Plugin Vulnerability

Popup Box Vulnerability – Best WordPress Popup Plugin – Missing Authorization to Information Exposure – CVE-2024-3897 | WordPress Plugin Vulnerability Report

By Your WP Guy / Apr 24, 2024

Plugin Name: Popup Box – Best WordPress Popup Plugin Key Information: Software Type: Plugin Software Slug: ays-popup-box Software Status: Active Software Author: ays-pro Software Downloads: 1,223,022 Active Installs: 30,000 Last Updated: May 9, 2024 Patched Versions: 4.3.7 Affected Versions: <= 4.3.6 Vulnerability Details: Name: Popup Box – Best WordPress Popup Plugin <= 4.3.6 Title: Missing…

Quick Featured Images Vulnerability – Missing Authorization to Authenticated (Contributor+) Arbitrary Thumbnail Deletion/Setting – CVE-2024-3664 | WordPress Plugin Vulnerability Report

By Your WP Guy / Apr 22, 2024

Plugin Name: Quick Featured Images Key Information: Software Type: Plugin Software Slug: quick-featured-images Software Status: Active Software Author: hinjiriyo Software Downloads: 992,333 Active Installs: 50,000 Last Updated: May 6, 2024 Patched Versions: 13.7.1 Affected Versions: <= 13.7.0 Vulnerability Details: Name: Quick Featured Images <= 13.7.0 Type: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N CVE: CVE-2024-3664 CVSS Score: 4.3 Publicly Published: April…

User Registration Vulnerability – Custom Registration Form, Login Form, and User Profile – Missing Authorization to Authenticated (Subscriber+) Privilege Escalation – CVE-2024-2417 | WordPress Plugin Vulnerability Report

By Your WP Guy / Apr 19, 2024

Plugin Name: User Registration – Custom Registration Form, Login Form, and User Profile WordPress Plugin Key Information: Software Type: Plugin Software Slug: user-registration Software Status: Active Software Author: wpeverest Software Downloads: 2,655,257 Active Installs: 70,000 Last Updated: May 2, 2024 Patched Versions: 3.2.0 Affected Versions: <=3.1.5 Vulnerability Details: Name: User Registration – Custom Registration Form,…

RSS Aggregator by Feedzy Vulnerability – Feed to Post, Autoblogging, News & YouTube Video Feeds Aggregator – Authenticated Blind Server-Side Request Forgery (SSRF) – CVE-2023-6805 | WordPress Plugin Vulnerability Report

By Your WP Guy / Apr 16, 2024

Plugin Name: RSS Aggregator by Feedzy – Feed to Post, Autoblogging, News & YouTube Video Feeds Aggregator Key Information: Software Type: Plugin Software Slug: feedzy-rss-feeds Software Status: Active Software Author: themeisle Software Downloads: 2,223,288 Active Installs: 50,000 Last Updated: April 25, 2024 Patched Versions: 4.4.8 Affected Versions: <= 4.4.7 Vulnerability Details: Name: RSS Aggregator by…

WP Show Posts Vulnerability – Improper Authorization to Information Exposure – CVE-2023-6731 | WordPress Plugin Vulnerability Report

By Your WP Guy / Apr 15, 2024

Plugin Name: WP Show Posts Key Information: Software Type: Plugin Software Slug: wp-show-posts Software Status: Active Software Author: edge22 Software Downloads: 534,403 Active Installs: 90,000 Last Updated: April 25, 2024 Patched Versions: 1.1.6 Affected Versions: <= 1.1.5 Vulnerability Details: Name: WP Show Posts <= 1.1.5 Title: Improper Authorization to Information Exposure Type: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N CVE: CVE-2023-6731…

Email Subscribers by Icegram Express Vulnerability – Email Marketing, Newsletters, Automation for WordPress & WooCommerce – Unauthenticated SQL Injection – CVE-2024-2876 | WordPress Plugin Vulnerability Report

By Your WP Guy / Apr 15, 2024

Plugin Name: Email Subscribers by Icegram Express – Email Marketing, Newsletters, Automation for WordPress & WooCommerce Key Information: Software Type: Plugin Software Slug: email-subscribers Software Status: Active Software Author: icegram Software Downloads: 10,452,815 Active Installs: 90,000 Last Updated: April 25, 2024 Patched Versions: 5.7.15 Affected Versions: <= 5.7.14 Vulnerability Details: Name: Icegram Express – Email…

Smart Slider 3 Vulnerability – Missing Authorization to Limited File Upload – CVE-2024-3027 | WordPress Plugin Vulnerability Report

By Your WP Guy / Apr 12, 2024

Plugin Name: Smart Slider 3 Key Information: Software Type: Plugin Software Slug: smart-slider-3 Software Status: Active Software Author: nextendweb Software Downloads: 17,368,541 Active Installs: 900,000 Last Updated: April 25, 2024 Patched Versions: 3.5.1.23 Affected Versions: <= 3.5.1.22 Vulnerability Details: Name: Smart Slider 3 <= 3.5.1.22 Title: Missing Authorization to Limited File Upload Type: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N CVE:…

Element Pack Elementor Addons (Header Footer, Template Library, Dynamic Grid & Carousel, Remote Arrows) Vulnerability – Sensitive Information Exposure – CVE-2024-2966 | WordPress Plugin Vulnerability Report

By Your WP Guy / Apr 10, 2024

Plugin Name: Element Pack Elementor Addons (Header Footer, Template Library, Dynamic Grid & Carousel, Remote Arrows) Key Information: Software Type: Plugin Software Slug: bdthemes-element-pack-lite Software Status: Active Software Author: bdthemes Software Downloads: 2,021,948 Active Installs: 100,000 Last Updated: April 24, 2024 Patched Versions: 5.6.0 Affected Versions: <= 5.5.6 Vulnerability Details: Name: Element Pack Elementor Addons…

BEAR Vulnerability – Bulk Editor and Products Manager Professional for WooCommerce by Pluginus.Net – Cross-Site Request Forgery to Notice Dismissal – CVE-2024-31430 | WordPress Plugin Vulnerability Report

By Your WP Guy / Apr 10, 2024

Plugin Name: BEAR – Bulk Editor and Products Manager Professional for WooCommerce by Pluginus.Net Key Information: Software Type: Plugin Software Slug: woo-bulk-editor Software Status: Active Software Author: realmag777 Software Downloads: 580,051 Active Installs: 30,000 Last Updated: April 25, 2024 Patched Versions: 1.1.4.2 Affected Versions: <= 1.1.4.1 Vulnerability Details: Name: BEAR <= 1.1.4.1 Title: Cross-Site Request…

RSS Aggregator by Feedzy Vulnerability – Feed to Post, Autoblogging, News & YouTube Video Feeds Aggregator – Authenticated Stored Cross-Site Scripting via Shortcode Error Message – CVE-2023-6877 | WordPress Plugin Vulnerability Report 

By Your WP Guy / Apr 6, 2024

Plugin Name: RSS Aggregator by Feedzy – Feed to Post, Autoblogging, News & YouTube Video Feeds Aggregator Key Information: Software Type: Plugin Software Slug: feedzy-rss-feeds Software Status: Active Software Author: themeisle Software Downloads: 2,215,056 Active Installs: 50,000 Last Updated: April 16, 2024 Patched Versions: 4.3.4 Affected Versions: <= 4.3.3 Vulnerability Details: Name: RSS Aggregator by…