Security

Translate WordPress and go Multilingual Vulnerability– Weglot – Authenticated (Contributor+) Stored Cross-Site Scripting via Block Attributes – CVE-2024-2124 | WordPress Plugin Vulnerability Report

By Your WP Guy / Mar 18, 2024

Plugin Name: Translate WordPress and go Multilingual – Weglot Key Information: Software Type: Plugin Software Slug: weglot Software Status: Active Software Author: remyb92 Software Downloads: 2,296,771 Active Installs: 60,000 Last Updated: March 19, 2024 Patched Versions: 4.2.6 Affected Versions: <= 4.2.5 Vulnerability Details: Name: Translate WordPress and go Multilingual – Weglot <= 4.2.5 Title: Authenticated…

Permalink Manager Pro Vulnerability – Missing Authorization to Authenticated (Author+) Arbitrary Post Slug Modification – CVE-2024-2538 | WordPress Plugin Vulnerability Report

By Your WP Guy / Mar 18, 2024

Plugin Name: Permalink Manager Pro Key Information: Software Type: Plugin Software Slug: permalink-manager Software Status: Active Software Author: mbis Software Downloads: 1,661,826 Active Installs: 80,000 Last Updated: March 19, 2024 Patched Versions: 2.4.3.2 Affected Versions: <= 2.4.3.1 Vulnerability Details: Name: Permalink Manager <= 2.4.3.1 Title: Missing Authorization to Authenticated (Author+) Arbitrary Post Slug Modification Type:…

Qi Addons For Elementor Vulnerability – Authenticated (Contributor+) Stored Cross-Site Scripting – CVE-2024-0826 | WordPress Plugin Vulnerability Report

By Your WP Guy / Mar 15, 2024

Plugin Name: Qi Addons For Elementor Key Information: Software Type: Plugin Software Slug: qi-addons-for-elementor Software Status: Active Software Author: qodeinteractive Software Downloads: 1,685,695 Active Installs: 100,000 Last Updated: March 19, 2024 Patched Versions: 1.6.8 Affected Versions: <= 1.6.7 Vulnerability Details: Name: Qi Addons For Elementor <= 1.6.7 Title: Authenticated (Contributor+) Stored Cross-Site Scripting Type: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N…

Backuply Vulnerability– Backup, Restore, Migrate and Clone – Authenticated (Admin+) Directory Traversal – CVE-2024-2294 | WordPress Plugin Vulnerability Report

By Your WP Guy / Mar 15, 2024

Plugin Name: Backuply – Backup, Restore, Migrate and Clone Key Information: Software Type: Plugin Software Slug: backuply Software Status: Active Software Author: softaculous Software Downloads: 2,266,088 Active Installs: 200,000 Last Updated: March 19, 2024 Patched Versions: 1.2.8 Affected Versions: <= 1.2.7 Vulnerability Details: Name: Backuply – Backup, Restore, Migrate and Clone <= 1.2.7 Title: Authenticated…

ElementsKit Elementor addons Vulnerability – Authenticated (Contributor+) Stored Cross-Site Scripting – CVE-2024-1239 | WordPress Plugin Vulnerability Report

By Your WP Guy / Mar 15, 2024

Plugin Name: ElementsKit Elementor addons Key Information: Software Type: Plugin Software Slug: elementskit-lite Software Status: Active Software Author: xspeedstudio Software Downloads: 16,983,084 Active Installs: 1,000,000 Last Updated: March 19, 2024 Patched Versions: 3.0.5 Affected Versions: <= 3.0.4 Vulnerability Details: Name: ElementsKit Elementor addons <= 3.0.4 Title: Authenticated (Contributor+) Stored Cross-Site Scripting Type: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N CVE: CVE-2024-1239…

Everest Forms Vulnerability- Unauthenticated Server-Side Request Forgery via font_url – CVE-2024-1812 | WordPress Plugin Vulnerability Report

By Your WP Guy / Mar 15, 2024

Plugin Name: Everest Forms – Build Contact Forms, Surveys, Polls, Quizzes, Newsletter & Application Forms, and Many More with Ease! Key Information: Software Type: Plugin Software Slug: everest-forms Software Status: Active Software Author: wpeverest Software Downloads: 5,605,349 Active Installs: 100,000 Last Updated: March 19, 2024 Patched Versions: 2.0.8 Affected Versions: <= 2.0.7 Vulnerability Details: Name:…

HT Mega Vulnerability– Absolute Addons For Elementor – Authenticated Directory Traversal – CVE-2024-1974 |WordPress Plugin Vulnerability Report

By Your WP Guy / Mar 14, 2024

Plugin Name: HT Mega – Absolute Addons For Elementor Key Information: Software Type: Plugin Software Slug: ht-mega-for-elementor Software Status: Active Software Author: devitemsllc Software Downloads: 3,604,562 Active Installs: 100,000 Last Updated: March 14, 2024 Patched Versions: 2.4.7 Affected Versions: <= 2.4.6 Vulnerability Details: Name: HT Mega – Absolute Addons For Elementor <= 2.4.6 Title: Authenticated…

HUSKY Vulnerability– Products Filter Professional for WooCommerce – Authenticated Stored Cross-Site Scripting via Shortcode – CVE-2024-1796 | WordPress Plugin Vulnerability Report 

By Your WP Guy / Mar 14, 2024

Plugin Name: HUSKY – Products Filter Professional for WooCommerce Key Information: Software Type: Plugin Software Slug: woocommerce-products-filter Software Status: Active Software Author: realmag777 Software Downloads: 1,674,101 Active Installs: 100,000 Last Updated: March 14, 2024 Patched Versions: 1.3.5.2 Affected Versions: <= 1.3.5.1 Vulnerability Details: Name: HUSKY – Products Filter for WooCommerce Professional <= 1.3.5.1 Title: Authenticated…

ShopLentor Vulnerability – WooCommerce Builder for Elementor & Gutenberg +12 Modules – All in One Solution (formerly WooLentor) – Authenticated Stored Cross-Site Scripting via Banner Link – CVE-2024-1960 | WordPress Plugin Vulnerability Report

By Your WP Guy / Mar 14, 2024

Plugin Name: ShopLentor – WooCommerce Builder for Elementor & Gutenberg +12 Modules – All in One Solution (formerly WooLentor) Key Information: Software Type: Plugin Software Slug: woolentor-addons Software Status: Active Software Author: devitemsllc Software Downloads: 3,272,321 Active Installs: 100,000 Last Updated: March 14, 2024 Patched Versions: 2.8.2 Affected Versions: <= 2.8.1 Vulnerability Details: Name: ShopLentor…

Contact Form 7 Vulnerability – Reflected Cross-Site Scripting – CVE-2024-2242 | WordPress Plugin Vulnerability Report

By Your WP Guy / Mar 13, 2024

Plugin Name: Contact Form 7 Key Information: Software Type: Plugin Software Slug: contact-form-7 Software Status: Active Software Author: takayukister Software Downloads: 318,916,329 Active Installs: 5,000,000 Last Updated: March 14, 2024 Patched Versions: 5.9.2 Affected Versions: <= 5.9 Vulnerability Details: Name: Contact Form 7 <= 5.9 Title: Reflected Cross-Site Scripting Type: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N CVE: CVE-2024-2242 CVSS Score:…