{"id":164651,"date":"2024-09-23T15:07:17","date_gmt":"2024-09-23T14:07:17","guid":{"rendered":"https:\/\/getshieldsecurity.com\/?p=164651"},"modified":"2024-09-23T15:07:18","modified_gmt":"2024-09-23T14:07:18","slug":"shieldnotes-ep33","status":"publish","type":"post","link":"https:\/\/getshieldsecurity.com\/blog\/shieldnotes-ep33\/","title":{"rendered":"ShieldNOTES Ep#33: Recent Vulnerabilities, Upcoming WP Agency Summit &amp; Important Update From Shield&#8217;s Team"},"content":{"rendered":"\n<p>This week\u2019s vulnerabilities underscore the need to stay informed.<\/p>\n\n\n\n<p>Don\u2019t miss the notice about switching to PHP 7.4.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">#1 &#8211; Vulnerable: MC4WP: Mailchimp Plugin<\/h2>\n\n\n\n<p>2+ million sites affected with malicious script injection.<\/p>\n\n\n\n<p><strong>How will I know I&#8217;m okay?<\/strong><br>Upgrade ASAP to v4.9.17+<\/p>\n\n\n\n<p><strong>What&#8217;s the risk?<\/strong><br>Severity risk <strong>7.1<\/strong>\/10 &#8211; XSS &#8211; allowing injection of malicious scripts into website that guests may execute.<\/p>\n\n\n\n<p>Editor Comment<br>Please use <a href=\"https:\/\/getshieldsecurity.com\/blog\/wordpress-plugin-vulnerability-scanner\/\" target=\"_blank\" rel=\"noreferrer noopener\">ShieldPRO&#8217;s auto-upgrade feature<\/a> for vulnerable plugins.<\/p>\n\n\n\n<p><a href=\"https:\/\/patchstack.com\/database\/vulnerability\/mailchimp-for-wp\/wordpress-mc4wp-plugin-4-9-9-4-9-16-reflected-cross-site-scripting-vulnerability\" target=\"_blank\" rel=\"noreferrer noopener\">More Info \u2192<\/a><\/p>\n\n\n\n<h2 class=\"wp-block-heading\">#2 &#8211; Vulnerable: Houzez Theme &amp; Login Register Plugin<\/h2>\n\n\n\n<p>Unauthorised access escalation risk.<\/p>\n\n\n\n<p><strong>How will I know I&#8217;m okay?<\/strong><br>Upgrade ASAP to v3.3.0+<\/p>\n\n\n\n<p><strong>What&#8217;s the risk?<\/strong><br>Severity risk <strong>8.8<\/strong>\/10 &#8211; Privilege Escalation &#8211; an attacker can gain full access to a site by escalating their low user privileges.<\/p>\n\n\n\n<p><strong>Editor Comment<\/strong><br>Please use <a href=\"https:\/\/getshieldsecurity.com\/blog\/wordpress-plugin-vulnerability-scanner\/\" target=\"_blank\" rel=\"noreferrer noopener\">ShieldPRO&#8217;s auto-upgrade feature<\/a> for vulnerable plugins.<\/p>\n\n\n\n<p><a href=\"https:\/\/patchstack.com\/database\/vulnerability\/houzez\/wordpress-houzez-theme-3-2-4-privilege-escalation-vulnerability\" target=\"_blank\" rel=\"noreferrer noopener\">More Info \u2192<\/a><\/p>\n\n\n\n<h2 class=\"wp-block-heading\">#3 &#8211; Vulnerable: WCFM Marketplace Plugin<\/h2>\n\n\n\n<p>Plugin actively exploited with XSS but <em>no official fix yet<\/em>.<\/p>\n\n\n\n<p><strong>How will I know I&#8217;m okay?<\/strong><br>No fix available yet; please replace or monitor for updates.<\/p>\n\n\n\n<p><strong>What&#8217;s the risk?<\/strong><br>Severity risk 7.1\/10 &#8211; XSS &#8211; allowing injection of malicious scripts into website that guests may execute.<\/p>\n\n\n\n<p><strong>Editor Comment<\/strong><br>Please use <a href=\"https:\/\/getshieldsecurity.com\/blog\/wordpress-plugin-vulnerability-scanner\/\" target=\"_blank\" rel=\"noreferrer noopener\">ShieldPRO&#8217;s auto-upgrade feature<\/a> for vulnerable plugins.<\/p>\n\n\n\n<p><a href=\"https:\/\/patchstack.com\/database\/vulnerability\/wc-multivendor-marketplace\/wordpress-wcfm-marketplace-3-6-10-reflected-cross-site-scripting-xss-vulnerability\" target=\"_blank\" rel=\"noreferrer noopener\">More Info \u2192<\/a><\/p>\n\n\n\n<h2 class=\"wp-block-heading\">#4 &#8211; WordPress Agency Summit 2024<\/h2>\n\n\n\n<p>A free online event starting this Friday, September 27th, will offer practical tips for building and optimizing fast, dynamic WordPress sites, covering topics like server optimization and security.<\/p>\n\n\n\n<p><strong>How can I get involved?<\/strong><br>You can join the LiveStreams when they&#8217;re announced.<\/p>\n\n\n\n<p><a href=\"https:\/\/crocoblock.com\/wordpress-agency-summit\/\" target=\"_blank\" rel=\"noreferrer noopener\">More Info \u2192<\/a><\/p>\n\n\n\n<h2 class=\"wp-block-heading\">#5 &#8211; Important Notice: Shield Security Will Require PHP 7.4+<\/h2>\n\n\n\n<p>Shield Security will soon need minimum PHP 7.4 to improve performance and take advantage of new PHP features, while continuing to support most users. Make sure to back up your site and talk to your web host about upgrading.<\/p>\n\n\n\n<p><a href=\"https:\/\/getshieldsecurity.com\/blog\/php-7-4\/\" target=\"_blank\" rel=\"noreferrer noopener\">More Info \u2192<\/a><\/p>\n\n\n\n<p>Thanks for reading, and have a great week!<\/p>\n\n\n\n<p><strong>Paul Goodchild<\/strong><br><em>Shield Security for WordPress<\/em><\/p>\n\n\n\n<p><\/p>\n","protected":false},"excerpt":{"rendered":"<p>This week\u2019s vulnerabilities underscore the need to stay informed. Don\u2019t miss the notice about switching to PHP 7.4.<\/p>\n","protected":false},"author":27,"featured_media":163832,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"footnotes":""},"categories":[153,201],"tags":[69],"class_list":["post-164651","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-security-wordpress-solutions","category-shieldnotes","tag-security"],"acf":[],"_links":{"self":[{"href":"https:\/\/getshieldsecurity.com\/wp-json\/wp\/v2\/posts\/164651","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/getshieldsecurity.com\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/getshieldsecurity.com\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/getshieldsecurity.com\/wp-json\/wp\/v2\/users\/27"}],"replies":[{"embeddable":true,"href":"https:\/\/getshieldsecurity.com\/wp-json\/wp\/v2\/comments?post=164651"}],"version-history":[{"count":2,"href":"https:\/\/getshieldsecurity.com\/wp-json\/wp\/v2\/posts\/164651\/revisions"}],"predecessor-version":[{"id":164653,"href":"https:\/\/getshieldsecurity.com\/wp-json\/wp\/v2\/posts\/164651\/revisions\/164653"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/getshieldsecurity.com\/wp-json\/wp\/v2\/media\/163832"}],"wp:attachment":[{"href":"https:\/\/getshieldsecurity.com\/wp-json\/wp\/v2\/media?parent=164651"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/getshieldsecurity.com\/wp-json\/wp\/v2\/categories?post=164651"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/getshieldsecurity.com\/wp-json\/wp\/v2\/tags?post=164651"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}