Vulnerabilities

Instant Images Vulnerability– One Click Image Uploads from Unsplash, Openverse, Pixabay, and Pexels – Authenticated (Author+) Arbitrary Options Update – CVE-2024-0869 |WordPress Plugin Vulnerability Report

By Your WP Guy / Jan 29, 2024

Plugin Name: Instant Images – One Click Image Uploads from Unsplash, Openverse, Pixabay, and Pexels Key Information: Software Type: Plugin Software Slug: instant-images Software Status: Active Software Author: connekthq Software Downloads: 1,803,436 Active Installs: 100,000 Last Updated: February 2, 2024 Patched Versions: 6.1.1 Affected Versions: <= 6.1.0 Vulnerability Details: Name: Instant Images <= 6.1.0 Title:…

MapPress Maps for WordPress Vulnerability- Authenticated (Contributor+) Stored Cross-Site Scripting – CVE-2023-7225 |WordPress Plugin Vulnerability Report

By Your WP Guy / Jan 29, 2024

Plugin Name: MapPress Maps for WordPress Key Information: Software Type: Plugin Software Slug: mappress-google-maps-for-wordpress Software Status: Active Software Author: chrisvrichardson Software Downloads: 4,193,183 Active Installs: 50,000 Last Updated: February 2, 2024 Patched Versions: 2.88.17 Affected Versions: <= 2.88.16 Vulnerability Details: Name: MapPress <= 2.88.16 Title: Authenticated (Contributor+) Stored Cross-Site Scripting via Map Settings Type: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N…

SEO Plugin by Squirrly SEO Vulnerability- Authenticated (Administrator+) Stored Cross-Site Scripting – CVE-2024-0597 |WordPress Plugin Vulnerability Report

By Your WP Guy / Jan 29, 2024

Plugin Name: SEO Plugin by Squirrly SEO Key Information: Software Type: Plugin Software Slug: squirrly-seo Software Status: Active Software Author: cifi Software Downloads: 4,689,778 Active Installs: 200,000 Last Updated: February 2, 2024 Patched Versions: 12.3.16 Affected Versions: <= 12.3.15 Vulnerability Details: Name: SEO Plugin by Squirrly SEO <= 12.3.15 Title: Authenticated (Administrator+) Stored Cross-Site Scripting…

Formidable Forms Vulnerability– Contact Form, Survey, Quiz, Payment, Calculator Form & Custom Form Builder – Cross-Site Request Forgery to Stored Cross-Site Scripting – CVE-2024-0660 |WordPress Plugin Vulnerability Report

By Your WP Guy / Jan 26, 2024

Plugin Name: Formidable Forms – Contact Form, Survey, Quiz, Payment, Calculator Form & Custom Form Builder Key Information: Software Type: Plugin Software Slug: formidable Software Status: Active Software Author: strategy11team Software Downloads: 19,521,336 Active Installs: 300,000 Last Updated: January 30, 2024 Patched Versions: 6.8 Affected Versions: <= 6.7.2 Vulnerability Details: Name: Formidable Forms <= 6.7.2…

WP Dashboard Notes Vulnerability- Missing Authorization to Arbitrary Private Notes Update – CVE-2023-7239 |WordPress Plugin Vulnerability Report

By Your WP Guy / Jan 26, 2024

Plugin Name: WP Dashboard Notes Key Information: Software Type: Plugin Software Slug: wp-dashboard-notes Software Status: Active Software Author: sormano Software Downloads: 176,276 Active Installs: 30,000 Last Updated: January 30, 2024 Patched Versions: 1.0.10 Affected Versions: <= 1.0.10 Vulnerability Details: Name: WP Dashboard Notes <= 1.0.10 Title: Missing Authorization to Arbitrary Private Notes Update Type: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N…

SiteOrigin Widgets Bundle Vulnerability- Authenticated (Contributor+) Stored Cross-Site Scripting – CVE-2024-0961 |WordPress Plugin Vulnerability Report

By Your WP Guy / Jan 26, 2024

Plugin Name: SiteOrigin Widgets Bundle Key Information: Software Type: Plugin Software Slug: so-widgets-bundle Software Status: Active Software Author: gpriday Software Downloads: 37,152,267 Active Installs: 600,000 Last Updated: February 1, 2024 Patched Versions: 1.58.2 Affected Versions: <= 1.58.1 Vulnerability Details: Name: SiteOrigin Widgets Bundle <= 1.58.1 Title: Authenticated (Contributor+) Stored Cross-Site Scripting Type: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N CVE: CVE-2024-0961…

Backuply Vulnerability– Backup, Restore, Migrate and Clone – Authenticated (Administrator+) Directory Traversal – CVE-2024-0697 |WordPress Plugin Vulnerability Report 

By Your WP Guy / Jan 26, 2024

Plugin Name: Backuply – Backup, Restore, Migrate and Clone Key Information: Software Type: Plugin Software Slug: backuply Software Status: Active Software Author: Softaculous Software Downloads: 1,893,554 Active Installs: 200,000 Last Updated: February 1, 2024 Patched Versions: 1.2.4 Affected Versions: <= 1.2.3 Vulnerability Details: Name: Backuply – Backup, Restore, Migrate and Clone <= 1.2.3 Title: Authenticated…

Exclusive Addons for Elementor Vulnerability- Stored Cross-Site Scripting Vulnerabilities – CVE-2024-0824 & CVE-2024-0823 |WordPress Plugin Vulnerability Report 

By Your WP Guy / Jan 26, 2024

Plugin Name: Exclusive Addons for Elementor Key Information: Software Type: Plugin Software Slug: exclusive-addons-for-elementor Software Status: Active Software Author: timstrifler Software Downloads: 688,917 Active Installs: 50,000 Last Updated: February 1, 2024 Patched Versions: 2.6.9 Affected Versions: <= 2.6.8 Vulnerability Details (Section 1): Name: Exclusive Addons for Elementor <= 2.6.8 Title: Authenticated (Contributor+) Stored Cross-Site Scripting…

Form Maker by 10Web Vulnerability– Mobile-Friendly Drag & Drop Contact Form Builder – Cross-Site Request Forgery to Limited Code Execution via Execute – CVE-2024-0667 |WordPress Plugin Vulnerability Report

By Your WP Guy / Jan 26, 2024

Plugin Name: Form Maker by 10Web – Mobile-Friendly Drag & Drop Contact Form Builder Key Information: Software Type: Plugin Software Slug: form-maker Software Status: Active Software Author: 10web Software Downloads: 4,670,950 Active Installs: 60,000 Last Updated: February 1, 2024 Patched Versions: 1.15.22 Affected Versions: <= 1.15.21 Vulnerability Details: Name: Form-Maker (twb_form-maker) <= 1.15.21 Title: Cross-Site…

10Web AI Assistant Vulnerability – AI Content Writing Assistant – Missing Authorization to Arbitrary Plugin Installation – CVE-2023-6985 |WordPress Plugin Vulnerability Report 

By Your WP Guy / Jan 25, 2024

Plugin Name: 10Web AI Assistant – AI Content Writing Assistant Key Information: Software Type: Plugin Software Slug: ai-assistant-by-10web Software Status: Active Software Author: 10web Software Downloads: 20,225 Active Installs: 30,000 Last Updated: January 30, 2024 Patched Versions: 1.0.19 Affected Versions: <= 1.0.18 Vulnerability Details: Name: 10Web AI Assistant – AI Content Writing Assistant <= 1.0.18…