Vulnerability Roundup – April 2022

Vulnerability reports and responsible disclosures are essential for website security awareness and education. Automated attacks targeting known software vulnerabilities are one of the leading causes of website compromises.

To help educate website owners on emerging threats to their environments, we’ve compiled a list of important security updates and vulnerability patches for the WordPress ecosystem this past month.

Remote Code Execution (RCE)
Elementor WordPress Plugin

  • Installations: 5,000,000+
  • Patched Version: 3.6.3
  • Vulnerability: Remote code execution (RCE)
  • Severity: Critical
  • CVE: CVE-2022-1329

This critical vulnerability leverages a lack of capability checks found in vulnerable versions of the Elementor plugin.

Continue reading Vulnerability Roundup – April 2022 at Sucuri Blog.

More great articles

$2,063 Bounty Awarded for Privilege Escalation Vulnerability Patched in User Registration WordPress Plugin

🎉 Did you know we’re running a Bug Bounty Extravaganza again? Earn over 6x our usual bounty rates, up to…

Read Story

8,000 WordPress Sites affected by Arbitrary File Upload Vulnerability in WP Hotel Booking WordPress Plugin

📢 Did you know Wordfence runs a Bug Bounty Program for all WordPress plugins and themes at no cost to…

Read Story

Wordfence Intelligence Weekly WordPress Vulnerability Report (July 22, 2024 to July 28, 2024)

Did you know Wordfence runs a Bug Bounty Program for all WordPress plugin and themes at no cost to vendors?…

Read Story

Emergency WordPress Help

One of our techs will get back to you within minutes.