Plugin Updates

Schema & Structured Data for WP & AMP – Authenticated Stored Cross-Site Scripting – CVE-2024-22146 | WordPress Plugin Vulnerability Report

By Your WP Guy / Jan 12, 2024

Plugin Name: Schema & Structured Data for WP & AMP Key Information: Software Type: Plugin Software Slug: schema-and-structured-data-for-wp Software Status: Active Software Author: magazine3 Software Downloads: 4,852,104 Active Installs: 100,000 Last Updated: January 12, 2024 Patched Versions: 1.26 Affected Versions: <= 1.25 Vulnerability Details: Name: Schema & Structured Data for WP & AMP <= 1.25…

Read More

WooCommerce Vulnerability – Reflected Cross-Site Scripting | WordPress Plugin Vulnerability Report

By Your WP Guy / Jan 12, 2024

Plugin Name: WooCommerce Key Information: Software Type: Plugin Software Slug: woocommerce Software Status: Active Software Author: woothemes Software Downloads: 289,194,192 Active Installs: 5,000,000 Last Updated: January 12, 2024 Patched Versions: 8.4.0 Affected Versions: < 8.4.0 Vulnerability Details: Name: WooCommerce < 8.4.0 Title: Reflected Cross-Site Scripting Type: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N CVE: NA CVSS Score: 6.1 Publicly Published: January…

Read More

The Events Calendar Vulnerability – Unauthenticated Sensitive Information Exposure – CVE-2023-6557 | WordPress Plugin Vulnerability Report

By Your WP Guy / Jan 12, 2024

Plugin Name: The Events Calendar Key Information: Software Type: Plugin Software Slug: the-events-calendar Software Status: Active Software Author: theeventscalendar Software Downloads: 53,054,073 Active Installs: 700,000 Last Updated: January 12, 2024 Patched Versions: 6.2.9 Affected Versions: <= 6.2.8.2 Vulnerability Details: Name: The Events Calendar <= 6.2.8.2 Title: Unauthenticated Sensitive Information Exposure Type: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N CVE: CVE-2023-6557 CVSS…

Read More

Contact Form 7 Vulnerability– Dynamic Text Extension – Insecure Direct Object Reference – CVE-2023-6630 | WordPress Plugin Vulnerability Report

By Your WP Guy / Jan 10, 2024

Plugin Name: Contact Form 7 – Dynamic Text Extension Key Information: Software Type: Plugin Software Slug: contact-form-7-dynamic-text-extension Software Status: Active Software Author: sevenspark Software Downloads: 1,173,724 Active Installs: 100,000 Last Updated: January 10, 2023 Patched Versions: 4.2.0 Affected Versions: <= 4.1.0 Vulnerability Details: Name: Contact Form 7 – Dynamic Text Extension <= 4.1.0 Title: Insecure…

Read More

Newsletter Vulnerability– Send Awesome Emails from WordPress – Cross-Site Request Forgery |WordPress Plugin Vulnerability Report

By Your WP Guy / Jan 10, 2024

Plugin Name: Newsletter – Send Awesome Emails from WordPress Key Information: Software Type: Plugin Software Slug: newsletter Software Status: Active Software Author: satollo Software Downloads: 23,000,399 Active Installs: 300,000 Last Updated: January 10, 2024 Patched Versions: 8.0.7 Affected Versions: <= 8.0.6 Vulnerability Details: Name: Newsletter <= 8.0.6 Title: Cross-Site Request Forgery (CSRF) Type: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:N/I:L/A:N CVE:…

Read More

POST SMTP Vulnerability – The #1 WordPress SMTP Plugin – Authorization Bypass via type connect-app API – CVE-2023-6875 | WordPress Plugin Vulnerability Report 

By Your WP Guy / Jan 10, 2024

Plugin Name: POST SMTP – The #1 WordPress SMTP Plugin with Advanced Email Logging and Delivery Failure Notifications Key Information: Software Type: Plugin Software Slug: post-smtp Software Status: Active Software Author: wpexpertsio Software Downloads: 11,120,456 Active Installs: 300,000 Last Updated: January 10, 2024 Patched Versions: 2.8.8 Affected Versions: <= 2.8.7 Vulnerability Details: Name: POST SMTP…

Read More

Customer Reviews for WooCommerce Vulnerability – Authenticated (Author+) Arbitrary File Upload – CVE-2023-6979 |WordPress Plugin Vulnerability Report

By Your WP Guy / Jan 9, 2024

Plugin Name: Customer Reviews for WooCommerce Key Information: Software Type: Plugin Software Slug: customer-reviews-woocommerce Software Status: Active Software Author: ivole Software Downloads: 3,786,034 Active Installs: 60,000 Last Updated: January 9, 2024 Patched Versions: 5.38.10 Affected Versions: <= 5.38.9 Vulnerability Details: Name: Customer Reviews for WooCommerce <= 5.38.9 Title: Authenticated (Author+) Arbitrary File Upload Type: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H…

Read More

Email Encoder Vulnerability – Protect Email Addresses and Phone Numbers – Authenticated (Contributor+) Stored Cross-Site Scripting – CVE-2023-7070 |WordPress Plugin Vulnerability Report

By Your WP Guy / Jan 9, 2024

Plugin Name: Email Encoder – Protect Email Addresses and Phone Numbers Key Information: Software Type: Plugin Software Slug: email-encoder-bundle Software Status: Active Software Author: ironikus Software Downloads: 996,589 Active Installs: 80,000 Last Updated: January 9, 2024 Patched Versions: 2.1.10 Affected Versions: <= 2.1.9 Vulnerability Details: Name: Email Encoder <= 2.1.9 Title: Authenticated (Contributor+) Stored Cross-Site…

Read More

Essential Blocks Vulnerability – Page Builder Gutenberg Blocks, Patterns & Templates – Authenticated (Contributor+) Stored Cross-Site Scripting – CVE-2023-7071 | WordPress Plugin Vulnerability Report

By Your WP Guy / Jan 9, 2024

Plugin Name: Essential Blocks – Page Builder Gutenberg Blocks, Patterns & Templates Key Information: Software Type: Plugin Software Slug: essential-blocks Software Status: Active Software Author: wpdevteam Software Downloads: 2,305,018 Active Installs: 100,000 Last Updated: January 9, 2024 Patched Versions: 4.4.7 Affected Versions: <= 4.4.6 Vulnerability Details: Name: Essential Blocks <= 4.4.6 Title: Authenticated (Contributor+) Stored…

Read More

Happy Addons for Elementor – Authenticated (Contributor+) Stored Cross-Site Scripting |WordPress Plugin Vulnerability Report 

By Your WP Guy / Jan 9, 2024

Plugin Name: Happy Addons for Elementor Key Information: Software Type: Plugin Software Slug: happy-elementor-addons Software Status: Active Software Author: thehappymonster Software Downloads: 5,771,889 Active Installs: 400,000 Last Updated: January 9, 2024 Patched Versions: 3.10.1 Affected Versions: <= 3.10.0 Vulnerability Details: Name: Happy Elementor Addons <= 3.10.0 Title: Authenticated (Contributor+) Stored Cross-Site Scripting Type: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N CVE:…

Read More