Widely used, unpatched, and removed WordPress plugins all feature in this week’s security roundup. Review the affected installations quickly, and learn how early alerts can help you respond sooner.

These plugins are used on millions of WordPress sites and contain vulnerabilities that are being actively exploited. Check your installations and apply any available updates.

Fluent Forms Pro Add On Pack Plugin
Deserialisation of untrusted data; 8.8/10; Update to v6.2.7+; Recurring 4x

BuddyPress Plugin
Deserialisation of untrusted data; 8.8/10; No fix; Remove/or replace.; Recurring 3x

Chaty Pro Plugin
SQL Injection; 8.5/10; Update to v3.5.6+; Recurring 2x

Backup Migration Plugin
Sensitive Data Exposure; 7.5/10; Update to v1.2.9+; Recurring 3x

Facebook for WordPress Plugin
XSS; 7.1/10; Update to v5.2.2+

Facebook for WooCommerce Plugin
XSS; 7.1/10; Update to v3.7.6+

WooCommerce Multilingual & Multicurrency Plugin
XSS; 7.1/10; Update to v5.5.7+

Rank Math SEO Plugin
XSS; 7.1/10; Update to v1.0.275+; Recurring 2x

Editor Comment

It’s worth taking a few minutes each week to perform a sites review to catch issues early and wherever possible, use ShieldPRO’s auto-upgrade feature for vulnerable plugins.

These less widely used plugins are also under active exploitation. Take urgent action if an affected one is unpatched or removed from WP.org.

WP Super Edit Plugin
Arbitrary File Upload; 10/10; No fix; Remove/or replace.

Backup and Staging by WP Time Capsule Plugin
Broken Authentication; 9.8/10; Update to v1.21.16+

Meta Box AIO Plugin
Broken Access Control; 9.3/10; Update to v3.9.0+

WPDM – Premium Packages Plugin
SQL Injection; 9.3/10; Update to v7.0.0+

WP Google Review Slider Plugin
SQL Injection; 9.3/10; No fix; Remove/or replace.

WordPress Survey & Poll Plugin
SQL Injection; 9.3/10; Removed from wp.org; No fix; Remove/or replace.

WP Fast Total Search Plugin
SQL Injection; 9.3/10; Removed from wp.org; No fix; Remove/or replace.

Editor Comment
It’s worth taking a few minutes each week to perform a sites review to catch issues early and wherever possible, use ShieldPRO’s auto-upgrade feature for vulnerable plugins.

#3 – Our blog: Early Threat Detection Guide

Stronger security starts with better visibility. Configure alerts for the events that matter most, so suspicious activity doesn’t go unnoticed.

More Info →

Thanks for reading, and have a wonderful week!

Paul Goodchild
Shield Security for WordPress