WordPress administrators must update numerous plugins, including Yoast SEO, WPForms, and Essential Addons for Elementor, to address critical and medium-risk security vulnerabilities discovered this month.
Key Points
- Yoast SEO (≤ 28.0) and WPForms (≤ 2.0.0.1) require updates to patch Stored Cross-Site Scripting (XSS) vulnerabilities.
- Essential Addons for Elementor (≤ 6.6.11) received multiple patches for XSS and account takeover risks.
- Loco Translate (≤ 2.8.5) and W3 Total Cache (≤ 2.9.4) were updated to fix high-risk Remote Code Execution and Arbitrary File Read flaws.
- Kirki (≤ 6.0.14) and Amelia (≤ 2.4.3) addressed critical SQL injection and path traversal vulnerabilities.
- Several plugins, including Complianz and Contact Form 7, currently lack patches for identified security risks, requiring alternative mitigation strategies.