Site icon Astra Security Blog

Monthly WordPress Security Roundup [April 2021]

Hello everyone, it’s Kanishk again from Astra Security, bringing you the latest WordPress security with another version of our Monthly WordPress Security Roundup for April 2021. 

Today, we’ll be discussing the vulnerabilities disclosures & bug fixes in the WP core, database, plugins and themes, and some other security issues related to the WordPress CMS platform.

Before we start, I want to let you know that if you’re using Astra WordPress Firewall then your site is completely secured from the following vulnerabilities.

If you’re a WP plugin or theme developer then you can follow this DIY security audit guide to make sure that your plugin has no security loopholes.

So, let’s get started with the news!

In April  2021, there were two new vulnerabilities found in the WordPress system.

These two security issues affected WordPress versions between 4.7 and 5.7 :
1) An XXE vulnerability within the media library affecting PHP 8  – Source and 
2) A data exposure vulnerability within the REST API 

These issues are fixed in the new version of WordPress that is released on April 15 – WordPress 5.7.1 quoted as “a short-cycle security and maintenance release”. WP v5.7.1 did not introduce new features but it is updated with 26 bug fixes that affected sites running on earlier versions.

In addition to this, we have seen a large number of plugin and theme vulnerabilities being actively exploited by hackers. Here are those:

Vulnerabilities Bulletin for WordPress plugins:

1. RSS for Yandex Turbo

RSS for Yandex Turbo plugin for WP allows its users to automatically create new RSS feeds for the Yandex. 

2. Stop Spammers

Stop Spammer plugin for WordPress allows its users to stop spam emails, spam comments, spam registration, and spam bots and spammers in general.

3. iThemes Security

IThemes Security WordPress plugin offers security solution to over 1 million WordPress sites.

4. WPGraphQL

WPGraphQL WordPress plugin provides an extendable GraphQL schema and API for any WordPress site.

5. Virtual Robots.txt

Virtual Robots.txt is a plugin for WP sites that allow its users to create and manage robots.txt file for their websites.

30,000 websites get hacked every single day. Are you next?

Secure your website from malware & hackers using Website Protection before it is too late.

6. SecuPress Pro

SecuPress Pro is an another WP security plugin that offers security to WordPress sites.

7. Erident Custom Login and Dashboard

Erident Custom Login and Dashboard plugin for WordPress allows its users to customize their login pages and WP dashboard.

8. Tutor LMS

Tutor LMS – eLearning and online course solution plugin for WP allows its users to create & sell courses online easily

9. Business Directory Plugin

Business Directory Plugin for WP allows its users to build a local directory, simple directory of business providers, a real estate listings site, a Yellow-Pages directory, a Yelp clone with review sections, a church directory, an address book directory, a book review site and more.

10. WPBakery Page Builder Clipboard

WPBakery Page Builder Clipboard plugin for WP allows its users to copy/cut and paste single content elements or stack of content elements across pages without ever leaving WPBakery Page Builder (backend) interface.

Get the ultimate WordPress security checklist with 300+ test parameters

Vulnerabilities discovered in WordPress themes:

1. WorkScout Job Board WordPress Theme

That does it for this month’s WordPress Security Roundup. Make sure to update to the latest version if you are running any of the above-mentioned WordPress plugins and themes.

Stay safe from any unanticipated attack and be aware of the security vulnerabilities and latest patches. From all of us here at Astra Security, have a great month ahead and we’ll catch you up next time.

Websites, plugins and themes that are protected by Astra Security Suite are already secured against vulnerabilities such as XSS, RCE, CSRF, arbitrary file upload & deletion, sensitive data exposure, and SQL injection.

Exit mobile version