Vulnerability Roundup – April 2022

Vulnerability reports and responsible disclosures are essential for website security awareness and education. Automated attacks targeting known software vulnerabilities are one of the leading causes of website compromises.

To help educate website owners on emerging threats to their environments, we’ve compiled a list of important security updates and vulnerability patches for the WordPress ecosystem this past month.

Remote Code Execution (RCE)
Elementor WordPress Plugin

  • Installations: 5,000,000+
  • Patched Version: 3.6.3
  • Vulnerability: Remote code execution (RCE)
  • Severity: Critical
  • CVE: CVE-2022-1329

This critical vulnerability leverages a lack of capability checks found in vulnerable versions of the Elementor plugin.

Continue reading Vulnerability Roundup – April 2022 at Sucuri Blog.

More great articles

Vulnerability in WP DSGVO Tools (GDPR) Plugin Allows Unauthenticated Page Deletion

Note: To receive disclosures like this in your inbox the moment they’re published, you can subscribe to our WordPress Security…

Read Story

Wordfence Intelligence CE Weekly Vulnerability Report (Feb 6, 2023 to Feb 12, 2023)

In case you missed it, Wordfence has curated an industry leading vulnerability database with all known WordPress core, theme, and…

Read Story

Multiple Reflected Cross-Site Scripting Vulnerabilities in Three WordPress Plugins Patched

The Wordfence Threat Intelligence Team recently disclosed several Reflected Cross-Site Scripting vulnerabilities that we discovered in three different plugins –…

Read Story

Emergency WordPress Help

One of our techs will get back to you within minutes.