Website Protection

Appointment Booking Calendar Vulnerability— Simply Schedule Appointments Booking Plugin – Authenticated (Subscriber+) SQL Injection – CVE-2024-2341 |WordPress Plugin Vulnerability Report

By Your WP Guy / Mar 20, 2024

Plugin Name: Appointment Booking Calendar – Simply Schedule Appointments Booking Plugin Key Information: Software Type: Plugin Software Slug: simply-schedule-appointments Software Status: Active Software Author: croixhaug Software Downloads: 963,505 Active Installs: 30,000 Last Updated: March 20, 2024 Patched Versions: 1.6.7.9 Affected Versions: <= 1.6.7.7 Vulnerability Details: Name: Appointment Booking Calendar – Simply Schedule Appointments Booking Plugin…

Read More

Permalink Manager Pro Vulnerability- Missing Authorization via get_uri_editor – CVE-2024-2543 |WordPress Plugin Vulnerability Report

By Your WP Guy / Mar 20, 2024

Plugin Name: Permalink Manager Pro Key Information: Software Type: Plugin Software Slug: permalink-manager Software Status: Active Software Author: mbis Software Downloads: 1,664,850 Active Installs: 80,000 Last Updated: March 20, 2024 Patched Versions: 2.4.3.2 Affected Versions: <= 2.4.3.1 Vulnerability Details: Name: Plugin Permalink <= 2.4.3.1 Type: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N CVE: CVE-2024-2543 CVSS Score: 4.3 Publicly Published: March 20,…

Read More

Essential Blocks Vulnerability – Page Builder Gutenberg Blocks, Patterns & Templates – Authenticated (Contributor+) Stored Cross-Site Scripting – CVE-2024-2255 |WordPress Plugin Vulnerability Report

By Your WP Guy / Mar 19, 2024

Plugin Name: Essential Blocks – Page Builder Gutenberg Blocks, Patterns & Templates Key Information: Software Type: Plugin Software Slug: essential-blocks Software Status: Active Software Author: wpdevteam Software Downloads: 2,747,397 Active Installs: 100,000 Last Updated: March 19, 2024 Patched Versions: 4.5.4 Affected Versions: <= 4.5.2 Vulnerability Details: Name: Essential Blocks – Page Builder Gutenberg Blocks, Patterns…

Read More

Smart Custom Fields Vulnerability – Missing Authorization to Authenticated (Subscriber+) Post Content Disclosure – CVE-2024-1995 | WordPress Plugin Vulnerability Report

By Your WP Guy / Mar 19, 2024

Plugin Name: Smart Custom Fields Key Information: Software Type: Plugin Software Slug: smart-custom-fields Software Status: Active Software Author: inc2734 Software Downloads: 224,550 Active Installs: 50,000 Last Updated: March 19, 2024 Patched Versions: 5.0.0 Affected Versions: <= 4.2.2 Vulnerability Details: Name: Smart Custom Fields <= 4.2.2 Title: Missing Authorization to Authenticated (Subscriber+) Post Content Disclosure Type:…

Read More

Backuply Vulnerability– Backup, Restore, Migrate and Clone – Authenticated (Admin+) Directory Traversal – CVE-2024-2294 | WordPress Plugin Vulnerability Report

By Your WP Guy / Mar 15, 2024

Plugin Name: Backuply – Backup, Restore, Migrate and Clone Key Information: Software Type: Plugin Software Slug: backuply Software Status: Active Software Author: softaculous Software Downloads: 2,266,088 Active Installs: 200,000 Last Updated: March 19, 2024 Patched Versions: 1.2.8 Affected Versions: <= 1.2.7 Vulnerability Details: Name: Backuply – Backup, Restore, Migrate and Clone <= 1.2.7 Title: Authenticated…

Read More

HT Mega Vulnerability– Absolute Addons For Elementor – Authenticated Directory Traversal – CVE-2024-1974 |WordPress Plugin Vulnerability Report

By Your WP Guy / Mar 14, 2024

Plugin Name: HT Mega – Absolute Addons For Elementor Key Information: Software Type: Plugin Software Slug: ht-mega-for-elementor Software Status: Active Software Author: devitemsllc Software Downloads: 3,604,562 Active Installs: 100,000 Last Updated: March 14, 2024 Patched Versions: 2.4.7 Affected Versions: <= 2.4.6 Vulnerability Details: Name: HT Mega – Absolute Addons For Elementor <= 2.4.6 Title: Authenticated…

Read More

Site Reviews Vulnerability – Authenticated Stored Cross-Site Scripting via Display Name – CVE-2024-2293 | WordPress Plugin Vulnerability Report 

By Your WP Guy / Mar 11, 2024

Plugin Name: Site Reviews Key Information: Software Type: Plugin Software Slug: site-reviews Software Status: Active Software Author: geminilabs Software Downloads: 2,210,571 Active Installs: 60,000 Last Updated: March 13, 2024 Patched Versions: 6.11.7 Affected Versions: <= 6.11.4 Vulnerability Details: Name: Site Reviews <= 6.11.4 Title: Authenticated(Subscriber+) Stored Cross-Site Scripting via Display Name Type: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N CVE: CVE-2024-2293…

Read More

WP Statistics Vulnerability- Unauthenticated Stored Cross-Site Scripting – CVE-2024-2194 |WordPress Plugin Vulnerability Report

By Your WP Guy / Mar 11, 2024

Plugin Name: WP Statistics Key Information: Software Type: Plugin Software Slug: wp-statistics Software Status: Active Software Author: mostafas1990 Software Downloads: 22,569,004 Active Installs: 600,000 Last Updated: March 13, 2024 Patched Versions: 14.5.1 Affected Versions: <= 14.5 Vulnerability Details: Name: WP Statistics <= 14.5 Title: Unauthenticated Stored Cross-Site Scripting Type: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N CVE: CVE-2024-2194 CVSS Score: 7.2…

Read More

Page Builder: Pagelayer Vulnerability– Drag and Drop website builder – Authenticated (Contributor+) Stored Cross-Site Scripting via Custom Attributes – CVE-2024-2127 |WordPress Plugin Vulnerability Report

By Your WP Guy / Mar 7, 2024

Plugin Name: Page Builder: Pagelayer – Drag and Drop website builder Key Information: Software Type: Plugin Software Slug: pagelayer Software Status: Active Software Author: softaculous Software Downloads: 5,791,472 Active Installs: 200,000 Last Updated: March 12, 2024 Patched Versions: 1.8.4 Affected Versions: <= 1.8.3 Vulnerability Details: Name: Page Builder: Pagelayer – Drag and Drop website builder…

Read More

WP Chat App Vulnerability – Authenticated (Contributor+) Stored Cross-Site Scripting via Block Attributes – CVE-2024-1761 |WordPress Plugin Vulnerability Report

By Your WP Guy / Mar 6, 2024

Plugin Name: WP Chat App Key Information: Software Type: Plugin Software Slug: wp-whatsapp Software Status: Active Software Author: ninjateam Software Downloads: 880,497 Active Installs: 100,000 Last Updated: March 8, 2024 Patched Versions: 3.6.2 Affected Versions: <= 3.6.1 Vulnerability Details: Name: WP Chat App <= 3.6.1 Title: Authenticated (Contributor+) Stored Cross-Site Scripting via Block Attributes Type:…

Read More