{"id":170466,"date":"2025-09-15T15:21:39","date_gmt":"2025-09-15T14:21:39","guid":{"rendered":"https:\/\/getshieldsecurity.com\/?p=170466"},"modified":"2025-09-15T15:21:40","modified_gmt":"2025-09-15T14:21:40","slug":"shieldnotes-74","status":"publish","type":"post","link":"https:\/\/getshieldsecurity.com\/blog\/shieldnotes-74\/","title":{"rendered":"Critical Vulnerabilities in Ninja Forms, The Events Calendar; &amp; Safe Theme Update Strategies"},"content":{"rendered":"\n<p>High-risk vulnerabilities hit Ninja Forms and The Events Calendar, impacting more than a million sites, with several other widely-used plugins close behind.<\/p>\n\n\n\n<p>Stay protected and preserve your tweaks with our safe theme update strategies. (see below)<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">#1 &#8211; High Security Risks in Popular Plugins<\/h2>\n\n\n\n<p>Over 1.3 million sites are vulnerable with extremely high-severity risk. Update these plugins ASAP.<\/p>\n\n\n\n<p><strong><a href=\"https:\/\/patchstack.com\/database\/wordpress\/plugin\/ninja-forms\/vulnerability\/wordpress-ninja-forms-plugin-3-11-1-unauthenticated-php-object-injection-vulnerability\" target=\"_blank\" rel=\"noreferrer noopener\">Ninja Forms Plugin<\/a><\/strong><br>PHP Object Injection; <strong>9.8<\/strong>\/10; Update to v3.11.1+<\/p>\n\n\n\n<p><strong><a href=\"https:\/\/patchstack.com\/database\/wordpress\/plugin\/the-events-calendar\/vulnerability\/wordpress-the-events-calendar-plugin-6-15-1-unauthenticated-sql-injection-vulnerability\" target=\"_blank\" rel=\"noreferrer noopener\">The Events Calendar Plugin<\/a><\/strong><br>SQL Injection; <strong>9.3<\/strong>\/10; Update to v6.15.1.1+<br><br><strong>Editor Comment<\/strong><br>It&#8217;s worth taking a few minutes each week to <a href=\"https:\/\/getshieldsecurity.com\/blog\/wordpress-security-vulnerabilities\/\" target=\"_blank\" rel=\"noreferrer noopener\">perform a sites review<\/a> to catch issues early and wherever possible, use <a href=\"https:\/\/shsec.io\/lw\" target=\"_blank\" rel=\"noreferrer noopener\">ShieldPRO&#8217;s auto-upgrade<\/a> feature for vulnerable plugins.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">#2 &#8211; Lower Security Risks in Popular Plugins<\/h2>\n\n\n\n<p>These plugins power 400,000+ sites, putting many at risk. Update yours.<\/p>\n\n\n\n<p><strong><a href=\"https:\/\/patchstack.com\/database\/wordpress\/plugin\/tutor\/vulnerability\/wordpress-tutor-lms-plugin-3-7-4-sql-injection-vulnerability\" target=\"_blank\" rel=\"noreferrer noopener\">Tutor LMS Plugin<\/a><\/strong><br>SQL Injection; 7.6\/10; Update to v3.8.0+<\/p>\n\n\n\n<p><strong><a href=\"https:\/\/patchstack.com\/database\/wordpress\/plugin\/wp-all-import\/vulnerability\/wordpress-wp-all-import-plugin-3-9-3-authenticated-admin-limited-unsafe-file-upload-vulnerability\" target=\"_blank\" rel=\"noreferrer noopener\">WP All Import Plugin<\/a><\/strong><br>Arbitrary File Upload; 7.2\/10; Update to v3.9.4+<\/p>\n\n\n\n<p><strong><a href=\"https:\/\/patchstack.com\/database\/wordpress\/plugin\/woolentor-addons\/vulnerability\/wordpress-shoplentor-plugin-3-2-0-cross-site-scripting-xss-vulnerability\" target=\"_blank\" rel=\"noreferrer noopener\">ShopLentor Plugin<\/a><\/strong><br>XSS; 6.5\/10; Update to v3.2.1+<\/p>\n\n\n\n<p><strong><a href=\"https:\/\/patchstack.com\/database\/wordpress\/plugin\/nitropack\/vulnerability\/wordpress-nitropack-plugin-1-18-4-missing-authorization-to-authenticated-subscriber-limited-settings-update-via-nitropack-set-compression-ajax-function-vulnerability\" target=\"_blank\" rel=\"noreferrer noopener\">NitroPack Plugin<\/a><\/strong><br>Broken Access Control; 5.4\/10; Update to v1.18.5+<\/p>\n\n\n\n<p><strong>Editor Comment<\/strong><br>It&#8217;s worth taking a few minutes each week to <a href=\"https:\/\/getshieldsecurity.com\/blog\/wordpress-security-vulnerabilities\/\" target=\"_blank\" rel=\"noreferrer noopener\">perform a sites review<\/a> to catch issues early and wherever possible, use <a href=\"https:\/\/shsec.io\/lw\" target=\"_blank\" rel=\"noreferrer noopener\">ShieldPRO&#8217;s auto-upgrade<\/a> feature for vulnerable plugins.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">#3 &#8211; High Security Risks in Less Popular Plugins and Themes<\/h2>\n\n\n\n<p>Hidden from the spotlight but critical\u2014one theme vulnerability scores 10\/10 and remains unpatched.<\/p>\n\n\n\n<p><strong><a href=\"https:\/\/patchstack.com\/database\/wordpress\/theme\/doccure\/vulnerability\/wordpress-doccure-plugin-1-4-8-unauthenticated-arbitrary-file-upload-vulnerability\" target=\"_blank\" rel=\"noreferrer noopener\">Doccure Theme<\/a><\/strong><br>Arbitrary File Upload; <strong>10<\/strong>\/10; No fix; Remove\/or replace.<\/p>\n\n\n\n<p><strong><a href=\"https:\/\/patchstack.com\/database\/wordpress\/theme\/mow\/vulnerability\/wordpress-mow-theme-4-10-cross-site-request-forgery-csrf-vulnerability\" target=\"_blank\" rel=\"noreferrer noopener\">Mow Theme<\/a><\/strong><br>CSRF; <strong>9.6<\/strong>\/10; Update to v4.11+<\/p>\n\n\n\n<p><strong><a href=\"https:\/\/patchstack.com\/database\/wordpress\/plugin\/responsive-filterable-portfolio\/vulnerability\/wordpress-responsive-filterable-portfolio-plugin-1-0-24-authenticated-admin-arbitrary-file-upload-vulnerability\" target=\"_blank\" rel=\"noreferrer noopener\">Responsive Filterable Portfolio Plugin<\/a><\/strong><br>Arbitrary File Upload; <strong>9.1<\/strong>\/10; Update to v1.0.25+<\/p>\n\n\n\n<p><strong>Editor Comment<\/strong><br>It&#8217;s worth taking a few minutes each week to <a href=\"https:\/\/getshieldsecurity.com\/blog\/wordpress-security-vulnerabilities\/\" target=\"_blank\" rel=\"noreferrer noopener\">perform a sites review<\/a> to catch issues early and wherever possible, use <a href=\"https:\/\/shsec.io\/lw\" target=\"_blank\" rel=\"noreferrer noopener\">ShieldPRO&#8217;s auto-upgrade<\/a> feature for vulnerable plugins.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">#4 &#8211; Our blog: How to Update WordPress Theme Without Losing Changes<\/h2>\n\n\n\n<p>Updating your WordPress theme doesn\u2019t have to mean losing your hard work. With the right strategy, your site can stay compatible, fast, and bug-free while preserving all your customisations.<\/p>\n\n\n\n<p><a href=\"https:\/\/getshieldsecurity.com\/blog\/how-to-update-wordpress-theme\/\" data-type=\"link\" data-id=\"https:\/\/getshieldsecurity.com\/blog\/how-to-update-wordpress-theme\/\" target=\"_blank\" rel=\"noreferrer noopener\">More Info \u2192<\/a><\/p>\n\n\n\n<p>Thanks for reading, and have a wonderful week!<\/p>\n\n\n\n<p><strong>Paul Goodchild<\/strong><br><em>Shield Security for WordPres<\/em>s<\/p>\n","protected":false},"excerpt":{"rendered":"<p>High-risk vulnerabilities hit Ninja Forms and The Events Calendar, impacting more than a million sites, with several other widely-used plugins close behind. Stay protected and preserve your tweaks with our safe theme update strategies.<\/p>\n","protected":false},"author":27,"featured_media":163832,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"footnotes":""},"categories":[153,201],"tags":[69],"class_list":["post-170466","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-security-wordpress-solutions","category-shieldnotes","tag-security"],"acf":[],"_links":{"self":[{"href":"https:\/\/getshieldsecurity.com\/wp-json\/wp\/v2\/posts\/170466","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/getshieldsecurity.com\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/getshieldsecurity.com\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/getshieldsecurity.com\/wp-json\/wp\/v2\/users\/27"}],"replies":[{"embeddable":true,"href":"https:\/\/getshieldsecurity.com\/wp-json\/wp\/v2\/comments?post=170466"}],"version-history":[{"count":3,"href":"https:\/\/getshieldsecurity.com\/wp-json\/wp\/v2\/posts\/170466\/revisions"}],"predecessor-version":[{"id":170469,"href":"https:\/\/getshieldsecurity.com\/wp-json\/wp\/v2\/posts\/170466\/revisions\/170469"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/getshieldsecurity.com\/wp-json\/wp\/v2\/media\/163832"}],"wp:attachment":[{"href":"https:\/\/getshieldsecurity.com\/wp-json\/wp\/v2\/media?parent=170466"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/getshieldsecurity.com\/wp-json\/wp\/v2\/categories?post=170466"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/getshieldsecurity.com\/wp-json\/wp\/v2\/tags?post=170466"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}