The WordPress security story keeps repeating: big-name plugins are once again facing a string of severe vulnerabilities. Find out what’s affected, protect your sites, and revisit our proven solutions if you ever find yourself locked out.
#1 – Extremely Critical Security Risks in Popular Plugins
Severe vulnerabilities keep resurfacing in these plugins, putting more than 21 million sites at risk. Check your sites, address the risks, and stay ahead of the next attack.
GiveWP Plugin
RCE; 10/10; Update to v4.16.7.2+; Recurring 21×
WPMU DEV Dashboard Plugin
Broken Authentication; 9.8/10; Update to v5.0.2+; Recurring 2×
CMP – Coming Soon & Maintenance Plugin
Privilege Escalation; 9.8/10; Update to v4.1.18+; Recurring 4×
Forminator Plugin
Privilege Escalation; 9.8/10; Update to v1.57.0.7+; Recurring 24×
Smush Image Compression and Optimization Plugin
RCE; 9.1/10; Update to v4.3.2+
Defender Security Plugin
RCE; 9.1/10; Update to v6.2.0+
Pods Plugin
RCE; 9.1/10; Update to v3.3.9.1+; Recurring 3×
#2 – Other Security Risks in Popular Plugins
Not the most severe vulnerabilities, but far too widespread to overlook. Identify any exposure, and take action on your site.
SiteGround Security Plugin
Bypass Vulnerability; 8.1/10; Update to v1.6.7+; Recurring 2×
Advanced File Manager Plugin
Arbitrary File Download; 7.5/10; Update to v5.4.13+; Recurring 2×
WP Rocket Plugin
Sensitive Data Exposure; 7.5/10; Update to v3.23.3.3+
Fluent Forms Pro Add On Pack Plugin
Privilege Escalation; 7.5/10; Update to v6.2.13+; Recurring 9×
Customer Reviews for WooCommerce Plugin
XSS; 7.1/10; Update to v5.107.0+; Recurring 7×
LiteSpeed Cache Plugin
XSS; 7.1/10; Update to v7.9+; Recurring 3×
AI Engine Plugin
Arbitrary File Download; 6.5/10; Update to v3.6.6+; Recurring 5×
TranslatePress Plugin
XSS; 6.5/10; Update to v3.3+; Recurring 7×
UpdraftPlus Plugin
CSRF; 5.4/10; Update to v1.26.7+; Recurring 2×
JetBackup (former Backup Guard) Plugin
Other Vulnerability Type; 4.4/10; Update to v3.1.23.5+; Recurring 2×
WP Statistics Plugin
Sensitive Data Exposure; 4.3/10; Update to v14.16.10+; Recurring 5×
Editor Comment
It’s worth taking a few minutes each week to perform a sites review to catch issues early and wherever possible, use ShieldPRO’s auto-upgrade feature for vulnerable plugins.
#3 – Critical Security Risks in Less Popular Plugins
Lower usage, but significant security risks. Review the plugins below and make sure any vulnerabilities are addressed.
Product Input Fields for WooCommerce Plugin
Arbitrary File Upload; 10/10; Update to v2.0.2+
Hash Form Plugin
Arbitrary File Upload; 10/10; Update to v1.4.3+; Recurring 3×
Throws SPAM Away Plugin
SQL Injection; 9.8/10; Update to v3.9+
WP Data Access Plugin
SQL Injection; 9.8/10; Update to v5.5.82+; Recurring 9×
Tickera Plugin
PHP Object Injection; 9.8/10; Update to v3.6.0.3+; Recurring 7×
Editor Comment
It’s worth taking a few minutes each week to perform a sites review to catch issues early and wherever possible, use ShieldPRO’s auto-upgrade feature for vulnerable plugins.
#4 – Our blog: WordPress Lockout Solutions
Locked out of your WordPress site? Don’t panic. We walk you through simple steps to regain access and get your site back up and running.
Thanks for reading, and have a wonderful week!
Paul Goodchild
Shield Security for WordPress