List of WordPress Plugins and Themes Vulnerabilities for April 2020
New WordPress plugin and theme vulnerabilities
This is a roundup of all WordPress plugin and theme vulnerabilities for the month of April. The list of vulnerable plugin and themes are collected from time to time to alert the users to take action.
Advert
WordPress plugins and themes often become vulnerable with time due to lack of constant update or as a result of omission by the developer. WordPress plugins and themes are however placed under watch while reports are also taken from the WordPress community on any vulnerable plugin or theme.
Advert
New WordPress plugin and theme vulnerabilities were disclosed during the first half of April, so we want to keep you aware. In this post, we cover recent WordPress plugin, theme and core vulnerabilities and what to do if you are running one of the vulnerable plugins or themes on your website.
The WordPress Vulnerability Roundup is divided into three different categories:
- WordPress core
- WordPress plugins
- WordPress themes
WordPress Core Vulnerabilities
There haven’t been any disclosed WordPress vulnerabilities in 2020.
WordPress Plugin Vulnerabilities
Several new WordPress plugin vulnerabilities have been discovered this month so far. Make sure to follow the suggested action below to update the plugin or completely uninstall it.
IMPress for IDX Broker
IMPress for IDX Broker below version 2.6.2 have an Authenticated Post Creation, Modification/Deletion and Authenticated Stored Cross-Site Scripting (XSS) via unprotected ‘idx_update_recaptcha_key’ vulnerabilities.
The vulnerabilities have been patched, and you should update to version 2.6.2.
CM Pop-Up banners for WordPress
CM Pop-Up banners for WordPress versions below 1.4.11 have an Authenticated Stored XSS vulnerability.
The vulnerability has been patched, and you should update to version 1.4.11.
Rank Math
Rank Math versions below 1.0.4.1 have a Redirect Creation and Privilege Escalation vulnerabilities.
The vulnerabilities have been patched, and you should update to version 1.4.1.
LifterLMS
LifterLMS versions below 3.37.15 have an Arbitrary File Writing vulnerability.
The vulnerability has been patched, and you should update to version 3.37.15.
Elementor Page Builder
Elementor Page Builder versions below 2.9.6 have an Authenticated Safe Mode Privilege Escalation vulnerability.
The vulnerability has been patched, and you should update to version 2.9.6.
LearnDash
LearnDash versions below 3.1.6 have an Unauthenticated SQL Injection vulnerability.
The vulnerability has been patched, and you should update to version 3.1.6.
Login by Auth0
Login by Auth0 versions below 4.0.0 have multiple vulnerabilities.
The vulnerability has been patched, and you should update to version 4.0.0.
WordPress WP-Advanced-Search
WordPress WP-Advanced-Search versions below 3.3.6 have an Unauthenticated SQL Injection vulnerability.
The vulnerability has been patched, and you should update to version 3.3.6.
Contact Form 7 Datepicker

All versions of Contact Form 7 Datepicker have an Authenticated Stored Cross-Site Scripting vulnerability.
Remove the plugin, it has been closed on the WordPress.org plugin repository pending review.
Art-Picture-Gallery

All versions of Art-Picture-Gallery have an Unauthenticated Arbitrary File Upload vulnerability.
Remove the plugin, it has been closed on the WordPress.org plugin repository pending review.
WP Last Modified Info
WP Last Modified Info versions below 1.6.6 have an Authenticated Stored XSS vulnerability.
The vulnerability has been patched, and you should update to version 1.6.6.
WP Lead Plus X
All versions of WP Lead Plus X have a Cross-Site Request Forgery vulnerability.
Remove the plugin until a patch is released.
Ultimate Addons for Gutenberg
Ultimate Addons for Gutenberg versions below 1.14.8 have an Authenticated Settings Change vulnerability.
The vulnerability has been patched, and you should update to version 1.14.8.
Klarna Checkout for WooCommerce
Klarna Checkout for WooCommerce versions below 2.0.10 have an Authenticated Arbitrary Plugin Deactivation, Activation and Installation vulnerability.
Ensure you install the latest version
Tickera – WordPress Event Ticketing
Tickera – WordPress Event Ticketing versions below 3.4.6.9 have an Unauthenticated Sensitive Data Exposure vulnerability.
The vulnerability has been patched, and you should update to version 3.4.6.9.
Responsive Poll

All versions of Responsive Poll have Broken Authentication and Missing Capability Checks on AJAX calls.
Remove the plugin, it has been closed on the WordPress.org plugin repository pending review.
Media Library Assistant
Media Library Assistant versions below 2.82 have an Authenticated Stored Cross-Site Scripting and Unauthenticated Limited Local File Inclusion vulnerabilities.
The vulnerability has been patched, and you should update to version 2.82.
WordPress Themes
There haven’t been any disclosed Theme vulnerabilities in April 2020.
As said earlier, outdated WordPress plugin or theme can make your site vulnerable to attacks and get your site hacked. It is most advisable for sites owners who do not frequently visit their sites to do so at least once a week in order to update all outdated plugins or themes. You can also set up automatic updates for your WordPress installation.
Also, check from our last post on WordPress Vulnerabilities to see anyone you might have missed.
Advert


















