cybersecurity for small businesses

Forminator Vulnerability – Contact Form, Payment Form & Custom Form Builder – Authenticated (Contributor+) Stored Cross-Site Scripting via forminator_form Shortcode – CVE-2024-3053 | WordPress Plugin Vulnerability Report

By Your WP Guy / Apr 8, 2024

Plugin Name: Forminator – Contact Form, Payment Form & Custom Form Builder Key Information: Software Type: Plugin Software Slug: forminator Software Status: Active Software Author: wpmudev Software Downloads: 6,757,114 Active Installs: 500,000 Last Updated: April 16, 2024 Patched Versions: 1.29.3 Affected Versions: <= 1.29.2 Vulnerability Details: Name: Forminator – Contact Form, Payment Form & Custom…

Read More

Unlimited Elements For Elementor (Free Widgets, Addons, Templates) Vulnerability – Authenticated (Contributor+) Stored Cross-Site Scripting via Widget Link – CVE-2024-0367 | WordPress Plugin Vulnerability Report

By Your WP Guy / Mar 29, 2024

Plugin Name: Unlimited Elements For Elementor (Free Widgets, Addons, Templates) Key Information: Software Type: Plugin Software Slug: unlimited-elements-for-elementor Software Status: Active Software Author: unitecms Software Downloads: 7,783,251 Active Installs: 200,000 Last Updated: April 1, 2024 Patched Versions: 1.5.97 Affected Versions: <= 1.5.96 Vulnerability Details: Name: Unlimited Elements For Elementor <= 1.5.96 Title: Authenticated (Contributor+) Stored…

Read More

WP Chat App Vulnerability – Authenticated (Contributor+) Stored Cross-Site Scripting via Block Image Attribute – CVE-2024-2513 |WordPress Plugin Vulnerability Report

By Your WP Guy / Mar 29, 2024

Plugin Name: WP Chat App Key Information: Software Type: Plugin Software Slug: wp-whatsapp Software Status: Active Software Author: ninjateam Software Downloads: 950,913 Active Installs: 100,000 Last Updated: April 1, 2024 Patched Versions: 3.6.3 Affected Versions: <= 3.6.2 Vulnerability Details: Name: WP Chat App <= 3.6.2 Title: Authenticated (Contributor+) Stored Cross-Site Scripting via Block Image Attribute…

Read More

HUSKY Vulnerability – Products Filter Professional for WooCommerce – Authenticated (Admin+) Local File Inclusion – CVE-2024-3061 | WordPress Plugin Vulnerability Report

By Your WP Guy / Mar 28, 2024

Plugin Name: HUSKY – Products Filter Professional for WooCommerce Key Information: Software Type: Plugin Software Slug: woocommerce-products-filter Software Status: Active Software Author: realmag777 Software Downloads: 1,693,230 Active Installs: 100,000 Last Updated: April 1, 2024 Patched Versions: 1.3.5.3 Affected Versions: <= 1.3.5.2 Vulnerability Details: Name: HUSKY – Products Filter Professional for WooCommerce <= 1.3.5.2 Title: Authenticated…

Read More

Media Library Assistant Vulnerability – Authenticated (Contributor+) Stored Cross-Site Scripting via mla_gallery Shortcode – CVE-2024-2475 |WordPress Plugin Vulnerability Report 

By Your WP Guy / Mar 28, 2024

Plugin Name: Media Library Assistant Key Information: Software Type: Plugin Software Slug: media-library-assistant Software Status: Active Software Author: dglingren Software Downloads: 1,901,312 Active Installs: 70,000 Last Updated: April 1, 2024 Patched Versions: 3.14 Affected Versions: <= 3.13 Vulnerability Details: Name: Media Library Assistant <= 3.13 Title: Authenticated (Contributor+) Stored Cross-Site Scripting via mla_gallery Shortcode Type:…

Read More

Ninja Forms Contact Form Vulnerability – The Drag and Drop Form Builder for WordPress – Cross-Site Request Forgery to Publicly Accessible Form Submission Export – CVE-2024-2113 | WordPress Plugin Vulnerability Report

By Your WP Guy / Mar 28, 2024

Plugin Name: Ninja Forms Contact Form – The Drag and Drop Form Builder for WordPress Key Information: Software Type: Plugin Software Slug: ninja-forms Software Status: Active Software Author: kstover Software Downloads: 43,897,090 Active Installs: 800,000 Last Updated: April 1, 2024 Patched Versions: 3.8.1 Affected Versions: <= 3.8.0 Vulnerability Details: Name: Ninja Forms Contact Form –…

Read More

Pods Vulnerability – Custom Content Types and Fields – Authenticated (Contributor+) SQL Injection via Shortcode – CVE-2023-6967 | WordPress Plugin Vulnerability Report

By Your WP Guy / Mar 28, 2024

Plugin Name: Pods – Custom Content Types and Fields Key Information: Software Type: Plugin Software Slug: pods Software Status: Active Software Author: sc0ttkclark Software Downloads: 4,033,656 Active Installs: 100,000 Last Updated: April 1, 2024 Patched Versions: 2.7.31.2, 2.8.23.2, 2.9.19.2, 3.0.10.2 Affected Versions: < 2.7.31, 3 – 3.0.10, 2.8 – 2.8.23 Vulnerability Details: Name: Pods –…

Read More

WordPress Infinite Scroll Vulnerability – Ajax Load More – Authenticated (Administrator+) Stored Cross-Site Scripting | WordPress Plugin Vulnerability Report

By Your WP Guy / Mar 28, 2024

Plugin Name: WordPress Infinite Scroll – Ajax Load More Key Information: Software Type: Plugin Software Slug: ajax-load-more Software Status: Active Software Author: connekthq Software Downloads: 1,881,197 Active Installs: 50,000 Last Updated: April 1, 2024 Patched Versions: 7.0.2 Affected Versions: <= 7.0.1 Vulnerability Details: Name: Ajax Load More <= 7.0.1 Title: Authenticated (Administrator+) Stored Cross-Site Scripting…

Read More

Check & Log Email Vulnerability – Unauthenticated Hook Injection – CVE-2024-0866 |WordPress Plugin Vulnerability Report

By Your WP Guy / Mar 25, 2024

Plugin Name: Check & Log Email Key Information: Software Type: Plugin Software Slug: check-email Software Status: Active Software Author: checkemail Software Downloads: 1,430,487 Active Installs: 100,000 Last Updated: March 25, 2024 Patched Versions: 1.0.10 Affected Versions: <= 1.0.9 Vulnerability Details: Name: Check & Log Email <= 1.0.9 Title: Unauthenticated Hook Injection Type: CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H CVE: CVE-2024-0866…

Read More

Post and Page Builder by BoldGrid Vulnerability – Visual Drag and Drop Editor – Authenticated (Contributor+) Stored Cross-Site Scripting |WordPress Plugin Vulnerability Report

By Your WP Guy / Mar 25, 2024

Plugin Name: Post and Page Builder by BoldGrid – Visual Drag and Drop Editor Key Information: Software Type: Plugin Software Slug: post-and-page-builder Software Status: Active Software Author: BoldGrid Software Downloads: 1,381,114 Active Installs: 80,000 Last Updated: March 25, 2024 Patched Versions: 1.26.3 Affected Versions: <= 1.26.2 Vulnerability Details: Name: Post and Page Builder by BoldGrid…

Read More