Cybersecurity

WP Plugin Vulnerabilities Image - Media Library Assistant Vulnerability- Authenticated (Author+) Arbitrary File Upload via mla-inline-edit-upload-scripts AJAX Action - CVE-2024-6823 | WordPress Plugin Vulnerability Report - Cybersecurity

Media Library Assistant Vulnerability- Authenticated (Author+) Arbitrary File Upload via mla-inline-edit-upload-scripts AJAX Action – CVE-2024-6823 | WordPress Plugin Vulnerability Report

By Your WP Guy / Aug 12, 2024

Plugin Name: Media Library Assistant Key Information: Software Type: Plugin Software Slug: media-library-assistant Software Status: Active Software Author: dglingren Software Downloads: 2,044,116 Active Installs: 70,000 Last Updated: August 18, 2024 Patched Versions: 3.19 Affected Versions: <= 3.18 Vulnerability Details: Name: Media Library Assistant <= 3.18 Title: Authenticated (Author+) Arbitrary File Upload via mla-inline-edit-upload-scripts AJAX Action…

Read More
WP Plugin Vulnerabilities Image - Premium Addons for Elementor Vulnerability - Missing Authorization to Authenticated (Contributor+) Arbitrary Content Deletion and Arbitrary Title Update - CVE-2024-6824 | WordPress Plugin Vulnerability Report - Cybersecurity

Premium Addons for Elementor Vulnerability – Missing Authorization to Authenticated (Contributor+) Arbitrary Content Deletion and Arbitrary Title Update – CVE-2024-6824 | WordPress Plugin Vulnerability Report

By Your WP Guy / Aug 7, 2024

Plugin Name: Premium Addons for Elementor Key Information: Software Type: Plugin Software Slug: premium-addons-for-elementor Software Status: Active Software Author: leap13 Software Downloads: 34,020,583 Active Installs: 700,000 Last Updated: August 12, 2024 Patched Versions: 4.10.39 Affected Versions: <= 4.10.38 Vulnerability Details: Name: Premium Addons for Elementor <= 4.10.38 Title: Missing Authorization to Authenticated (Contributor+) Arbitrary Content…

Read More
WP Plugin Vulnerabilities Image - Lightbox & Modal Popup WordPress Plugin – FooBox Vulnerability - Authenticated (Contributor+) Stored DOM-Based Cross-Site Scripting via HTML Data Attributes - CVE-2024-5668 | WordPress Plugin Vulnerability Report - Cybersecurity

Lightbox & Modal Popup WordPress Plugin – FooBox Vulnerability – Authenticated (Contributor+) Stored DOM-Based Cross-Site Scripting via HTML Data Attributes – CVE-2024-5668 | WordPress Plugin Vulnerability Report

By Your WP Guy / Aug 7, 2024

Plugin Name: Lightbox & Modal Popup WordPress Plugin – FooBox Key Information: Software Type: Plugin Software Slug: foobox-image-lightbox Software Status: Active Software Author: bradvin Software Downloads: 2,407,136 Active Installs: 100,000 Last Updated: August 12, 2024 Patched Versions: 2.7.32 Affected Versions: <= 2.7.28 Vulnerability Details: Name: Lightbox & Modal Popup WordPress Plugin – FooBox <= 2.7.28…

Read More
WP Plugin Vulnerabilities Image - Forminator – Contact Form, Payment Form & Custom Form Builder Vulnerability - HubSpot Developer API Key Sensitive Information Exposure - CVE-2024-7389 | WordPress Plugin Vulnerability Report - Cybersecurity

Forminator – Contact Form, Payment Form & Custom Form Builder Vulnerability – HubSpot Developer API Key Sensitive Information Exposure – CVE-2024-7389 | WordPress Plugin Vulnerability Report

By Your WP Guy / Aug 1, 2024

Plugin Name: Forminator – Contact Form, Payment Form & Custom Form Builder Key Information: Software Type: Plugin Software Slug: forminator Software Status: Active Software Author: wpmudev Software Downloads: 7,946,481 Active Installs: 500,000 Last Updated: August 6, 2024 Patched Versions: 1.29.2 Affected Versions: <= 1.29.1 Vulnerability Details: Name: Forminator <= 1.29.1 Title: HubSpot Developer API Key…

Read More
WP Plugin Vulnerabilities Image - Essential Addons for Elementor Vulnerability - Authenticated (Contributor+) Stored Cross-Site Scripting - CVE-2024-39649 | WordPress Plugin Vulnerability Report - Cybersecurity

Essential Addons for Elementor Vulnerability – Authenticated (Contributor+) Stored Cross-Site Scripting – CVE-2024-39649 | WordPress Plugin Vulnerability Report

By Your WP Guy / Aug 1, 2024

Plugin Name: Essential Addons for Elementor – Best Elementor Templates, Widgets, Kits & WooCommerce Builders Key Information: Software Type: Plugin Software Slug: essential-addons-for-elementor-lite Software Status: Active Software Author: wpdevteam Software Downloads: 79,388,161 Active Installs: 2,000,000 Last Updated: August 12, 2024 Patched Versions: 5.9.27 Affected Versions: <= 5.9.26 Vulnerability Details: Name: Essential Addons for Elementor <=…

Read More
WP Plugin Vulnerabilities Image - Formidable Forms – Contact Form Plugin, Survey, Quiz, Payment, Calculator Form & Custom Form Builder Vulnerability - Authenticated (Subscriber+) Stored Cross-Site Scripting - CVE-2024-6725 | WordPress Plugin Vulnerability Report - Cybersecurity

Formidable Forms – Contact Form Plugin, Survey, Quiz, Payment, Calculator Form & Custom Form Builder Vulnerability – Authenticated (Subscriber+) Stored Cross-Site Scripting – CVE-2024-6725 | WordPress Plugin Vulnerability Report

By Your WP Guy / Jul 30, 2024

Plugin Name: Formidable Forms – Contact Form Plugin, Survey, Quiz, Payment, Calculator Form & Custom Form Builder Key Information: Software Type: Plugin Software Slug: formidable Software Status: Active Software Author: strategy11team Software Downloads: 21,415,029 Active Installs: 400,000 Last Updated: August 6, 2024 Patched Versions: 6.11.2 Affected Versions: <= 6.11.1 Vulnerability Details: Name: Formidable Forms <=…

Read More
WP Plugin Vulnerabilities Image - Download Manager Vulnerability - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode - CVE-2024-6208 | WordPress Plugin Vulnerability Report - Cybersecurity

Download Manager Vulnerability – Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode – CVE-2024-6208 | WordPress Plugin Vulnerability Report

By Your WP Guy / Jul 30, 2024

Plugin Name: Download Manager Key Information: Software Type: Plugin Software Slug: download-manager Software Status: Active Software Author: codename065 Software Downloads: 8,808,376 Active Installs: 100,000 Last Updated: August 12, 2024 Patched Versions: 3.2.98 Affected Versions: <= 3.2.97 Vulnerability Details: Name: Download Manager <= 3.2.97 Title: Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode Type: Stored Cross-Site Scripting…

Read More
WP Plugin Vulnerabilities Image - SiteOrigin Widgets Bundle Vulnerability - Authenticated (Contributor+) Stored Cross-Site Scripting in Image Grid Widget - CVE-2024-5901 | WordPress Plugin Vulnerability Report - Cybersecurity

SiteOrigin Widgets Bundle Vulnerability – Authenticated (Contributor+) Stored Cross-Site Scripting in Image Grid Widget – CVE-2024-5901 | WordPress Plugin Vulnerability Report

By Your WP Guy / Jul 30, 2024

Plugin Name: SiteOrigin Widgets Bundle Key Information: Software Type: Plugin Software Slug: so-widgets-bundle Software Status: Active Software Author: gpriday Software Downloads: 40,680,217 Active Installs: 600,000 Last Updated: August 12, 2024 Patched Versions: 1.62.3 Affected Versions: <= 1.62.2 Vulnerability Details: Name: SiteOrigin Widgets Bundle <= 1.62.2 Title: Authenticated (Contributor+) Stored Cross-Site Scripting in Image Grid Widget…

Read More
WP Plugin Vulnerabilities Image - Happy Addons for Elementor Vulnerability - Authenticated (Contributor+) Stored Cross-Site Scripting via PDF View Widget - CVE-2024-6627 | WordPress Plugin Vulnerability Report - Cybersecurity

Happy Addons for Elementor Vulnerability – Authenticated (Contributor+) Stored Cross-Site Scripting via PDF View Widget – CVE-2024-6627 | WordPress Plugin Vulnerability Report

By Your WP Guy / Jul 26, 2024

Plugin Name: Happy Addons for Elementor Key Information: Software Type: Plugin Software Slug: happy-elementor-addons Software Status: Active Software Author: thehappymonster Software Downloads: 7,563,441 Active Installs: 400,000 Last Updated: July 29, 2024 Patched Versions: 3.11.3 Affected Versions: <= 3.11.2 Vulnerability Details: Name: Happy Addons for Elementor <= 3.11.2 Type: Authenticated (Contributor+) Stored Cross-Site Scripting via PDF…

Read More
WP Plugin Vulnerabilities Image - LiteSpeed Cache Vulnerability - Cross-Site Request Forgery to Stored Cross-Site Scripting - CVE-2024-3246 | WordPress Plugin Vulnerability Report - Cybersecurity

LiteSpeed Cache Vulnerability – Cross-Site Request Forgery to Stored Cross-Site Scripting – CVE-2024-3246 | WordPress Plugin Vulnerability Report

By Your WP Guy / Jul 23, 2024

Plugin Name: LiteSpeed Cache Key Information: Software Type: Plugin Software Slug: litespeed-cache Software Status: Active Software Author: litespeedtech Software Downloads: 70,093,541 Active Installs: 5,000,000 Last Updated: July 29, 2024 Patched Versions: 6.3 Affected Versions: <= 6.2.0.1 Vulnerability Details: Name: LiteSpeed Cache <= 6.2.0.1 Type: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N CVE: CVE-2024-3246 CVSS Score: 6.1 Publicly Published: July 23, 2024…

Read More