Plugin Vulnerabilities for March 2022

Is your site up to date? Outdate plugins & themes are the #1 reason sites get hacked. Don’t leave your WooCommerce store vulnerable! MC4WP Vulnerability: Admin+ Stored Cross-Site Scripting Severity: Low Fixed: update to version 4.8.7 Translate WordPress with GTranslate CSRF to Account Takeover Severity: High Fixed: update to version 2.9.9 Popup Builder SQL Injection....

Plugin Vulnerabilities for January 2022

Is your site up to date? Outdate plugins & themes are the #1 reason sites get hacked. Don’t leave your WooCommerce store vulnerable! SVG Support Plugin: SVG Support Vulnerability: Admin+ Stored Cross-Site Scripting Active Installation: 800,000+ Patched in Version: 2.3.20 Severity Score: Low Asset CleanUp Plugin: Asset CleanUp Vulnerability: Reflected Cross-Site Scripting via AJAX Action Active Installation: 100,000+ Patched....

Plugin Vulnerabilities for December 2021

Is your site up to date? Outdate plugins & themes are the #1 reason sites get hacked. Don’t leave your WooCommerce store vulnerable! Events Manager Plugin: Events Manager Vulnerability: Admin+ SQL Injection Patched in Version: 5.9.8 Rich Reviews by Starfish Plugin: Rich Reviews by Starfish Vulnerability: Admin+ SQL Injection Patched in Version: 1.9.6 Typebot Plugin: Typebot Vulnerability: Admin+....

More Plugin Vulnerabilities for November 2021

Is your site up to date? Outdate plugins & themes are the #1 reason sites get hacked. Don’t leave your WooCommerce store vulnerable! Pixel Cat Lite Plugin: Pixel Cat Lite Vulnerability: Admin+ Stored Cross-Site Scripting Patched in Version: 2.6.3 All-In-One-Gallery Plugin: All-In-One-Gallery Vulnerability: Admin+ Local File Inclusion Patched in Version: 2.5.0 StopBadBots Plugin: StopBadBots  Vulnerability: Reflected Cross-Site Scripting Patched....

November 18, 2021 Plugin Vulnerabilities

Is your site up to date? Outdate plugins & themes are the #1 reason sites get hacked. Don’t leave your WooCommerce store vulnerable! Registrations for the Events Calendar Plugin: Registrations for the Events Calendar Vulnerability: Unauthenticated SQL Injection Patched in Version: 2.7.6 LoginWP Plugin: LoginWP  Vulnerability: Reflected Cross-Site Scripting Patched in Version: 3.0.0.5 WooCommerce Currency Switcher Plugin: WooCommerce....

September 29, 2021 Plugin Vulnerabilities

Is your site up to date? Outdate plugins & themes are the #1 reason sites get hacked. Don’t leave your WooCommerce store vulnerable! Comments – wpDiscuz Plugin: Comments – wpDiscuz Vulnerability: Admin+ Stored Cross-Site Scripting Patched in Version: 7.3.2 Page Generator Plugin: Page Generator  Vulnerability: Reflected Cross-Site Scripting Patched in Version: 1.5.9 WordPress to Hootsuite Plugin: WordPress to....

August 25, 2021 Plugin Vulnerabilities

Is your site up to date? Outdate plugins & themes are the #1 reason sites get hacked. Don’t leave your WooCommerce store vulnerable! Pinterest Automatic Plugin: WordPress Automatic Vulnerability: Unauthenticated Arbitrary Options Update Patched in Version: 3.53.3 ELEX WooCommerce Google Shopping Plugin: ELEX WooCommerce Google Shopping  Vulnerability: Reflected Cross-Site Scripting (XSS) Patched in Version: 1.2.4 User Registration....

August 25, 2021 Plugin Vulnerabilities

Is your site up to date? Outdate plugins & themes are the #1 reason sites get hacked. Don’t leave your WooCommerce store vulnerable! rucy Plugin: rucy Vulnerability: CSRF Bypass Patched in Version: No known fix  WP-Backgrounds Lite Plugin: WP-Backgrounds Lite Vulnerability: CSRF Bypass Patched in Version: No known fix Severity Score: Medium WP Security Question Plugin: WP Security Question  Vulnerability: CSRF Bypass....

End of August 2021 Plugin Vulnerabilities

Is your site up to date? Outdate plugins & themes are the #1 reason sites get hacked. Don’t leave your WooCommerce store vulnerable! Clean Login Plugin: Clean Login Vulnerability: Reflected Cross-Site Scripting Patched in Version: 1.12.6.4 Severity Score: Medium Business Hours Indicator Plugin: Business Hours Indicator  Vulnerability: Authenticated Stored XSS Patched in Version: 2.3.5 Severity Score: Low SliceWP Plugin: SliceWP Vulnerability: Reflected....

More August 2021 Plugin Vulnerabilities

Is your site up to date? Outdate plugins & themes are the #1 reason sites get hacked. Don’t leave your WooCommerce store vulnerable! Sitewide Notice WP Plugin: Sitewide Notice WP Vulnerability: Authenticated Stored XSS Patched in Version: 2.3 Business Hours Indicator Plugin: Business Hours Indicator  Vulnerability: Authenticated Stored XSS Patched in Version: 2.3.5 Severity Score: Low Bold Page Builder....