Website Protection

WP Dashboard Notes Vulnerability- Missing Authorization to Arbitrary Private Notes Update – CVE-2023-7239 |WordPress Plugin Vulnerability Report

By Your WP Guy / Jan 26, 2024

Plugin Name: WP Dashboard Notes Key Information: Software Type: Plugin Software Slug: wp-dashboard-notes Software Status: Active Software Author: sormano Software Downloads: 176,276 Active Installs: 30,000 Last Updated: January 30, 2024 Patched Versions: 1.0.10 Affected Versions: <= 1.0.10 Vulnerability Details: Name: WP Dashboard Notes <= 1.0.10 Title: Missing Authorization to Arbitrary Private Notes Update Type: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N…

Form Maker by 10Web Vulnerability– Mobile-Friendly Drag & Drop Contact Form Builder – Cross-Site Request Forgery to Limited Code Execution via Execute – CVE-2024-0667 |WordPress Plugin Vulnerability Report

By Your WP Guy / Jan 26, 2024

Plugin Name: Form Maker by 10Web – Mobile-Friendly Drag & Drop Contact Form Builder Key Information: Software Type: Plugin Software Slug: form-maker Software Status: Active Software Author: 10web Software Downloads: 4,670,950 Active Installs: 60,000 Last Updated: February 1, 2024 Patched Versions: 1.15.22 Affected Versions: <= 1.15.21 Vulnerability Details: Name: Form-Maker (twb_form-maker) <= 1.15.21 Title: Cross-Site…

10Web AI Assistant Vulnerability – AI Content Writing Assistant – Missing Authorization to Arbitrary Plugin Installation – CVE-2023-6985 |WordPress Plugin Vulnerability Report 

By Your WP Guy / Jan 25, 2024

Plugin Name: 10Web AI Assistant – AI Content Writing Assistant Key Information: Software Type: Plugin Software Slug: ai-assistant-by-10web Software Status: Active Software Author: 10web Software Downloads: 20,225 Active Installs: 30,000 Last Updated: January 30, 2024 Patched Versions: 1.0.19 Affected Versions: <= 1.0.18 Vulnerability Details: Name: 10Web AI Assistant – AI Content Writing Assistant <= 1.0.18…

Elementor Addons by Livemesh Vulnerability – Authenticated (Contributor+) Stored Cross-Site Scripting – CVE-2024-0448 |WordPress Plugin Vulnerability Report

By Your WP Guy / Jan 25, 2024

Plugin Name: Elementor Addons by Livemesh Key Information: Software Type: Plugin Software Slug: addons-for-elementor Software Status: Active Software Author: livemesh Software Downloads: 3,692,182 Active Installs: 70,000 Last Updated: January 30, 2024 Patched Versions: 8.3.2 Affected Versions: <= 8.3.1 Vulnerability Details: Name: Elementor Addons by Livemesh <= 8.3.1 Title: Authenticated (Contributor+) Stored Cross-Site Scripting Type: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N…

WP RSS Aggregator Vulnerability– RSS Import, News Feeds, Feed to Post, and Autoblogging – Authenticated (Admin+) Stored Cross-Site Scripting via RSS Feed Source – CVE-2024-0630 |WordPress Plugin Vulnerability Report 

By Your WP Guy / Jan 25, 2024

Plugin Name: WP RSS Aggregator – RSS Import, News Feeds, Feed to Post, and Autoblogging Key Information: Software Type: Plugin Software Slug: wp-rss-aggregator Software Status: Active Software Author: jeangalea Software Downloads: 2,603,596 Active Installs: 60,000 Last Updated: January 30, 2024 Patched Versions: 4.23.5 Affected Versions: <= 4.23.4 Vulnerability Details: Name: WP RSS Aggregator <= 4.23.4…

AI Engine Vulnerability – Authenticated(Editor+) Arbitrary File Upload via add_image_from_url – CVE-2024-0699 | WordPress Plugin Vulnerability Report

By Your WP Guy / Jan 18, 2024

Plugin Name: AI Engine Key Information: Software Type: Plugin Software Slug: ai-engine Software Status: Active Software Author: tigroumeow Software Downloads: 1,716,148 Active Installs: 50,000 Last Updated: January 18, 2024 Patched Versions: 2.1.5 Affected Versions: <= 2.1.4 Vulnerability Details: Name: AI Engine <= 2.1.4 – Authenticated(Editor+) Arbitrary File Upload via add_image_from_url Title: Authenticated(Editor+) Arbitrary File Upload via add_image_from_url Type: Unrestricted Upload of File with Dangerous Type CVE: CVE-2024-0699 CVSS…

Getwid – Gutenberg Blocks – Missing Authorization & Captcha Bypass – CVE-2023-6959 & CVE-2023-6963 | WordPress Plugin Vulnerability Report 

By Your WP Guy / Jan 17, 2024

Plugin Name: Getwid – Gutenberg Blocks Key Information: Software Type: Plugin Software Slug: getwid Software Status: Active Software Author: jetmonsters Software Downloads: 1,066,235 Active Installs: 50,000 Last Updated: January 25, 2024 Patched Versions: 2.0.5 Affected Versions: <= 2.0.4 Vulnerability Details – Section 1: Name: Getwid – Gutenberg Blocks <= 2.0.4 Title: Missing Authorization to Recaptcha…

Essential Addons for Elementor Vulnerabilities- Authenticated Stored Cross-Site Scripting – CVE-2024-0586 & CVE-2024-0585 | WordPress Plugin Vulnerability Report

By Your WP Guy / Jan 17, 2024

Plugin Name: Essential Addons for Elementor – Best Elementor Templates, Widgets, Kits & WooCommerce Builders Key Information: Software Type: Plugin Software Slug: essential-addons-for-elementor-lite Software Status: Active Software Author: wpdevteam Software Downloads: 64,711,817 Active Installs: 2,000,000 Last Updated: January 17, 2024 Patched Versions: 5.9.5 Affected Versions: <= 5.9.4 Vulnerability Details – Section 1: Name: Essential Addons…

WP Recipe Maker Vulnerability – Authenticated (Contributor+) Stored Cross-Site Scripting via header_tag – CVE-2024-0382 | WordPress Plugin Vulnerability Report

By Your WP Guy / Jan 17, 2024

Plugin Name: WP Recipe Maker Key Information: Software Type: Plugin Software Slug: wp-recipe-maker Software Status: Active Software Author: brechtvds Software Downloads: 2,536,653 Active Installs: 50,000 Last Updated: January 22, 2024 Patched Versions: 9.1.1 Affected Versions: <= 9.1.0 Vulnerability Details: Name: WP Recipe Maker <= 9.1.0 Title: Authenticated (Contributor+) Stored Cross-Site Scripting via header_tag Type: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N…

 Advanced Custom Fields (ACF) – Authenticated (Contributor+) Stored Cross-Site Scripting via Custom Field – CVE-2023-6701 | WordPress Plugin Vulnerability Report

By Your WP Guy / Jan 17, 2024

Plugin Name: Advanced Custom Fields (ACF) Key Information: Software Type: Plugin Software Slug: advanced-custom-fields Software Status: Active Software Author: wpengine Software Downloads: 44,336,988 Active Installs: 2,000,000 Last Updated: January 25, 2024 Patched Versions: 6.2.5 Affected Versions: <= 6.2.4 Vulnerability Details: Name: Advanced Custom Fields <= 6.2.4 Title: Authenticated (Contributor+) Stored Cross-Site Scripting via Custom Field…