WordPress Plugin Vulnerability Report – SiteOrigin Widgets Bundle – Authenticated (Admin+) Local File Inclusion – CVE-2023-6295

WP Plugin Vulnerabilities Image - WordPress Plugin Vulnerability Report - SiteOrigin Widgets Bundle - Authenticated (Admin+) Local File Inclusion - CVE-2023-6295 - Vulnerabilities

Plugin Name: SiteOrigin Widgets Bundle Key Information: Software Type: Plugin Software Slug: so-widgets-bundle Software Status: Active Software Author: gpriday Software Downloads: 36,509,376 Active Installs: 600,000 Last Updated: November 27, 2023 Patched Versions: 1.51.0 Affected Versions: <= 1.50.1 Vulnerability Details: Name: SiteOrigin Widgets Bundle < 1.51.0 – Authenticated (Admin+) Local File Inclusion Title: Authenticated (Admin+) Local File Inclusion Type: Improper Control of Filename for Include/Require Statement in PHP…

Read More

When Uptime Matters, Your WP Guy Delivers for WordPress Sites

Uptime Video 5 - When Uptime Matters, Your WP Guy Delivers for WordPress Sites - Vulnerabilities

Tired of Your Website Going Down? Learn How This Company Keeps Sites Up 99.9% of the Time Frustrated by a slow, unreliable website plagued by constant downtime? In this revealing interview, Jonathan Wofford, founder of Your WP Guy, pulls back the curtain on their foolproof system for nearly perfect WordPress uptime. Leveraging proactive 24/7 monitoring,…

Read More

WordPress Plugin Vulnerability Report – HUSKY – Missing Authorization via woof_meta_get_keys() – CVE-2023-40334

WP Plugin Vulnerabilities Image - WordPress Plugin Vulnerability Report - HUSKY - Missing Authorization via woof_meta_get_keys() - CVE-2023-40334 - Vulnerabilities

Plugin Name: HUSKY Key Information: Software Type: Plugin Software Slug: woocommerce-products-filter Software Status: Active Software Author: realmag777 Software Downloads: 1,602,499 Active Installs: 100,000 Last Updated: November 23, 2023 Patched Versions: 1.3.4.3 Affected Versions: <= 1.3.4.2 Vulnerability Details: Name: HUSKY – Products Filter for WooCommerce (formerly WOOF) <= 1.3.4.2 – Missing Authorization via woof_meta_get_keys() Title: Missing Authorization via woof_meta_get_keys() Type: Missing Authorization CVE: CVE-2023-40334 CVSS Score: 4.3 (Medium) Publicly Published: November…

Read More

WordPress Plugin Vulnerability Report – BackWPup – Authenticated (Administrator+) Directory Traversal – CVE-2023-5504

WP Plugin Vulnerabilities Image - WordPress Plugin Vulnerability Report - BackWPup - Authenticated (Administrator+) Directory Traversal - CVE-2023-5504 - Vulnerabilities

Plugin Name: BackWPup Key Information: Software Type: Plugin Software Slug: backwpup Software Status: Active Software Author: wp_media Software Downloads: 13,284,859 Active Installs: 600,000 Last Updated: November 22, 2023 Patched Versions: 4.0.2 Affected Versions: <= 4.0.1 Vulnerability Details: Name: BackWPup <= 4.0.1 – Authenticated (Administrator+) Directory Traversal Title: Authenticated (Administrator+) Directory Traversal Type: Improper Limitation of a Pathname to a Restricted Directory (‘Path Traversal’) CVE: CVE-2023-5504 CVSS Score: 8.7 (High)…

Read More

WordPress Plugin Vulnerability Report – Widgets for Google Reviews – Authenticated (Editor+) Arbitrary File Upload – CVE-2023-48275

WP Plugin Vulnerabilities Image - WordPress Plugin Vulnerability Report - Widgets for Google Reviews - Authenticated (Editor+) Arbitrary File Upload - CVE-2023-48275 - Vulnerabilities

Plugin Name: Widgets for Google Reviews Key Information: Software Type: Plugin Software Slug: wp-reviews-plugin-for-google Software Status: Active Software Author: trustindex Software Downloads: 4,619,317 Active Installs: 300,000 Last Updated: November 22, 2023 Patched Versions: 11.1 Affected Versions: <= 11.0.2 Vulnerability Details: Name: Widgets for Google Reviews <= 11.0.2 – Authenticated (Editor+) Arbitrary File Upload Title: Authenticated…

Read More

WordPress Plugin Vulnerability Report – Abandoned Cart Lite for WooCommerce – Improper Authorization Vulnerabilities

WP Plugin Vulnerabilities Image - WordPress Plugin Vulnerability Report - Abandoned Cart Lite for WooCommerce - Improper Authorization Vulnerabilities - Vulnerabilities

Plugin Name: Abandoned Cart Lite for WooCommerce Key Information: Software Type: Plugin Software Slug: woocommerce-abandoned-cart Software Status: Active Software Author: tychesoftwares Software Downloads: 995,970 Active Installs: 30,000 Last Updated: November 21, 2023 Patched Versions: 5.16.1 Affected Versions: < 5.16.1 Vulnerability Details: Name: Abandoned Cart Lite for WooCommerce <= 5.16.0 – Improper Authorization via wcal_delete_expired_used_coupon_code Title:…

Read More

How to Evaluate Your Website’s Hosting Needs: A Step-by-Step Guide

server room interior in datacenter 3d render 2022 12 16 12 01 13 utc - How to Evaluate Your Website's Hosting Needs: A Step-by-Step Guide - Vulnerabilities

Imagine this: It’s Black Friday, and your e-commerce site is primed for unprecedented traffic. Orders are pouring in when suddenly…website crashed! Server overloaded! The horror is mounting as your site remains down right in the thick of peak sales season. This is the nightmare reality for many businesses with websites hosted on inappropriate plans unable…

Read More

WordPress Plugin Vulnerability Report – Analytify – Cross-Site Request Forgery

WP Plugin Vulnerabilities Image - WordPress Plugin Vulnerability Report - Analytify - Cross-Site Request Forgery - Vulnerabilities

Plugin Name: Analytify Key Information: Software Type: Plugin Software Slug: wp-analytify Software Status: Active Software Author: hiddenpearls Software Downloads: 1,817,063 Active Installs: 40,000 Last Updated: November 20, 2023 Patched Versions: 5.2.0 Affected Versions: <= 5.1.0 Vulnerability Details: Name: Analytify Dashboard <= 5.1.0 – Cross-Site Request Forgery Title: Cross-Site Request Forgery Type: Cross-Site Request Forgery (CSRF) CVSS Score: 4.3 (Medium) Publicly Published: November 20, 2023 Description: The Analytify – Google Analytics…

Read More

Your WP Guy Promises Prompt WordPress Assistance, Not Endless Waiting

Client Communication Video 6 - Your WP Guy Promises Prompt WordPress Assistance, Not Endless Waiting - Vulnerabilities

 Do You Struggle With Slow WordPress Support? Watch This Interview With the Founder of Your WP Guy In this candid interview, Jonathan Wofford, founder of Your WP Guy, shares insider tips on their exceptional WordPress support and communication with clients. He outlines the monthly reporting to summarize website activities and prompt responses to support…

Read More