CSRF FEB 2021 - Cross-Site Request Forgery FEB 2021
Managed WordPress Security Report
Be informed about the latest Cross-Site Request Forgery FEB 2021, identified and reported publicly. As these CSRF FEB 2021 vulnerabilities have a severe negative impact on any WordPress Security, consider our FREE security AUDIT.
An estimated 2.2+ million active WordPress installations are susceptible to this attack type, considering only the publicly available numbers. The estimated number can increase by 5-10% with premium versions as they are private purchases.
Furthermore, the initial estimation can triple if we consider the already patched versions BUT NOT UPDATED by owners, as the vulnerability remains active within their domain. As these owners start changing their hosting provider (due to constant unexplained issues), they actively migrate these vulnerabilities behind protected areas, possibly exposing other clean WP to different attack types.
It is a whopping 1200% increase compared to January 2022. Read more about our previous report here: Abuse: 1 CSRF JAN 2021 – Cross-Site Request Forgery JAN 2021. The following cases made headlines just last month in the CSRF FEB 2021 category:
- Better Search < 2.5.3 - CSRF Nonce Bypass in Import/Export
- Better Search replaces the default WordPress search engine with a more powerful search engine that gives search results relevant to the title and content of the post. This means that visitors to your blog will find what they are looking for quicker than if you didn’t have Better Search installed. Active installations: 8,000+
- Contact Form 7 Style <= 3.1.9 - Cross-Site Request Forgery to Stored Cross-Site Scripting
-
No known fix - plugin closed - Active installations: 50,000+
-
- Custom Banners < 3.3 - CSRF Nonce Bypass in saveCustomFields
- Custom Banners is a WordPress plugin that allows you to easily manage several banners (ads) and display them on the front end. Active installations: 7,000+
- eCommerce Product Catalog Plugin for WordPress < 3.0.18 - CSRF Nonce Bypass
- eCommerce Product Catalog is a beautiful, easy-to-use, 100% responsive, and free product catalog plugin for WordPress eCommerce or a simple product catalog website with a request for a quote functionality. Active installations: 10,000+