Security News > 2022 > March > Nearly 30% of critical WordPress plugin bugs don't get a patch
Patchstack, a leader in WordPress security and threat intelligence, has released a whitepaper to present the state of WordPress security in 2021, and the report paints a dire picture.
More specifically, 2021 has seen a growth of 150% in the reported vulnerabilities compared to the previous year, while 29% of the critical flaws in WordPress plugins never received a security update.
Of all the reported flaws in 2021, only 0.58% were in WordPress core, with the rest being on themes and plugins for the platform, coming from various sources and different developers.
Two notable examples covered by Bleeping Computer last year are the "OptinMonster" plugin that impacted 1 million sites and the "All in One" SEO plugin that exposed 3 million websites to takeover attacks.
The most targeted outdated plugins in 2021 were OptinMonster, PublishPress Capabilities, Booster for WooCommerce plugin, and Image Hover Effects Ultimate plugin.
In summary, Patchstack's report highlights that WordPress site admins can manage most security risks by using paid plugins instead of free offerings, keeping the number of installed add-ons at a minimum, and upgrading them to the latest available version as soon as possible.
News URL
Related news
- CISA Urges Agencies to Patch Critical "Array Networks" Flaw Amid Active Attacks (source)
- Critical WordPress Anti-Spam Plugin Flaws Expose 200,000+ Sites to Remote Attacks (source)
- Exploit released for critical WhatsUp Gold RCE flaw, patch now (source)
- Veeam Issues Patch for Critical RCE Vulnerability in Service Provider Console (source)
- BeyondTrust Issues Urgent Patch for Critical Vulnerability in PRA and RS Products (source)
- Patch Alert: Critical Apache Struts Flaw Found, Exploitation Attempts Detected (source)
- Premium WPLMS WordPress plugins address seven critical flaws (source)
- Critical SQL Injection Vulnerability in Apache Traffic Control Rated 9.9 CVSS — Patch Now (source)
- Unpatched critical flaws impact Fancy Product Designer WordPress plugin (source)