Site icon Astra Security Blog

Monthly WordPress Security Roundup [May 2021]

Monthly Security Roundup May 2021

Hello everyone, it’s Kanishk again from Astra Security, bringing you the latest WordPress security with another version of our Monthly WordPress Security Roundup for May 2021. 

Through this article, we will be discussing the vulnerabilities disclosures & bug fixes in the WP core, database, plugins and themes, and some other security issues related to the WordPress CMS platform.

So, let’s get started!

In May 2021, WordPress fixed a medium severity vulnerability named Object Injection in PHPMailer that impacted sites running on WordPress versions between v3.7 and v5.7. The vulnerability is fixed in the latest version WordPress 5.7.2  that was released on May 13th, 2021.

Here are the CVE IDs for the vulnerabilities: CVE-2020-36326 and CVE-2018-19296.

In addition to this, we have seen a large number of plugin and theme vulnerabilities being actively exploited by hackers. Here are those:

Vulnerabilities Bulletin for WordPress plugins:

1. WP Super Cache

2. Autoptimize

3. All in One SEO

4. GA Google Analytics

5. Photo Gallery by 10Web

6. Ultimate Member

7. Database Backup for WordPress

8. PickPlugins Product Slider for WooCommerce

9. Spam protection, AntiSpam, FireWall by CleanTalk

Vulnerabilities discovered in WordPress themes:

1. Car Repair Services & Auto Mechanic WordPress Theme + RTL

2. Bello- Directory and Listing

3. Listeo – Directory & Listings With Booking – WordPress Theme

That does it for this month’s WordPress Security Roundup. Make sure to update to the latest version if you are running any of the above-mentioned WordPress plugins and themes.

Websites, plugins and themes that are protected by Astra Security Suite are already secured against vulnerabilities such as XSS, RCE, CSRF, arbitrary file upload & deletion, sensitive data exposure, and SQL injection.

Check out WordPress plugin security guide for WP plugin developers to better secure their WordPress plugins against vulnerability exploits and other hacking attempts.

Stay safe from any unanticipated attack and be aware of the security vulnerabilities and latest patches. From all of us here at Astra Security, have a great month ahead and we’ll catch you up next time.

Thank you!

Exit mobile version