This update is for week 11 of 2022. This week is all about plugin vulnerabilities and the State of WordPress Security 2021 whitepaper. View this email in your browser (https://mailchi.mp/patchstack/14-vulnerabilities-that-affect-about-25-million-sites-4941864?e=89e008f344) Podcast Episode #14 Patchstack Weekly: The State Of WordPress Security 2021 Hi Coffigniez​, it's another week of Patchstack Weekly update. We have been busy for the last few months preparing the State of WordPress Security Whitepaper for 2021. In this update, Robert introduces the key highlights from the whitepaper. 👇 Check out the highlights 👀 (https://patchstack.com/articles/patchstack-weekly-week-11-state-of-wordpress-security-2021/) Vulnerability news ** WordPress 5.9.2 ------------------------------------------------------------ Vulnerability: Stored Cross-Site Scripting (XSS) Fixed in version: 5.9.2 Number of sites affected: N/A CVSS 3.0 score: 5.4 (Medium - Requires contributor or higher role user authentication.) ** Ninja Forms File Uploads Extension premium ------------------------------------------------------------ Vulnerability: Unauthenticated Arbitrary File Upload Fixed in version: 3.3.1 Number of sites affected: N/A CVSS 3.0 score: 9.8 (Critical - Can be exploited remotely without any authentication.) ** Church Admin ------------------------------------------------------------ Vulnerability: Unauthenticated Plugin's Backup Disclosure Fixed in version: 3.4.135 Number of sites affected: 1,000+ CVSS 3.0 score: 7.5 (High - Can be exploited remotely without any authentication.) If you are using any of the mentioned plugins, you need to update it to the latest version as soon as possible. Websites with Patchstack installed are protected from the security issues mentioned below. You can find all the vulnerabilities from our vulnerability database (https://patchstack.com/database/) . Always keep your plugins updated. If possible, enable automatic updates. You can enable automatic updates with Patchstack here (https://app.patchstack.com/components/updates) . If you are not protecting your WordPress site against plugin vulnerabilities yet go and start for free here (https://app.patchstack.com/register) . Are you on Facebook? Join the Patchstack community (https://www.facebook.com/groups/patchstackcommunity) and be the first to hear about new feature updates, news, and announcements. ============================================================ ** LinkedIn (https://www.linkedin.com/company/patchtsack) ** Facebook (https://www.facebook.com/patchstackapp) ** Twitter (https://twitter.com/patchstackapp) ** Spotify (https://open.spotify.com/show/1LsZ2aGUmw8ule2BHZHb0r?si=e9fe0ecb62014f91) Copyright © 2022 Patchstack, All rights reserved. You are receiving this email because you opted in via our website. Our mailing address is: Patchstack Akadeemia 1 Forwardspace Parnu 80011 Estonia Want to change how you receive these emails? You can ** update your preferences (https://patchstack.us7.list-manage.com/profile?u=7ea59008200002d7f0db008f6&id=5bd388ff7d&e=89e008f344&c=33220fe623) or ** unsubscribe from this list (https://patchstack.us7.list-manage.com/unsubscribe?u=7ea59008200002d7f0db008f6&id=5bd388ff7d&e=89e008f344&c=33220fe623) .