A shared vulnerability has put multiple Newfold Digital plugins at risk, and they’re not the only ones requiring attention this week. Read on for the latest patching priorities, WordPress’ new automated security screening, and a refresher on the defences that matter most.

#1 – Critical Security Risks in Newfold Digital Plugins

These high-risk plugins could let an unauthenticated attacker forge a valid authentication token and log in as an admin, gaining full control of the site without ever needing a username or password. If you’re hosted with any of these providers, check your plugin version now and update immediately.

WP Plugin Bluehost Plugin
Broken Authentication; 9.8/10; Update to v4.19.1+

WP Plugin HostGator Plugin
Broken Authentication; 9.8/10; Update to v3.2.1+

WP Plugin Web Plugin
Broken Authentication; 9.8/10; Update to v2.3.6+

WP Plugin Crazy Domains Plugin
Broken Authentication; 9.8/10; Update to v2.5.3+

WP Module Data Plugin
Broken Authentication; 9.8/10; Update to v2.9.8+

Editor Comment
It’s worth taking a few minutes each week to perform a sites review to catch issues early and wherever possible, use ShieldPRO’s auto-upgrade feature for vulnerable plugins.

Countless sites use the plugins below, including three with highly critical security risks. Make sure you have the latest fixes in place.

Events Calendar Plugin
Deserialization of untrusted data; 9.8/10; Update to v6.17.4.1+; Recurring 27×

ThemeREX Addons Plugin
PHP Object Injection; 9.8/10; Update to v2.45.0+; Recurring

Everest Forms Plugin
PHP Object Injection; 9.8/10; Update to v3.6.1+; Recurring 11×

Temporary Login Without Password Plugin
Privilege Escalation; 7.2/10; Update to v1.9.9+

bbPress Plugin
Sensitive Data Exposure; 5.3/10; Update to v2.6.15+

Editor Comment
It’s worth taking a few minutes each week to perform a sites review to catch issues early and wherever possible, use ShieldPRO’s auto-upgrade feature for vulnerable plugins.

The first two on this high-risk list have no fixes and have been removed from wp.org. Review these plugins carefully, apply available fixes, and remove any that remain unpatched or abandoned.

Teddy Bear Customize Addon Plugin
Arbitrary File Upload; 10/10; Removed from wp.org; No fix; Remove/or replace; Recurring

WPStoreCart Plugin
Deserialization of untrusted data; 9.8/10; Removed from wp.org; No fix; Remove/or replace.

Site Reviews Plugin
Deserialization of untrusted data; 9.8/10; Update to v2.45.0+; Recurring

WP Grid Builder Plugin
Privilege Escalation; 9.8/10; Update to v2.3.4+

Post Grid and Gutenberg Blocks Plugin
Arbitrary Code Execution; 9.8/10; Update to v2.3.9+

miniOrange’s Google Authenticator Plugin
Settings Change; 9.3/10; Update to v19.3+; Recurring

MPG Plugin
SQL Injection; 9.3/10; Update to v4.2.2+; Recurring 2×

zipMoney(Zip Co) Payments Plugin for WooCommerce Plugin
Broken Access Control; 9.1/10; Update to v2.4.0+

Editor Comment
It’s worth taking a few minutes each week to perform a sites review to catch issues early and wherever possible, use ShieldPRO’s auto-upgrade feature for vulnerable plugins.

#4 – WordPress Screens Every Plugin Update

Every plugin release now goes through an automated security review before it’s ever distributed via the WordPress.org update API. Releases flagged as a potential security risk, whether intentional or accidental, get blocked automatically, protecting the millions of sites that update plugins without manually checking each changelog.

More Info →

#5 – Our blog: WordPress Hardening Checklist

This checklist walks through the essential layers, login protection, file permissions, server configuration, and security headers, that make your site a much harder target regardless of which plugin gets hit next.

More Info →

Thanks for reading, and have a wonderful week!

Paul Goodchild
Shield Security for WordPress