Best WordPress Hosting
 

WordPress Vulnerability Report – May 17, 2023

via ithemes.com => original post link

This week, WordPress 6.2.1 was released — the first security and maintenance update for the 6.2 version line. This release patched 5 security vulnerabilities, including Cross-Site Scripting (XSS), Cross-site request forgery (CSRF), and path traversal vulnerabilities. If you have your site set to auto-update point releases for WordPress core, your site is likely already protected. Still, it is good practice to verify that the update has been applied to protect your site. For a full review of these patches, you can review WordPress trac tickets for 6.2.1.

In the plugin and theme ecosystem, 146 total vulnerabilities emerged in public disclosure. They may affect over 17 million WordPress sites. Out of the total number, there are 92 plugin vulnerabilities and 5 in themes that have security patches available. This includes Elementor (used on 5+ million sites) and Divi, which is used on over 4 million sites.

Additionally, there are 49 plugin vulnerabilities with no patch available yet. If you are using any unpatched plugins or themes, check their vendors’ intentions and progress on a security release. If no patch is forthcoming or the vulnerable software has been closed and dropped from the official WordPress theme and plugin repositories, you should consider deactivation and removal in favor of alternative solutions.