{"id":166429,"date":"2024-12-23T13:35:46","date_gmt":"2024-12-23T13:35:46","guid":{"rendered":"https:\/\/getshieldsecurity.com\/?p=166429"},"modified":"2024-12-23T13:35:47","modified_gmt":"2024-12-23T13:35:47","slug":"shieldnotes-46","status":"publish","type":"post","link":"https:\/\/getshieldsecurity.com\/blog\/shieldnotes-46\/","title":{"rendered":"Elementor &amp; LiteSpeed At Risk (again!); &amp; wp.org Services Paused;"},"content":{"rendered":"\n<p>It doesn&#8217;t seem to take very long for either, or both, of Elementor or LiteSpeed to make an appearance on our ShieldNOTES editions.<\/p>\n\n\n\n<p>There are also 2 Elementor-related plugins with vulnerabilities, and the popular User Role Editor plugin faces exposes sites to a CSRF of severity 9.8\/10.<\/p>\n\n\n\n<p>\ud83c\udf84 If you don&#8217;t hear from us beforehand, we wish all those who celebrate Christmas, a very merry Christmas holiday season, and everyone a prosperous New Year for 2025! \ud83c\udf84<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">#1 &#8211; High Security Risks in Popular Plugin<\/h2>\n\n\n\n<p>This is a high risk plugin, affecting 700,000+ sites.<\/p>\n\n\n\n<p><strong><a href=\"https:\/\/patchstack.com\/database\/wordpress\/plugin\/user-role-editor\/vulnerability\/wordpress-user-role-editor-plugin-4-64-3-cross-site-request-forgery-to-privilege-escalation-vulnerability\" target=\"_blank\" rel=\"noreferrer noopener\">User Role Editor Plugin<\/a><\/strong><br>CSRF; <strong>9.8<\/strong>\/10; Update to v4.64.4+<\/p>\n\n\n\n<p><strong>Editor Comment<\/strong><br>It&#8217;s worth taking a few minutes each week to <a href=\"https:\/\/getshieldsecurity.com\/blog\/wordpress-security-vulnerabilities\/\" target=\"_blank\" rel=\"noreferrer noopener\">perform a sites review<\/a> to catch issues early and wherever possible, use <a href=\"https:\/\/shsec.io\/lw\" target=\"_blank\" rel=\"noreferrer noopener\">ShieldPRO&#8217;s auto-upgrade<\/a> feature for vulnerable plugins.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">#2 &#8211; Lower Security Risks in Popular Plugins<\/h2>\n\n\n\n<p>These are widely used plugins with security threats, impacting millions of sites.<\/p>\n\n\n\n<p><strong><a href=\"https:\/\/patchstack.com\/database\/wordpress\/plugin\/elementor\/vulnerability\/wordpress-elementor-plugin-3-25-9-authenticated-contributor-stored-cross-site-scripting-via-typography-settings-vulnerability\" target=\"_blank\" rel=\"noreferrer noopener\">Elementor Website Builder Plugin<\/a><\/strong><br>XSS; 6.5\/10; Update to v3.25.10+<\/p>\n\n\n\n<p><strong><a href=\"https:\/\/patchstack.com\/database\/wordpress\/plugin\/litespeed-cache\/vulnerability\/wordpress-litespeed-cache-plugin-6-5-2-cross-site-scripting-xss-vulnerability\" target=\"_blank\" rel=\"noreferrer noopener\">LiteSpeed Cache Plugin<\/a><\/strong><br>XSS; 6.5\/10; Update to v6.5.3+<\/p>\n\n\n\n<p><strong><a href=\"https:\/\/patchstack.com\/database\/wordpress\/plugin\/header-footer-elementor\/vulnerability\/wordpress-elementor-header-footer-builder-plugin-1-6-46-authenticated-contributor-stored-cross-site-scripting-via-page-title-widget-vulnerability\" target=\"_blank\" rel=\"noreferrer noopener\">Elementor \u2013 Header, Footer &amp; Blocks Template Plugin<\/a><\/strong><br>XSS; 6.5\/10; Update to v1.6.47+<\/p>\n\n\n\n<p><strong><a href=\"https:\/\/patchstack.com\/database\/wordpress\/plugin\/download-manager\/vulnerability\/wordpress-download-manager-plugin-3-3-03-admin-stored-xss-vulnerability\" target=\"_blank\" rel=\"noreferrer noopener\">Download Manager Plugin<\/a><\/strong><br>XSS; 5.9\/10; Update to v3.3.03+<\/p>\n\n\n\n<p><strong><a href=\"https:\/\/patchstack.com\/database\/wordpress\/plugin\/bdthemes-element-pack-lite\/vulnerability\/wordpress-element-pack-elementor-addons-plugin-5-10-12-missing-authorization-vulnerability\" target=\"_blank\" rel=\"noreferrer noopener\">Element Pack Elementor Addons Plugin<\/a><\/strong><br>Broken Access Control; 4.3\/10; Update to v5.10.13+<\/p>\n\n\n\n<p><strong>Editor Comment<\/strong><br>It&#8217;s worth taking a few minutes each week to <a href=\"https:\/\/getshieldsecurity.com\/blog\/wordpress-security-vulnerabilities\/\" target=\"_blank\" rel=\"noreferrer noopener\">perform a sites review<\/a> to catch issues early and wherever possible, use <a href=\"https:\/\/shsec.io\/lw\" target=\"_blank\" rel=\"noreferrer noopener\">ShieldPRO&#8217;s auto-upgrade<\/a> feature for vulnerable plugins.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">#3 &#8211; High Security Risks in Less Popular Plugins &amp; Themes<\/h2>\n\n\n\n<p>Despite their limited use, these plugins and themes pose serious security risks.<\/p>\n\n\n\n<p><strong><a href=\"https:\/\/patchstack.com\/database\/wordpress\/plugin\/wplms-plugin\/vulnerability\/wordpress-wplms-plugin-1-9-9-5-3-subscriber-arbitrary-file-upload-vulnerability\">WPLMS Plugin<\/a><\/strong><br>Arbitrary File Upload; <strong>9.9<\/strong>\/10; Update to v1.9.9.5.3+<\/p>\n\n\n\n<p><strong><a href=\"https:\/\/patchstack.com\/database\/wordpress\/theme\/adforest\/vulnerability\/wordpress-adforest-plugin-5-1-6-authentication-bypass-vulnerability\" target=\"_blank\" rel=\"noreferrer noopener\">AdForest Theme<\/a><\/strong><br>Broken Access Control; <strong>9.8<\/strong>\/10; Update to v5.1.7+<\/p>\n\n\n\n<p><strong><a href=\"https:\/\/patchstack.com\/database\/wordpress\/plugin\/biagiotti-membership\/vulnerability\/wordpress-biagiotti-membership-plugin-1-0-2-authentication-bypass-via-biagiotti-membership-check-facebook-user-vulnerability\" target=\"_blank\" rel=\"noreferrer noopener\">Biagiotti Membership Plugin<\/a><\/strong><br>Privilege Escalation; <strong>9.8<\/strong>\/10; Update to v1.1+<\/p>\n\n\n\n<p><strong><a href=\"https:\/\/patchstack.com\/database\/wordpress\/plugin\/vibebp\/vulnerability\/wordpress-vibebp-plugin-1-9-9-7-7-unauthenticated-sql-injection-vulnerability\" target=\"_blank\" rel=\"noreferrer noopener\">VibeBP Plugin<\/a><\/strong><br>SQL Injection; <strong>9.3<\/strong>\/10; Update to v1.9.9.7.7+<\/p>\n\n\n\n<p><strong><a href=\"https:\/\/patchstack.com\/database\/wordpress\/theme\/traveler\/vulnerability\/wordpress-traveler-plugin-3-1-6-unauthenticated-sql-injection-via-order-id-vulnerability\" target=\"_blank\" rel=\"noreferrer noopener\">Traveler Theme<\/a><\/strong><br>SQL Injection; <strong>9.3<\/strong>\/10; Update to v3.1.7+<\/p>\n\n\n\n<p><strong><a href=\"https:\/\/patchstack.com\/database\/wordpress\/plugin\/acf-frontend-form-element\/vulnerability\/wordpress-frontend-admin-by-dynamiapps-plugin-3-25-1-unauthenticated-sql-injection-vulnerability\" target=\"_blank\" rel=\"noreferrer noopener\">Frontend Admin by DynamiApps Plugin<\/a><\/strong><br>SQL Injection; <strong>9.3<\/strong>\/10; Update to v3.25.2+<\/p>\n\n\n\n<p><strong><a href=\"https:\/\/patchstack.com\/database\/wordpress\/plugin\/collapsing-categories\/vulnerability\/wordpress-collapsing-categories-plugin-3-0-8-unauthenticated-sql-injection-vulnerability\" target=\"_blank\" rel=\"noreferrer noopener\">Collapsing Categories Plugin<\/a><\/strong><br>SQL Injection; <strong>9.3<\/strong>\/10; Update to v3.0.9+<\/p>\n\n\n\n<p><strong>Editor Comment<\/strong><br>It&#8217;s worth taking a few minutes each week to <a href=\"https:\/\/getshieldsecurity.com\/blog\/wordpress-security-vulnerabilities\/\" target=\"_blank\" rel=\"noreferrer noopener\">perform a sites review<\/a> to catch issues early and wherever possible, use <a href=\"https:\/\/shsec.io\/lw\" target=\"_blank\" rel=\"noreferrer noopener\">ShieldPRO&#8217;s auto-upgrade<\/a> feature for vulnerable plugins.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">#4 &#8211; wp.org Temporarily Shuts Down Most Services<\/h2>\n\n\n\n<p>With the WP vs WP Engine saga continuing to play out, Matt has put several free services on pause, with no end date provided. Users can still set up WordPress installations and accounts during this time.<\/p>\n\n\n\n<p><a href=\"https:\/\/wordpress.org\/news\/2024\/12\/holiday-break\/\" target=\"_blank\" rel=\"noreferrer noopener\">More Info \u2192<\/a><\/p>\n\n\n\n<h2 class=\"wp-block-heading\">#5 &#8211; Our blog: How to Force HTTPS on WordPress<\/h2>\n\n\n\n<p>Our beginner-friendly guide explores how HTTPS protects WordPress sites and user data, addressing security vulnerabilities and implementation challenges. You&#8217;ll learn its importance and how to adopt it effectively.<\/p>\n\n\n\n<p><a href=\"https:\/\/getshieldsecurity.com\/blog\/wordpress-https\/\" target=\"_blank\" rel=\"noreferrer noopener\">More Info \u2192<\/a><\/p>\n\n\n\n<p>Thanks for reading, and have a great week!<\/p>\n\n\n\n<p><strong>Paul Goodchild<\/strong><br><em>Shield Security for WordPress<\/em><\/p>\n","protected":false},"excerpt":{"rendered":"<p>It doesn&#8217;t seem to take very long for either, or both, of Elementor or LiteSpeed to make an appearance on our ShieldNOTES emails. There are also 2 Elementor-related plugins with vulnerabilities, and the popular User Role Editor plugin faces exposes sites to a CSRF of severity 9.8\/10.<\/p>\n","protected":false},"author":27,"featured_media":163832,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"footnotes":""},"categories":[153,201],"tags":[69],"class_list":["post-166429","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-security-wordpress-solutions","category-shieldnotes","tag-security"],"acf":[],"_links":{"self":[{"href":"https:\/\/getshieldsecurity.com\/wp-json\/wp\/v2\/posts\/166429","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/getshieldsecurity.com\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/getshieldsecurity.com\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/getshieldsecurity.com\/wp-json\/wp\/v2\/users\/27"}],"replies":[{"embeddable":true,"href":"https:\/\/getshieldsecurity.com\/wp-json\/wp\/v2\/comments?post=166429"}],"version-history":[{"count":12,"href":"https:\/\/getshieldsecurity.com\/wp-json\/wp\/v2\/posts\/166429\/revisions"}],"predecessor-version":[{"id":166444,"href":"https:\/\/getshieldsecurity.com\/wp-json\/wp\/v2\/posts\/166429\/revisions\/166444"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/getshieldsecurity.com\/wp-json\/wp\/v2\/media\/163832"}],"wp:attachment":[{"href":"https:\/\/getshieldsecurity.com\/wp-json\/wp\/v2\/media?parent=166429"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/getshieldsecurity.com\/wp-json\/wp\/v2\/categories?post=166429"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/getshieldsecurity.com\/wp-json\/wp\/v2\/tags?post=166429"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}