Plugin Updates
OneClick Chat to Order Vulnerability – Authenticated Stored Cross-Site Scripting via Shortcode | WordPress Plugin Vulnerability Report
Plugin Name: OneClick Chat to Order Key Information: Software Type: Plugin Software Slug: oneclick-whatsapp-order Software Status: Active Software Author: walterpinem Software Downloads: 205,924 Active Installs: 30,000 Last Updated: January 8, 2024 Patched Versions: 1.0.6 Affected Versions: <= 1.0.5 Vulnerability Details: Name: OneClick Chat to Order <= 1.0.5 Title: Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode…
Read MoreElementsKit Vulnerability – Unauthenticated Sensitive Information Exposure – CVE-2023-6582 | WordPress Plugin Vulnerability Report
Plugin Name: ElementsKit Elementor addons Key Information: Software Type: Plugin Software Slug: elementskit-lite Software Status: Active Software Author: xpeedstudio Software Downloads: 15,802,981 Active Installs: 1,000,000 Last Updated: January 9, 2024 Patched Versions: 3.0.4 Affected Versions: <= 3.0.3 Vulnerability Details: Name: ElementsKit Lite <= 3.0.3 Title: Unauthenticated Sensitive Information Exposure Type: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N CVE: CVE-2023-6582 CVSS Score:…
Read MoreDownload Monitor Vulnerability – Authenticated (Admin+) SQL Injection | WordPress Plugin Vulnerability Report
Plugin Name: Download Monitor Key Information: Software Type: Plugin Software Slug: download-monitor Software Status: Active Software Author: wpchill Software Downloads: 4,783,527 Active Installs: 100,000 Last Updated: January 8, 2024 Patched Versions: 4.9.5 Affected Versions: < 4.9.5 Vulnerability Details: Name: Download Monitor <= 4.9.4 Title: Authenticated (Admin+) SQL Injection Type: CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H CVE: NA CVSS Score: 7.2…
Read MoreFormidable Forms Vulnerability – Contact Form, Survey, Quiz, Payment, Calculator Form & Custom Form Builder – Authenticated (Administrator+) Stored Cross-Site Scripting – CVE-2023-6842 | WordPress Plugin Vulnerability Report
Plugin Name: Formidable Forms – Contact Form, Survey, Quiz, Payment, Calculator Form & Custom Form Builder Key Information: Software Type: Plugin Software Slug: formidable Software Status: Active Software Author: sswells Software Downloads: 19,370,348 Active Installs: 300,000 Last Updated: January 8, 2024 Patched Versions: 6.7.1 Affected Versions: <= 6.7 Vulnerability Details: Name: Formidable Forms <= 6.7…
Read MoreMetform Elementor Contact Form Builder Vulnerability – Cross-Site Request Forgery – CVE-2023-6788 | WordPress Plugin Vulnerability Report
Plugin Name: Metform Elementor Contact Form Builder Key Information: Software Type: Plugin Software Slug: metform Software Status: Active Software Author: xpeedstudio Software Downloads: 2,891,443 Active Installs: 300,000 Last Updated: January 8, 2024 Patched Versions: 3.8.2 Affected Versions: <= 3.8.1 Vulnerability Details: Name: Metform Elementor Contact Form Builder <= 3.8.1 Title: Cross-Site Request Forgery Type: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N…
Read MoreRSS Aggregator by Feedzy Vulnerability – Missing Authorization – CVE-2023-6798 | WordPress Plugin Vulnerability Report
Plugin Name: RSS Aggregator by Feedzy – Feed to Post, Autoblogging, News & YouTube Video Feeds Aggregator Key Information: Software Type: Plugin Software Slug: feedzy-rss-feeds Software Status: Active Software Author: themeisle Software Downloads: 1,986,458 Active Installs: 50,000 Last Updated: January 5, 2024 Patched Versions: 4.3.3 Affected Versions: <= 4.3.2 Vulnerability Details: Name: RSS Aggregator by…
Read MoreOrbit Fox by ThemeIsle Vulnerability – Authenticated Stored Cross-Site Scripting – CVE-2023-6781 | WordPress Plugin Vulnerability Report
Plugin Name: Orbit Fox by ThemeIsle Key Information: Software Type: Plugin Software Slug: themeisle-companion Software Status: Active Software Author: themeisle Software Downloads: 10,910,881 Active Installs: 200,000 Last Updated: January 5, 2024 Patched Versions: <= 2.10.26 Affected Versions: 2.10.27 Vulnerability Details: Name: Orbit Fox Companion <= 2.10.26 Title: Authenticated (Contributor+) Stored Cross-Site Scripting via custom…
Read MoreLightStart Vulnerability – Maintenance Mode, Coming Soon and Landing Page Builder – Missing Authorization – CVE-2023-7019| WordPress Plugin Vulnerability Report
Plugin Name: LightStart – Maintenance Mode, Coming Soon and Landing Page Builder Key Information: Software Type: Plugin Software Slug: wp-maintenance-mode Software Status: Active Software Author: themeisle Software Downloads: 15,432,322 Active Installs: 700,000 Last Updated: January 5th, 2024 Patched Versions: 2.6.9 Affected Versions: <= 2.6.8 Vulnerability Details: Name: LightStart – Maintenance Mode, Coming Soon and Landing…
Read More