A shared vulnerability has put multiple Newfold Digital plugins at risk, and they’re not the only ones requiring attention this week. Read on for the latest patching priorities, WordPress’ new automated security screening, and a refresher on the defences that matter most.
#1 – Critical Security Risks in Newfold Digital Plugins
These high-risk plugins could let an unauthenticated attacker forge a valid authentication token and log in as an admin, gaining full control of the site without ever needing a username or password. If you’re hosted with any of these providers, check your plugin version now and update immediately.
WP Plugin Bluehost Plugin
Broken Authentication; 9.8/10; Update to v4.19.1+
WP Plugin HostGator Plugin
Broken Authentication; 9.8/10; Update to v3.2.1+
WP Plugin Web Plugin
Broken Authentication; 9.8/10; Update to v2.3.6+
WP Plugin Crazy Domains Plugin
Broken Authentication; 9.8/10; Update to v2.5.3+
WP Module Data Plugin
Broken Authentication; 9.8/10; Update to v2.9.8+
Editor Comment
It’s worth taking a few minutes each week to perform a sites review to catch issues early and wherever possible, use ShieldPRO’s auto-upgrade feature for vulnerable plugins.
#2 – Security Risks in Other Popular Plugins
Countless sites use the plugins below, including three with highly critical security risks. Make sure you have the latest fixes in place.
Events Calendar Plugin
Deserialization of untrusted data; 9.8/10; Update to v6.17.4.1+; Recurring 27×
ThemeREX Addons Plugin
PHP Object Injection; 9.8/10; Update to v2.45.0+; Recurring 2×
Everest Forms Plugin
PHP Object Injection; 9.8/10; Update to v3.6.1+; Recurring 11×
Temporary Login Without Password Plugin
Privilege Escalation; 7.2/10; Update to v1.9.9+
bbPress Plugin
Sensitive Data Exposure; 5.3/10; Update to v2.6.15+
Editor Comment
It’s worth taking a few minutes each week to perform a sites review to catch issues early and wherever possible, use ShieldPRO’s auto-upgrade feature for vulnerable plugins.
#3 – Critical Security Risks in Less Popular Plugins
The first two on this high-risk list have no fixes and have been removed from wp.org. Review these plugins carefully, apply available fixes, and remove any that remain unpatched or abandoned.
Teddy Bear Customize Addon Plugin
Arbitrary File Upload; 10/10; Removed from wp.org; No fix; Remove/or replace; Recurring 2×
WPStoreCart Plugin
Deserialization of untrusted data; 9.8/10; Removed from wp.org; No fix; Remove/or replace.
Site Reviews Plugin
Deserialization of untrusted data; 9.8/10; Update to v2.45.0+; Recurring 3×
WP Grid Builder Plugin
Privilege Escalation; 9.8/10; Update to v2.3.4+
Post Grid and Gutenberg Blocks Plugin
Arbitrary Code Execution; 9.8/10; Update to v2.3.9+
miniOrange’s Google Authenticator Plugin
Settings Change; 9.3/10; Update to v19.3+; Recurring 3×
MPG Plugin
SQL Injection; 9.3/10; Update to v4.2.2+; Recurring 2×
zipMoney(Zip Co) Payments Plugin for WooCommerce Plugin
Broken Access Control; 9.1/10; Update to v2.4.0+
Editor Comment
It’s worth taking a few minutes each week to perform a sites review to catch issues early and wherever possible, use ShieldPRO’s auto-upgrade feature for vulnerable plugins.
#4 – WordPress Screens Every Plugin Update
Every plugin release now goes through an automated security review before it’s ever distributed via the WordPress.org update API. Releases flagged as a potential security risk, whether intentional or accidental, get blocked automatically, protecting the millions of sites that update plugins without manually checking each changelog.
#5 – Our blog: WordPress Hardening Checklist
This checklist walks through the essential layers, login protection, file permissions, server configuration, and security headers, that make your site a much harder target regardless of which plugin gets hit next.
Thanks for reading, and have a wonderful week!
Paul Goodchild
Shield Security for WordPress