5 WordPress Vulnerabilities Today: One Has No Fix
Good morning. Here are the five WordPress security stories worth knowing about today.
First up, WordPress itself has a new security update. WordPress 7.1.1 is now available, and it fixes 11 security issues. One involves malicious comments, another affects the WordPress REST API, and another could let a contributor overwrite somebody else’s post.
The important bit is simple. If you run WordPress, update to version 7.1.1. Automatic updates may already be running, but don’t assume they worked. Check the site, confirm the update, and then move on.
Next up, a serious problem in JetFormBuilder. This one affects more than 80,000 WordPress sites, and it’s a big one. An attacker doesn’t need an account. They can potentially exploit a public form and create themselves a WordPress administrator.
That’s effectively a complete site takeover. The vulnerability has been fixed, so if you use JetFormBuilder, update it to the latest version now. And if your site was running a vulnerable version, check your administrator accounts.
Make sure you recognise every one of them, because with this vulnerability, updating the plugin closes the door, but it doesn’t tell you whether somebody already came through it. If you find an account you don’t recognise, that’s the point where hacked website repair becomes the job, not just an update.
Next up, WP Import Export Lite has another security update. This plugin is used on around 40,000 WordPress sites, and the problem involves user imports and permissions. The technical details get complicated, but the important part is simple.
Import plugins have a lot of power. They can create users, they can modify content, and they can move huge amounts of data. The safe version is 3.9.35, so if you use WP Import Export Lite, make sure you’re on 3.9.35 or later.
And if you run WordPress Multisite, I’d give this one extra attention, because an import tool isn’t just another WordPress plugin. It’s a plugin with authority to change a lot of your website.
Story number four is for WordPress Multisite users. There’s a new vulnerability in WP Cookie Consent, and this one starts with an anonymous visitor. They can submit malicious content which gets stored inside the consent logs.
Nothing necessarily happens immediately. The danger comes later, when an administrator opens that poisoned information. Malicious code can then run inside the administrator’s browser.
The good news is that normal single WordPress sites aren’t affected by this particular bug; this is a Multisite issue. The current version is 4.4.5, so if you’re running this plugin on WordPress Multisite, update it.
And there’s a broader lesson here. Something being inside WP Admin doesn’t automatically make it trusted. If the data originally came from a visitor, it’s still untrusted data.
And finally this morning, a small plugin with a very serious problem. It’s called Multi-Upload Uploader for Gravity Forms. The install base is tiny, but the vulnerability scores 9.8 out of 10.
An attacker doesn’t need to log in. They may be able to upload almost any type of file to the server, and under the right conditions, that can become complete control of the website.
But here’s the important part: there is currently no known safe version. So this isn’t an “upgrade your plugin” story. If you have Multi-Upload Uploader for Gravity Forms installed, disable it, remove it, and check the website for unexpected files, because sometimes the correct security update is deleting the plugin completely.
And that’s your WordPress security briefing for today. The big one is WordPress itself, so make sure you’re running 7.1.1. Then check your plugin inventory for the other four.
And remember, don’t update plugins blindly. Know what you actually run, know what is actually vulnerable, and fix the sites that are genuinely exposed.