{"id":168640,"date":"2025-05-05T14:20:16","date_gmt":"2025-05-05T13:20:16","guid":{"rendered":"https:\/\/getshieldsecurity.com\/?p=168640"},"modified":"2025-05-05T14:20:16","modified_gmt":"2025-05-05T13:20:16","slug":"shieldnotes-64","status":"publish","type":"post","link":"https:\/\/getshieldsecurity.com\/blog\/shieldnotes-64\/","title":{"rendered":"Stay Alert: Latest Plugin Risks and WordPress Pingbacks Security"},"content":{"rendered":"\n<p>SureTriggers is back to the high-risk radar after a quiet week, with other plugins on the horizon. For those dealing with disabling WordPress pingbacks, don\u2019t miss our blog for the full guide.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">#1 &#8211; Security Risks in Popular Plugins<\/h2>\n\n\n\n<p>Top plugins, top risks\u2014make sure you\u2019re using the latest version.<\/p>\n\n\n\n<p><strong><a href=\"https:\/\/patchstack.com\/database\/wordpress\/plugin\/suretriggers\/vulnerability\/wordpress-suretriggers-1-0-82-privilege-escalation-vulnerability\" target=\"_blank\" rel=\"noreferrer noopener\">SureTriggers Plugin<\/a><\/strong><br>Privilege Escalation; <strong>9.8<\/strong>\/10; Update to v1.0.83+<\/p>\n\n\n\n<p><strong><a href=\"https:\/\/patchstack.com\/database\/wordpress\/plugin\/sitepress-multilingual-cms\/vulnerability\/wordpress-wpml-multilingual-cms-plugin-3-6-0-4-7-3-authenticated-contributor-stored-cross-site-scripting-via-wpml-language-switcher-shortcode\" target=\"_blank\" rel=\"noreferrer noopener\">Multilingual CMS Plugin<\/a><\/strong><br>XSS; 6.5\/10; Update to v4.7.4+<\/p>\n\n\n\n<p><strong><a href=\"https:\/\/patchstack.com\/database\/wordpress\/plugin\/sureforms\/vulnerability\/wordpress-sureforms-plugin-1-4-4-admin-stored-xss-vulnerability\" target=\"_blank\" rel=\"noreferrer noopener\">SureForms Plugin<\/a><\/strong><br>XSS; 5.9\/10; Update to v1.4.4+<\/p>\n\n\n\n<p><strong><a href=\"https:\/\/patchstack.com\/database\/wordpress\/plugin\/wp-statistics\/vulnerability\/wordpress-wp-statistics-the-most-popular-privacy-friendly-analytics-plugin-plugin-14-13-3-missing-authorization-to-authenticated-subscriber-arbitrary-plugin-settings-update-vulnerability\" target=\"_blank\" rel=\"noreferrer noopener\">WP Statistics Plugin<\/a><\/strong><br>Broken Access Control; 5.4\/10; Update to v14.13.4+<\/p>\n\n\n\n<p><strong>Editor Comment<\/strong><br>It&#8217;s worth taking a few minutes each week to <a href=\"https:\/\/getshieldsecurity.com\/blog\/wordpress-security-vulnerabilities\/\" target=\"_blank\" rel=\"noreferrer noopener\">perform a sites review<\/a> to catch issues early and wherever possible, use <a href=\"https:\/\/shsec.io\/lw\" target=\"_blank\" rel=\"noreferrer noopener\">ShieldPRO&#8217;s auto-upgrade<\/a> feature for vulnerable plugins.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">#2 &#8211; High Security Risks in Less Popular Plugins<\/h2>\n\n\n\n<p>Fewer users, yet bigger risks\u2014don\u2019t overlook these plugins.<\/p>\n\n\n\n<p><strong><a href=\"https:\/\/patchstack.com\/database\/wordpress\/plugin\/otpless\/vulnerability\/wordpress-otp-less-one-tap-sign-in-plugin-2-0-14-2-0-59-unauthenticated-arbitrary-email-update-to-account-takeover-privilege-escalation-vulnerability\" target=\"_blank\" rel=\"noreferrer noopener\">OTP-less one tap Sign in Plugin<\/a><\/strong><br>Privilege Escalation; <strong>9.8<\/strong>\/10; Removed from wp.org; No fix; Remove\/or replace.<\/p>\n\n\n\n<p><strong><a href=\"https:\/\/patchstack.com\/database\/wordpress\/plugin\/ap-plugin-scripteo\/vulnerability\/wordpress-ads-pro-plugin-multi-purpose-wordpress-advertising-manager-plugin-4-88-unauthenticated-sql-injection-vulnerability\" target=\"_blank\" rel=\"noreferrer noopener\">Ads Pro Plugin<\/a><\/strong><br>SQL Injection; <strong>9.3<\/strong>\/10; Update to v4.89+<\/p>\n\n\n\n<p><strong><a href=\"https:\/\/patchstack.com\/database\/wordpress\/plugin\/ultimate-woocommerce-auction-pro\/vulnerability\/wordpress-ultimate-auction-pro-plugin-1-5-2-unauthenticated-sql-injection-via-auction-id-vulnerability\" target=\"_blank\" rel=\"noreferrer noopener\">Ultimate Auction Pro Plugin<\/a><\/strong><br>SQL Injection; <strong>9.3<\/strong>\/10; Update to v1.5.3+<\/p>\n\n\n\n<p><strong><a href=\"https:\/\/patchstack.com\/database\/wordpress\/plugin\/scw-seat-reservation\/vulnerability\/wordpress-advance-seat-reservation-management-for-woocommerce-plugin-3-3-unauthenticated-sql-injection-vulnerability\" target=\"_blank\" rel=\"noreferrer noopener\">Advance Seat Reservation Management for WooCommerce Plugin<\/a><\/strong><br>SQL Injection; <strong>9.3<\/strong>\/10; Update to v3.4+<\/p>\n\n\n\n<p><strong>Editor Comment<\/strong><br>It&#8217;s worth taking a few minutes each week to <a href=\"https:\/\/getshieldsecurity.com\/blog\/wordpress-security-vulnerabilities\/\" target=\"_blank\" rel=\"noreferrer noopener\">perform a sites review<\/a> to catch issues early and wherever possible, use <a href=\"https:\/\/shsec.io\/lw\" target=\"_blank\" rel=\"noreferrer noopener\">ShieldPRO&#8217;s auto-upgrade<\/a> feature for vulnerable plugins.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">#3 &#8211; Our blog: Disable Pingbacks on WordPress<\/h2>\n\n\n\n<p>Pingbacks might seem easy to turn off, but WordPress doesn\u2019t fully disable them by default. That leaves your site open to attacks. We guide you through a simple shutdown.<\/p>\n\n\n\n<p><a href=\"https:\/\/getshieldsecurity.com\/blog\/disable-pingback-wordpress\/\" target=\"_blank\" rel=\"noreferrer noopener\">More Info \u2192<\/a><\/p>\n\n\n\n<p>Thanks for reading, and have a wonderful week!<\/p>\n\n\n\n<p><strong>Paul Goodchild<\/strong><br><em>Shield Security for WordPress<\/em><\/p>\n","protected":false},"excerpt":{"rendered":"<p>SureTriggers is back to the high-risk radar after a quiet week, with other plugins on the horizon. For those dealing with disabling WordPress pingbacks, don\u2019t miss our blog for the full guide.<\/p>\n","protected":false},"author":27,"featured_media":163832,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"footnotes":""},"categories":[153,201],"tags":[69],"class_list":["post-168640","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-security-wordpress-solutions","category-shieldnotes","tag-security"],"acf":[],"_links":{"self":[{"href":"https:\/\/getshieldsecurity.com\/wp-json\/wp\/v2\/posts\/168640","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/getshieldsecurity.com\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/getshieldsecurity.com\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/getshieldsecurity.com\/wp-json\/wp\/v2\/users\/27"}],"replies":[{"embeddable":true,"href":"https:\/\/getshieldsecurity.com\/wp-json\/wp\/v2\/comments?post=168640"}],"version-history":[{"count":10,"href":"https:\/\/getshieldsecurity.com\/wp-json\/wp\/v2\/posts\/168640\/revisions"}],"predecessor-version":[{"id":168655,"href":"https:\/\/getshieldsecurity.com\/wp-json\/wp\/v2\/posts\/168640\/revisions\/168655"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/getshieldsecurity.com\/wp-json\/wp\/v2\/media\/163832"}],"wp:attachment":[{"href":"https:\/\/getshieldsecurity.com\/wp-json\/wp\/v2\/media?parent=168640"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/getshieldsecurity.com\/wp-json\/wp\/v2\/categories?post=168640"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/getshieldsecurity.com\/wp-json\/wp\/v2\/tags?post=168640"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}