Hi Coffigniezâ, it's another week of Patchstack Weekly update. This week Robert talks about 3 plugins that have each been patched due to high-risk security bugs found in their code and defensive coding strategies for a common security bug in WordPress.
Vulnerability: Nonce token leak leading to arbitrary file upload, theme deletion, plugin settings change Fixed in version: 4.1.8 Number of sites affected: 100,000+ CVSS 3.0 score: 8.3 (High - Requires subscriber or higher role user authentication.)
Stop Bad Bots
Vulnerability: Unauthenticated SQL Injection (SQLi) Fixed in version: 6.930 Number of sites affected: 10,000+ CVSS 3.0 score: 8.3 (High - Can be exploited remotely without any authentication.)
If you are using any of the mentioned plugins, you need to update it to the latest version as soon as possible. Websites with Patchstack installed are protected from the security issues mentioned below.