Patchstack Weekly: Several vulnerabilities and risks
Hi Coffigniezâ, it's another week of Patchstack Weekly update, and firstly, let's go over important vulnerabilities.
UpdraftPlus
Vulnerability: Arbitrary Backup Downloads Fixed in version: 1.22.3 Number of sites affected: 3+ million CVSS 3.0 score: 8.5 (High - Requires subscriber or higher role user authentication.)
WP Statistics
Vulnerability: Multiple Cross-Site Scripting and SQL injection vulnerabilities Fixed in version: 13.1.6 Number of sites affected: 600,000+ CVSS 3.0 score: 7.2 (High - Can be exploited remotely without any authentication.)
If you are using any of the mentioned plugins, you need to update it to the latest version as soon as possible. Websites with Patchstack installed are protected from the security issues mentioned below.