securing wordpress

ElementsKit Vulnerability – Unauthenticated Sensitive Information Exposure – CVE-2023-6582 | WordPress Plugin Vulnerability Report

By Your WP Guy / Jan 8, 2024

Plugin Name: ElementsKit Elementor addons Key Information: Software Type: Plugin Software Slug: elementskit-lite Software Status: Active Software Author: xpeedstudio Software Downloads: 15,802,981 Active Installs: 1,000,000 Last Updated: January 9, 2024 Patched Versions: 3.0.4 Affected Versions: <= 3.0.3 Vulnerability Details: Name: ElementsKit Lite <= 3.0.3 Title: Unauthenticated Sensitive Information Exposure Type: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N CVE: CVE-2023-6582 CVSS Score:…

Read More

RSS Aggregator by Feedzy Vulnerability – Missing Authorization – CVE-2023-6798 | WordPress Plugin Vulnerability Report

By Your WP Guy / Jan 5, 2024

Plugin Name: RSS Aggregator by Feedzy – Feed to Post, Autoblogging, News & YouTube Video Feeds Aggregator Key Information: Software Type: Plugin Software Slug: feedzy-rss-feeds Software Status: Active Software Author: themeisle Software Downloads: 1,986,458 Active Installs: 50,000 Last Updated: January 5, 2024 Patched Versions: 4.3.3 Affected Versions: <= 4.3.2 Vulnerability Details: Name: RSS Aggregator by…

Read More

Orbit Fox by ThemeIsle Vulnerability – Authenticated Stored Cross-Site Scripting – CVE-2023-6781 | WordPress Plugin Vulnerability Report

By Your WP Guy / Jan 5, 2024

  Plugin Name: Orbit Fox by ThemeIsle Key Information: Software Type: Plugin Software Slug: themeisle-companion Software Status: Active Software Author: themeisle Software Downloads: 10,910,881 Active Installs: 200,000 Last Updated: January 5, 2024 Patched Versions: <= 2.10.26 Affected Versions: 2.10.27 Vulnerability Details: Name: Orbit Fox Companion <= 2.10.26 Title: Authenticated (Contributor+) Stored Cross-Site Scripting via custom…

Read More

LightStart Vulnerability – Maintenance Mode, Coming Soon and Landing Page Builder – Missing Authorization – CVE-2023-7019| WordPress Plugin Vulnerability Report

By Your WP Guy / Jan 5, 2024

Plugin Name: LightStart – Maintenance Mode, Coming Soon and Landing Page Builder Key Information: Software Type: Plugin Software Slug: wp-maintenance-mode Software Status: Active Software Author: themeisle Software Downloads: 15,432,322 Active Installs: 700,000 Last Updated: January 5th, 2024 Patched Versions: 2.6.9 Affected Versions: <= 2.6.8 Vulnerability Details: Name: LightStart – Maintenance Mode, Coming Soon and Landing…

Read More

What are Abandoned WordPress Plugins?

By Your WP Guy / Aug 22, 2023

Imagine you own a small online business. You built your website on WordPress and installed a few plugins to add useful features like contact forms, social sharing buttons, and SEO optimization. These plugins worked great initially. But over time some of them have stopped receiving updates. The developers seem to have abandoned these plugins altogether.…

Read More