There’s plenty to keep an eye on in this edition, from three extremely severe vulnerabilities, including one affecting Admin Menu Editor Pro with no fix, to other security risks affecting WordPress sites. We also share practical tips on database repair and recovery, from our blog.
#1 – Extremely Critical Security Risks in Popular Plugins
These widely used plugins have serious security vulnerabilities to be aware of, with the first one requiring particular attention as no patch has been released yet.
Admin Menu Editor Pro Plugin
Backdoor; 10/10; No fix available yet; please replace or monitor for updates.
Gravity Forms Plugin
Arbitrary File Upload; 10/10; Update to v3.1.1+; Recurring 7×
Forminator Plugin
Broken Access Control; 9.1/10; Update to v1.57.3+; Recurring 25×
Editor Comment
It’s worth taking a few minutes each week to perform a sites review to catch issues early and wherever possible, use ShieldPRO’s auto-upgrade feature for vulnerable plugins.
#2 – Other Security Risks in Popular Plugins
If you have any of these plugins installed, now is a good time to check for updates and address the vulnerabilities affecting them.
All-in-One WP Migration Plugin
Privilege Escalation; 7.2/10; Update to v7.111+; Recurring 6×
Asset CleanUp: Page Speed Booster Plugin
XSS; 7.1/10; Update to v1.4.0.6+; Recurring 3×
ShopLentor Plugin
XSS; 7.1/10; Update to v3.5.2+; Recurring 8×
Jeg Kit for Elementor Plugin
XSS; 7.1/10; Update to v3.2.17+; Recurring 8×
Tutor LMS Plugin
XSS; 7.1/10; Update to v4.0.9+; Recurring 36×
Divi Essentials Plugin
Broken Access Control; 6.5/10; Update to v5.9.0+
Ultimate Member Plugin
XSS; 6.5/10; Update to v2.12.0+; Recurring 13×
WooCommerce Checkout Manager Plugin
Arbitrary File Deletion; 4.3/10; Update to v7.9.7+; Recurring 3×
Editor Comment
It’s worth taking a few minutes each week to perform a sites review to catch issues early and wherever possible, use ShieldPRO’s auto-upgrade feature for vulnerable plugins.
#3 – Critical Security Risks in Less Popular Plugins
Don’t overlook these plugins either. Check your sites and update where needed.
GeoDirectory Location Manager Plugin
SQL Injection; 9.3/10; Update to v2.3.39+
WP Multi Store Locator Pro Plugin
SQL Injection; 9.3/10; Update to v4.5.2+
WP Recipe Maker Plugin
Broken Access Control; 9.1/10; Update to v10.8.2+; Recurring 9x
AF Companion Plugin
Arbitrary File Upload; 9.1/10; Update to v2.2.0+
Editor Comment
It’s worth taking a few minutes each week to perform a sites review to catch issues early and wherever possible, use ShieldPRO’s auto-upgrade feature for vulnerable plugins.
#4 – Our blog: When Your WordPress Database Goes Wrong
When your WordPress database starts causing trouble, your whole site can feel the impact. From unnecessary data to corruption, here’s what you can do to repair and recover it.
Thanks for reading, and have a wonderful week!
Paul Goodchild
Shield Security for WordPress