{"id":170797,"date":"2026-03-16T13:50:59","date_gmt":"2026-03-16T13:50:59","guid":{"rendered":"https:\/\/getshieldsecurity.com\/?p=170797"},"modified":"2026-03-16T13:51:00","modified_gmt":"2026-03-16T13:51:00","slug":"shieldnotes-99","status":"publish","type":"post","link":"https:\/\/getshieldsecurity.com\/blog\/shieldnotes-99\/","title":{"rendered":"WordPress Security Patch, Recurring Plugin Risks &amp; Early Threat Monitoring"},"content":{"rendered":"\n<p>WordPress rolled out a new security patch, but the story doesn\u2019t end there \u2014 recurring vulnerabilities continue to affect popular plugins, including the critical MetForm Pro with no fix yet. Monitor your site for suspicious activity (details below).<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">#1 &#8211; WordPress Core Vulnerability<\/h2>\n\n\n\n<p>WordPress first released update 6.9.2 to address security issues, but it caused some sites to crash (show a white screen). They quickly released v6.9.3 to fix that problem. Now they\u2019ve released <strong><em>a final v6.9.4 <\/em><\/strong>because some security issues were still not fully fixed.<\/p>\n\n\n\n<p><strong><a href=\"https:\/\/wordpress.org\/news\/2026\/03\/wordpress-6-9-4-release\/\" target=\"_blank\" rel=\"noreferrer noopener\">WordPress Core<\/a><br><\/strong>XML External Entity (XXE); 6.5\/10; Update to v6.9.4+<strong><br><br>Editor Comment<\/strong><br>It&#8217;s worth taking a few minutes each week to <a href=\"https:\/\/getshieldsecurity.com\/blog\/wordpress-security-vulnerabilities\/\" target=\"_blank\" rel=\"noreferrer noopener\">perform a sites review<\/a> to catch issues early and keep your WordPress installation updated.\u00a0<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">#2 &#8211; High Security Risks in Popular Plugins<\/h2>\n\n\n\n<p>The plugins below suffer from extremely severe security flaws, leaving around 1.5 million sites vulnerable. Please take action ASAP.<\/p>\n\n\n\n<p><strong><a href=\"https:\/\/patchstack.com\/database\/wordpress\/plugin\/google-analytics-dashboard-for-wp\/vulnerability\/wordpress-exactmetrics-plugin-7-1-0-9-0-2-authenticated-custom-improper-privilege-management-to-role-privilege-escalation-via-settings-update-vulnerability\" target=\"_blank\" rel=\"noreferrer noopener\">ExactMetrics Plugin<\/a><br><\/strong>Privilege Escalation; <strong>9.8<\/strong>\/10; Update to v9.0.3+<\/p>\n\n\n\n<p><strong><a href=\"https:\/\/patchstack.com\/database\/wordpress\/plugin\/pojo-accessibility\/vulnerability\/wordpress-ally-web-accessibility-usability-plugin-4-0-3-unauthenticated-sql-injection-via-url-path-vulnerability\" target=\"_blank\" rel=\"noreferrer noopener\">Ally Plugin<\/a><br><\/strong>SQL Injection; <strong>9.3<\/strong>\/10; Update to v4.1.0+<\/p>\n\n\n\n<p><strong><a href=\"https:\/\/patchstack.com\/database\/wordpress\/plugin\/mystickymenu\/vulnerability\/wordpress-my-sticky-bar-plugin-2-8-6-unauthenticated-sql-injection-via-stickymenu-contact-lead-form-action-vulnerability\" target=\"_blank\" rel=\"noreferrer noopener\">My Sticky Bar Plugin<\/a><br><\/strong>SQL Injection; <strong>9.3<\/strong>\/10; Update to v2.8.7+<\/p>\n\n\n\n<p><strong><a href=\"https:\/\/patchstack.com\/database\/wordpress\/plugin\/metform-pro\/vulnerability\/wordpress-metform-pro-plugin-3-9-1-broken-access-control-vulnerability-2\" target=\"_blank\" rel=\"noreferrer noopener\">MetForm Pro Plugin<\/a><br><\/strong>Broken Access Control; <strong>9.1<\/strong>\/10; No fix; Remove\/or replace.<strong><br><br>Editor Comment<\/strong><br>It&#8217;s worth taking a few minutes each week to <a href=\"https:\/\/getshieldsecurity.com\/blog\/wordpress-security-vulnerabilities\/\" target=\"_blank\" rel=\"noreferrer noopener\">perform a sites review<\/a> to catch issues early and wherever possible, use <a href=\"https:\/\/shsec.io\/lw\" target=\"_blank\" rel=\"noreferrer noopener\">ShieldPRO&#8217;s auto-upgrade<\/a> feature for vulnerable plugins.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">#3 &#8211; Other Security Risks in Popular Plugins<\/h2>\n\n\n\n<p>Plugins below have known vulnerabilities affecting millions of sites, possibly including yours, and is actively being exploited. Update now to avoid unnecessary risk.<\/p>\n\n\n\n<p><strong><a href=\"https:\/\/patchstack.com\/database\/wordpress\/plugin\/wp-user-avatar\/vulnerability\/wordpress-profilepress-plugin-4-16-11-insecure-direct-object-reference-to-authenticated-subscriber-arbitrary-subscription-cancellation-expiration-vulnerability\" target=\"_blank\" rel=\"noreferrer noopener\">ProfilePress Plugin<\/a><br><\/strong>IDOR; 8.1\/10; Update to v4.16.12+<\/p>\n\n\n\n<p><strong><a href=\"https:\/\/patchstack.com\/database\/wordpress\/plugin\/the-events-calendar\/vulnerability\/wordpress-the-events-calendar-plugin-6-15-17-authenticated-author-arbitrary-file-read-via-ajax-create-import-vulnerability\" target=\"_blank\" rel=\"noreferrer noopener\">The Events Calendar Plugin<\/a><br><\/strong>Arbitrary File Download; 7.5\/10; Update to v6.15.17.1+<\/p>\n\n\n\n<p><strong><a href=\"https:\/\/patchstack.com\/database\/wordpress\/plugin\/formidable\/vulnerability\/wordpress-formidable-forms-plugin-6-28-missing-authorization-to-unauthenticated-payment-integrity-bypass-via-paymentintent-reuse-vulnerability\" target=\"_blank\" rel=\"noreferrer noopener\">Formidable Forms Plugin<\/a><br><\/strong>Broken Access Control; 7.5\/10; Update to v6.29+<\/p>\n\n\n\n<p><strong><a href=\"https:\/\/patchstack.com\/database\/wordpress\/plugin\/pixelyoursite-pro\/vulnerability\/wordpress-pixelyoursite-pro-plugin-12-4-0-2-unauthenticated-stored-cross-site-scripting-vulnerability\" target=\"_blank\" rel=\"noreferrer noopener\">PixelYourSite PRO Plugin<\/a><br><\/strong>XSS; 7.1\/10; Update to v12.4.0.3+<\/p>\n\n\n\n<p><strong><a href=\"https:\/\/patchstack.com\/database\/wordpress\/plugin\/everest-forms-pro\/vulnerability\/wordpress-everest-forms-pro-plugin-1-9-10-cross-site-scripting-xss-vulnerability\" target=\"_blank\" rel=\"noreferrer noopener\">Everest Forms Pro Plugin<\/a><br><\/strong>XSS; 7.1\/10; No fix; Remove\/or replace.<\/p>\n\n\n\n<p><strong><a href=\"https:\/\/patchstack.com\/database\/wordpress\/plugin\/fusion-core\/vulnerability\/wordpress-avada-core-plugin-5-15-0-cross-site-scripting-xss-vulnerability\" target=\"_blank\" rel=\"noreferrer noopener\">Avada Core Plugin<\/a><br><\/strong>XSS; 6.5\/10; Update to v5.15.0+<\/p>\n\n\n\n<p><strong><a href=\"https:\/\/patchstack.com\/database\/wordpress\/plugin\/mailchimp-for-wp\/vulnerability\/wordpress-mc4wp-mailchimp-for-wordpress-plugin-4-11-1-missing-authorization-to-unauthenticated-arbitrary-subscription-deletion-vulnerability\" target=\"_blank\" rel=\"noreferrer noopener\">MC4WP Plugin<\/a><br><\/strong>Broken Access Control; 6.5\/10; Update to v4.12.0+<\/p>\n\n\n\n<p><strong><a href=\"https:\/\/patchstack.com\/database\/wordpress\/plugin\/gravityforms\/vulnerability\/wordpress-gravity-forms-plugin-2-9-28-1-authenticated-subscriber-stored-cross-site-scripting-via-form-title-vulnerability\" target=\"_blank\" rel=\"noreferrer noopener\">Gravity Forms Plugin<\/a><br><\/strong>XSS; 6.5\/10; Update to v2.9.29+<\/p>\n\n\n\n<p><strong><a href=\"https:\/\/patchstack.com\/database\/wordpress\/plugin\/social-icons-widget-by-wpzoom\/vulnerability\/wordpress-social-icons-widget-block-plugin-4-5-8-missing-authorization-to-authenticated-subscriber-sharing-configuration-creation-vulnerability\" target=\"_blank\" rel=\"noreferrer noopener\">Social Icons Widget &amp; Block by WPZOOM Plugin<\/a><br><\/strong>Broken Access Control; 4.3\/10; Update to v4.5.9+<\/p>\n\n\n\n<p><strong>Editor Comment<\/strong><br>It&#8217;s worth taking a few minutes each week to <a href=\"https:\/\/getshieldsecurity.com\/blog\/wordpress-security-vulnerabilities\/\" target=\"_blank\" rel=\"noreferrer noopener\">perform a sites review<\/a> to catch issues early and wherever possible, use <a href=\"https:\/\/shsec.io\/lw\" target=\"_blank\" rel=\"noreferrer noopener\">ShieldPRO&#8217;s auto-upgrade<\/a> feature for vulnerable plugins.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">#4 &#8211; High Security Risks in Less Popular Plugins<\/h2>\n\n\n\n<p>The plugins below are also under active attack. They may be less common, but their vulnerabilities are especially critical.<\/p>\n\n\n\n<p><strong><a href=\"https:\/\/patchstack.com\/database\/wordpress\/plugin\/divi-booster\/vulnerability\/wordpress-divi-booster-plugin-5-0-2-unauthenticated-php-object-injection-vulnerability\" target=\"_blank\" rel=\"noreferrer noopener\">Divi Booster Plugin<\/a><br><\/strong>PHP Object Injection; <strong>9.8<\/strong>\/10; Update to v5.0.2+<\/p>\n\n\n\n<p><strong><a href=\"https:\/\/patchstack.com\/database\/wordpress\/plugin\/xagio-seo\/vulnerability\/wordpress-xagio-seo-plugin-7-1-0-30-privilege-escalation-vulnerability\" target=\"_blank\" rel=\"noreferrer noopener\">Xagio SEO Plugin<\/a><br><\/strong>Privilege Escalation; <strong>9.8<\/strong>\/10; Update to v7.1.0.31+<\/p>\n\n\n\n<p><strong><a href=\"https:\/\/patchstack.com\/database\/wordpress\/plugin\/simply-schedule-appointments\/vulnerability\/wordpress-appointment-booking-calendar-plugin-1-6-9-27-unauthenticated-sql-injection-via-append-where-sql-parameter-vulnerability\" target=\"_blank\" rel=\"noreferrer noopener\">Simply Schedule Appointments Plugin<\/a><br><\/strong>SQL Injection; <strong>9.3<\/strong>\/10; Update to v1.6.9.29+<\/p>\n\n\n\n<p><strong>Editor Comment<\/strong><br>It&#8217;s worth taking a few minutes each week to <a href=\"https:\/\/getshieldsecurity.com\/blog\/wordpress-security-vulnerabilities\/\" target=\"_blank\" rel=\"noreferrer noopener\">perform a sites review<\/a> to catch issues early and wherever possible, use <a href=\"https:\/\/shsec.io\/lw\" target=\"_blank\" rel=\"noreferrer noopener\">ShieldPRO&#8217;s auto-upgrade<\/a> feature for vulnerable plugins.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">#5 &#8211; Our blog: Let Custom Alerts Watch Over Your Site<\/h2>\n\n\n\n<p>WordPress sites face cyber threats every day, and hackers constantly look for new ways to break security systems. Custom security alerts help protect your site by detecting suspicious activity in real time, such as unauthorised logins, file changes, or plugin issues.<\/p>\n\n\n\n<p><a href=\"https:\/\/getshieldsecurity.com\/blog\/wordpress-security-alerts\/\" data-type=\"link\" data-id=\"https:\/\/getshieldsecurity.com\/blog\/wordpress-security-alerts\/\" target=\"_blank\" rel=\"noreferrer noopener\">More Info \u2192<\/a><\/p>\n\n\n\n<p>Thanks for reading, and have a wonderful week!<\/p>\n\n\n\n<p><strong>Paul Goodchild<\/strong><br><em>Shield Security for WordPres<\/em>s<\/p>\n","protected":false},"excerpt":{"rendered":"<p>WordPress has a new security patch, and major plugin vulnerabilities persist, including unpatched MetForm Pro. Plus, see how to use custom security alerts.<\/p>\n","protected":false},"author":27,"featured_media":163832,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"footnotes":""},"categories":[153,201],"tags":[69],"class_list":["post-170797","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-security-wordpress-solutions","category-shieldnotes","tag-security"],"acf":[],"_links":{"self":[{"href":"https:\/\/getshieldsecurity.com\/wp-json\/wp\/v2\/posts\/170797","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/getshieldsecurity.com\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/getshieldsecurity.com\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/getshieldsecurity.com\/wp-json\/wp\/v2\/users\/27"}],"replies":[{"embeddable":true,"href":"https:\/\/getshieldsecurity.com\/wp-json\/wp\/v2\/comments?post=170797"}],"version-history":[{"count":4,"href":"https:\/\/getshieldsecurity.com\/wp-json\/wp\/v2\/posts\/170797\/revisions"}],"predecessor-version":[{"id":170801,"href":"https:\/\/getshieldsecurity.com\/wp-json\/wp\/v2\/posts\/170797\/revisions\/170801"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/getshieldsecurity.com\/wp-json\/wp\/v2\/media\/163832"}],"wp:attachment":[{"href":"https:\/\/getshieldsecurity.com\/wp-json\/wp\/v2\/media?parent=170797"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/getshieldsecurity.com\/wp-json\/wp\/v2\/categories?post=170797"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/getshieldsecurity.com\/wp-json\/wp\/v2\/tags?post=170797"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}