{"id":167566,"date":"2025-03-03T15:32:50","date_gmt":"2025-03-03T15:32:50","guid":{"rendered":"https:\/\/getshieldsecurity.com\/?p=167566"},"modified":"2025-03-03T15:32:51","modified_gmt":"2025-03-03T15:32:51","slug":"shieldnotes-55","status":"publish","type":"post","link":"https:\/\/getshieldsecurity.com\/blog\/shieldnotes-55\/","title":{"rendered":"Some vulnerable plugins removed from WP.org; &amp; the &#8216;Security Through Obscurity&#8217; myth"},"content":{"rendered":"\n<p>There&#8217;s a few ultra critical vulnerabilities this week, with some removed from the WP repo.<\/p>\n\n\n\n<p>You can check out the upcoming WP virtual conference and uncover the &#8220;Security Through Obscurity&#8221; myth from our blog archive.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">#1 &#8211; Security Risks in Popular Plugins &amp; Themes<\/h2>\n\n\n\n<p>These high-profile plugins and theme are being targeted; 1 plugin stands out as a major risk due to missing fixes.<\/p>\n\n\n\n<p><strong><a href=\"https:\/\/patchstack.com\/database\/wordpress\/plugin\/squirrly-seo\/vulnerability\/wordpress-squirrly-seo-plugin-12-4-05-broken-access-control-vulnerability\" target=\"_blank\" rel=\"noreferrer noopener\">SEO Plugin by Squirrly SEO<\/a><\/strong><br>Broken Access Control; 7.1\/10; No fix; Remove\/or replace.<\/p>\n\n\n\n<p><strong><a href=\"https:\/\/patchstack.com\/database\/wordpress\/plugin\/site-mailer\/vulnerability\/wordpress-site-mailer-plugin-1-2-3-unauthenticated-stored-cross-site-scripting-vulnerability\" target=\"_blank\" rel=\"noreferrer noopener\">Site Mailer Plugin<\/a><\/strong><br>XSS; 7.1\/10; Update to v1.2.4+<\/p>\n\n\n\n<p><strong><a href=\"https:\/\/patchstack.com\/database\/wordpress\/plugin\/chaty\/vulnerability\/wordpress-chaty-plugin-3-3-5-authenticated-contributor-dom-based-stored-cross-site-scripting-vulnerability\" target=\"_blank\" rel=\"noreferrer noopener\">Chaty Plugin<\/a><\/strong><br>XSS; 6.5\/10; Update to v3.3.6+<\/p>\n\n\n\n<p><strong><a href=\"https:\/\/patchstack.com\/database\/wordpress\/plugin\/essential-blocks\/vulnerability\/wordpress-essential-blocks-for-gutenberg-plugin-5-2-3-authenticated-contributor-stored-cross-site-scripting-vulnerability\" target=\"_blank\" rel=\"noreferrer noopener\">Essential Blocks for Gutenberg Plugin<\/a><\/strong><br>XSS; 6.5\/10; Update to v5.3.0+<\/p>\n\n\n\n<p><strong><a href=\"https:\/\/patchstack.com\/database\/wordpress\/theme\/enfold\/vulnerability\/wordpress-enfold-theme-6-0-9-authenticated-subscriber-server-side-request-forgery-via-attachment-id-vulnerability\" target=\"_blank\" rel=\"noreferrer noopener\">Enfold Theme<\/a><\/strong><br>SSRF; 6.4\/10; Update to v7.0+<\/p>\n\n\n\n<p><strong><a href=\"https:\/\/patchstack.com\/database\/wordpress\/plugin\/nextgen-gallery\/vulnerability\/wordpress-nextgen-gallery-plugin-3-59-9-admin-stored-xss-vulnerability\" target=\"_blank\" rel=\"noreferrer noopener\">NextGEN Gallery Plugin<\/a><\/strong><br>XSS; 5.9\/10; Update to v3.59.9+<\/p>\n\n\n\n<p><strong><a href=\"https:\/\/patchstack.com\/database\/wordpress\/plugin\/advanced-google-recaptcha\/vulnerability\/wordpress-advanced-google-recaptcha-plugin-1-27-built-in-math-captcha-bypass-vulnerability\" target=\"_blank\" rel=\"noreferrer noopener\">Advanced Google reCAPTCHA Plugin<\/a><\/strong><br>Bypass Vulnerability; 5.3\/10; Update to v1.28+<\/p>\n\n\n\n<p><strong>Editor Comment<\/strong><br>It&#8217;s worth taking a few minutes each week to <a href=\"https:\/\/getshieldsecurity.com\/blog\/wordpress-security-vulnerabilities\/\" target=\"_blank\" rel=\"noreferrer noopener\">perform a sites review<\/a> to catch issues early and wherever possible, use <a href=\"https:\/\/shsec.io\/lw\" target=\"_blank\" rel=\"noreferrer noopener\">ShieldPRO&#8217;s auto-upgrade<\/a> feature for vulnerable plugins.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">#2 &#8211; Security Risks in Less Popular Plugins &amp; Themes<\/h2>\n\n\n\n<p>These less popular plugins and theme often fly under the radar, but they still pose significant security risks, particularly 2 that remained unpatched.<\/p>\n\n\n\n<p><strong><a href=\"https:\/\/patchstack.com\/database\/wordpress\/plugin\/woocommerce-ultimate-gift-card\/vulnerability\/wordpress-woocommerce-ultimate-gift-card-plugin-2-6-0-unauthenticated-arbitrary-file-upload-vulnerability\" target=\"_blank\" rel=\"noreferrer noopener\">WooCommerce Ultimate Gift Card Plugin<\/a><\/strong><br>Arbitrary File Upload; <strong>10<\/strong>\/10; Removed from wp.org; No fix; Remove\/or replace.<\/p>\n\n\n\n<p><strong><a href=\"https:\/\/patchstack.com\/database\/wordpress\/plugin\/dhvc-form\/vulnerability\/wordpress-dhvc-form-plugin-2-4-7-unauthenticated-privilege-escalation-vulnerability\" target=\"_blank\" rel=\"noreferrer noopener\">DHVC Form Plugin<\/a><\/strong><br>Privilege Escalation; <strong>9.8<\/strong>\/10; Update to v2.4.8+<\/p>\n\n\n\n<p><strong><a href=\"https:\/\/patchstack.com\/database\/wordpress\/plugin\/whmpress\/vulnerability\/wordpress-whmpress-plugin-6-3-revision-0-unauthenticated-local-file-inclusion-to-arbitrary-options-update-vulnerability\" target=\"_blank\" rel=\"noreferrer noopener\">WHMpress Plugin<\/a><\/strong><br>Local File Inclusion; <strong>9.8<\/strong>\/10; Update to v6.3+<\/p>\n\n\n\n<p><strong><a href=\"https:\/\/patchstack.com\/database\/wordpress\/plugin\/academist-membership\/vulnerability\/wordpress-academist-membership-plugin-1-1-6-authentication-bypass-via-account-takeover-vulnerability\" target=\"_blank\" rel=\"noreferrer noopener\">Academist Membership Plugin<\/a><\/strong><br>Broken Authentication; <strong>9.8<\/strong>\/10; Update to v1.2+<\/p>\n\n\n\n<p><strong><a href=\"https:\/\/patchstack.com\/database\/wordpress\/plugin\/templines-helper-core\/vulnerability\/wordpress-templines-elementor-helper-core-plugin-2-7-authenticated-subscriber-privilege-escalation-vulnerability\" target=\"_blank\" rel=\"noreferrer noopener\">Templines Elementor Helper Core Plugin<\/a><\/strong><br>Privilege Escalation; 8.8\/10; Update to v2.8+<\/p>\n\n\n\n<p><strong><a href=\"https:\/\/patchstack.com\/database\/wordpress\/theme\/traveler\/vulnerability\/wordpress-traveler-theme-3-1-8-authenticated-contributor-local-file-inclusion-via-shortcode-vulnerability\" target=\"_blank\" rel=\"noreferrer noopener\">Traveler Theme<\/a><\/strong><br>Local File Inclusion; 8.8\/10; No fix; Remove\/or replace.<\/p>\n\n\n\n<p><strong>Editor Comment<\/strong><br>It&#8217;s worth taking a few minutes each week to <a href=\"https:\/\/getshieldsecurity.com\/blog\/wordpress-security-vulnerabilities\/\" target=\"_blank\" rel=\"noreferrer noopener\">perform a sites review<\/a> to catch issues early and wherever possible, use <a href=\"https:\/\/shsec.io\/lw\" target=\"_blank\" rel=\"noreferrer noopener\">ShieldPRO&#8217;s auto-upgrade<\/a> feature for vulnerable plugins.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">#3 &#8211; WP:25 Virtual Conference<\/h2>\n\n\n\n<p>A free online conference starting this Thursday, March 6th, will highlight why WordPress remains a leading platform in 2025, along with research updates and the key topics that enterprise brands must focus on for the year ahead.<\/p>\n\n\n\n<p><strong>How can I get involved?<\/strong><br>You can signup and join the LiveStreams when they&#8217;re announced.<\/p>\n\n\n\n<p><a href=\"https:\/\/humanmade.com\/wordpress-in-2025-event\/\" target=\"_blank\" rel=\"noreferrer noopener\">More Info \u2192<\/a><\/p>\n\n\n\n<h2 class=\"wp-block-heading\">#4 &#8211; Our blog: Security Through Obscurity: Does It Work?<\/h2>\n\n\n\n<p>We clear up common WordPress security myths often raised at Shield, focusing on the tactic known as \u201cSecurity Through Obscurity\u201d and how it\u2019s often used with WordPress.<\/p>\n\n\n\n<p><a href=\"https:\/\/getshieldsecurity.com\/blog\/wordpress-security-through-obscurity\/\" target=\"_blank\" rel=\"noreferrer noopener\">More Info \u2192<\/a><\/p>\n\n\n\n<p>Thanks for reading, and have a wonderful week!<\/p>\n\n\n\n<p><strong>Paul Goodchild<\/strong><br><em>Shield Security for WordPress<\/em><\/p>\n\n\n\n<p><\/p>\n","protected":false},"excerpt":{"rendered":"<p>There&#8217;s a few ultra critical vulnerabilities this week, with some removed from the WP repo. You can check out the upcoming WP virtual conference and uncover the &#8220;Security Through Obscurity&#8221; myth from our blog archive.<\/p>\n","protected":false},"author":27,"featured_media":163832,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"footnotes":""},"categories":[153,201],"tags":[69],"class_list":["post-167566","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-security-wordpress-solutions","category-shieldnotes","tag-security"],"acf":[],"_links":{"self":[{"href":"https:\/\/getshieldsecurity.com\/wp-json\/wp\/v2\/posts\/167566","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/getshieldsecurity.com\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/getshieldsecurity.com\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/getshieldsecurity.com\/wp-json\/wp\/v2\/users\/27"}],"replies":[{"embeddable":true,"href":"https:\/\/getshieldsecurity.com\/wp-json\/wp\/v2\/comments?post=167566"}],"version-history":[{"count":4,"href":"https:\/\/getshieldsecurity.com\/wp-json\/wp\/v2\/posts\/167566\/revisions"}],"predecessor-version":[{"id":167570,"href":"https:\/\/getshieldsecurity.com\/wp-json\/wp\/v2\/posts\/167566\/revisions\/167570"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/getshieldsecurity.com\/wp-json\/wp\/v2\/media\/163832"}],"wp:attachment":[{"href":"https:\/\/getshieldsecurity.com\/wp-json\/wp\/v2\/media?parent=167566"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/getshieldsecurity.com\/wp-json\/wp\/v2\/categories?post=167566"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/getshieldsecurity.com\/wp-json\/wp\/v2\/tags?post=167566"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}