WordPress plugin vulnerability

Elementor Website Builder Vulnerability – Authenticated (Contributor+) DOM-Based Stored Cross-Site Scripting – CVE-2024-4619 | WordPress Plugin Vulnerability Report

By Your WP Guy / May 20, 2024

Plugin Name: Elementor Website Builder Key Information: Software Type: Plugin Software Slug: elementor Software Status: Active Software Author: elemntor Software Downloads: 443,549,337 Active Installs: 10,000,000 Last Updated: May 20, 2024 Patched Versions: 3.21.6 Affected Versions: <= 3.21.5 Vulnerability Details: Name: Elementor Website Builder – More than Just a Page Builder <= 3.21.5 – Authenticated (Contributor+)…

Read More

Essential Blocks Vulnerability – Authenticated (Contributor+) Stored Cross-Site Scripting – CVE-2024-4891 | WordPress Plugin Vulnerability Report

By Your WP Guy / May 16, 2024

Plugin Name: Essential Blocks Key Information: Software Type: Plugin Software Slug: essential-blocks Software Status: Active Software Author: wpdevteam Software Downloads: 3,418,922 Active Installs: 100,000 Last Updated: May 16, 2024 Patched Versions: 4.5.13 Affected Versions: <= 4.5.12 Vulnerability Details: Name: Essential Blocks – Page Builder Gutenberg Blocks, Patterns & Templates <= 4.5.12 – Authenticated (Contributor+) Stored…

Read More

Post and Page Builder by BoldGrid Vulnerability – Authenticated (Contributer+) Stored Cross-Site Scripting – CVE-2024-4400 | WordPress Plugin Vulnerability Report

By Your WP Guy / May 15, 2024

Plugin Name: Post and Page Builder by BoldGrid Key Information: Software Type: Plugin Software Slug: post-and-page-builder Software Status: Active Software Author: boldgrid Software Downloads: 1,446,399 Active Installs: 80,000 Last Updated: May 15, 2024 Patched Versions: 1.26.5 Affected Versions: <= 1.26.4 Vulnerability Details: Name: Post and Page Builder by BoldGrid – Visual Drag and Drop Editor…

Read More

Rank Math SEO Vulnerability – Authenticated (Contributor+) Stored Cross-Site Scripting – CVE-2024-4617 | WordPress Plugin Vulnerability Report

By Your WP Guy / May 15, 2024

Plugin Name: Rank Math SEO Key Information: Software Type: Plugin Software Slug: seo-by-rank-math Software Status: Active Software Author: rankmath Software Downloads: 95,765,382 Active Installs: 2,000,000 Last Updated: May 15, 2024 Patched Versions: 1.0.219-beta Affected Versions: <= 1.0.218 Vulnerability Details: Name: Rank Math SEO with AI Best SEO Tools <= 1.0.218 – Authenticated (Contributor+) Stored Cross-Site…

Read More

Tutor LMS Vulnerability – Multiple Vulnerabilities – CVE-2024-4279, CVE-2024-4318, CVE-2024-4223 | WordPress Plugin Vulnerability Report

By Your WP Guy / May 15, 2024

Plugin Name: Tutor LMS Key Information: Software Type: Plugin Software Slug: tutor Software Status: Active Software Author: themeum Software Downloads: 2,095,500 Active Installs: 80,000 Last Updated: May 15, 2024 Patched Versions: 2.7.1 Affected Versions: <= 2.7.0 Vulnerability 1 Details: Name: Tutor LMS – eLearning and online course solution <= 2.7.0 – Authenticated (Instructor+) Insecure Direct Object Reference to Arbitrary Course Deletion Title: Authenticated (Instructor+) Insecure…

Read More

Blocksy Companion Vulnerability – Authenticated (Contributor+) Stored Cross-Site Scripting via SVG Uploads – CVE-2024-4487 | WordPress Plugin Vulnerability Report

By Your WP Guy / May 10, 2024

Plugin Name: Blocksy Companion Key Information: Software Type: Plugin Software Slug: blocksy-companion Software Status: Active Software Author: creativethemeshq Software Downloads: 7,639,072 Active Installs: 200,000 Last Updated: May 10, 2024 Patched Versions: 2.0.46 Affected Versions: <= 2.0.45 Vulnerability Details: Name: Blocksy Companion <= 2.0.45 – Authenticated (Contributor+) Stored Cross-Site Scripting via SVG Uploads Type: Improper Neutralization…

Read More

TranslatePress Vulnerability – Cross-Site Request Forgery – CVE-2024-34827 | WordPress Plugin Vulnerability Report

By Your WP Guy / May 9, 2024

Plugin Name: TranslatePress Key Information: Software Type: Plugin Software Slug: translatepress-multilingual Software Status: Active Software Author: madalinungureanu Software Downloads: 10,058,842 Active Installs: 300,000 Last Updated: May 9, 2024 Patched Versions: 2.7.6 Affected Versions: <= 2.7.5 Vulnerability Details: Name: Translate Multilingual sites – TranslatePress <= 2.7.5 – Cross-Site Request Forgery Type: Cross-Site Request Forgery (CSRF) CVE:…

Read More

Content Views Vulnerability – Authenticated (Contributor+) Stored Cross-Site Scripting via pagingType Parameter – CVE-2024-4446 | WordPress Plugin Vulnerability Report

By Your WP Guy / May 6, 2024

Plugin Name: Content Views Key Information: Software Type: Plugin Software Slug: content-views-query-and-display-post-page Software Status: Active Software Author: pt-guy Software Downloads: 4,327,206 Active Installs: 100,000 Last Updated: May 6, 2024 Vulnerability Details: Name: Content Views – Post Grid & Filter, Recent Posts, Category Posts, & More (Gutenberg Blocks and Shortcode) <= 3.7.1 – Authenticated (Contributor+) Stored…

Read More

Print Invoice & Delivery Notes for WooCommerce Vulnerability – Missing Authorization to Notice Dismissal – CVE-2024-4233 | WordPress Plugin Vulnerability Report 

By Your WP Guy / Apr 26, 2024

Plugin Name: Print Invoice & Delivery Notes for WooCommerce Key Information: Software Type: Plugin Software Slug: woocommerce-delivery-notes Software Status: Active Software Author: tychesoftwares Software Downloads: 999,558 Active Installs: 40,000 Last Updated: May 10, 2024 Patched Versions: 4.9.0 Affected Versions: <= 4.8.1 Vulnerability Details: Name: Multiple Plugins by tychesoftwares <= 4.8.1 Title: Missing Authorization to Notice…

Read More

Contact Form 7 Database Addon Vulnerability – CFDB7 – Unauthenticated Sensitive Information Exposure – CVE-2024-3870 | WordPress Plugin Vulnerability Report 

By Your WP Guy / Apr 26, 2024

Plugin Name: Contact Form 7 Database Addon – CFDB7 Key Information: Software Type: Plugin Software Slug: contact-form-cfdb7 Software Status: Active Software Author: arshidkv12 Software Downloads: 5,113,134 Active Installs: 600,000 Last Updated: May 10, 2024 Patched Versions: 1.2.7 Affected Versions: <= 1.2.6.8 Vulnerability Details: Name: Contact Form 7 Database Addon – CFDB7 <= 1.2.6.8 Title: Unauthenticated…

Read More