Cybersecurity for WordPress

SecuPress Free Vulnerability — WordPress Security – Cross-Site Request Forgery to Banned IP Address – CVE-2024-1504 | WordPress Plugin Vulnerability Report

By Your WP Guy / Apr 1, 2024

Plugin Name: SecuPress Free – WordPress Security Key Information: Software Type: Plugin Software Slug: secupress Software Status: Active Software Author: SecuPress Software Downloads: 623,070 Active Installs: 40,000 Last Updated: April 2, 2024 Patched Versions: 2.2.5.2 Affected Versions: <= 2.2.5.1 Vulnerability Details: Name: SecuPress Free – WordPress Security <= 2.2.5.1 Title: Cross-Site Request Forgery to Banned…

Read More

Exclusive Addons for Elementor Vulnerability – Authenticated Contributor+ Stored Cross-Site Scripting – CVE-2024-1234 | WordPress Plugin Vulnerability Report

By Your WP Guy / Feb 29, 2024

Plugin Name: Exclusive Addons for Elementor Key Information: Software Type: Plugin Software Slug: exclusive-addons-for-elementor Software Status: Active Software Author: timstrifler Software Downloads: 717,031 Active Installs: 60,000 Last Updated: March 1, 2024 Patched Versions: 2.6.9.1 Affected Versions: <= 2.6.9 Vulnerability Details: Name: Exclusive Addons for Elementor <= 2.6.9 Title: Authenticated (Contributor+) Stored Cross-Site Scripting Type: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N…

Read More

Meta Box Vulnerability– WordPress Custom Fields Framework – Authenticated (Contributor+) Stored Cross-Site Scripting – CVE-2023-6526 |WordPress Plugin Vulnerability Report

By Your WP Guy / Feb 5, 2024

Plugin Name: Meta Box – WordPress Custom Fields Framework Key Information: Software Type: Plugin Software Slug: meta-box Software Status: Active Software Author: rilwis Software Downloads: 16,593,050 Active Installs: 700,000 Last Updated: February 8, 2024 Patched Versions: 5.9.3 Affected Versions: <= 5.9.2 Vulnerability Details: Name: Meta Box – WordPress Custom Fields Framework <= 5.9.2 Title: Authenticated…

Read More

WP Recipe Maker Vulnerability – Authenticated (Contributor+) Stored Cross-Site Scripting via header_tag – CVE-2024-0382 | WordPress Plugin Vulnerability Report

By Your WP Guy / Jan 17, 2024

Plugin Name: WP Recipe Maker Key Information: Software Type: Plugin Software Slug: wp-recipe-maker Software Status: Active Software Author: brechtvds Software Downloads: 2,536,653 Active Installs: 50,000 Last Updated: January 22, 2024 Patched Versions: 9.1.1 Affected Versions: <= 9.1.0 Vulnerability Details: Name: WP Recipe Maker <= 9.1.0 Title: Authenticated (Contributor+) Stored Cross-Site Scripting via header_tag Type: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N…

Read More

 Advanced Custom Fields (ACF) – Authenticated (Contributor+) Stored Cross-Site Scripting via Custom Field – CVE-2023-6701 | WordPress Plugin Vulnerability Report

By Your WP Guy / Jan 17, 2024

Plugin Name: Advanced Custom Fields (ACF) Key Information: Software Type: Plugin Software Slug: advanced-custom-fields Software Status: Active Software Author: wpengine Software Downloads: 44,336,988 Active Installs: 2,000,000 Last Updated: January 25, 2024 Patched Versions: 6.2.5 Affected Versions: <= 6.2.4 Vulnerability Details: Name: Advanced Custom Fields <= 6.2.4 Title: Authenticated (Contributor+) Stored Cross-Site Scripting via Custom Field…

Read More

Burst Statistics Vulnerability – Authenticated (Editor+) SQL Injection – CVE-2024-0405 | WordPress Plugin Vulnerability Report 

By Your WP Guy / Jan 16, 2024

Plugin Name: Burst Statistics – Privacy-Friendly Analytics for WordPress Key Information: Software Type: Plugin Software Slug: burst-statistics Software Status: Active Software Author: rogierlankhorst Software Downloads: 1,470,512 Active Installs: 100,000 Last Updated: January 25, 2024 Patched Versions: 1.5.4 Affected Versions: <= 1.5.3 Vulnerability Details: Name: Burst Statistics Really Simple Plugins <= 1.5.3 Title: Authenticated (Editor+) SQL…

Read More