{"id":167680,"date":"2025-03-12T13:05:40","date_gmt":"2025-03-12T13:05:40","guid":{"rendered":"https:\/\/getshieldsecurity.com\/?p=167680"},"modified":"2025-03-12T13:07:01","modified_gmt":"2025-03-12T13:07:01","slug":"shieldnotes-56","status":"publish","type":"post","link":"https:\/\/getshieldsecurity.com\/blog\/shieldnotes-56\/","title":{"rendered":"Weekly Vulnerabilities; Trust-Building and Performance Strategies"},"content":{"rendered":"\n<p>This is a fresh roundup of plugin and theme vulnerabilities with key maintenance steps to keep your WordPress site secure, reliable, and performing at its best.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">#1 &#8211; Security Risks in Popular Plugins<\/h2>\n\n\n\n<p>These plugins aren&#8217;t heavily affected, but their popularity makes them important to monitor.<\/p>\n\n\n\n<p><strong><a href=\"https:\/\/patchstack.com\/database\/wordpress\/plugin\/post-smtp\/vulnerability\/wordpress-post-smtp-plugin-3-1-2-authenticated-administrator-sql-injection-via-columns-parameter-vulnerability\" target=\"_blank\" rel=\"noreferrer noopener\">Post SMTP Plugin<\/a><\/strong><br>SQL Injection; 7.6\/10; Update to v3.1.3+<\/p>\n\n\n\n<p><strong><a href=\"https:\/\/patchstack.com\/database\/wordpress\/plugin\/the-plus-addons-for-elementor-page-builder\/vulnerability\/wordpress-the-plus-addons-for-elementor-page-builder-lite-plugin-6-2-2-authenticated-contributor-stored-cross-site-scripting-via-multiple-widgets-vulnerability\" target=\"_blank\" rel=\"noreferrer noopener\">The Plus Addons for Elementor Page Builder Lite Plugin<\/a><\/strong><br>XSS; 6.5\/10; Update to v6.2.3+<\/p>\n\n\n\n<p><strong><a href=\"https:\/\/patchstack.com\/database\/wordpress\/plugin\/foogallery\/vulnerability\/wordpress-foogallery-plugin-2-4-29-authenticated-custom-stored-cross-site-scripting-via-album-title-size-vulnerability\" target=\"_blank\" rel=\"noreferrer noopener\">FooGallery Plugin<\/a><\/strong><br>XSS; 6.5\/10; Update to v2.4.30+<\/p>\n\n\n\n<p><strong><a href=\"https:\/\/patchstack.com\/database\/wordpress\/plugin\/file-manager-advanced\/vulnerability\/wordpress-advanced-file-manager-plugin-5-2-14-authenticated-subscriber-stored-cross-site-scripting-via-svg-file-upload-vulnerability\" target=\"_blank\" rel=\"noreferrer noopener\">Advanced File Manager Plugin<\/a><\/strong><br>XSS; 6.5\/10; Update to v5.3.0+<\/p>\n\n\n\n<p><strong><a href=\"https:\/\/patchstack.com\/database\/wordpress\/plugin\/download-manager\/vulnerability\/wordpress-download-manager-plugin-3-3-06-unauthenticated-information-disclosure-via-unprotected-directory-vulnerability\" target=\"_blank\" rel=\"noreferrer noopener\">Download Manager Plugin<\/a><\/strong><br>Sensitive Data Exposure; 5.3\/10; Update to v3.3.07+<\/p>\n\n\n\n<p><strong>Editor Comment<\/strong><br>It&#8217;s worth taking a few minutes each week to <a href=\"https:\/\/getshieldsecurity.com\/blog\/wordpress-security-vulnerabilities\/\" target=\"_blank\" rel=\"noreferrer noopener\">perform a sites review<\/a> to catch issues early and wherever possible, use <a href=\"https:\/\/shsec.io\/lw\" target=\"_blank\" rel=\"noreferrer noopener\">ShieldPRO&#8217;s auto-upgrade<\/a> feature for vulnerable plugins.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">#2 &#8211; Security Risks in Less Popular Plugins &amp; Themes<\/h2>\n\n\n\n<p>These plugins\/themes carry high security risks, especially 2 that remain unaddressed.<\/p>\n\n\n\n<p><strong><a href=\"https:\/\/patchstack.com\/database\/wordpress\/plugin\/javo-core\/vulnerability\/wordpress-javo-core-plugin-3-0-0-080-unauthenticated-privilege-escalation-in-ajax-signup-vulnerability\" target=\"_blank\" rel=\"noreferrer noopener\">Javo Core Plugin<\/a><\/strong><br>Privilege Escalation; <strong>9.8<\/strong>\/10; Update to v3.0.0.266+<\/p>\n\n\n\n<p><a href=\"https:\/\/patchstack.com\/database\/wordpress\/plugin\/iwjob\/vulnerability\/wordpress-inwave-jobs-plugin-3-5-1-unauthenticated-privilege-escalation-via-password-reset-vulnerability\" target=\"_blank\" rel=\"noreferrer noopener\">I<strong>nWave Jobs Plugin<\/strong><\/a><br>Privilege Escalation; <strong>9.8<\/strong>\/10; Removed from wp.org; No fix; Remove\/or replace.<\/p>\n\n\n\n<p><strong><a href=\"https:\/\/patchstack.com\/database\/wordpress\/theme\/golo\/vulnerability\/wordpress-golo-theme-1-6-10-missing-authorization-to-privilege-escalation-via-unauthenticated-arbitrary-user-password-change-vulnerability\" target=\"_blank\" rel=\"noreferrer noopener\">Golo Theme<\/a><\/strong><br>Broken Access Control; <strong>9.8<\/strong>\/10; Update to v1.6.11+<\/p>\n\n\n\n<p><strong><a href=\"https:\/\/patchstack.com\/database\/wordpress\/plugin\/wpcom-member\/vulnerability\/wordpress-wpcom-member-plugin-1-7-5-authentication-bypass-via-user-phone-vulnerability\" target=\"_blank\" rel=\"noreferrer noopener\">WPCOM Member Plugin<\/a><\/strong><br>Privilege Escalation; <strong>9.8<\/strong>\/10; Update to v1.7.6+<\/p>\n\n\n\n<p><strong><a href=\"https:\/\/patchstack.com\/database\/wordpress\/plugin\/wp-recall\/vulnerability\/wordpress-wp-recall-plugin-16-26-10-unauthenticated-sql-injection-vulnerability\" target=\"_blank\" rel=\"noreferrer noopener\">WP-Recall Plugin<\/a><\/strong><br>SQL Injection; <strong>9.3<\/strong>\/10; Update to v16.26.12+<\/p>\n\n\n\n<p><strong><a href=\"https:\/\/patchstack.com\/database\/wordpress\/plugin\/miniorange-login-openid-pro\/vulnerability\/wordpress-miniorange-social-login-and-register-pro-addon-plugin-200-3-9-authentication-bypass-vulnerability\" target=\"_blank\" rel=\"noreferrer noopener\">miniOrange Social Login and Register Pro Addon Plugin<\/a><\/strong><br>Broken Authentication; 8.1\/10; No fix; Remove\/or replace.<\/p>\n\n\n\n<p><strong>Editor Comment<\/strong><br>It&#8217;s worth taking a few minutes each week to <a href=\"https:\/\/getshieldsecurity.com\/blog\/wordpress-security-vulnerabilities\/\" target=\"_blank\" rel=\"noreferrer noopener\">perform a sites review<\/a> to catch issues early and wherever possible, use <a href=\"https:\/\/shsec.io\/lw\" target=\"_blank\" rel=\"noreferrer noopener\">ShieldPRO&#8217;s auto-upgrade<\/a> feature for vulnerable plugins.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">#3 &#8211; Our blog: Essential Tips for WordPress Website Maintenance<\/h2>\n\n\n\n<p>Visitor trust relies on the reliability and performance of your WordPress site. Regular maintenance is key to keeping it secure and running smoothly, going beyond bug fixes and updates. It ensures a smooth user experience and protects both you and your audience online.<\/p>\n\n\n\n<p><a href=\"https:\/\/getshieldsecurity.com\/blog\/wordpress-website-maintenance\" target=\"_blank\" rel=\"noreferrer noopener\">More Info \u2192<\/a><\/p>\n\n\n\n<p>Thanks for reading, and have a wonderful week!<\/p>\n\n\n\n<p><strong>Paul Goodchild<\/strong><br><em>Shield Security for WordPress<\/em><\/p>\n","protected":false},"excerpt":{"rendered":"<p>This is a fresh roundup of plugin and theme vulnerabilities with key maintenance steps to keep your WordPress site secure, reliable, and performing at its best.<\/p>\n","protected":false},"author":27,"featured_media":163832,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"footnotes":""},"categories":[153,201],"tags":[69],"class_list":["post-167680","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-security-wordpress-solutions","category-shieldnotes","tag-security"],"acf":[],"_links":{"self":[{"href":"https:\/\/getshieldsecurity.com\/wp-json\/wp\/v2\/posts\/167680","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/getshieldsecurity.com\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/getshieldsecurity.com\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/getshieldsecurity.com\/wp-json\/wp\/v2\/users\/27"}],"replies":[{"embeddable":true,"href":"https:\/\/getshieldsecurity.com\/wp-json\/wp\/v2\/comments?post=167680"}],"version-history":[{"count":13,"href":"https:\/\/getshieldsecurity.com\/wp-json\/wp\/v2\/posts\/167680\/revisions"}],"predecessor-version":[{"id":167712,"href":"https:\/\/getshieldsecurity.com\/wp-json\/wp\/v2\/posts\/167680\/revisions\/167712"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/getshieldsecurity.com\/wp-json\/wp\/v2\/media\/163832"}],"wp:attachment":[{"href":"https:\/\/getshieldsecurity.com\/wp-json\/wp\/v2\/media?parent=167680"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/getshieldsecurity.com\/wp-json\/wp\/v2\/categories?post=167680"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/getshieldsecurity.com\/wp-json\/wp\/v2\/tags?post=167680"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}