Wordfence acaba de emitir um novo aviso sobre as dezenas de vulnerabilidades encontradas em instalações WordPress. Foram 31 pesquisadores destas vulnerabilidades que contribuíram para catalogar tudo isso e divulgar para todos os donos de sites de WordPress. As recomendações são sempre verificar e corrigir caso o seu site esteja vulnerável. Assim, saiba que são 80 vulnerabilidades nos últimos 6 dias.
Essas dezenas de vulnerabilidades foram encontradas em 69 plugins e 1 tema WordPress. Deste número, apenas 53 correções foram lançadas. Vale lembrar que não é um problema do CMS, mas de plugins de terceiros que adicionam funcionalidades aos sites WordPress.
Saiba quais são os plugins WordPress que estão vulneráveis
No momento da escrita deste artigo os plugins abaixo estão vulneráveis. Porém, os desenvolvedores podem corrigir isso a qualquer momento. Localizei o plugin que você utiliza com os comandos Ctrl + F e confira se ele está listado.
Software Name | Software Slug |
Advance WordPress Search Plugin | th-advance-product-search |
All-In-One Security (AIOS) – Security and Firewall | all-in-one-wp-security-and-firewall |
BigContact Contact Page | bigcontact |
Branded Social Images – Open Graph Images with logo and extra text layer | branded-social-images |
CBX Currency Converter | cbcurrencyconverter |
Contact Form Email | contact-form-to-email |
Contact Form Plugin – Fastest Contact Form Builder Plugin for WordPress by Fluent Forms | fluentform |
ConvertBox Auto Embed WordPress plugin | convertbox-auto-embed |
Custom Field Template | custom-field-template |
Cyberus Key | cyberus-key |
Disqus Conditional Load | disqus-conditional-load |
Easy Table of Contents | easy-table-of-contents |
Enhanced Plugin Admin | enhanced-plugin-admin |
Event Manager and Tickets Selling Plugin for WooCommerce | mage-eventpress |
Events Made Easy | events-made-easy |
Export Users Data Distinct | export-users-data-distinct |
Floating Cart and Menu Cart for WooCommerce | th-all-in-one-woo-cart |
Gallery by BestWebSoft – Customizable Image and Photo Galleries for WordPress | gallery-plugin |
GamiPress – Youtube integration | gamipress-youtube-integration |
GiveWP – Donation Plugin and Fundraising Platform | give |
Google XML Sitemap for Mobile | google-mobile-sitemap |
Hummingbird – Optimize Speed, Enable Cache, Minify CSS & Defer Critical JS | hummingbird-performance |
I Recommend This | i-recommend-this |
If Menu – Visibility control for Menus | if-menu |
InPost Gallery | inpost-gallery |
JS Job Manager | js-jobs |
JetEngine | jet-engine |
Kanban Boards for WordPress | kanban |
Klaviyo | klaviyo |
Lazy Social Comments | lazy-facebook-comments |
MDTF – Meta Data and Taxonomies Filter | wp-meta-data-filter-and-taxonomy-filter |
Open Graphite | open-graphite |
Owl Carousel | owl-carousel |
Pagination by BestWebSoft – Customizable WordPress Content Splitter and Navigation Plugin | pagination |
Photo Gallery by 10Web – Mobile-Friendly Image Gallery | photo-gallery |
Pricing Tables For WPBakery Page Builder (formerly Visual Composer) | pricing-tables-for-wpbakery-page-builder |
Product Feed PRO for WooCommerce | woo-product-feed-pro |
Safe SVG | safe-svg |
Scheduled Announcements Widget | scheduled-announcements-widget |
Simple Custom Author Profiles | simple-custom-author-profiles |
Simple Giveaways – Grow your business, email lists and traffic with contests | giveasap |
Simple Mobile URL Redirect | simple-mobile-url-redirect |
Slider, Gallery, and Carousel by MetaSlider – Responsive WordPress Slideshows | ml-slider |
Stock Sync for WooCommerce | stock-sync-for-woocommerce |
Store Locator WordPress | agile-store-locator |
Stylish Cost Calculator | stylish-cost-calculator-premium |
Team Member – Team with Slider | team-showcase-supreme |
Thank You Page Customizer for WooCommerce – Increase Your Sales | woo-thank-you-page-customizer |
Time Sheets | time-sheets |
TreePress – Easy Family Trees & Ancestor Profiles | treepress |
User Registration – Custom Registration Form, Login Form And User Profile For WordPress | user-registration |
Userlike – WordPress Live Chat plugin | userlike |
Variation Swatches for WooCommerce | th-variation-swatches |
Vertical scroll recent post | vertical-scroll-recent-post |
VigilanTor | vigilantor |
W4 Post List | w4-post-list |
WP Content Filter – Censor All Offensive Content From Your Site | wp-content-filter |
WP Popup Banners | wp-popup-banners |
WP VR – 360 Panorama and Virtual Tour Builder For WordPress | wpvr |
Waiting: One-click countdowns | waiting |
Wbcom Designs – BuddyPress Activity Social Share | bp-activity-social-share |
Weather Station | live-weather-station |
WooCommerce JazzCash Gateway Plugin | jazzcash-woocommerce-gateway |
WooCommerce Payments – Fully Integrated Solution Built and Supported by Woo | woocommerce-payments |
WordPress Amazon S3 Plugin | wp-s3 |
WordPress CRM, Email & Marketing Automation for WordPress | Award Winner — Groundhogg | groundhogg |
WordPress Pinterest Plugin – Make a Popup, User Profile, Masonry and Gallery Layout | gs-pinterest-portfolio |
amr users | amr-users |
eRoom – Zoom Meetings & Webinars | eroom-zoom-meetings-webinar |
E o tema para WordPress vulnerável é:
Software Name | Software Slug |
Resoto | resoto |
Se você precisar de mais informações, consulte o post completo com todos os detalhes das vulnerabilidades no Blog do Wordfence.