WordPress Plugin Vulnerability Report: EmbedPress – Cross-Site Request Forgery

WP Plugin Vulnerabilities Image - WordPress Plugin Vulnerability Report: EmbedPress - Cross-Site Request Forgery - Vulnerabilities

Plugin Name: EmbedPress Key Information: Software Type: Plugin Software Slug: embedpress Software Status: Active Software Author: wpdevteam Software Downloads: 1,709,151 Active Installs: 80,000 Last Updated: September 8, 2023 Patched Versions: 3.8.4 Affected Versions: <3.8.4 Vulnerability Details: Name: EmbedPress <= 3.8.3 – Cross-Site Request Forgery Type: Cross-Site Request Forgery (CSRF) CVSS Score: 4.3 (Medium) Publicly Published:…

Read More

WordPress Plugin Vulnerability Report: Duplicate Post Page Menu & Custom Post Type – Missing Authorization to Post Duplication – CVE-2023-4792

WP Plugin Vulnerabilities Image - WordPress Plugin Vulnerability Report: Duplicate Post Page Menu & Custom Post Type - Missing Authorization to Post Duplication - CVE-2023-4792 - Vulnerabilities

Plugin Name: Duplicate Post Page Menu & Custom Post Type Key Information: Software Type: Plugin Software Slug: duplicate-post-page-menu-custom-post-type Software Status: Removed Software Author: inqsys Software Downloads: 300,152 Active Installs: 30,000 Last Updated: September 7, 2023 Patched Versions: 2.4.0 Affected Versions: <=2.3.1 Vulnerability Details: Name: Duplicate Post Page Menu & Custom Post Type <= 2.3.1 -…

Read More

WordPress Plugin Vulnerability Report: Starter Templates – Incorrect Authorization – CVE-2023-41805

WP Plugin Vulnerabilities Image - WordPress Plugin Vulnerability Report: Starter Templates - Incorrect Authorization - CVE-2023-41805 - Vulnerabilities

Plugin Name: Starter Templates Key Information: Software Type: Plugin Software Slug: astra-sites Software Status: Active Software Author: brainstormforce Software Downloads: 38,934,354 Active Installs: 1,000,000 Last Updated: September 8, 2023 Patched Versions: 3.2.6 Affected Versions: <=3.2.5 Vulnerability Details: Name: Starter Templates <= 3.2.5 – Incorrect Authorization Type: Missing Authorization CVE: CVE-2023-41805 CVSS Score: 4.3 (Medium) Publicly…

Read More

WordPress Plugin Vulnerability Report: User Feedback – Unauthenticated Stored Cross-Site Scripting – CVE-2023-39308

WP Plugin Vulnerabilities Image - WordPress Plugin Vulnerability Report: User Feedback – Unauthenticated Stored Cross-Site Scripting - CVE-2023-39308 - Vulnerabilities

Plugin Name: User Feedback Key Information: Software Type: Plugin Software Slug: userfeedback-lite Software Status: Active Software Author: smub Software Downloads: 348,588 Active Installs: 100,000 Last Updated: September 7, 2023 Patched Versions: 1.0.8 Affected Versions: <=1.0.7 Vulnerability Details: Name: User Feedback <= 1.0.7 – Unauthenticated Stored Cross-Site Scripting Type: Improper Neutralization of Input During Web Page…

Read More

Broken Website Emergency: First Steps to Diagnose and Fix

error office and hands typing on a laptop working 2023 02 15 00 41 42 utc - Broken Website Emergency: First Steps to Diagnose and Fix - Vulnerabilities

It’s every business owner’s nightmare – you wake up one morning to find your website is down. Or even worse, it’s up but full of glaring errors. Customers are complaining they can’t access your site or complete purchases. Your daily traffic has plummeted. Panic sets in. What caused this? Who can fix it? How quickly…

Read More

What are Abandoned WordPress Plugins?

inside of an abandoned warehouse - What are Abandoned WordPress Plugins? - Vulnerabilities

Imagine you own a small online business. You built your website on WordPress and installed a few plugins to add useful features like contact forms, social sharing buttons, and SEO optimization. These plugins worked great initially. But over time some of them have stopped receiving updates. The developers seem to have abandoned these plugins altogether.…

Read More