Patchstack Weekly: New Set Of WP-CLI Security Commands
Hi Coffigniezâ, it's another week of Patchstack Weekly update. This week Robert talks about WordPress plugins with high-risk security bugs found in their code andintroduces a new set of WP-CLI security commands.
Vulnerability: Unauthenticated Arbitrary Function Call Fixed in version: 3.1.2 Number of sites affected: 8,000+ CVSS 3.0 score: 7.3 (High - Can be exploited remotely without any authentication.)
Ad Injection
Vulnerability: Unauthenticated SQL Injection (SQLi) Fixed in version: no known fix Number of sites affected: N/A CVSS 3.0 score: 7.5 (High - Requires high role user authentication like admin.)
RSVP and Event Management Plugin
Vulnerability: Unauthenticated Entries Export Fixed in version: 2.7.8 Number of sites affected: 5,000+ CVSS 3.0 score: 7.5 (High - Can be exploited remotely without any authentication.)
If you are using any of the mentioned plugins, you need to update it to the latest version as soon as possible. Websites with Patchstack installed are protected from the security issues mentioned below.