Small Business Online Security

Master Addons Vulnerability – Free Widgets, Hover Effects, Toggle, Conditions, Animations for Elementor – Authenticated (Contributor+) Stored Cross-Site Scripting via Pricing Table Widget – CVE-2024-2139 |WordPress Plugin Vulnerability Report

By Your WP Guy / Mar 26, 2024

Plugin Name: Master Addons – Free Widgets, Hover Effects, Toggle, Conditions, Animations for Elementor Key Information: Software Type: Plugin Software Slug: master-addons Software Status: Active Software Author: litonice13 Software Downloads: 1,012,079 Active Installs: 40,000 Last Updated: March 26, 2024 Patched Versions: 2.0.5.7 Affected Versions: <= 2.0.5.6 Vulnerability Details: Name: Master Addons for Elementor <= 2.0.5.6…

Read More

Page scroll to id – Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode – CVE-2024-1445 |WordPress Plugin Vulnerability Report

By Your WP Guy / Feb 16, 2024

Plugin Name: Page scroll to id Key Information: Software Type: Plugin Software Slug: page-scroll-to-id Software Status: Active Software Author: malihu Software Downloads: 1,684,219 Active Installs: 100,000 Last Updated: February 27, 2024 Patched Versions: 1.7.9 Affected Versions: <= 1.7.8 Vulnerability Details: Name: Page scroll to id <= 1.7.8 Title: Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode…

Read More

 Advanced Custom Fields (ACF) – Authenticated (Contributor+) Stored Cross-Site Scripting via Custom Field – CVE-2023-6701 | WordPress Plugin Vulnerability Report

By Your WP Guy / Jan 17, 2024

Plugin Name: Advanced Custom Fields (ACF) Key Information: Software Type: Plugin Software Slug: advanced-custom-fields Software Status: Active Software Author: wpengine Software Downloads: 44,336,988 Active Installs: 2,000,000 Last Updated: January 25, 2024 Patched Versions: 6.2.5 Affected Versions: <= 6.2.4 Vulnerability Details: Name: Advanced Custom Fields <= 6.2.4 Title: Authenticated (Contributor+) Stored Cross-Site Scripting via Custom Field…

Read More

Burst Statistics Vulnerability – Authenticated (Editor+) SQL Injection – CVE-2024-0405 | WordPress Plugin Vulnerability Report 

By Your WP Guy / Jan 16, 2024

Plugin Name: Burst Statistics – Privacy-Friendly Analytics for WordPress Key Information: Software Type: Plugin Software Slug: burst-statistics Software Status: Active Software Author: rogierlankhorst Software Downloads: 1,470,512 Active Installs: 100,000 Last Updated: January 25, 2024 Patched Versions: 1.5.4 Affected Versions: <= 1.5.3 Vulnerability Details: Name: Burst Statistics Really Simple Plugins <= 1.5.3 Title: Authenticated (Editor+) SQL…

Read More