5 Unrestricted Access Issues – WordPress Security DEC, 2020
Be informed about the latest Unrestricted Access Issues, identified and reported publicly in December 2020. As these WordPress Security vulnerabilities have a severe negative impact for any website, consider a security AUDIT. The following PLUGINS made headlines just last month.
- Newsletter <= 1.5.1 - Unauthenticated Insecure Deserialisation
- Newsletter is a real newsletter and email marketing system for your WordPress blog: perfect for list building, you can easily create, send and track e-mails, headache-free. It just works out of box! Active installations: 300,000+
- Total Upkeep – WordPress Backup Plugin plus Restore & Migrate by BoldGrid < 1.14.10 - Unauthenticated Backup Download
- Total Upkeep is more than just a “backup plugin”. It can help stop website crashes before they even happen. Website data loss can happen even if you’re doing everything “right”, like keeping your WordPress and plugins updated or having a backup plugin installed. There’s so many things outside of your control that could totally wipe out your website without any warning. Active installations: 60,000+
- Contact Form 7 < 5.3.2 - Unrestricted File Upload
- Contact Form 7 can manage multiple contact forms, plus you can customize the form and the mail contents flexibly with simple markup. The form supports Ajax-powered submitting, CAPTCHA, Akismet spam filtering and so on.Active installations: 5+ million
- Limit Login Attempts Reloaded < 2.17.4 - Login Rate Limiting Bypass
- Limit the number of login attempts that are possible through the normal login as well as XMLRPC, Woocommerce and custom login pages. WordPress by default allows unlimited login attempts. This can lead to passwords being easily cracked via brute-force. Limit Login Attempts Reloaded blocks an Internet address (IP) from making further attempts after a specified limit on retries has been reached, making a brute-force attack difficult or impossible. Active installations: 1+ million
- DiveBook <= 1.1.4 - Improper Authorisation Check
- This plugin has been closed as of December 9, 2020 and is not available for download. This closure is temporary, pending a full review.Active installations: 60,000+