Site icon Astra Security Blog

Top WordPress Vulnerabilities [June 2020]

Top WordPress Vulnerabilities June 2020

In the last month, a lot of new WordPress vulnerabilities were discovered and patched in the WP core, plugins, and themes. Many of these plugins and themes are quite popular with WordPress website owners and there is a strong possibility you might be using one. To stay safe from any unanticipated attack, you need to be aware. We do not want you to miss updating the patched version and be vulnerable. So we have compiled the list of all the major core updates, plugin, and theme vulnerabilities that happened in June 2020.

WordPress Vulnerabilities (Core) – fixed in version 5.4.2

1. Authenticated XSS via Media Files

2. Authenticated XSS via Theme Upload

3. Disclosure of Password-Protected Page/Post Comments

4. Misuse of set-screen-option Leading to Privilege Escalation

5. Open Redirection

6. Authenticated XSS in Block Editor

7. Authenticated Cross-Site Scripting (XSS) in Customizer

Attackers have also been targeting the wp-config.php file, which could lead to them gaining access to the site’s database. 

Get the ultimate WordPress security checklist with 300+ test parameters

WordPress Plugin Vulnerabilities

1. Elementor Page Builder XSS Vulnerabilities

2. WooCommerce XSS Vulnerability via SelectWoo

3. Authenticated Stored Cross Site Scripting in SeedProd Coming Soon Plugin

4. Authenticated SQL Injection in AdRotate

5. Multiple issues in KingComposer plugin

WordPress Theme Vulnerabilities

1. Unauthenticated Reflected XSS in TownHub

2. Authenticated XSS issue in Newspaper theme

3. Unauthenticated Reflected XSS & SQL Injection in Nexos

A lot of these attacks and XSS campaigns target older WordPress vulnerabilities in outdated plugins or themes, especially those that allow files to be downloaded or exported. It is, therefore, extremely important to be regular with updates! Software developers constantly roll out patches and updates to fix these vulnerabilities, so if you have the latest version of the plugin or theme, then your site is safe from all the patched WordPress vulnerabilities, and thus way less likely to be attacked. 

Another way to keep your site safe is to invest in a good firewall and get regular security audits like from Astra. This could reveal potential vulnerabilities in your site and could help fend off attackers. With round-the-clock expert care, you never have to worry about getting hacked again!

Exit mobile version