There’s plenty to keep an eye on in this edition, from three extremely severe vulnerabilities, including one affecting Admin Menu Editor Pro with no fix, to other security risks affecting WordPress sites. We also share practical tips on database repair and recovery, from our blog.

These widely used plugins have serious security vulnerabilities to be aware of, with the first one requiring particular attention as no patch has been released yet.

Admin Menu Editor Pro Plugin
Backdoor; 10/10; No fix available yet; please replace or monitor for updates.

Gravity Forms Plugin
Arbitrary File Upload; 10/10; Update to v3.1.1+; Recurring

Forminator Plugin
Broken Access Control; 9.1/10; Update to v1.57.3+; Recurring 25×

Editor Comment
It’s worth taking a few minutes each week to perform a sites review to catch issues early and wherever possible, use ShieldPRO’s auto-upgrade feature for vulnerable plugins.

If you have any of these plugins installed, now is a good time to check for updates and address the vulnerabilities affecting them.

All-in-One WP Migration Plugin
Privilege Escalation; 7.2/10; Update to v7.111+; Recurring

Asset CleanUp: Page Speed Booster Plugin
XSS; 7.1/10; Update to v1.4.0.6+; Recurring

ShopLentor Plugin
XSS; 7.1/10; Update to v3.5.2+; Recurring 8× 

Jeg Kit for Elementor Plugin
XSS; 7.1/10; Update to v3.2.17+; Recurring

Tutor LMS Plugin
XSS; 7.1/10; Update to v4.0.9+; Recurring 36×

Divi Essentials Plugin
Broken Access Control; 6.5/10; Update to v5.9.0+

Ultimate Member Plugin
XSS; 6.5/10; Update to v2.12.0+; Recurring 13×

WooCommerce Checkout Manager Plugin
Arbitrary File Deletion; 4.3/10; Update to v7.9.7+; Recurring

Editor Comment
It’s worth taking a few minutes each week to perform a sites review to catch issues early and wherever possible, use ShieldPRO’s auto-upgrade feature for vulnerable plugins.

Don’t overlook these plugins either. Check your sites and update where needed.

GeoDirectory Location Manager Plugin
SQL Injection; 9.3/10; Update to v2.3.39+

WP Multi Store Locator Pro Plugin
SQL Injection; 9.3/10; Update to v4.5.2+

WP Recipe Maker Plugin
Broken Access Control; 9.1/10; Update to v10.8.2+; Recurring 9x

AF Companion Plugin
Arbitrary File Upload; 9.1/10; Update to v2.2.0+

Editor Comment
It’s worth taking a few minutes each week to perform a sites review to catch issues early and wherever possible, use ShieldPRO’s auto-upgrade feature for vulnerable plugins.

#4 – Our blog: When Your WordPress Database Goes Wrong

When your WordPress database starts causing trouble, your whole site can feel the impact. From unnecessary data to corruption, here’s what you can do to repair and recover it.

More Info →

Thanks for reading, and have a wonderful week!

Paul Goodchild
Shield Security for WordPress