Web safety

Contact Form 7 Vulnerability– Dynamic Text Extension – Insecure Direct Object Reference – CVE-2023-6630 | WordPress Plugin Vulnerability Report

By Your WP Guy / Jan 10, 2024

Plugin Name: Contact Form 7 – Dynamic Text Extension Key Information: Software Type: Plugin Software Slug: contact-form-7-dynamic-text-extension Software Status: Active Software Author: sevenspark Software Downloads: 1,173,724 Active Installs: 100,000 Last Updated: January 10, 2023 Patched Versions: 4.2.0 Affected Versions: <= 4.1.0 Vulnerability Details: Name: Contact Form 7 – Dynamic Text Extension <= 4.1.0 Title: Insecure…

Read More

Newsletter Vulnerability– Send Awesome Emails from WordPress – Cross-Site Request Forgery |WordPress Plugin Vulnerability Report

By Your WP Guy / Jan 10, 2024

Plugin Name: Newsletter – Send Awesome Emails from WordPress Key Information: Software Type: Plugin Software Slug: newsletter Software Status: Active Software Author: satollo Software Downloads: 23,000,399 Active Installs: 300,000 Last Updated: January 10, 2024 Patched Versions: 8.0.7 Affected Versions: <= 8.0.6 Vulnerability Details: Name: Newsletter <= 8.0.6 Title: Cross-Site Request Forgery (CSRF) Type: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:N/I:L/A:N CVE:…

Read More

POST SMTP Vulnerability – The #1 WordPress SMTP Plugin – Authorization Bypass via type connect-app API – CVE-2023-6875 | WordPress Plugin Vulnerability Report 

By Your WP Guy / Jan 10, 2024

Plugin Name: POST SMTP – The #1 WordPress SMTP Plugin with Advanced Email Logging and Delivery Failure Notifications Key Information: Software Type: Plugin Software Slug: post-smtp Software Status: Active Software Author: wpexpertsio Software Downloads: 11,120,456 Active Installs: 300,000 Last Updated: January 10, 2024 Patched Versions: 2.8.8 Affected Versions: <= 2.8.7 Vulnerability Details: Name: POST SMTP…

Read More

Customer Reviews for WooCommerce Vulnerability – Authenticated (Author+) Arbitrary File Upload – CVE-2023-6979 |WordPress Plugin Vulnerability Report

By Your WP Guy / Jan 9, 2024

Plugin Name: Customer Reviews for WooCommerce Key Information: Software Type: Plugin Software Slug: customer-reviews-woocommerce Software Status: Active Software Author: ivole Software Downloads: 3,786,034 Active Installs: 60,000 Last Updated: January 9, 2024 Patched Versions: 5.38.10 Affected Versions: <= 5.38.9 Vulnerability Details: Name: Customer Reviews for WooCommerce <= 5.38.9 Title: Authenticated (Author+) Arbitrary File Upload Type: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H…

Read More

Email Encoder Vulnerability – Protect Email Addresses and Phone Numbers – Authenticated (Contributor+) Stored Cross-Site Scripting – CVE-2023-7070 |WordPress Plugin Vulnerability Report

By Your WP Guy / Jan 9, 2024

Plugin Name: Email Encoder – Protect Email Addresses and Phone Numbers Key Information: Software Type: Plugin Software Slug: email-encoder-bundle Software Status: Active Software Author: ironikus Software Downloads: 996,589 Active Installs: 80,000 Last Updated: January 9, 2024 Patched Versions: 2.1.10 Affected Versions: <= 2.1.9 Vulnerability Details: Name: Email Encoder <= 2.1.9 Title: Authenticated (Contributor+) Stored Cross-Site…

Read More

Essential Blocks Vulnerability – Page Builder Gutenberg Blocks, Patterns & Templates – Authenticated (Contributor+) Stored Cross-Site Scripting – CVE-2023-7071 | WordPress Plugin Vulnerability Report

By Your WP Guy / Jan 9, 2024

Plugin Name: Essential Blocks – Page Builder Gutenberg Blocks, Patterns & Templates Key Information: Software Type: Plugin Software Slug: essential-blocks Software Status: Active Software Author: wpdevteam Software Downloads: 2,305,018 Active Installs: 100,000 Last Updated: January 9, 2024 Patched Versions: 4.4.7 Affected Versions: <= 4.4.6 Vulnerability Details: Name: Essential Blocks <= 4.4.6 Title: Authenticated (Contributor+) Stored…

Read More

Happy Addons for Elementor – Authenticated (Contributor+) Stored Cross-Site Scripting |WordPress Plugin Vulnerability Report 

By Your WP Guy / Jan 9, 2024

Plugin Name: Happy Addons for Elementor Key Information: Software Type: Plugin Software Slug: happy-elementor-addons Software Status: Active Software Author: thehappymonster Software Downloads: 5,771,889 Active Installs: 400,000 Last Updated: January 9, 2024 Patched Versions: 3.10.1 Affected Versions: <= 3.10.0 Vulnerability Details: Name: Happy Elementor Addons <= 3.10.0 Title: Authenticated (Contributor+) Stored Cross-Site Scripting Type: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N CVE:…

Read More

WordPress Plugin Vulnerability Report – Embed Calendly – Authenticated Stored Cross-Site Scripting – CVE-2023-4995

By Your WP Guy / Oct 13, 2023

Plugin Name: Embed Calendly Key Information: Software Type: Plugin Software Slug: embed-calendly-scheduling Software Status: Active Software Author: turn2honey Software Downloads: 165,873 Active Installs: 20,000 Last Updated: October 13th, 2023 Patched Versions: 3.7 Affected Versions: <= 3.6 Vulnerability Details: Name: Embed Calendly <= 3.6 – Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode Type: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N CVE: CVE-2023-4995…

Read More

WordPress Plugin Vulnerability Report – Modern Events Calendar Lite – Authenticated (Admin+) Stored Cross-Site Scripting – CVE-2023-4021

By Your WP Guy / Sep 29, 2023

Plugin Name: Modern Events Calendar Lite Key Information: Software Type: PluginSoftware Slug: modern-events-calendar-liteSoftware Status: RemovedSoftware Author: webnus/Software Downloads: 3,047,787Active Installs: 100,000Last Updated: September 28, 2023Patched Versions: 7.1.0Affected Versions: <7.1.0 Vulnerability Details: Name: Modern Events Calendar lite < 7.1.0 – Authenticated (Admin+) Stored Cross-Site ScriptingType: Improper Neutralization of Input During Web Page Generation (‘Cross-site Scripting’)CVE: CVE-2023-4021CVSS…

Read More