cybersecurity best practices

Smash Balloon Social Post Feed Vulnerability – Cross-Site Request Forgery – CVE-2024-31379 | WordPress Plugin Vulnerability Report

By Your WP Guy / Apr 10, 2024

Plugin Name: Smash Balloon Social Post Feed Key Information: Software Type: Plugin Software Slug: custom-facebook-feed Software Status: Active Software Author: smub Software Downloads: 7,212,481 Active Installs: 200,000 Last Updated: April 22, 2024 Patched Versions: 4.2.2 Affected Versions: <= 4.2.1 Vulnerability Details: Name: Smash Balloon Social Post Feed <= 4.2.1 Title: Cross-Site Request Forgery Type: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N…

Read More

WP Encryption Vulnerability – One Click Free SSL Certificate & SSL / HTTPS Redirect to Force HTTPS – Sensitive Information Exposure via Insufficiently Protected Files – CVE-2023-7046 | WordPress Plugin Vulnerability Report

By Your WP Guy / Apr 9, 2024

Plugin Name: WP Encryption – One Click Free SSL Certificate & SSL / HTTPS Redirect to Force HTTPS, Security+ Key Information: Software Type: Plugin Software Slug: wp-letsencrypt-ssl Software Status: Active Software Author: gowebsmarty Software Downloads: 2,018,679 Active Installs: 60,000 Last Updated: April 16, 2024 Patched Versions: 7.1.0 Affected Versions: <= 7.0 Vulnerability Details: Name: WP…

Read More

Starbox Vulnerability– the Author Box for Humans – Authenticated (Subscriber+) Stored Cross-Site Scripting via Job Settings – CVE-2023-6806 | WordPress Plugin Vulnerability Report 

By Your WP Guy / Feb 6, 2024

Plugin Name: Starbox – the Author Box for Humans Key Information: Software Type: Plugin Software Slug: starbox Software Status: Active Software Author: cifi Software Downloads: 449,615 Active Installs: 50,000 Last Updated: February 13, 2024 Patched Versions: 3.5.0 Affected Versions: <= 3.4.8 Vulnerability Details: Name: Starbox <= 3.4.8 Title: Authenticated (Subscriber+) Stored Cross-Site Scripting via Job…

Read More