Vulnerabilities Digest: March 2020

Fixed Plugins and Vulnerabilities

Plugin
Vulnerability
Patched Version
Installs

Cookiebot
Reflected Cross-Site Scripting
3.6.1
40000

Data Tables Generator By Supsystic
Authenticated Stored XSS
1.9.92
30000

WPvivid Backup
Database Leak
0.9.36
40000

Advanced Ads
Reflected XSS
1.17.4
100000

Category Page Icons
Arbitrary File Upload/Deletion
0.9.1
Closed

Cookiebot
Reflected Cross-Site Scripting
3.6.1
40000

Custom Post Type UI
CSRF to Stored XSS
1.7.4
800000

Fruitful
Authenticated Stored XSS
3.8.2
9000

responsive-add-ons
Unprotected AJAX Endpoints
2.2.6
40000

Import Export WordPress Users
Authenticated Arbitrary User Creation
1.3.9
30000

LearnPress
Privilege Escalation
3.2.6.7
70000

Multiple Plugins
Unauthenticated RCE via PHPUnit
all

Multiple WebToffee Plugins
CSRF
1.3.3
2000

Popup Builder
Multiple Issues
3.64.1
100000

Viral Optins
Arbitrary File Upload
all
closed

WordPress File Upload
Directory Traversal to RCE
4.13.0
20000

WPML
Cross Site Request Forgery to RCE
4.3.7
30000

Highlights for March 2020

Cross site scripting and Cross Site Request Forgery vulnerabilities were most prevalent this month.

Continue reading Vulnerabilities Digest: March 2020 at Sucuri Blog.

More great articles

Critical Privilege Escalation Vulnerability in Charitable WordPress Plugin Affects Over 10,000 sites

On August 10, 2023, our Wordfence Threat Intelligence team identified and began the responsible disclosure process for a Privilege Escalation…

Read Story

Introducing Free Wordfence Intelligence WordPress Vulnerability Webhook Notifications!

We’re incredibly excited to announce that we have launched a webhook integration for vulnerabilities as part of Wordfence Intelligence, which…

Read Story

PSA: Critical Unauthenticated Arbitrary File Upload Vulnerability in Royal Elementor Addons and Templates Being Actively Exploited

Today, on October 13, 2023, the Wordfence Threat Intelligence Team became aware of a vulnerability that was recently patched in…

Read Story

Emergency WordPress Help

One of our techs will get back to you within minutes.