Plugins
WordPress Plugin Vulnerability Report – GiveWP – Cross-Site Request Forgery – CVE-2023-4247, CVE-2023-4248
Plugin Name: GiveWP Key Information: Software Type: Plugin Software Slug: give Software Status: Active Software Author: webdevmattcrom Software Downloads: 6,043,447 Active Installs: 100,000 Last Updated: October 31, 2023 Patched Versions: 2.33.4 Affected Versions: <= 2.33.3 Vulnerability 1 Details: Name: GiveWP <= 2.33.3 – Cross-Site Request Forgery to plugin deactivation Title: Cross-Site Request Forgery to plugin deactivation Type: Cross-Site Request Forgery (CSRF) CVE: CVE-2023-4247 CVSS Score: 5.4 (Medium) Publicly Published: October…
WordPress Plugin Vulnerability Report – News & Blog Designer Pack – Unauthenticated Remote Code Execution via Local File Inclusion – CVE-2023-5815
Plugin Name: News & Blog Designer Pack Key Information: Software Type: Plugin Software Slug: blog-designer-pack Software Status: Active Software Author: infornweb Software Downloads: 408,098 Active Installs: 30,000 Last Updated: October 26, 2023 Patched Versions: 3.4.2 Affected Versions: <=3.4.1 Vulnerability Details: Name: News & Blog Designer Pack – WordPress Blog Plugin <= 3.4.1 – Unauthenticated Remote Code Execution via Local File Inclusion Title: Unauthenticated Remote Code Execution…
WordPress Plugin Vulnerability Report – WordPress Popular Posts – Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode
Plugin Name: WordPress Popular Posts Key Information: Software Type: Plugin Software Slug: wordpress-popular-posts Software Status: Active Software Author: hcabrera Software Downloads: 7,045,880 Active Installs: 200,000 Last Updated: October 6, 2023 Patched Versions: <=6.3.2 Affected Versions: 6.3.3 Vulnerability Details: Name: WordPress Popular Posts <= 6.3.2 – Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode Type: Improper Neutralization of Input During Web Page Generation (‘Cross-site Scripting’)…
The Hidden Dangers of Outdated Plugins and Themes: How Your WordPress Website Could Be at Risk
Did you know that over 1 million WordPress sites were hacked in 2021, with 90% involving outdated or vulnerable plugins? Keeping your WordPress website up-to-date may seem like a low priority amidst the whirlwind of running a business. But overlooking those pending updates can put your site at serious risk. Outdated plugins and themes open…
What is the WordPress Core?
Never skip core day! Wait a second-hop out of that plank. We’re talking, of course, about WordPress Core. WordPress Core is the foundation of WordPress, providing the basic features and functions that makeup, well, the core of WordPress! It includes features such as user registration, post types, media handling, catalogs, custom fields, and more. Every…
What Is WordPress Maintenance in 2023?
Does your WordPress site run slower than you’d like? WordPress is a powerful platform, but it needs to be maintained to stay fast, secure, and reliable. That’s where Your WP Guy comes in. We offer comprehensive WordPress maintenance services that keep your site running like new. Proper WordPress maintenance keeps your website running well. And…
What is WordPress?
The easy answer to this question is WordPress is a software anyone can use to edit and create a website. Before WordPress, it was very difficult to get a website running without the help of someone who could write code, like CSS, PHP and JavaScript. Now anyone can create a website quickly by installing the…