Site icon Astra Security Blog

Monthly WordPress Security Roundup [March 2021]

Before we start, I want to let you know that if you’re using Astra WordPress Firewall then your site is completely secured from the following vulnerabilities.

If you’re a WP plugin or theme developer then you can follow this DIY security audit guide to make sure that your plugin has no security loopholes.

So, let’s get started with the news!

In March 2021, thankfully, there were no new vulnerabilities found in the WordPress core system.

Image Source: WordPress

However, a new version of WordPress “Esperanza” is released – WordPress 5.7 which introduced features for site security such as switching a site from HTTP to HTTPS in a single click, a way to send password reset emails, and a few other 142 bug fixes that affected sites running on earlier versions. 

In addition to this, we have seen a large number of plugin and theme vulnerabilities being actively exploited by hackers. Here are those:

Vulnerabilities Bulletin for WordPress plugins:

1. Ivory Search – WordPress Search Plugin

Ivory Search – WordPress Search Plugin allows its users to create custom search forms for their WordPress site/s.

2. Cooked – Recipe Plugin

Cooked – Recipe plugin for WordPress allows its users to create & display recipes with WordPress.

3. WP File Manager

WP File Manager WordPress plugin allows its users to edit, delete, upload, download, zip, copy and paste files and folders directly from the WordPress backend.

4. WP Super Cache

WP Super Cache plugin for WordPress allows its users to generate static HTML files from your dynamic WordPress blog, and also offer other features to ultimately optimize a site’s performance.

5. The Plus Addons for Elementor Page Builder

The Plus Addons for Elementor Page Builder WordPress plugin assists its users in the development of pages for a WordPress site with its multiple available widgets.

6. Elementor Website Builder

Elementor Website Builder plugin for WordPress provides you all the tools you need to start, manage, and grow your membership site.

It is one small security loophole v/s your entire website or web application

Get your web app audited with Astra’s Continuous Pentest Solution

7. BuddyPress

BuddyPress WordPress plugin:

8. GiveWP – Donation Plugin and Fundraiser Platform

GiveWP – Donation Plugin and Fundraiser Platform plugin for WordPress provide you with a powerful donation platform optimized for online giving.

9. Facebook for WordPress

Facebook for WordPress plugin allows its users to install a Facebook Pixel for their page to capture the actions site visitors take when they interact with the page.

10. Quiz and Survey Master

Quiz and Survey Master – Best Quiz, Exam and Survey Plugin for WordPress allows you to create a viral quiz, trivia quiz for kids, customer satisfaction surveys and employee surveys. 

11. Super Interactive Maps for WordPress

Super Interactive Maps for WordPress plugin allows you to create maps of country, continent and regions in your WordPress site. 

12. Forminator

Forminator – Contact Form, Payment Form and Custom Form Builder is a drag and drop form builder for WordPress sites.

13. Defender Security

Defender Security – Malware Scanner, Login Security and Firewall is a WordPress security plugin.

Get the ultimate WordPress security checklist with 300+ test parameters

Vulnerabilities Bullein for WordPress themes:

1. Thrive Suite (Themes & Plugins)

2. Listeo Premium Themes

3. WorkScout Themes

4. Findeo Themes

That does it for this month’s WordPress Security Roundup. Make sure to update to the latest version if you are running any of the above-mentioned WordPress plugins and themes.

Stay safe from any unanticipated attack and be aware of the security vulnerabilities and latest patches. From all of us here at Astra Security, have a great month ahead and we’ll catch you up next time.

Websites, plugins and themes that are protected by Astra Security Suite are already secured against vulnerabilities such as XSS, RCE, CSRF, arbitrary file upload & deletion, sensitive data exposure, and SQL injection.

Exit mobile version