Patch day turned into attack day: hackers targeted a critical WordPress core flaw within hours of its fix. GiveWP has a severe vulnerability too, while Ad Inserter, Blocksy, ShortPixel and other plugins need attention. Don’t miss our guide to updating WordPress safely.
#1 – Critical WordPress Core Risk
WordPress 7.1.1 and earlier versions contain a critical flaw (9.2/10 severity). Under certain conditions, this can lead to RCE. Attackers started targeting it within hours of the release. The WordPress fixed it in v7.1.2 and also included fixes for older affected versions.
Editor Comment
Monitor WordPress updates closely and install security fixes immediately upon release to protect your site from these vulnerabilities. Also, it’s worth taking a few minutes each week to perform a sites review to catch issues early.
#2 – Critical Security Risks in Popular Plugin
This widely used donation plugin has a critical authentication flaw. If you run it, update now.
GiveWP Plugin
Broken Authentication; 9.1/10; Update to v4.17.0+; Recurring 19×
Editor Comment
It’s worth taking a few minutes each week to perform a sites review to catch issues early and wherever possible, use ShieldPRO’s auto-upgrade feature for vulnerable plugins.
#3 – Other Security Risks in Popular Plugins
From page builders to backup tools, these plugins run on millions of WordPress sites. None of the flaws are critical, but we highly recommend checking your sites and updating where needed.
Elementor Website Builder Plugin
CSRF; 8.8/10; Update to v4.3.2+; Recurring 8×
Modula Image Gallery Plugin
Arbitrary File Deletion; 8.1/10; Update to v3.0.3+; Recurring 6×
Ad Inserter Plugin
RCE; 7.5/10; Update to v2.8.19+; Recurring 7×
SureCart Plugin
Privilege Escalation; 7.2/10; Update to v4.7.3+; Recurring 9×
WPForms Plugin
Broken Access Control; 7.5/10; Update to v2.2.2+; Recurring 31×
AMP for WP Plugin
XSS; 7.1/10; Update to v1.1.17+; Recurring 3×
CMB2 Plugin
Privilege Escalation; 6.8/10; Update to v2.13.0+
EmbedPress Plugin
XSS; 6.5/10; Update to v4.6.7+; Recurring 7×
Blocksy Companion Plugin
Broken Access Control; 6.5/10; Update to v2.1.56+; Recurring 8×
Optimole Plugin
XSS; 5.9/10; Update to v4.2.13+; Recurring 4×
Asset CleanUp: Page Speed Booster Plugin
SSRF; 5.5/10; Update to v1.4.0.6+; Recurring 4×
Mailchimp for WooCommerce Plugin
IDOR; 5.3/10; Update to v6.3+; Recurring 3×
UpdraftPlus Plugin
Broken Access Control; 5.3/10; Update to v1.26.8+; Recurring 3×
ShortPixel Image Optimizer Plugin
PHP Object Injection; 4.9/10; Update to v6.5.6+; Recurring 5×
Editor Comment
It’s worth taking a few minutes each week to perform a sites review to catch issues early and wherever possible, use ShieldPRO’s auto-upgrade feature for vulnerable plugins.
#4 – High Security Risks in Less Popular Plugins
These plugins have smaller user bases, but each one carries a 9.8 rating. If any of them are on your sites, act today.
Visual Composer Website Builder Plugin
Local File Inclusion; 9.8/10; Update to v45.16.1+; Recurring 3×
Wawp Plugin
Privilege Escalation; 9.8/10; Update to v4.8.7+; Recurring 2×
Estatik Plugin
Privilege Escalation; 9.8/10; Update to v4.3.6+; Recurring 4×
Editor Comment
It’s worth taking a few minutes each week to perform a sites review to catch issues early and wherever possible, use ShieldPRO’s auto-upgrade feature for vulnerable plugins.
#5 – Our blog: How to Update WordPress Safely
WordPress 7.1.1 is a reminder that security updates can’t wait. Our step-by-step guide shows you how to update it safely, from small security releases to major upgrades, and how to prepare in case an update doesn’t go to plan.
Thanks for reading, and have a wonderful week!
Paul Goodchild
Shield Security for WordPress