上周以来,WordPress生态系统新出现126个漏洞,其中主题漏洞5个,插件漏洞121个。49 个易受攻击的插件和主题仍未修补,但 Solid Security Pro 用户受到 Patchstack 虚拟修补的保护,在这份报告中,公开披露了126个漏洞,其中 77 个插件和主题的安全补丁现已推出,因此请尽快运行这些更新。如果您是 Solid Security Pro 用户,版本管理工具可能已经警告您并更新了这些插件,具体取决于您的设置。
此外,还有 49 个插件和主题漏洞尚未提供补丁。如果您是 Solid Security Pro 用户,这些漏洞已受到Solid Security 防火墙的保护。当漏洞被认为是高风险或中风险时,将应用来自 Patchstack 的虚拟补丁。如果供应商没有发布补丁,或者易受攻击的软件已被标记为“已关闭”并从官方 WordPress 存储库中删除,您应该尽快停用它并寻找替代解决方案。
除了用户帐户安全性差之外,易受攻击的插件和主题也是WordPress 网站遭到黑客攻击的原因之一,不幸的是,网络攻击的数量和复杂性正在增加,它们也越来越多地针对中小型企业。
WordPress 核心
WordPress 6.4.3于 2024 年 1 月 30 日发布,作为一个短周期维护和安全版本,修复了 5 个核心错误和 16 个块编辑器错误修复。
建议您立即更新您的网站
下一个主要版本将是WordPress 6.5,计划于 2024 年 3 月 26 日发布。
详情请查阅 WordPress 官网:https://wordpress.org/news/2024/01/wordpress-6-4-3-maintenance-and-security-release/
以下是 WordPress 插件的列表:
- Adsmonetizer
- AI Engine
- Advanced iFrame
- ArtiBot
- AWeber – Free Sign Up Form and Landing Page Builder Plugin for Lead Generation and Email Newsletter Growth
- Backup
- Beaver Builder – WordPress Page Builder
- BeePress
- Blue Triad EZAnalytics
- Build & Control Block Patterns
- Calculated Fields Form
- Chat Bubble – Floating Chat with Contact Chat Icons, Messages, Telegram, Email, SMS, Call me back
- CodeMirror Blocks
- Complianz – GDPR/CCPA Cookie Consent
- Configure SMTP
- Contact Form 7 – PayPal & Stripe Add-on
- Conversios.io
- Custom Field Suite
- Custom fields shortcode
- Disable Json API, Login Lockdown, XMLRPC, Pingback, Stop User Enumeration Anti Hacker Scan
- Download Manager
- Duitku Payment Gateway
- Easy PayPal & Stripe Buy Now Button
- Easy!Appointments
- Ebook Store
- Elementor Pro
- Envo’s Elementor Templates & Widgets for WooCommerce
- Essential Blocks – Page Builder Gutenberg Blocks, Patterns & Templates
- Events Manager – Calendar, Bookings, Tickets, and more!
- Exclusive Addons for Elementor
- FeedWordPress
- Finale Lite – Sales Countdown Timer & Discount for WooCommerce
- Fontific | Google Fonts
- Friends
- GenerateBlocks
- Gestpay for WooCommerce
- Giveaways and Contests by RafflePress – Get More Website Traffic, Email Subscribers, and Social Followers
- Happy Addons for Elementor
- IDonate – blood request management system
- Image Optimizer, Resizer and CDN – Sirv
- JM Twitter Cards
- JobSearch
- LifterLMS – WordPress LMS Plugin for eLearning
- LiteSpeed Cache
- MainWP Dashboard – WordPress Manager for Multiple Websites Maintenance
- Marketing Optimizer
- Master Slider
- Media Alt Renamer
- NextMove Lite – Thank You Page for WooCommerce
- Nextend Social Login and Register
- NotificationX – Best FOMO, Social Proof, WooCommerce Sales Popup & Notification Bar Plugin With Elementor
- Oliver POS – A WooCommerce Point of Sale (POS)
- Orbit Fox by ThemeIsle
- Page Builder Sandwich – Front-End Page Builder
- Page Duplicator
- Page Restrict
- Page Restriction WordPress (WP) – Protect WP Pages/Post
- Password Protected Store for WooCommerce
- PayU India
- Plugin for Elementor – Header, Footer & Blocks
- Post SMTP Mailer/Email Log
- Premium Addons for Elementor
- Rolo Slider
- Restrict User Access – Ultimate Membership & Content Protection
- Seraphinite Accelerator
- Simple Tweet
- SiteOrigin Widgets Bundle
- Slivery Extender
- Slider Responsive Slideshow – Image slider, Gallery slideshow
- Smart Forms – when you need more than just a contact form
- SMS Alert Order Notifications – WooCommerce
- SoundCloud Shortcode
- Spiffy Calendar
- SportsPress – Sports Club & League Manager
- Thank You Page Customizer for WooCommerce – Increase Your Sales
- Under Construction / Maintenance Mode from Acurax
- Ultimate Bootstrap Elements for Elementor
- User Shortcodes Plus
- Visual Composer Website Builder, Landing Page Builder, Custom Theme Builder, Maintenance Mode & Coming Soon Pages
- Vimeography: Vimeo Video Gallery WordPress Plugin
- Watermark RELOADED
- WP Dashboard Notes
- WP eCommerce
- WP Show Posts
- WP Shortcodes Plugin — Shortcodes Ultimate
- WP Social Widget
- WPvivid Backup for MainWP
- Wp Social Login and Register Social Counter
- WP Access Control
- WP Event Manager – Events Calendar, Registrations, Sell Tickets with WooCommerce
- WP Private Content Plus
- WP Restrict
- WP Social Login
- WP Universal Post Manager
- WP User Role Editor
- WP User Groups
- WP User Groups
- WP User Role Editor
- WP User Role Editor
- WP User Role Editor
- WP User Role Editor
- WPvivid Backup for MainWP
以下是 WordPress 主题的列表:
1. Atahualpa
2. Avada
3. Yuki
我们的 WordPress 漏洞报告涵盖了最新出现的 WordPress 插件、主题和核心漏洞。 每个漏洞的严重程度分为低、中、高或严重。 负责任地披露漏洞对于保证 WordPress 社区的安全至关重要。 请分享此报告,以帮助传播信息并使 WordPress 和网络更加安全。