The WordPress security story keeps repeating: big-name plugins are once again facing a string of severe vulnerabilities. Find out what’s affected, protect your sites, and revisit our proven solutions if you ever find yourself locked out.

Severe vulnerabilities keep resurfacing in these plugins, putting more than 21 million sites at risk. Check your sites, address the risks, and stay ahead of the next attack.

GiveWP Plugin
RCE; 10/10; Update to v4.16.7.2+; Recurring 21×

WPMU DEV Dashboard Plugin
Broken Authentication; 9.8/10; Update to v5.0.2+; Recurring

CMP – Coming Soon & Maintenance  Plugin
Privilege Escalation; 9.8/10; Update to v4.1.18+; Recurring

Forminator Plugin
Privilege Escalation; 9.8/10; Update to v1.57.0.7+; Recurring 24×

Smush Image Compression and Optimization Plugin
RCE; 9.1/10; Update to v4.3.2+

Defender Security Plugin
RCE; 9.1/10; Update to v6.2.0+

Pods Plugin
RCE; 9.1/10; Update to v3.3.9.1+; Recurring

Not the most severe vulnerabilities, but far too widespread to overlook. Identify any exposure, and take action on your site.

SiteGround Security Plugin
Bypass Vulnerability; 8.1/10; Update to v1.6.7+; Recurring

Advanced File Manager Plugin
Arbitrary File Download; 7.5/10; Update to v5.4.13+; Recurring

WP Rocket Plugin
Sensitive Data Exposure; 7.5/10; Update to v3.23.3.3+

Fluent Forms Pro Add On Pack Plugin
Privilege Escalation; 7.5/10; Update to v6.2.13+; Recurring

Customer Reviews for WooCommerce Plugin
XSS; 7.1/10; Update to v5.107.0+; Recurring

LiteSpeed Cache Plugin
XSS; 7.1/10; Update to v7.9+; Recurring

AI Engine Plugin
Arbitrary File Download; 6.5/10; Update to v3.6.6+; Recurring

TranslatePress Plugin
XSS; 6.5/10; Update to v3.3+; Recurring

UpdraftPlus Plugin
CSRF; 5.4/10; Update to v1.26.7+; Recurring

JetBackup (former Backup Guard) Plugin
Other Vulnerability Type; 4.4/10; Update to v3.1.23.5+; Recurring

WP Statistics Plugin
Sensitive Data Exposure; 4.3/10; Update to v14.16.10+; Recurring

Editor Comment
It’s worth taking a few minutes each week to perform a sites review to catch issues early and wherever possible, use ShieldPRO’s auto-upgrade feature for vulnerable plugins.

Lower usage, but significant security risks. Review the plugins below and make sure any vulnerabilities are addressed.

Product Input Fields for WooCommerce Plugin
Arbitrary File Upload; 10/10; Update to v2.0.2+

Hash Form Plugin
Arbitrary File Upload; 10/10; Update to v1.4.3+; Recurring

Throws SPAM Away Plugin
SQL Injection; 9.8/10; Update to v3.9+

WP Data Access Plugin
SQL Injection; 9.8/10; Update to v5.5.82+; Recurring

Tickera Plugin
PHP Object Injection; 9.8/10; Update to v3.6.0.3+; Recurring

Editor Comment
It’s worth taking a few minutes each week to perform a sites review to catch issues early and wherever possible, use ShieldPRO’s auto-upgrade feature for vulnerable plugins.

#4 – Our blog: WordPress Lockout Solutions

Locked out of your WordPress site? Don’t panic. We walk you through simple steps to regain access and get your site back up and running.

More Info →

Thanks for reading, and have a wonderful week!

Paul Goodchild
Shield Security for WordPress