WordPress vulnerability news is a weekly digest of highlighted WordPress plugin security vulnerabilities or vulnerability discloses that have been published (there are other, less critical vulnerabilities on smaller plugins that unfortunately don’t make it to the list).
Keeping up to date with security vulnerabilities in WordPress and other CMSs is an important part of security. That is why we are analyzing WordPress plugins and newly disclosed vulnerabilities to make sure the sites using the mentioned plugins or themes are protected.
All the vulnerabilities you find in this article have received a vPatch to the Patchstack security module. It means that if you use Patchstack, your site is safe from these vulnerabilities, but it’s always strongly advised to update or delete vulnerable plugins from your site.
You can find all the vulnerabilities mentioned in our WordPress vulnerability news from our vulnerability database.
Active Directory Integration / LDAP Integration

Active Directory Integration / LDAP Integration Login for Intranet Sites plugin allows you to authenticate your users using their Active Directory/LDAP credentials into your WordPress site.
Vulnerability: Sensitive Data Exposure
Fixed in version: 4.1.1
Number of sites affected: 6,000+
CVSS 3.0 score: 7.5 (High severity)
Update the WordPress Active Directory Integration / LDAP Integration plugin to the latest available version (at least 4.1.1).
Lana Codes discovered and reported this Sensitive Data Exposure vulnerability in WordPress Active Directory Integration / LDAP Integration Plugin. This vulnerability has been fixed in version 4.1.1.

Profile Builder is the all-in-one user profile and registration plugin for WordPress.
Vulnerability: Sensitive Data Exposure
Fixed in version: 3.9.1
Number of sites affected: 60,000+
CVSS 3.0 score: 9.8 (Critical severity)
Lana Codes discovered and reported this Sensitive Data Exposure vulnerability in WordPress Profile Builder Plugin. This vulnerability has been fixed in version 3.9.1.
Update the WordPress Profile Builder plugin to the latest available version (at least 3.9.1).