{"id":167037,"date":"2025-01-28T12:59:18","date_gmt":"2025-01-28T12:59:18","guid":{"rendered":"https:\/\/getshieldsecurity.com\/?p=167037"},"modified":"2025-01-28T12:59:19","modified_gmt":"2025-01-28T12:59:19","slug":"shieldnotes-50","status":"publish","type":"post","link":"https:\/\/getshieldsecurity.com\/blog\/shieldnotes-50\/","title":{"rendered":"Spotlight on Popular Plugins and Themes; &amp; Elementor Security Strategies"},"content":{"rendered":"\n<p>This week, new security risks in popular plugins and themes, including Avada and Really Simple SSL, came to light.<\/p>\n\n\n\n<p>Our latest blog post also covers Elementor vulnerabilities and offers ways to mitigate threats and protect your site.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">#1 &#8211; Security Risks in Popular Plugins &amp; Themes<\/h2>\n\n\n\n<p>The following plugins and themes, while not critically compromised, affect millions of sites, and you might likely be using 1 of them.<\/p>\n\n\n\n<p><strong><a href=\"https:\/\/patchstack.com\/database\/wordpress\/plugin\/string-locator\/vulnerability\/wordpress-string-locator-plugin-2-6-6-unauthenticated-php-object-injection-vulnerability\" target=\"_blank\" rel=\"noreferrer noopener\">String Locator Plugin<\/a><\/strong><br>PHP Object Injection; 7.2\/10; Update to v2.6.7+<\/p>\n\n\n\n<p><strong><a href=\"https:\/\/patchstack.com\/database\/wordpress\/plugin\/the-events-calendar\/vulnerability\/wordpress-the-events-calendar-plugin-6-9-0-authenticated-contributor-stored-cross-site-scripting-vulnerability\" target=\"_blank\" rel=\"noreferrer noopener\">The Events Calendar Plugin<\/a><\/strong><br>XSS; 6.5\/10; Update to v6.9.1+<\/p>\n\n\n\n<p><strong><a href=\"https:\/\/patchstack.com\/database\/wordpress\/theme\/betheme\/vulnerability\/wordpress-betheme-theme-27-6-1-authenticated-contributor-stored-cross-site-scripting-via-custom-js-vulnerability\" target=\"_blank\" rel=\"noreferrer noopener\">Betheme Theme<\/a><\/strong><br>XSS; 6.5\/10; Update to v27.6.2+<\/p>\n\n\n\n<p><strong><a href=\"https:\/\/patchstack.com\/database\/wordpress\/plugin\/bdthemes-prime-slider-lite\/vulnerability\/wordpress-prime-slider-addons-for-elementor-plugin-3-16-5-authenticated-contributor-stored-cross-site-scripting-vulnerability\" target=\"_blank\" rel=\"noreferrer noopener\">Prime Slider \u2013 Addons For Elementor Plugin<\/a><\/strong><br>XSS; 6.5\/10; Update to v3.16.6+<\/p>\n\n\n\n<p><strong><a href=\"https:\/\/patchstack.com\/database\/wordpress\/plugin\/stackable-ultimate-gutenberg-blocks\/vulnerability\/wordpress-stackable-plugin-3-13-11-authenticated-contributor-stored-cross-site-scripting-vulnerability\" target=\"_blank\" rel=\"noreferrer noopener\">Stackable Plugin<\/a><\/strong><br>XSS; 6.5\/10; Update to v3.13.12+<\/p>\n\n\n\n<p><strong><a href=\"https:\/\/patchstack.com\/database\/wordpress\/plugin\/jet-elements\/vulnerability\/wordpress-jet-elements-plugin-2-7-2-1-authenticated-contributor-stored-cross-site-scripting-via-multiple-widgets-vulnerability\" target=\"_blank\" rel=\"noreferrer noopener\">JetElements For Elementor Plugin<\/a><\/strong><br>XSS; 6.5\/10; Update to v2.7.3+<\/p>\n\n\n\n<p><strong><a href=\"https:\/\/patchstack.com\/database\/wordpress\/theme\/avada\/vulnerability\/wordpress-avada-theme-7-11-10-broken-access-control-vulnerability\" target=\"_blank\" rel=\"noreferrer noopener\">Avada Theme<\/a><\/strong><br>Broken Access Control; 5.3\/10; Update to v7.11.11+<\/p>\n\n\n\n<p><strong><a href=\"https:\/\/patchstack.com\/database\/wordpress\/plugin\/really-simple-ssl\/vulnerability\/wordpress-really-simple-security-plugin-9-1-4-cross-site-request-forgery-csrf-vulnerability\" target=\"_blank\" rel=\"noreferrer noopener\">Really Simple SSL Plugin<\/a><\/strong><br>CSRF; 4.3\/10; Update to v9.2.0+<\/p>\n\n\n\n<p><strong><a href=\"https:\/\/patchstack.com\/database\/wordpress\/plugin\/astra-sites\/vulnerability\/wordpress-starter-templates-plugin-4-4-9-cross-site-request-forgery-csrf-vulnerability\" target=\"_blank\" rel=\"noreferrer noopener\">Starter Templates Plugin<\/a><\/strong><br>CSRF; 4.3\/10; Update to v4.4.10+<\/p>\n\n\n\n<p><strong><a href=\"https:\/\/patchstack.com\/database\/wordpress\/plugin\/fluent-smtp\/vulnerability\/wordpress-fluentsmtp-plugin-2-2-80-cross-site-request-forgery-csrf-vulnerability\" target=\"_blank\" rel=\"noreferrer noopener\">FluentSMTP Plugin<\/a><\/strong><br>CSRF; 4.3\/10; Update to v2.2.81+<\/p>\n\n\n\n<p><strong>Editor Comment<\/strong><br>It&#8217;s worth taking a few minutes each week to <a href=\"https:\/\/getshieldsecurity.com\/blog\/wordpress-security-vulnerabilities\/\" target=\"_blank\" rel=\"noreferrer noopener\">perform a sites review<\/a> to catch issues early and wherever possible, use <a href=\"https:\/\/shsec.io\/lw\" target=\"_blank\" rel=\"noreferrer noopener\">ShieldPRO&#8217;s auto-upgrade<\/a> feature for vulnerable plugins.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">#2 &#8211; High Security Risks in Less Popular Plugins &amp; Themes<\/h2>\n\n\n\n<p>These plugins and themes may have lower usage, but they bring extremely high risks.<\/p>\n\n\n\n<p><strong><a href=\"https:\/\/patchstack.com\/database\/wordpress\/plugin\/wpbot-pro\/vulnerability\/wordpress-wpbot-pro-wordpress-chatbot-plugin-13-5-4-unauthenticated-arbitrary-file-upload-vulnerability\" target=\"_blank\" rel=\"noreferrer noopener\">WPBot Pro WordPress Chatbot Plugin<\/a><\/strong><br>Arbitrary File Upload; <strong>10<\/strong>\/10; Update to v13.5.6+<\/p>\n\n\n\n<p><strong><a href=\"https:\/\/patchstack.com\/database\/wordpress\/theme\/realhomes\/vulnerability\/wordpress-real-homes-plugin-4-3-6-privilege-escalation-vulnerability\" target=\"_blank\" rel=\"noreferrer noopener\">RealHomes Theme<\/a><\/strong><br>Privilege Escalation; <strong>9.8<\/strong>\/10; No fix; Remove\/or replace.<\/p>\n\n\n\n<p><strong><a href=\"https:\/\/patchstack.com\/database\/wordpress\/theme\/adforest\/vulnerability\/wordpress-adforest-plugin-5-1-8-authentication-bypass-vulnerability\" target=\"_blank\" rel=\"noreferrer noopener\">AdForest Theme<\/a><\/strong><br>Broken Authentication; <strong>9.8<\/strong>\/10; Update to v5.1.9+<\/p>\n\n\n\n<p><strong><a href=\"https:\/\/patchstack.com\/database\/wordpress\/plugin\/gamipress\/vulnerability\/wordpress-gamipress-plugin-7-2-1-unauthenticated-sql-injection-via-orderby-parameter-vulnerability\" target=\"_blank\" rel=\"noreferrer noopener\">GamiPress Plugin<\/a><\/strong><br>SQL Injection; <strong>9.3<\/strong>\/10; Update to v7.2.2+<\/p>\n\n\n\n<p><strong><a href=\"https:\/\/patchstack.com\/database\/wordpress\/plugin\/woo-product-tables\/vulnerability\/wordpress-product-table-by-wbw-plugin-2-1-2-unuthenticated-sql-injection-vulnerability\" target=\"_blank\" rel=\"noreferrer noopener\">Product Table by WBW Plugin<\/a><\/strong><br>SQL Injection; <strong>9.3<\/strong>\/10; Update to v2.1.3+<\/p>\n\n\n\n<p><strong>Editor Comment<\/strong><br>It&#8217;s worth taking a few minutes each week to <a href=\"https:\/\/getshieldsecurity.com\/blog\/wordpress-security-vulnerabilities\/\" target=\"_blank\" rel=\"noreferrer noopener\">perform a sites review<\/a> to catch issues early and wherever possible, use <a href=\"https:\/\/shsec.io\/lw\" target=\"_blank\" rel=\"noreferrer noopener\">ShieldPRO&#8217;s auto-upgrade<\/a> feature for vulnerable plugins.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">#3 &#8211; Our blog: Protect Your Site from Elementor Security Risks<\/h2>\n\n\n\n<p>Tools like Elementor, while trusted, can still face security issues. That\u2019s why it&#8217;s important to not only rely on updates but also take extra precautions to protect from emerging threats.<\/p>\n\n\n\n<p>Explore what steps you can take to strengthen your site.<\/p>\n\n\n\n<p><a href=\"https:\/\/getshieldsecurity.com\/blog\/elementor-vulnerabilities\/\" target=\"_blank\" rel=\"noreferrer noopener\">More Info \u2192<\/a><\/p>\n\n\n\n<p>Thanks for reading, and have a wonderful week!<\/p>\n\n\n\n<p><strong>Paul Goodchild<\/strong><br><em>Shield Security for WordPress<\/em><\/p>\n","protected":false},"excerpt":{"rendered":"<p>This week, new security risks in popular plugins and themes, including Avada and Really Simple SSL, came to light. Our latest blog post also covers Elementor vulnerabilities and offers ways to mitigate threats and protect your site.<\/p>\n","protected":false},"author":27,"featured_media":163832,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"footnotes":""},"categories":[153,201],"tags":[69],"class_list":["post-167037","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-security-wordpress-solutions","category-shieldnotes","tag-security"],"acf":[],"_links":{"self":[{"href":"https:\/\/getshieldsecurity.com\/wp-json\/wp\/v2\/posts\/167037","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/getshieldsecurity.com\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/getshieldsecurity.com\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/getshieldsecurity.com\/wp-json\/wp\/v2\/users\/27"}],"replies":[{"embeddable":true,"href":"https:\/\/getshieldsecurity.com\/wp-json\/wp\/v2\/comments?post=167037"}],"version-history":[{"count":7,"href":"https:\/\/getshieldsecurity.com\/wp-json\/wp\/v2\/posts\/167037\/revisions"}],"predecessor-version":[{"id":167064,"href":"https:\/\/getshieldsecurity.com\/wp-json\/wp\/v2\/posts\/167037\/revisions\/167064"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/getshieldsecurity.com\/wp-json\/wp\/v2\/media\/163832"}],"wp:attachment":[{"href":"https:\/\/getshieldsecurity.com\/wp-json\/wp\/v2\/media?parent=167037"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/getshieldsecurity.com\/wp-json\/wp\/v2\/categories?post=167037"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/getshieldsecurity.com\/wp-json\/wp\/v2\/tags?post=167037"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}