small business cybersecurity

Cookie Information | Free GDPR Consent Solution Vulnerability – Authenticated (Subscriber+) Arbitrary Options Update – CVE-2023-6700 | WordPress Plugin Vulnerability Report

By Your WP Guy / Jan 29, 2024

Plugin Name: Cookie Information | Free GDPR Consent Solution Key Information: Software Type: Plugin Software Slug: wp-gdpr-compliance Software Status: Active Software Author: cookieinformation Software Downloads: 3,745,212 Active Installs: 100,000 Last Updated: February 2, 2024 Patched Versions: 2.0.23 Affected Versions: <= 2.0.22 Vulnerability Details: Name: Cookie Information | Free GDPR Consent Solution <= 2.0.22 Title: Authenticated…

Instant Images Vulnerability– One Click Image Uploads from Unsplash, Openverse, Pixabay, and Pexels – Authenticated (Author+) Arbitrary Options Update – CVE-2024-0869 |WordPress Plugin Vulnerability Report

By Your WP Guy / Jan 29, 2024

Plugin Name: Instant Images – One Click Image Uploads from Unsplash, Openverse, Pixabay, and Pexels Key Information: Software Type: Plugin Software Slug: instant-images Software Status: Active Software Author: connekthq Software Downloads: 1,803,436 Active Installs: 100,000 Last Updated: February 2, 2024 Patched Versions: 6.1.1 Affected Versions: <= 6.1.0 Vulnerability Details: Name: Instant Images <= 6.1.0 Title:…

MapPress Maps for WordPress Vulnerability- Authenticated (Contributor+) Stored Cross-Site Scripting – CVE-2023-7225 |WordPress Plugin Vulnerability Report

By Your WP Guy / Jan 29, 2024

Plugin Name: MapPress Maps for WordPress Key Information: Software Type: Plugin Software Slug: mappress-google-maps-for-wordpress Software Status: Active Software Author: chrisvrichardson Software Downloads: 4,193,183 Active Installs: 50,000 Last Updated: February 2, 2024 Patched Versions: 2.88.17 Affected Versions: <= 2.88.16 Vulnerability Details: Name: MapPress <= 2.88.16 Title: Authenticated (Contributor+) Stored Cross-Site Scripting via Map Settings Type: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N…

Formidable Forms Vulnerability– Contact Form, Survey, Quiz, Payment, Calculator Form & Custom Form Builder – Cross-Site Request Forgery to Stored Cross-Site Scripting – CVE-2024-0660 |WordPress Plugin Vulnerability Report

By Your WP Guy / Jan 26, 2024

Plugin Name: Formidable Forms – Contact Form, Survey, Quiz, Payment, Calculator Form & Custom Form Builder Key Information: Software Type: Plugin Software Slug: formidable Software Status: Active Software Author: strategy11team Software Downloads: 19,521,336 Active Installs: 300,000 Last Updated: January 30, 2024 Patched Versions: 6.8 Affected Versions: <= 6.7.2 Vulnerability Details: Name: Formidable Forms <= 6.7.2…

Form Maker by 10Web Vulnerability– Mobile-Friendly Drag & Drop Contact Form Builder – Cross-Site Request Forgery to Limited Code Execution via Execute – CVE-2024-0667 |WordPress Plugin Vulnerability Report

By Your WP Guy / Jan 26, 2024

Plugin Name: Form Maker by 10Web – Mobile-Friendly Drag & Drop Contact Form Builder Key Information: Software Type: Plugin Software Slug: form-maker Software Status: Active Software Author: 10web Software Downloads: 4,670,950 Active Installs: 60,000 Last Updated: February 1, 2024 Patched Versions: 1.15.22 Affected Versions: <= 1.15.21 Vulnerability Details: Name: Form-Maker (twb_form-maker) <= 1.15.21 Title: Cross-Site…

WP RSS Aggregator Vulnerability– RSS Import, News Feeds, Feed to Post, and Autoblogging – Authenticated (Admin+) Stored Cross-Site Scripting via RSS Feed Source – CVE-2024-0630 |WordPress Plugin Vulnerability Report 

By Your WP Guy / Jan 25, 2024

Plugin Name: WP RSS Aggregator – RSS Import, News Feeds, Feed to Post, and Autoblogging Key Information: Software Type: Plugin Software Slug: wp-rss-aggregator Software Status: Active Software Author: jeangalea Software Downloads: 2,603,596 Active Installs: 60,000 Last Updated: January 30, 2024 Patched Versions: 4.23.5 Affected Versions: <= 4.23.4 Vulnerability Details: Name: WP RSS Aggregator <= 4.23.4…

Contact Form 7 Vulnerability– Dynamic Text Extension – Insecure Direct Object Reference – CVE-2023-6630 | WordPress Plugin Vulnerability Report

By Your WP Guy / Jan 10, 2024

Plugin Name: Contact Form 7 – Dynamic Text Extension Key Information: Software Type: Plugin Software Slug: contact-form-7-dynamic-text-extension Software Status: Active Software Author: sevenspark Software Downloads: 1,173,724 Active Installs: 100,000 Last Updated: January 10, 2023 Patched Versions: 4.2.0 Affected Versions: <= 4.1.0 Vulnerability Details: Name: Contact Form 7 – Dynamic Text Extension <= 4.1.0 Title: Insecure…

Email Encoder Vulnerability – Protect Email Addresses and Phone Numbers – Authenticated (Contributor+) Stored Cross-Site Scripting – CVE-2023-7070 |WordPress Plugin Vulnerability Report

By Your WP Guy / Jan 9, 2024

Plugin Name: Email Encoder – Protect Email Addresses and Phone Numbers Key Information: Software Type: Plugin Software Slug: email-encoder-bundle Software Status: Active Software Author: ironikus Software Downloads: 996,589 Active Installs: 80,000 Last Updated: January 9, 2024 Patched Versions: 2.1.10 Affected Versions: <= 2.1.9 Vulnerability Details: Name: Email Encoder <= 2.1.9 Title: Authenticated (Contributor+) Stored Cross-Site…

Essential Blocks Vulnerability – Page Builder Gutenberg Blocks, Patterns & Templates – Authenticated (Contributor+) Stored Cross-Site Scripting – CVE-2023-7071 | WordPress Plugin Vulnerability Report

By Your WP Guy / Jan 9, 2024

Plugin Name: Essential Blocks – Page Builder Gutenberg Blocks, Patterns & Templates Key Information: Software Type: Plugin Software Slug: essential-blocks Software Status: Active Software Author: wpdevteam Software Downloads: 2,305,018 Active Installs: 100,000 Last Updated: January 9, 2024 Patched Versions: 4.4.7 Affected Versions: <= 4.4.6 Vulnerability Details: Name: Essential Blocks <= 4.4.6 Title: Authenticated (Contributor+) Stored…

Happy Addons for Elementor – Authenticated (Contributor+) Stored Cross-Site Scripting |WordPress Plugin Vulnerability Report 

By Your WP Guy / Jan 9, 2024

Plugin Name: Happy Addons for Elementor Key Information: Software Type: Plugin Software Slug: happy-elementor-addons Software Status: Active Software Author: thehappymonster Software Downloads: 5,771,889 Active Installs: 400,000 Last Updated: January 9, 2024 Patched Versions: 3.10.1 Affected Versions: <= 3.10.0 Vulnerability Details: Name: Happy Elementor Addons <= 3.10.0 Title: Authenticated (Contributor+) Stored Cross-Site Scripting Type: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N CVE:…