29 vulnerabilities this week, with 5 needing a fix (with some, possibly, on the way). The first 3 vulnerabilities in the list are confirmations of possible vulnerabilities from last week. Search Exclude returns as last week’s fix wasn’t sufficient, LMS / VLE plugin LifterLMS has a serious vulnerability, Slimstat analytics returns for the third time […]
26 vulnerabilities this week, with 7 needing a fix (with some, possibly, on the way). Formidable Forms appears for the fourth time in a month, so you may wish to look elsewhere. Landing Pages by SwiftCloud is still on the directory (but closed), but the latest commit has deleted everything for unknown security reasons. In […]
27 vulnerabilities this week, with 4 unfixed, but 1 being worked on. WooCommerce PayU India (PayUmoney – PayUbiz) , Instamojo for WooCommerce and DW Mega Menu are all closed and show no sign of a fix – Ovic Addon Toolkit is closed, but is being worked on. It is an arbitrary file deletion vulnerability, so […]
Vulnerable Plugins There are eighteen issues this week, with two unfixed, and five where fixes have been committed but aren’t showing as available yet in the public repository. The most critical this week are a Privilege Escalation vulnerability in WP Front End Profile (fix available), a CSV Injection vulnerability in Import Export WordPress Users (fix […]
Vulnerable Plugins There are eighteen issues this week, with eight unfixed. The most critical this week is an Arbitrary File Upload vulnerability via Cross-Site Request Forgery vulnerability in the Maintenance plugin. No fix is available as of this publishing date, and the plugin has been closed in the public repository. View this week’s vulnerable plugins […]
Vulnerable Plugins There are eighteen issues this week, with three unfixed. The most critical this week are Privilege Escalation vulnerabilities via Unauthenticated Option Update vulnerabilities in the Donations, Booking, Learning Courses, and Restaurant Reservations plugins (fixes available for all). View this week’s vulnerable plugins list. Other News I’m back! Huge thank you goes out to […]
23 vulnerabilities this week, with 9 unfixed (some are commercial plugins where a change log isn’t easily available, some are dot org plugins are being worked on – see the notes column for more) View this week’s vulnerable plugins list
27 vulnerabilities this week (which means so far in july we’ve had 105 issues), with 4 unfixed. It’s bad week for cache plugins, with WP Super Cache, WP fastest cache and breeze all having fixes. View this week’s vulnerable plugins list The WPCampus 2019 conference is currently happening! Check out the schedule for lots of […]
26 issues this week, with 6 so far unfixed – though Advanced CF7 DB (Advanced Contact form 7 DB) seems to be being worked on. All-in-one migration has multiple issues with one remaining unresolved. View this week’s vulnerable plugins list
Vulnerable Plugins There are twenty nine issues this week, with only one unfixed. The most critical this week are Authenticated (low privileged user) Arbitrary Options Update vulnerability in the One Click SSL plugin (fix available) and in the WPTF Hybrid Composer plugin (fix available), and multiple critical issues in the File Manager (by mndpsingh287) plugin […]
Vulnerable Plugins There are twenty four issues this week, with five unfixed. The most critical this week is an unfixed Authenticated Arbitrary File Upload vulnerability with the MapsSVG Lite plugin and an unfixed Authenticate Remote Code Execution vulnerability in the Newsletter plugin. Both plugins have been closed in the public plugin repository. In addition, there […]
Vulnerable Plugins There are nineteen issues this week, with five unfixed. The most critical this week are two Arbitrary File Upload vulnerabilities in Finale WooCommerce Sale Countdown (fix available) and in LionScripts IP Blocker Lite (unfixed, remove immediately) plugins, an Authenticated Arbitrary File Upload vulnerability in Shipping Servientrega Woocommerce (unfixed, remove immediately), and an Authenticated […]
Vulnerable Plugins There are thirteen issues this week, with five unfixed. The most critical this week is an Arbitrary File Upload vulnerability in Crelly Slider, discovered by NinTechNet. View this week’s vulnerable plugins list.
Vulnerable Plugins There are sixteen issues this week, with two unfixed. The most critical this week are a privilege escalation issue in Slick Popups and an Unauthenticated Administrator Creation vulnerability in Convert Plus. Both issues were discovered by WordFence/Defiant. View this week’s vulnerable plugins list.
Vulnerable Plugins There are fifteen issues this week, with five unfixed. The most critical this week is in WPGraphQL which includes Create administrative users Post comments on articles bypassing article restrictions and global moderation Retrieve content of password-protected posts/articles/pages Retrieve full list of registered users in the platform Retrieve full list of media, comments, themes […]
Vulnerable Plugins There are nineteen issues this week, with five unfixed. The most critical this week is the Sensitive Information Disclosure, Arbitrary File Deletion, and multiple Cross-Site Scripting vulnerabilities in Ultimate Member discovered by Sucri earlier this week. There was also a Local File Inclusion vulnerability disclosed in Photo Gallery by 10Web that does not […]
Vulnerable Plugins Twenty-two issues over the last two weeks, with only two issues unfixed. The most critical updates are the Remote Code Execution vulnerability in the plugins W3 Total Cache, and Kanzu Support Desk and then Arbitrary File Upload vulnerabilities in the plugins Polldeep, User Submitted Posts, and WP Live Chat Support Pro. View this […]