WordPress Core just took a hit, two critical, high severity vulnerabilities landed, and some widely used plugins weren’t far behind with flaws of their own. On top of that, we’ve got a blog archive guide on WordPress maintenance, so your site stays secure, not just patched.

#1 – Critical Security Risks in WordPress Core

WordPress Core <= 7.0.1 is vulnerable to Broken Access Control (severity 9.1/10) and SQL Injection (severity 9.8/10).

WordPress has released a fix, v7.0.2 and enabled forced updates through the auto update system for sites running affected versions.

Editor Comment
Monitor WordPress updates closely and install security fixes immediately upon release to protect your site from these vulnerabilities. Also, it’s worth taking a few minutes each week to perform a sites review to catch issues early.

This plugin can be used in mass exploit campaigns, hitting thousands of sites at once. Traffic or popularity doesn’t matter. If you’re on the affected version, please update.

Ultimate Member Plugin
SQL Injection; 9.3/10; Update to v2.10.2+; Recurring

Editor Comment

It’s worth taking a few minutes each week to perform a sites review to catch issues early and wherever possible, use ShieldPRO’s auto-upgrade feature for vulnerable plugins.

These plugins power millions of sites, so exposure is high. Act now and lock down your security.

Essential Addons for Elementor Plugin
Broken Authentication; 8.8/10; Update to v6.6.11+; Recurring

SureCart Plugin
Privilege Escalation; 8.1/10; Update to v4.3.0+; Recurring

W3 Total Cache Plugin
Arbitrary File Download; 7.5/10; Update to v2.10.0+; Recurring

SureForms Plugin
Broken Access Control; 7.5/10; Update to v2.2.2+; Recurring

Under Construction Plugin
Arbitrary File Download; 6.5/10; Update to v5.81+

Smart Slider 3 Plugin
Sensitive Data Exposure; 4.3/10; Update to v3.5.1.38+; Recurring

Editor Comment
It’s worth taking a few minutes each week to perform a sites review to catch issues early and wherever possible, use ShieldPRO’s auto-upgrade feature for vulnerable plugins.

These plugins rarely make the news, but they hit hard when things go wrong. Update now to undo the damage.

WP Ultimate CSV Importer Plugin
RCE; 10/10; Update to v8.1+

miniOrange Social Login and Register Plugin
Privilege Escalation; 9.8/10; Update to v7.8.0+

Aimogen Pro Plugin
Privilege Escalation; 9.8/10; Update to v2.8.5+; Recurring

Booking Package Plugin
SQL Injection; 9.3/10; Update to v1.7.21+

GEO my WordPress Plugin
SQL Injection; 9.3/10; Update to v4.5.5+; Recurring

WordPress CTA Plugin
SQL Injection; 9.3/10; Update to v2.3.0+

Booking Calendar, Appointment Booking System Plugin
SQL Injection; 9.3/10; Update to v3.2.18+

Editor Comment
It’s worth taking a few minutes each week to perform a sites review to catch issues early and wherever possible, use ShieldPRO’s auto-upgrade feature for vulnerable plugins.

#5 – Our blog: WordPress Maintenance: Beyond Updates and Bug Fixes

A slow or broken site loses visitor trust fast. Regular WordPress maintenance keeps things fast, secure, and reliable, well beyond just updates and bug fixes.

More Info →

Thanks for reading, and have a wonderful week!

Paul Goodchild
Shield Security for WordPress