Vulnerable Plugins There are twenty issues this week, with three unfixed. The most critical this week are an Arbitrary Settings Update vulnerability in Real Estate Manager (unfixed), a Cross-Site Request Forgery vulnerability that can lead to an Arbitrary File Upload in LionScripts: IP Blocker Lite (fix available), and a Cross-Site Request Forgery vulnerability that can […]
The WPCampus Blog
Vulnerable Plugins There are nineteen issues this week, with five unfixed. The most critical this week are two Arbitrary File Upload vulnerabilities in Finale WooCommerce Sale Countdown (fix available) and in LionScripts IP Blocker Lite (unfixed, remove immediately) plugins, an Authenticated Arbitrary File Upload vulnerability in Shipping Servientrega Woocommerce (unfixed, remove immediately), and an Authenticated […]
Vulnerable Plugins There are thirteen issues this week, with five unfixed. The most critical this week is an Arbitrary File Upload vulnerability in Crelly Slider, discovered by NinTechNet. View this week’s vulnerable plugins list.
Vulnerable Plugins There are sixteen issues this week, with two unfixed. The most critical this week are a privilege escalation issue in Slick Popups and an Unauthenticated Administrator Creation vulnerability in Convert Plus. Both issues were discovered by WordFence/Defiant. View this week’s vulnerable plugins list.
Vulnerable Plugins There are fifteen issues this week, with five unfixed. The most critical this week is in WPGraphQL which includes Create administrative users Post comments on articles bypassing article restrictions and global moderation Retrieve content of password-protected posts/articles/pages Retrieve full list of registered users in the platform Retrieve full list of media, comments, themes […]
The WPCampus community is delighted to announce our official Diversity, Equity, and Inclusion statement. This statement came from a desire by the WPCampus leadership to prioritize issues of equity and diversity. As many of you know, accessibility is a major focus for our initiatives and events. We believe that accessibility can only be achieved through […]
Vulnerable Plugins There are nineteen issues this week, with five unfixed. The most critical this week is the Sensitive Information Disclosure, Arbitrary File Deletion, and multiple Cross-Site Scripting vulnerabilities in Ultimate Member discovered by Sucri earlier this week. There was also a Local File Inclusion vulnerability disclosed in Photo Gallery by 10Web that does not […]
Vulnerable Plugins Twenty-two issues over the last two weeks, with only two issues unfixed. The most critical updates are the Remote Code Execution vulnerability in the plugins W3 Total Cache, and Kanzu Support Desk and then Arbitrary File Upload vulnerabilities in the plugins Polldeep, User Submitted Posts, and WP Live Chat Support Pro. View this […]
WPCampus is excited to announce that our accessibility testing vendor, Tenon LLC, will host a public webinar and question-and-answer session to discuss the results of the Gutenberg accessibility audit. The webinar will take place Monday, May 13, 2019 at 12:00 PM CDT. You must register to attend.
In late 2018, WPCampus released a request for proposals to conduct an accessibility audit of the WordPress block editor, also known as Gutenberg. In early 2019, we announced our selection of Tenon, LLC to conduct the audit. We are excited to share the results of the Gutenberg accessibility audit.