Cybersecurity

PDF Flipbook, 3D Flipbook Vulnerability– DearFlip – Authenticated (Contributor+) Stored Cross-Site Scripting – CVE-2024-0895 | WordPress Plugin Vulnerability Report 

By Your WP Guy / Feb 2, 2024

Plugin Name: PDF Flipbook, 3D Flipbook – DearFlip Key Information: Software Type: Plugin Software Slug: 3d-flipbook-dflip-lite Software Status: Active Software Author: dearhive Software Downloads: 1,178,266 Active Installs: 100,000 Last Updated: February 8, 2024 Patched Versions: 2.2.27 Affected Versions: <= 2.2.26 Vulnerability Details: Name: PDF Flipbook, 3D Flipbook – DearFlip <= 2.2.26 Title: Authenticated (Contributor+) Stored…

Essential Addons for Elementor Vulnerability– Best Elementor Templates, Widgets, Kits & WooCommerce Builders – Authenticated (Contributor+) Stored Cross-Site Scripting – CVE-2024-0954 | WordPress Plugin Vulnerability Report

By Your WP Guy / Feb 1, 2024

Plugin Name: Essential Addons for Elementor – Best Elementor Templates, Widgets, Kits & WooCommerce Builders Key Information: Software Type: Plugin Software Slug: essential-addons-for-elementor-lite Software Status: Active Software Author: wpdevteam Software Downloads: 66,002,609 Active Installs: 2,000,000 Last Updated: February 12, 2024 Patched Versions: 5.9.8 Affected Versions: <= 5.9.7 Vulnerability Details: Name: Essential Addons for Elementor –…

Advanced iFrame Vulnerability- Authenticated (Contributor+) Stored Cross-Site Scripting – CVE-2023-7069 | WordPress Plugin Vulnerability Report

By Your WP Guy / Jan 31, 2024

 Plugin Name: Advanced iFrame Key Information: Software Type: Plugin Software Slug: advanced-iframe Software Status: Active Software Author: mdempfle Software Downloads: 1,840,037 Active Installs: 60,000 Last Updated: February 1, 2024 Patched Versions: 2024.0 Affected Versions: <= 2023.10 Vulnerability Details: Name: Advanced iFrame <= 2023.10 Title: Authenticated (Contributor+) Stored Cross-Site Scripting (XSS) Type: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N CVE: CVE-2023-7069 CVSS…

Website Builder by SeedProd Vulnerability – Missing Authorization via seedprod_lite_new_lpage – CVE-2024-1072 | WordPress Plugin Vulnerability Report

By Your WP Guy / Jan 31, 2024

Plugin Name: Website Builder by SeedProd – Theme Builder, Landing Page Builder, Coming Soon Page, Maintenance Mode Key Information: Software Type: Plugin Software Slug: coming-soon Software Status: Active Software Author: seedprod Software Downloads: 23,816,722 Active Installs: 900,000 Last Updated: February 1, 2024 Patched Versions: 6.15.23 Affected Versions: <= 6.15.21 Vulnerability Details: Name: Website Builder by…

Cookie Information | Free GDPR Consent Solution Vulnerability – Authenticated (Subscriber+) Arbitrary Options Update – CVE-2023-6700 | WordPress Plugin Vulnerability Report

By Your WP Guy / Jan 29, 2024

Plugin Name: Cookie Information | Free GDPR Consent Solution Key Information: Software Type: Plugin Software Slug: wp-gdpr-compliance Software Status: Active Software Author: cookieinformation Software Downloads: 3,745,212 Active Installs: 100,000 Last Updated: February 2, 2024 Patched Versions: 2.0.23 Affected Versions: <= 2.0.22 Vulnerability Details: Name: Cookie Information | Free GDPR Consent Solution <= 2.0.22 Title: Authenticated…

SEO Plugin by Squirrly SEO Vulnerability- Authenticated (Administrator+) Stored Cross-Site Scripting – CVE-2024-0597 |WordPress Plugin Vulnerability Report

By Your WP Guy / Jan 29, 2024

Plugin Name: SEO Plugin by Squirrly SEO Key Information: Software Type: Plugin Software Slug: squirrly-seo Software Status: Active Software Author: cifi Software Downloads: 4,689,778 Active Installs: 200,000 Last Updated: February 2, 2024 Patched Versions: 12.3.16 Affected Versions: <= 12.3.15 Vulnerability Details: Name: SEO Plugin by Squirrly SEO <= 12.3.15 Title: Authenticated (Administrator+) Stored Cross-Site Scripting…

WP Dashboard Notes Vulnerability- Missing Authorization to Arbitrary Private Notes Update – CVE-2023-7239 |WordPress Plugin Vulnerability Report

By Your WP Guy / Jan 26, 2024

Plugin Name: WP Dashboard Notes Key Information: Software Type: Plugin Software Slug: wp-dashboard-notes Software Status: Active Software Author: sormano Software Downloads: 176,276 Active Installs: 30,000 Last Updated: January 30, 2024 Patched Versions: 1.0.10 Affected Versions: <= 1.0.10 Vulnerability Details: Name: WP Dashboard Notes <= 1.0.10 Title: Missing Authorization to Arbitrary Private Notes Update Type: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N…

Backuply Vulnerability– Backup, Restore, Migrate and Clone – Authenticated (Administrator+) Directory Traversal – CVE-2024-0697 |WordPress Plugin Vulnerability Report 

By Your WP Guy / Jan 26, 2024

Plugin Name: Backuply – Backup, Restore, Migrate and Clone Key Information: Software Type: Plugin Software Slug: backuply Software Status: Active Software Author: Softaculous Software Downloads: 1,893,554 Active Installs: 200,000 Last Updated: February 1, 2024 Patched Versions: 1.2.4 Affected Versions: <= 1.2.3 Vulnerability Details: Name: Backuply – Backup, Restore, Migrate and Clone <= 1.2.3 Title: Authenticated…

Exclusive Addons for Elementor Vulnerability- Stored Cross-Site Scripting Vulnerabilities – CVE-2024-0824 & CVE-2024-0823 |WordPress Plugin Vulnerability Report 

By Your WP Guy / Jan 26, 2024

Plugin Name: Exclusive Addons for Elementor Key Information: Software Type: Plugin Software Slug: exclusive-addons-for-elementor Software Status: Active Software Author: timstrifler Software Downloads: 688,917 Active Installs: 50,000 Last Updated: February 1, 2024 Patched Versions: 2.6.9 Affected Versions: <= 2.6.8 Vulnerability Details (Section 1): Name: Exclusive Addons for Elementor <= 2.6.8 Title: Authenticated (Contributor+) Stored Cross-Site Scripting…

10Web AI Assistant Vulnerability – AI Content Writing Assistant – Missing Authorization to Arbitrary Plugin Installation – CVE-2023-6985 |WordPress Plugin Vulnerability Report 

By Your WP Guy / Jan 25, 2024

Plugin Name: 10Web AI Assistant – AI Content Writing Assistant Key Information: Software Type: Plugin Software Slug: ai-assistant-by-10web Software Status: Active Software Author: 10web Software Downloads: 20,225 Active Installs: 30,000 Last Updated: January 30, 2024 Patched Versions: 1.0.19 Affected Versions: <= 1.0.18 Vulnerability Details: Name: 10Web AI Assistant – AI Content Writing Assistant <= 1.0.18…