SpeedyCache Vulnerability – Missing Authorization to Plugin Options Update – CVE-2023-6598 | WordPress Plugin Vulnerability Report

WP Plugin Vulnerabilities Image - SpeedyCache Vulnerability - Missing Authorization to Plugin Options Update - CVE-2023-6598 | WordPress Plugin Vulnerability Report - Vulnerabilities

Plugin Name: SpeedyCache Key Information: Software Type: Plugin Software Slug: speedycache Software Status: Active Software Author: softaculous Software Downloads: 861,450 Active Installs: 100,000 Last Updated: December 16, 2023 Patched Versions: 1.1.4 Affected Versions: <= 1.1.3 Vulnerability Details: Name: SpeedyCache <= 1.1.3 – Missing Authorization to Plugin Options Update Type: Missing Authorization CVE: CVE-2023-6598 CVSS Score: 4.3 (Medium) Publicly Published: December 16, 2023 Researcher: Lucio Sá Description: The SpeedyCache plugin for WordPress…

Read More

Post Grid Combo Vulnerability – Authenticated (Contributor+) Cross-Site Scripting – CVE-2023-6645 | WordPress Plugin Vulnerability Report

WP Plugin Vulnerabilities Image - Post Grid Combo Vulnerability - Authenticated (Contributor+) Cross-Site Scripting - CVE-2023-6645 | WordPress Plugin Vulnerability Report - Vulnerabilities

Plugin Name: Post Grid Combo Key Information: Software Type: Plugin Software Slug: post-grid Software Status: Active Software Author: pickplugins Software Downloads: 2,566,872 Active Installs: 50,000 Last Updated: December 15, 2023 Patched Versions: 2.2.65 Affected Versions: <= 2.2.64 Vulnerability Details: Name: Post Grid Combo – 36+ Gutenberg Blocks <= 2.2.64 – Authenticated (Contributor+) Cross-Site Scripting Title: Authenticated (Contributor+) Cross-Site Scripting Type: Improper Neutralization of Script-Related HTML Tags in…

Read More

MW WP Form Vulnerability – Improper Limitation of File Name to Unauthenticated Arbitrary File Deletion – CVE-2023-6559 | WordPress Plugin Vulnerability Report

WP Plugin Vulnerabilities Image - MW WP Form Vulnerability - Improper Limitation of File Name to Unauthenticated Arbitrary File Deletion - CVE-2023-6559 | WordPress Plugin Vulnerability Report - Vulnerabilities

Plugin Name: MW WP Form Key Information: Software Type: Plugin Software Slug: mw-wp-form Software Status: Active Software Author: inc2734 Software Downloads: 1,536,050 Active Installs: 200,000 Last Updated: December 15, 2023 Patched Versions: 5.0.4 Affected Versions: <= 5.0.3 Vulnerability Details: Name: MW WP Form <= 5.0.3 – Improper Limitation of File Name to Unauthenticated Arbitrary File Deletion Title: Improper Limitation of File Name to Unauthenticated Arbitrary File…

Read More

Featured Image from URL Vulnerability – Authenticated (Contributor+) Stored Cross-Site Scripting via featured image alt text – CVE-2023-6561 | WordPress Plugin Vulnerability Report

WP Plugin Vulnerabilities Image - Featured Image from URL Vulnerability - Authenticated (Contributor+) Stored Cross-Site Scripting via featured image alt text - CVE-2023-6561 | WordPress Plugin Vulnerability Report - Vulnerabilities

Plugin Name: Featured Image from URL Key Information: Software Type: Plugin Software Slug: featured-image-from-url Software Status: Active Software Author: marceljm Software Downloads: 4,535,007 Active Installs: 90,000 Last Updated: December 14, 2023 Patched Versions: NA Affected Versions: <= 4.5.3 Vulnerability Details: Name: Featured Image from URL (FIFU) <= 4.5.3 – Authenticated (Contributor+) Stored Cross-Site Scripting via featured image alt text Title: Authenticated (Contributor+) Stored Cross-Site Scripting via…

Read More

WordPress Plugin Vulnerability Report – Export and Import Users and Customers – Authenticated (Shop Manager+) Arbitrary File Upload – CVE-2023-6558

WP Plugin Vulnerabilities Image - WordPress Plugin Vulnerability Report - Export and Import Users and Customers - Authenticated (Shop Manager+) Arbitrary File Upload - CVE-2023-6558 - Vulnerabilities

Plugin Name: Export and Import Users and Customers Key Information: Software Type: Plugin Software Slug: users-customers-import-export-for-wp-woocommerce Software Status: Active Software Author: webtoffee Software Downloads: 2,025,020 Active Installs: 70,000 Last Updated: December 12, 2023 Patched Versions: 2.4.9 Affected Versions: <= 2.4.8 Vulnerability Details: Name: Export and Import Users and Customers <= 2.4.8 – Authenticated (Shop Manager+) Arbitrary File Upload Title: Authenticated (Shop Manager+) Arbitrary File Upload Type: Unrestricted…

Read More

Demystifying the Backend: A Layman’s Guide to Website Technicalities

information server 2023 11 27 04 49 52 utc - Demystifying the Backend: A Layman’s Guide to Website Technicalities - Vulnerabilities

Website technicalities often seem utterly bewildering to the average small business owner. You built your site, filled it with stellar content, and want to focus on your actual business, not the perplexing intricacies behind the scenes. But whether you pay attention or not, those complex backend functions have a huge impact on your site’s speed,…

Read More

WordPress Plugin Vulnerability Report – Backup Migration – Unauthenticated Remote Code Execution – CVE-2023-6553

WP Plugin Vulnerabilities Image - WordPress Plugin Vulnerability Report - Backup Migration - Unauthenticated Remote Code Execution - CVE-2023-6553 - Vulnerabilities

Plugin Name: Backup Migration Key Information: Software Type: Plugin Software Slug: backup-backup Software Status: Active Software Author: migrate Software Downloads: 1,095,099 Active Installs: 90,000 Last Updated: December 11, 2023 Patched Versions: 1.3.8 Affected Versions: <= 1.3.7 Vulnerability Details: Name: Backup Migration <= 1.3.7 – Unauthenticated Remote Code Execution Type: Improper Control of Generation of Code (‘Code Injection’) CVE: CVE-2023-6553 CVSS Score: 9.8 (Critical) Publicly Published: December 11, 2023 Researcher: Nex…

Read More

WordPress Plugin Vulnerability Report – Import and export users and customers – Authenticated(Contributor+) Stored Cross-Site Scripting via shortcode – CVE-2023-6624

WP Plugin Vulnerabilities Image - WordPress Plugin Vulnerability Report - Import and export users and customers - Authenticated(Contributor+) Stored Cross-Site Scripting via shortcode - CVE-2023-6624 - Vulnerabilities

Plugin Name: Import and export users and customers Key Information: Software Type: Plugin Software Slug: import-users-from-csv-with-meta Software Status: Active Software Author: carazo Software Downloads: 3,901,440 Active Installs: 80,000 Last Updated: December 11, 2023 Patched Versions: Affected Versions: Vulnerability Details: Name: Import and export users and customers <= 1.24.3 – Authenticated(Contributor+) Stored Cross-Site Scripting via shortcode Title: Authenticated(Contributor+) Stored Cross-Site Scripting via shortcode Type: Improper Neutralization…

Read More

How Your WP Guy Guards Against Sneaky WordPress Malware

Malware Protection Video 3 - How Your WP Guy Guards Against Sneaky WordPress Malware - Vulnerabilities

This Scary Loophole Leaves Most WordPress Sites Wide Open to Hackers Think your WordPress site is safe just because it has an active security plugin? Think again. In this bombshell interview, Your WP Guy founder Jonathan Wofford explains how a dangerous software blind spot allows hackers to breach websites right under most hosts’ noses. Jonathan…

Read More

WordPress Plugin Vulnerability Report – Google Language Translator – Missing Authorization to Notice Dismissal

WP Plugin Vulnerabilities Image - WordPress Plugin Vulnerability Report - Google Language Translator - Missing Authorization to Notice Dismissal - Vulnerabilities

Plugin Name: Google Language Translator Key Information: Software Type: Plugin Software Slug: google-language-translator Software Status: Active Software Author: edo888 Software Downloads: 3,145,040 Active Installs: 100,000 Last Updated: December 8, 2023 Patched Versions: 6.0.20 Affected Versions: < 6.0.20 Vulnerability Details: Name: Google Language Translator <= 6.0.20 – Missing Authorization to Notice Dismissal Type: Missing Authorization CVSS Score: 5.3 (Medium) Publicly Published: December 8, 2023 Description: The Translate WordPress – Google…

Read More