Plugin Updates
Ninja Forms – The Contact Form Builder That Grows With You Vulnerability – Authenticated (Subscriber+) Arbitrary Shortcode Execution – CVE-2024-37934 | WordPress Plugin Vulnerability Report
Plugin name: Ninja Forms – The Contact Form Builder That Grows With You Key Information: Software Type: Plugin Software Slug: ninja-forms Software Status: Active Software Author: kstover Software Downloads: 45,866,064 Active Installs: 800,000 Last Updated: July 27, 2024 Patched Versions: 3.8.5 Affected Versions: <= 3.8.4 Vulnerability Details: Name: Ninja Forms <= 3.8.4 Title: Authenticated (Subscriber+)…
Read MorePage Builder Gutenberg Blocks – CoBlocks Vulnerability – Authenticated (Contributor+) Server-Side Request Forgery – CVE-2024-4260 | WordPress Plugin Vulnerability Report
Plugin Name: Page Builder Gutenberg Blocks – CoBlocks Key Information: Software Type: Plugin Software Slug: coblocks Software Status: Active Software Author: godaddy Software Downloads: 22,494,227 Active Installs: 400,000 Last Updated: August 12, 2024 Patched Versions: 3.1.12 Affected Versions: <= 3.1.11 Vulnerability Details: Name: Page Builder Gutenberg Blocks – CoBlocks <= 3.1.11 Title: Authenticated (Contributor+) Server-Side…
Read MoreElementor Header & Footer Builder Vulnerability – Authenticated (Contributor+) Stored Cross-Site Scripting – CVE-2024-33933 | WordPress Plugin Vulnerability Report
Plugin name: Elementor Header & Footer Builder Key Information: Software Type: Plugin Software Slug: header-footer-elementor Software Status: Active Software Author: brainstormforce Software Downloads: 30,625,064 Active Installs: 2,000,000 Last Updated: July 27, 2024 Patched Versions: NA Affected Versions: <= 1.6.35 Vulnerability Details: Name: Elementor – Header, Footer & Blocks Template <= 1.6.35 Title: Authenticated (Contributor+) Stored…
Read MoreLoco Translate Vulnerability – Cross-Site Request Forgery – CVE-2024-37236 | WordPress Plugin Vulnerability Report
Plugin Name: Loco Translate Key Information: Software Type: Plugin Software Slug: loco-translate Software Status: Active Software Author: timwhitlock Software Downloads: 26,085,928 Active Installs: 1,000,000 Last Updated: July 16, 2024 Patched Versions: 2.6.10 Affected Versions: <= 2.6.9 Vulnerability Details: Name: Loco Translate <= 2.6.9 Type: Cross-Site Request Forgery CVE: CVE-2024-37236 CVSS Score: 4.3 Publicly Published: June…
Read MoreSEOPress – On-site SEO Vulnerability – Authenticated (Contributor+) Stored Cross-Site Scripting via Social Image URL – CVE-2024-1168 | WordPress Plugin Vulnerability Report
Plugin Name: SEOPress – On-site SEO Key Information: Software Type: Plugin Software Slug: wp-seopress Software Status: Active Software Author: rainbowgeek Software Downloads: 12,850,995 Active Installs: 300,000 Last Updated: August 12, 2024 Patched Versions: 7.9.1 Affected Versions: <= 7.9 Vulnerability Details: Name: SEOPress – On-site SEO <= 7.9 Title: Authenticated (Contributor+) Stored Cross-Site Scripting via Social…
Read MoreWP Reset – Most Advanced WordPress Reset Tool Vulnerability – Missing Authorization to License Key Modification – CVE-2024-4661 | WordPress Plugin Vulnerability Report
Plugin Name: WP Reset – Most Advanced WordPress Reset Tool Key Information: Software Type: Plugin Software Slug: wp-reset Software Status: Active Software Author: webfactory Software Downloads: 7,859,387 Active Installs: 300,000 Last Updated: June 20, 2024 Patched Versions: 2.03 Affected Versions: <= 2.01 Vulnerability Details: Name: WP Reset <= 2.02 Title: Missing Authorization to License Key…
Read MoreQi Addons For Elementor Vulnerability – Authenticated (Contributor+) Local File Inclusion – CVE-2024-4887 | WordPress Plugin Vulnerability Report
Plugin Name: Qi Addons For Elementor Key Information: Software Type: Plugin Software Slug: qi-addons-for-elementor Software Status: Active Software Author: qodeinteractive Software Downloads: 2,212,748 Active Installs: 200,000 Last Updated: June 20, 2024 Patched Versions: 1.7.3 Affected Versions: <= 1.7.2 Vulnerability Details: Name: Qi Addons For Elementor <= 1.7.2 Title: Authenticated (Contributor+) Local File Inclusion Type: CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H …
Read MoreTutor LMS – eLearning and online course solution Vulnerability – Authenticated (Instructor+) Insecure Direct Object Reference to Arbitrary Quiz Attempt Deletion & Authenticated (Administrator+) SQL Injection – CVE-2024-5438, CVE-2024-4902 | WordPress Plugin Vulnerability Report
Plugin Name: Tutor LMS – eLearning and online course solution Key Information: Software Type: Plugin Software Slug: tutor Software Status: Active Software Author: themeum Software Downloads: 2,142,088 Active Installs: 90,000 Last Updated: June 20, 2024 Patched Versions: 2.7.2 Affected Versions: <= 2.7.1 Vulnerability 1 Details: Name: Tutor LMS – eLearning and online course solution <=…
Read More