Cybercriminals continue hunting for vulnerable WordPress plugins, with SigmaForms Pro scoring the highest possible 10/10 risk rating. It’s far from the only one making headlines. Here’s what’s currently at stake and how to stop user enumeration attacks.

This plugin carries the max. severity rating. An attacker can upload any type of file, including malicious backdoors that could provide further unauthorised access to 350,000+ affected installations.

SigmaForms Pro – AI Generated Forms Plugin
Arbitrary File Upload; 10/10; Update to v1.4.6+; Recurring

Editor Comment
It’s worth taking a few minutes each week to perform a sites review to catch issues early and wherever possible, use ShieldPRO’s auto-upgrade feature for vulnerable plugins.

Millions of sites rely on these plugins and themes, many facing recurring security risks. Update now to stay protected.

ACF Extended Plugin
Privilege Escalation; 8.1/10; Update to v0.9.2.7+; Recurring

WooCommerce Plugin
SQL Injection; 7.6/10; Update to v11.0+; Recurring

WPvivid Backup and Migration Plugin
SQL Injection; 7.6/10; Update to v0.9.133+; Recurring

Migrate Guru – Site Migration & Cloning Plugin
DoS Attack; 7.5/10; Update to v6.72+

MalCare Security Plugin
DoS Attack; 7.5/10; Update to v6.72+

Jetpack Plugin
PHP Object Injection; 7.2/10; Update to v16.1.3+; Recurring

Iubenda Plugin
XSS; 7.1/10; Update to v3.13.5+

Photo Gallery by 10Web Plugin
XSS; 7.1/10; Update to v1.8.44.+; Recurring

Social Media & Share Icons Plugin
XSS; 7.1/10; Update to v3.0.1+; Recurring

GutenKit Plugin
XSS; 6.5/10; Update to v2.4.5+; Recurring

WoodMart Theme
XSS; 6.5/10; Update to v8.3.8+; Recurring

Divi Theme
XSS; 6.5/10; Update to v4.27.7+; Recurring

Enfold Theme
XSS; 5.8/10; Update to v8.1+; Recurring

SEOPress Plugin
SSRF; 5.4/10; Update to v10.2+; Recurring

Really Simple SSL Plugin
DoS Attack; 5.3/10; Update to v9.8.1+; Recurring

Otter – Gutenberg Block Plugin
Broken Access Control; 5.3/10; Update to v3.1.8+; Recurring

SureForms Plugin
IDOR; 5.3/10; Update to v2.12.6+; Recurring

Rank Math SEO Plugin
Other Vulnerability Type; 5.3/10; Update to v1.0.277.1+; Recurring 11×

JetFormBuilder Plugin
Broken Access Control; 5.3/10; Update to v3.6.2.1+; Recurring

Unlimited Elements For Elementor (Free Widgets, Addons,Templates) Plugin
Broken Access Control; 5.3/10; Update to v2.0.18+; Recurring 11×

Editor Comment
It’s worth taking a few minutes each week to perform a sites review to catch issues early and wherever possible, use ShieldPRO’s auto-upgrade feature for vulnerable plugins.

Not on your radar? They may be on an attacker’s. Same rules apply.

LearnDash LMS Plugin
Arbitrary File Upload; 10/10; Update to v5.1.5.1+; Recurring 2x

Divi Ajax Filter Plugin
Local File Inclusion; 9.8/10; Update to v5.1.3+

Authorizer Plugin
Privilege Escalation; 9.8/10; Update to v3.15.2+

WCFM Marketplace Plugin
SQL Injection; 9.8/10; Update to v3.8.2+; Recurring 6x

Hummingbird Plugin
RCE; 9.1/10; Update to v3.21.2+

Editor Comment
It’s worth taking a few minutes each week to perform a sites review to catch issues early and wherever possible, use ShieldPRO’s auto-upgrade feature for vulnerable plugins.

#4 – Our blog: Secure WordPress from User Enumeration Attacks

User enumeration lets attackers uncover valid usernames on your WordPress site, then use them for targeted brute force or dictionary attacks. Get expert advice on catching and blocking these attempts early.

More Info →

Thanks for reading, and have a wonderful week!

Paul Goodchild
Shield Security for WordPress