
Continue reading Google My Business now accepts appointments at DeKalb County Online.
Vulnerabilities have been reported in the Formidable Forms, Duplicator and Yoast SEO WordPress plugins. The Premium version of Wordfence protects against all of these vulnerabilities, even if you have not updated your plugins yet. We do recommend that you update immediately, whether or not you are using the Premium version of Wordfence.
The details of the vulnerabilities are as follows:
Jouko Pynnönen disclosed multiple vulnerabilities in Formidable Forms version 2.05.02 and older. The report included multiple serious problems:
Formidable Forms is used by over 200,000 active sites according to WordPress.org. The Formidable Forms team has released multiple updates addressing these issues, starting at 2.05.02. We released a firewall rule today, protecting Wordfence Premium customers from attempts to exploit this vulnerability. Free users should upgrade to version 2.05.05 immediately.
WPVulnDB also reports that the Duplicator, running on over 1 million active sites, fixed a stored cross site scripting vulnerability affecting versions 1.2.28 and older. This report also included the code changes.
Duplicator version 1.2.29 fixed this issue, but their changelog does not mention a vulnerability (there is no currently entry at all for version 1.2.29). Wordfence includes built-in protection against attacks of this nature, so both Premium and free users should be safe.
Ryan Dewhurst’s WPVulnDB is reporting that Yoast SEO fixed an unauthenticated cross site scripting vulnerability that affected versions 5.7.1 and older. The code change showing the fix is linked to from the WPVulnDB report.
Wordfence also protects against this exploit (both free and Premium).
We encourage you to share these vulnerabilities with the larger WordPress community to help keep site owners safe from exploitation.
The post Vulnerabilities in Formidable Forms, Duplicator and Yoast SEO Plugins appeared first on Wordfence.