Small Business Security

SiteOrigin Widgets Bundle Vulnerability – Authenticated (Contributor+) Stored Cross-Site Scripting in Image Grid Widget – CVE-2024-5901 | WordPress Plugin Vulnerability Report

By Your WP Guy / Jul 30, 2024

Plugin Name: SiteOrigin Widgets Bundle Key Information: Software Type: Plugin Software Slug: so-widgets-bundle Software Status: Active Software Author: gpriday Software Downloads: 40,680,217 Active Installs: 600,000 Last Updated: August 12, 2024 Patched Versions: 1.62.3 Affected Versions: <= 1.62.2 Vulnerability Details: Name: SiteOrigin Widgets Bundle <= 1.62.2 Title: Authenticated (Contributor+) Stored Cross-Site Scripting in Image Grid Widget…

Read More

Happy Addons for Elementor Vulnerability – Authenticated (Contributor+) Stored Cross-Site Scripting via PDF View Widget – CVE-2024-6627 | WordPress Plugin Vulnerability Report

By Your WP Guy / Jul 26, 2024

Plugin Name: Happy Addons for Elementor Key Information: Software Type: Plugin Software Slug: happy-elementor-addons Software Status: Active Software Author: thehappymonster Software Downloads: 7,563,441 Active Installs: 400,000 Last Updated: July 29, 2024 Patched Versions: 3.11.3 Affected Versions: <= 3.11.2 Vulnerability Details: Name: Happy Addons for Elementor <= 3.11.2 Type: Authenticated (Contributor+) Stored Cross-Site Scripting via PDF…

Read More

LiteSpeed Cache Vulnerability – Cross-Site Request Forgery to Stored Cross-Site Scripting – CVE-2024-3246 | WordPress Plugin Vulnerability Report

By Your WP Guy / Jul 23, 2024

Plugin Name: LiteSpeed Cache Key Information: Software Type: Plugin Software Slug: litespeed-cache Software Status: Active Software Author: litespeedtech Software Downloads: 70,093,541 Active Installs: 5,000,000 Last Updated: July 29, 2024 Patched Versions: 6.3 Affected Versions: <= 6.2.0.1 Vulnerability Details: Name: LiteSpeed Cache <= 6.2.0.1 Type: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N CVE: CVE-2024-3246 CVSS Score: 6.1 Publicly Published: July 23, 2024…

Read More

Royal Elementor Addons and Templates Vulnerability – Authenticated (Contributor+) DOM-Based Stored Cross-Site Scripting via Magazine Grid/Slider Widget – CVE-2024-5818 | WordPress Plugin Vulnerability Report

By Your WP Guy / Jul 23, 2024

Plugin Name: Royal Elementor Addons and Templates Key Information: Software Type: Plugin Software Slug: royal-elementor-addons Software Status: Active Software Author: wproyal Software Downloads: 6,367,071 Active Installs: 400,000 Last Updated: July 29, 2024 Patched Versions: 1.3.981 Affected Versions: <= 1.3.980 Vulnerability Details: Name: Royal Elementor Addons and Templates <= 1.3.980 Type: Authenticated (Contributor+) DOM-Based Stored Cross-Site…

Read More

Security Optimizer Vulnerability – Missing Authorization via hide_notice() – CVE-2024-38774 | WordPress Plugin Vulnerability Report

By Your WP Guy / Jul 19, 2024

Plugin Name: Security Optimizer – The All-In-One Protection Plugin Key Information: Software Type: Plugin Software Slug: sg-security Software Status: Active Software Author: siteground Software Downloads: 22,051,479 Active Installs: 1,000,000 Last Updated: July 29, 2024 Patched Versions: 1.5.1 Affected Versions: <= 1.5.0 Vulnerability Details: Name: Security Optimizer – The All-In-One Protection Plugin <= 1.5.0 Type: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N…

Read More

ElementsKit Elementor Addons Vulnerability – Unauthenticated Information Exposure via ekit_widgetarea_content Function – CVE-2024-6455 | WordPress Plugin Vulnerability Report

By Your WP Guy / Jul 18, 2024

Plugin Name: ElementsKit Elementor addons Key Information: Software Type: Plugin Software Slug: elementskit-lite Software Status: Active Software Author: xpeedstudio Software Downloads: 21,730,790 Active Installs: 1,000,000 Last Updated: July 29, 2024 Patched Versions: 3.2.1 Affected Versions: <= 3.2.0 Vulnerability Details: Name: ElementsKit Elementor addons <= 3.2.0 Type: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N CVE: CVE-2024-6455 CVSS Score: 5.4 Publicly Published: July…

Read More

Premium Addons for Elementor Vulnerability – Authenticated (Contributor+) Stored DOM-Based Cross-Site Scripting via Animated Text Widget – CVE-2024-6495 | WordPress Plugin Vulnerability Report

By Your WP Guy / Jul 11, 2024

Plugin Name: Premium Addons for Elementor Key Information: Software Type: Plugin Software Slug: premium-addons-for-elementor Software Status: Active Software Author: leap13 Software Downloads: 33,726,442 Active Installs: 700,000 Last Updated: July 27, 2024 Patched Versions: 4.10.37 Affected Versions: <= 4.10.36 Vulnerability Details: Name: Premium Addons for Elementor <= 4.10.36 Type: Authenticated (Contributor+) Stored DOM-Based Cross-Site Scripting via…

Read More

Ocean Extra Vulnerability – Authenticated (Contributor+) Stored Cross-Site Scripting – CVE-2024-37489 | WordPress Plugin Vulnerability Report

By Your WP Guy / Jul 4, 2024

Plugin Name: Ocean Extra Key Information: Software Type: Plugin Software Slug: ocean-extra Software Status: Active Software Author: oceanwp Software Downloads: 21,640,506 Active Installs: 600,000 Last Updated: July 26, 2024 Patched Versions: 2.3.0 Affected Versions: <= 2.2.9 Vulnerability Details: Name: Ocean Extra <= 2.2.9 Type: Authenticated (Contributor+) Stored Cross-Site Scripting CVE: CVE-2024-37489 CVSS Score: 6.4 Publicly…

Read More

Page Builder Gutenberg Blocks – CoBlocks Vulnerability – Authenticated (Contributor+) Server-Side Request Forgery – CVE-2024-4260 | WordPress Plugin Vulnerability Report

By Your WP Guy / Jul 2, 2024

Plugin Name: Page Builder Gutenberg Blocks – CoBlocks Key Information: Software Type: Plugin Software Slug: coblocks Software Status: Active Software Author: godaddy Software Downloads: 22,484,801 Active Installs: 400,000 Last Updated: August 6, 2024 Patched Versions: 3.1.12 Affected Versions: <= 3.1.11 Vulnerability Details: Name: Page Builder Gutenberg Blocks – CoBlocks <= 3.1.11 Type: Authenticated (Contributor+) Server-Side…

Read More

ElementsKit Elementor addons Vulnerability – Missing Authorization – CVE-2024-37255 | WordPress Plugin Vulnerability Report 

By Your WP Guy / Jun 27, 2024

Plugin Name: ElementsKit Elementor addons Key Information: Software Type: Plugin Software Slug: elementskit-lite Software Status: Active Software Author: xpeedstudio Software Downloads: 20,999,885 Active Installs: 1,000,000 Last Updated: July 22, 2024 Patched Versions: 3.2.0 Affected Versions: <= 3.1.4 Vulnerability Details: Name: ElementsKit Elementor addons <= 3.1.4 Title: Missing Authorization Type: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N CVE: CVE-2024-37255 CVSS Score: 5.3…

Read More