Three WordPress plugins you should update immediately WPML Litespeed GIveWP
This month, three WordPress plug-ins were released in which security vulnerabilities were found. If you have installed these plug-ins, you should install the corresponding updates as soon as possible. In this blog, we will explain which vulnerabilities are involved and how you can fix them on your website.
WPML
The widely used WordPress multilingual (multiple languages) plugin, WPML, which is used on more than a million websites, has recently fixed a remote code execution vulnerability (CVE-2024-6386). This vulnerability, classified as "critical" by researchers, received a CVSS score of 9.9.
users are strongly advised to update their websites to the latest version WPML 4.6.13.0. Security researcher Mat Rollings, known as Stealthcopter, discovered the vulnerability and reported it via the Wordfence Bug Bounty program, for which he received a reward of 1,639 US dollars. István Márton of Wordfence explained that "the WPML plugin for WordPress in all versions up to and including 4.6.12 is vulnerable to remote code execution due to a Twig server-side template injection.
This issue is caused by the lack of adequate input validation and sanitization in the render function, which allows authenticated attackers with at least contributor access code to execute on the server." So update the plugin immediately if you have it installed on your hosting and consider enabling automatic updates for it. Then the latest version will be installed immediately and without your intervention.
GiveWP
GiveWP, a widely used donation plugin for WordPress, has fixed a vulnerability that allowed unauthenticated PHP object injection to lead to remote code execution. This vulnerability allowed malicious actors to execute arbitrary remote code and delete files.
The plugin, which is part of the Liquid Web product family, has more than 100,000 active installations. villu164 (Villu Orav) reported the vulnerability as part of the Wordfence Bug Bounty program and received a reward of 4,998 US dollars.
The researchers classify the vulnerability as "critical" with a CVSS score of 10.0 and strongly recommend updating to the latest version. According to Wordfence, the GiveWP plugin "is vulnerable to PHP object injection in all versions up to and including 3.14.1 by deserializing untrusted input via the 'give_title' parameter. This allows unauthenticated attackers to inject a PHP object. The presence of a POP chain then allows attackers to execute remote code and delete arbitrary files.
LiteSpeed Cache
The LiteSpeed Cache plugin, which is widely used to improve the speed and performance of WordPress websites, recently fixed a critical vulnerability that allows unauthenticated privilege escalation (CVE-2024-28000).
With more than 5 million active installations, this plugin is an indispensable tool for many WordPress users. John Blackbourn, a member of the Patchstack Alliance community, discovered the vulnerability and received a reward of $14,400, the highest reward in the history of WordPress bug bounty programs. Oliver Sild, CEO of Patchstack, told WPTavern, "LiteSpeed Cache has its mVDP program through Patchstack, which reported the vulnerability to the Patchstack Zero Day program.
We work closely with researchers and plugin developers to ensure vulnerabilities are properly fixed before they are released." Due to the severity of the vulnerability, the researchers have classified it as "critical", with a CVSS score of 9.8. It is strongly recommended to update to version 6.4 or higher as soon as possible. Again, you should enable automatic updates for this plugin for this purpose.
Keep your WordPress website up to date
With any website, it's important to keep up with updates, both front-end and back-end, with WordPress being the most popular method of creating a website. As WordPress is the most popular method of building websites, it is also prone to vulnerabilities as it is widely used and highly regarded by malicious individuals.
We recommend maintaining your WordPress website at least once a month and, where possible, enabling automatic updates to plug-ins and the WordPress core to reduce the risk of website infection, although there is always a risk. Therefore, it is not enough to just update your website, you should also create an up-to-date backup of your entire website. You can do this through a manual backup, or you can use tools and plug-ins.
We have tested several of these and presented them in a previous blog post. Source:wptavern.com
.jpeg)