digital protection

FancyBox for WordPress Vulnerability – Authenticated (Admin+) Stored Cross-Site Scripting – CVE-2024-0662 | WordPress Plugin Vulnerability Report

By Your WP Guy / Apr 5, 2024

Plugin Name: FancyBox for WordPress Key Information: Software Type: Plugin Software Slug: fancybox-for-wordpress Software Status: Active Software Author: colorlibplugins Software Downloads: 1,832,612 Active Installs: 50,000 Last Updated: April 10, 2024 Patched Versions: 3.3.4 Affected Versions: 3.0.2 – 3.3.3 Vulnerability Details: Name: FancyBox for WordPress 3.0.2 – 3.3.3 Title: Authenticated (Admin+) Stored Cross-Site Scripting Type: CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:L/I:L/A:N…

Read More

Contact Form 7 Vulnerability– Dynamic Text Extension – Insecure Direct Object Reference – CVE-2023-6630 | WordPress Plugin Vulnerability Report

By Your WP Guy / Jan 10, 2024

Plugin Name: Contact Form 7 – Dynamic Text Extension Key Information: Software Type: Plugin Software Slug: contact-form-7-dynamic-text-extension Software Status: Active Software Author: sevenspark Software Downloads: 1,173,724 Active Installs: 100,000 Last Updated: January 10, 2023 Patched Versions: 4.2.0 Affected Versions: <= 4.1.0 Vulnerability Details: Name: Contact Form 7 – Dynamic Text Extension <= 4.1.0 Title: Insecure…

Read More

Newsletter Vulnerability– Send Awesome Emails from WordPress – Cross-Site Request Forgery |WordPress Plugin Vulnerability Report

By Your WP Guy / Jan 10, 2024

Plugin Name: Newsletter – Send Awesome Emails from WordPress Key Information: Software Type: Plugin Software Slug: newsletter Software Status: Active Software Author: satollo Software Downloads: 23,000,399 Active Installs: 300,000 Last Updated: January 10, 2024 Patched Versions: 8.0.7 Affected Versions: <= 8.0.6 Vulnerability Details: Name: Newsletter <= 8.0.6 Title: Cross-Site Request Forgery (CSRF) Type: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:N/I:L/A:N CVE:…

Read More

POST SMTP Vulnerability – The #1 WordPress SMTP Plugin – Authorization Bypass via type connect-app API – CVE-2023-6875 | WordPress Plugin Vulnerability Report 

By Your WP Guy / Jan 10, 2024

Plugin Name: POST SMTP – The #1 WordPress SMTP Plugin with Advanced Email Logging and Delivery Failure Notifications Key Information: Software Type: Plugin Software Slug: post-smtp Software Status: Active Software Author: wpexpertsio Software Downloads: 11,120,456 Active Installs: 300,000 Last Updated: January 10, 2024 Patched Versions: 2.8.8 Affected Versions: <= 2.8.7 Vulnerability Details: Name: POST SMTP…

Read More

Customer Reviews for WooCommerce Vulnerability – Authenticated (Author+) Arbitrary File Upload – CVE-2023-6979 |WordPress Plugin Vulnerability Report

By Your WP Guy / Jan 9, 2024

Plugin Name: Customer Reviews for WooCommerce Key Information: Software Type: Plugin Software Slug: customer-reviews-woocommerce Software Status: Active Software Author: ivole Software Downloads: 3,786,034 Active Installs: 60,000 Last Updated: January 9, 2024 Patched Versions: 5.38.10 Affected Versions: <= 5.38.9 Vulnerability Details: Name: Customer Reviews for WooCommerce <= 5.38.9 Title: Authenticated (Author+) Arbitrary File Upload Type: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H…

Read More