Small Business Security

Bold Page Builder Vulnerability – Stored Cross-Site Scripting – CVE-2024-3267 & CVE-2024-3266 | WordPress Plugin Vulnerability Report

By Your WP Guy / Apr 5, 2024

Plugin Name: Bold Page Builder Key Information: Software Type: Plugin Software Slug: bold-page-builder Software Status: Active Software Author: BoldThemes Software Downloads: 1,754,649 Active Installs: 50,000 Last Updated: April 16, 2024 Patched Versions: 4.8.9 Affected Versions: <= 4.8.8 Vulnerability 1 Details: Name: Bold Page Builder <= 4.8.8 Title: Authenticated (Contributor+) Stored Cross-Site Scripting via bt_bb_price_list Shortcode…

CMB2 Vulnerability – Authenticated PHP Object Injection – CVE-2024-1792 | WordPress Plugin Vulnerability Report

By Your WP Guy / Apr 3, 2024

Plugin Name: CMB2 Key Information: Software Type: Plugin Software Slug: cmb2 Software Status: Active Software Author: jtsternberg Software Downloads: 4,198,199 Active Installs: 300,000 Last Updated: April 3, 2024 Patched Versions: 2.11.0 Affected Versions: <= 2.10.1 Vulnerability Details: Name: CMB2 <= 2.10.1 Title: Authenticated PHP Object Injection Type: CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H CVE: CVE-2024-1792 CVSS Score: 7.2 Publicly Published:…

BoldGrid Easy SEO Vulnerability – Authenticated(Contributor+) Stored Cross-Site Scripting via Meta Description – CVE-2024-1692 |WordPress Plugin Vulnerability Report

By Your WP Guy / Mar 29, 2024

Plugin Name: BoldGrid Easy SEO – Simple and Effective SEO Key Information: Software Type: Plugin Software Slug: boldgrid-easy-seo Software Status: Active Software Author: boldgrid Software Downloads: 692,441 Active Installs: 70,000 Last Updated: April 1, 2024 Patched Versions: 1.6.14 Affected Versions: <= 1.6.13 Vulnerability Details: Name: BoldGrid Easy SEO – Simple and Effective SEO <= 1.6.13…

Appointment Booking Calendar Vulnerability— Simply Schedule Appointments Booking Plugin – Authenticated (Subscriber+) SQL Injection – CVE-2024-2341 |WordPress Plugin Vulnerability Report

By Your WP Guy / Mar 20, 2024

Plugin Name: Appointment Booking Calendar – Simply Schedule Appointments Booking Plugin Key Information: Software Type: Plugin Software Slug: simply-schedule-appointments Software Status: Active Software Author: croixhaug Software Downloads: 963,505 Active Installs: 30,000 Last Updated: March 20, 2024 Patched Versions: 1.6.7.9 Affected Versions: <= 1.6.7.7 Vulnerability Details: Name: Appointment Booking Calendar – Simply Schedule Appointments Booking Plugin…

Permalink Manager Pro Vulnerability- Missing Authorization via get_uri_editor – CVE-2024-2543 |WordPress Plugin Vulnerability Report

By Your WP Guy / Mar 20, 2024

Plugin Name: Permalink Manager Pro Key Information: Software Type: Plugin Software Slug: permalink-manager Software Status: Active Software Author: mbis Software Downloads: 1,664,850 Active Installs: 80,000 Last Updated: March 20, 2024 Patched Versions: 2.4.3.2 Affected Versions: <= 2.4.3.1 Vulnerability Details: Name: Plugin Permalink <= 2.4.3.1 Type: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N CVE: CVE-2024-2543 CVSS Score: 4.3 Publicly Published: March 20,…

Appointment Booking Calendar Vulnerability— Simply Schedule Appointments Booking Plugin – Cross-Site Request Forgery to Plugin Data Reset – CVE-2024-1760 | WordPress Plugin Vulnerability Report

By Your WP Guy / Mar 5, 2024

Plugin Name: Appointment Booking Calendar – Simply Schedule Appointments Booking Plugin Key Information: Software Type: Plugin Software Slug: simply-schedule-appointments Software Status: Active Software Author: croixhaug Software Downloads: 943,138 Active Installs: 60,000 Last Updated: March 7, 2024 Patched Versions: 1.6.6.24 Affected Versions: <= 1.6.6.20 Vulnerability Details: Name: Appointment Booking Calendar – Simply Schedule Appointments Booking Plugin…

Download Manager Vulnerability- Missing Authorization – CVE-2023-6785 | WordPress Plugin Vulnerability Report

By Your WP Guy / Feb 28, 2024

Plugin Name: Download Manager Key Information: Software Type: Plugin Software Slug: download-manager Software Status: Active Software Author: codename065 Software Downloads: 8,301,669 Active Installs: 100,000 Last Updated: March 1, 2024 Patched Versions: 3.2.85 Affected Versions: <=3.2.84 Vulnerability Details: Name: Download Manager <= 3.2.84 Title: Missing Authorization Type: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N CVE: CVE-2023-6785 CVSS Score: 5.3 Publicly Published: February…

ProfilePress Vulnerability – Authenticated (Contributor+) Stored Cross-Site Scripting via profilepress-edit-profile Shortcode – CVE-2024-1806 | WordPress Plugin Vulnerability Report

By Your WP Guy / Feb 23, 2024

Plugin Name: Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content – ProfilePress Key Information: Software Type: Plugin Software Slug: wp-user-avatar Software Status: Active Software Author: collizo4sky Software Downloads: 12,533,974 Active Installs: 200,000 Last Updated: February 27, 2024 Patched Versions: 4.15.1 Affected Versions: <= 4.15.1 Vulnerability Details: Name: ProfilePress <=…

Ocean Extra Vulnerability- Authenticated (Contributor+) Stored Cross-Site Scripting – CVE-2024-1277 | WordPress Plugin Vulnerability Report 

By Your WP Guy / Feb 16, 2024

Plugin Name: Ocean Extra Key Information: Software Type: Plugin Software Slug: ocean-extra Software Status: Active Software Author: oceanwp Software Downloads: 20,016,876 Active Installs: 700,000 Last Updated: February 27, 2024 Patched Versions: 2.2.5 Affected Versions: <= 2.2.4 Vulnerability Details: Name: Ocean Extra <= 2.2.4 Title: Authenticated (Contributor+) Stored Cross-Site Scripting Type: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N CVE: CVE-2024-1277 CVSS Score:…

Microsoft Clarity Vulnerability- Cross-Site Request Forgery to Stored Cross-Site Scripting – CVE-2024-0590 |WordPress Plugin Vulnerability Report

By Your WP Guy / Feb 16, 2024

Plugin Name: Microsoft Clarity Key Information: Software Type: Plugin Software Slug: microsoft-clarity Software Status: Active Software Author: sammartin Software Downloads: 312,923 Active Installs: 70,000 Last Updated: February 27, 2024 Patched Versions: 0.9.4 Affected Versions: <= 0.9.3 Vulnerability Details: Name: Microsoft Clarity <= 0.9.3 Title: Cross-Site Request Forgery to Stored Cross-Site Scripting Type: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N CVE: CVE-2024-0590…