{"id":170710,"date":"2026-01-19T12:58:00","date_gmt":"2026-01-19T12:58:00","guid":{"rendered":"https:\/\/getshieldsecurity.com\/?p=170710"},"modified":"2026-01-19T12:58:01","modified_gmt":"2026-01-19T12:58:01","slug":"shieldnotes-91","status":"publish","type":"post","link":"https:\/\/getshieldsecurity.com\/blog\/shieldnotes-91\/","title":{"rendered":"All In One SEO and Other Severe Risks; &amp; WordPress SQL injection Defense"},"content":{"rendered":"\n<p>Security is in focus again, with high-severity vulnerabilities in Supreme Modules Lite and a new All In One SEO risk impacting millions. Highlights from our SQL injection prevention blog round out this week\u2019s update.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">#1 &#8211; Security Risks in Popular Plugins<\/h2>\n\n\n\n<p>These plugins are widely used, and the first one on the list is the most critical, with a <em><strong>9.1<\/strong>\/10<\/em> severity score. Update as soon as possible if you have them installed.<\/p>\n\n\n\n<p><strong><a href=\"https:\/\/patchstack.com\/database\/wordpress\/plugin\/supreme-modules-for-divi\/vulnerability\/wordpress-supreme-modules-lite-plugin-2-5-62-authenticated-author-arbitrary-file-upload-via-json-upload-bypass-vulnerability\" target=\"_blank\" rel=\"noreferrer noopener\">Supreme Modules Lite Plugin<\/a><br><\/strong>Arbitrary File Upload; <strong>9.1<\/strong>\/10; Update to v2.5.63+<\/p>\n\n\n\n<p><strong><a href=\"https:\/\/patchstack.com\/database\/wordpress\/plugin\/advanced-ads\/vulnerability\/wordpress-advanced-ads-ad-manager-adsense-plugin-2-0-15-authenticated-admin-sql-injection-vulnerability\" target=\"_blank\" rel=\"noreferrer noopener\">Advanced Ads Plugin<\/a><br><\/strong>SQL Injection; 7.6\/10; Update to v2.0.16+<\/p>\n\n\n\n<p><strong><a href=\"https:\/\/patchstack.com\/database\/wordpress\/plugin\/youtube-feed-pro\/vulnerability\/wordpress-feeds-for-youtube-pro-plugin-2-6-0-unauthenticated-arbitrary-file-read-via-path-traversal-vulnerability\" target=\"_blank\" rel=\"noreferrer noopener\">YouTube Feed Pro Plugin<\/a><br><\/strong>Arbitrary File Upload; 7.5\/10; Update to v2.6.1+<\/p>\n\n\n\n<p><strong><a href=\"https:\/\/patchstack.com\/database\/wordpress\/plugin\/breeze\/vulnerability\/wordpress-breeze-plugin-2-2-21-broken-access-control-vulnerability\" target=\"_blank\" rel=\"noreferrer noopener\">Breeze Plugin<\/a><br><\/strong>Broken Access Control; 5.3\/10; Update to v2.2.22+<\/p>\n\n\n\n<p><strong><a href=\"https:\/\/patchstack.com\/database\/wordpress\/plugin\/all-in-one-seo-pack\/vulnerability\/wordpress-all-in-one-seo-powerful-seo-plugin-to-boost-seo-rankings-increase-traffic-plugin-4-9-2-missing-authorization-to-authenticated-contributor-ai-access-token-and-credit-disclosure-vulnerability\" target=\"_blank\" rel=\"noreferrer noopener\">All In One SEO Pack Plugin<\/a><br><\/strong>Broken Access Control; 4.3\/10; Update to v4.9.3+<\/p>\n\n\n\n<p><strong>Editor Comment<\/strong><br>It&#8217;s worth taking a few minutes each week to <a href=\"https:\/\/getshieldsecurity.com\/blog\/wordpress-security-vulnerabilities\/\" target=\"_blank\" rel=\"noreferrer noopener\">perform a sites review<\/a> to catch issues early and wherever possible, use <a href=\"https:\/\/shsec.io\/lw\" target=\"_blank\" rel=\"noreferrer noopener\">ShieldPRO&#8217;s auto-upgrade<\/a> feature for vulnerable plugins.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">#2 &#8211; High Security Risks in Less Popular Plugins and Themes<\/h2>\n\n\n\n<p>These components have smaller install counts but very high severity scores, which makes them critical on any site where they are present.<\/p>\n\n\n\n<p><strong><a href=\"https:\/\/patchstack.com\/database\/wordpress\/plugin\/modular-connector\/vulnerability\/wordpress-modular-ds-monitor-update-and-backup-multiple-websites-plugin-2-5-1-privilege-escalation-vulnerability\" target=\"_blank\" rel=\"noreferrer noopener\">Modular DS Plugin<\/a><br><\/strong>Privilege Escalation; <strong>10<\/strong>\/10; Update to v2.5.2+<\/p>\n\n\n\n<p><strong><a href=\"https:\/\/patchstack.com\/database\/wordpress\/theme\/blogzee\/vulnerability\/wordpress-blogzee-theme-1-0-5-arbitrary-file-upload-vulnerability\" target=\"_blank\" rel=\"noreferrer noopener\">Blogzee Theme<\/a><br><\/strong>Arbitrary File Upload; <strong>9.9<\/strong>\/10; No fix; Remove\/or replace.<\/p>\n\n\n\n<p><strong><a href=\"https:\/\/patchstack.com\/database\/wordpress\/plugin\/custom-registration-form-builder-with-submission-manager\/vulnerability\/wordpress-registrationmagic-plugin-6-0-7-1-privilege-escalation-via-admin-order-vulnerability\" target=\"_blank\" rel=\"noreferrer noopener\">RegistrationMagic Plugin<\/a><br><\/strong>Privilege Escalation; <strong>9.8<\/strong>\/10; Update to v6.0.7.2+<\/p>\n\n\n\n<p><strong><a href=\"https:\/\/patchstack.com\/database\/wordpress\/plugin\/simply-schedule-appointments\/vulnerability\/wordpress-simply-schedule-appointments-plugin-1-6-9-9-unauthenticated-sql-injection-via-order-and-append-where-sql-parameters-vulnerability\" target=\"_blank\" rel=\"noreferrer noopener\">Simply Schedule Appointments Plugin<\/a><br><\/strong>SQL Injection; <strong>9.3<\/strong>\/10; Update to v1.6.9.13+<\/p>\n\n\n\n<p><strong>Editor Comment<\/strong><br>It&#8217;s worth taking a few minutes each week to <a href=\"https:\/\/getshieldsecurity.com\/blog\/wordpress-security-vulnerabilities\/\" target=\"_blank\" rel=\"noreferrer noopener\">perform a sites review<\/a> to catch issues early and wherever possible, use <a href=\"https:\/\/shsec.io\/lw\" target=\"_blank\" rel=\"noreferrer noopener\">ShieldPRO&#8217;s auto-upgrade<\/a> feature for vulnerable plugins.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">#3 &#8211; Our blog: Prevent SQL Injection in WordPress<\/h2>\n\n\n\n<p>SQL injections are a serious threat that can severely impact WordPress sites. We cut through the technical jargon and provide clear, practical guidance to help you protect your site, regardless of your level of technical experience.<\/p>\n\n\n\n<p><a href=\"https:\/\/getshieldsecurity.com\/blog\/sql-injection-wordpress\/\" data-type=\"link\" data-id=\"https:\/\/getshieldsecurity.com\/blog\/sql-injection-wordpress\/\" target=\"_blank\" rel=\"noreferrer noopener\">More Info \u2192<\/a><\/p>\n\n\n\n<p>Thanks for reading, and have a wonderful week!<\/p>\n\n\n\n<p><strong>Paul Goodchild<\/strong><br><em>Shield Security for WordPres<\/em>s<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Security is in focus again, with high-severity vulnerabilities in Supreme Modules Lite and a new All In One SEO risk impacting millions. Highlights from our SQL injection prevention blog round out this week\u2019s update.<\/p>\n","protected":false},"author":27,"featured_media":163832,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"footnotes":""},"categories":[153,201],"tags":[69],"class_list":["post-170710","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-security-wordpress-solutions","category-shieldnotes","tag-security"],"acf":[],"_links":{"self":[{"href":"https:\/\/getshieldsecurity.com\/wp-json\/wp\/v2\/posts\/170710","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/getshieldsecurity.com\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/getshieldsecurity.com\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/getshieldsecurity.com\/wp-json\/wp\/v2\/users\/27"}],"replies":[{"embeddable":true,"href":"https:\/\/getshieldsecurity.com\/wp-json\/wp\/v2\/comments?post=170710"}],"version-history":[{"count":2,"href":"https:\/\/getshieldsecurity.com\/wp-json\/wp\/v2\/posts\/170710\/revisions"}],"predecessor-version":[{"id":170712,"href":"https:\/\/getshieldsecurity.com\/wp-json\/wp\/v2\/posts\/170710\/revisions\/170712"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/getshieldsecurity.com\/wp-json\/wp\/v2\/media\/163832"}],"wp:attachment":[{"href":"https:\/\/getshieldsecurity.com\/wp-json\/wp\/v2\/media?parent=170710"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/getshieldsecurity.com\/wp-json\/wp\/v2\/categories?post=170710"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/getshieldsecurity.com\/wp-json\/wp\/v2\/tags?post=170710"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}