It’s been a busy week for WordPress security: a patch shipped for multiple Core vulnerabilities, and some plugins turned out to carry critical risks of their own, meaning updates should top your to-do list right now. Since XSS was behind a few of these, our blog covers key layers of advanced defence.
#1 – Critical Security Risks in WordPress Core
WordPress Core up to 7.0.2 is affected with a vulnerability chain, headlined by a pre-auth reflected XSS on the login screen with potential to lead to PHP code execution and SSRF.
WordPress has released a security update, v7.0.3, and enabled forced updates through the auto update system for sites running affected versions. Please keep in mind that only the most recent version of WordPress is actively supported.
Editor Comment
Monitor WordPress updates closely and install security fixes immediately upon release to protect your site from these vulnerabilities. Also, it’s worth taking a few minutes each week to perform a sites review to catch issues early.
#2 – Critical Security Risks in Popular Plugins
We’ve listed these plugins next because they pose the most serious security risk at the moment. Prioritise updating them as well.
Ajax Search Lite Plugin
PHP Object Injection; 9.8/10; Update to v4.14.5+
Ultimate Member Plugin
Privilege Escalation; 9.8/10; Update to v2.12.1+; Recurring 4x
CTX Feed Plugin
RCE; 9.1/10; Update to v6.6.43+
Editor Comment
It’s worth taking a few minutes each week to perform a sites review to catch issues early and wherever possible, use ShieldPRO’s auto-upgrade feature for vulnerable plugins.
#3 – Other Security Risks in Popular Plugins
Attackers are currently going after these widely adopted plugins too. Make sure all are updated to their newest builds, with extra focus on the one lacking a fix.
TranslatePress Plugin
XSS; 7.1/10; Update to v3.3+
Independent Analytics – Google Analytics Alternative for WordPress Plugin
XSS; 7.1/10; Update to v2.15.1+; Recurring 3x
FluentSMTP Plugin
XSS; 7.1/10; Update to v2.3.0+
Download Manager Plugin
XSS; 5.9/10; Update to v3.3.66+; Recurring 6x
CAPTCHA 4WP Plugin
Bypass Vulnerability; 5.3/10; No fix; Remove/or replace.
Polylang Pro Plugin
Sensitive Data Exposure; 4.3/10; Update to v3.8.6+; Recurring 2x
Editor Comment
It’s worth taking a few minutes each week to perform a sites review to catch issues early and wherever possible, use ShieldPRO’s auto-upgrade feature for vulnerable plugins.
#4 – High Security Risks in Less Popular Plugins
Low usage numbers don’t make these plugins any safer, especially the first, which carries a 10/10 (max.) severity score across thousands of installs. Check your site and update.
Kali Forms Plugin
RCE; 10/10; Update to v2.4.21+; Recurring 2x
Login/Signup Popup Plugin
Privilege Escalation; 9.8/10; Update to v3.2.5+
Salon Booking System Plugin
Broken Authentication; 9.8/10; Update to v10.30.27+
SMS Alert Order Notifications Plugin
Privilege Escalation; 9.8/10; Update to v3.9.8+; Recurring 4x
If-So Dynamic Content Personalization Plugin
SQL Injection; 9.3/10; Update to v1.10.0.1+
Database Collation Fix Plugin
SQL Injection; 9.3/10; Update to v1.2.11+
Editor Comment
It’s worth taking a few minutes each week to perform a sites review to catch issues early and wherever possible, use ShieldPRO’s auto-upgrade feature for vulnerable plugins.
#5 – Our blog: Protect Your WordPress Site From XSS Attacks
XSS is one of the most common ways attackers exploit vulnerabilities in your WordPress site. We show you how to protect it from this type of attack and other vulnerabilities, all while maintaining the flexibility and usability your visitors expect.
Thanks for reading, and have a wonderful week!
Paul Goodchild
Shield Security for WordPress