.9.9.6+
SMS Alert Order Notifications Plugin
Broken Authentication; 9.8/10; Update to v3.9.6+
EventON Plugin
SQL Injection; 9.3/10; No fix; Remove/or replace.
WP Review Slider Pro Plugin
SQL Injection; 9.3/10; Update to v12.7.3+
GeekyBot Plugin
SQL Injection; 9.3/10; Update to v1.2.6+
WP Database Backup Plugin
Arbitrary Code Execution; 9.1/10; Update to v7.12+
Five Star Business Profile and Schema Plugin
Arbitrary Code Execution; 9.1/10; No fix; Remove/or replace.
Editor Comment
It’s worth taking a few minutes each week to perform a sites review to catch issues early and wherever possible, use ShieldPRO’s auto-upgrade feature for vulnerable plugins.
#4 – Our blog: The Complete Guide to WordPress Spam Prevention
Layer WordPress spam defences: built-in settings, plugin filtering, invisible form protection, CAPTCHA only when needed. Privacy-first.
Thanks for reading, and have a wonderful week!
Paul Goodchild
Shield Security for WordPress