wordpress plugins

WP Plugin Vulnerabilities Image - WordPress Plugin Vulnerability Report - Ocean Extra - Cross-Site Request Forgery to Arbitrary Plugin Activation - wordpress plugins

WordPress Plugin Vulnerability Report – Ocean Extra – Cross-Site Request Forgery to Arbitrary Plugin Activation

By Your WP Guy / Nov 28, 2023

Plugin Name: Ocean Extra Key Information: Software Type: Plugin Software Slug: ocean-extra Software Status: Active Software Author: oceanwp Software Downloads: 19,047,434 Active Installs: 700,000 Last Updated: November 28, 2023 Patched Versions: 2.2.3 Affected Versions: <= 2.2.2 Vulnerability Details: Name: Ocean Extra <= 2.2.2 – Cross-Site Request Forgery to Arbitrary Plugin Activation Title: Cross-Site Request Forgery to Arbitrary Plugin Activation Type: Cross-Site Request Forgery (CSRF) CVSS Score: 4.3 (Medium)…

Read More
WP Plugin Vulnerabilities Image - WordPress Plugin Vulnerability Report - Slider - Missing Authorization via AJAX action - wordpress plugins

WordPress Plugin Vulnerability Report – Slider – Missing Authorization via AJAX action

By Your WP Guy / Nov 16, 2023

Plugin Name: Slider – Ultimate Responsive Image Slider Key Information: Software Type: Plugin Software Slug: ultimate-responsive-image-slider Software Status: Active Software Author: farazfrank Software Downloads: 1,338,384 Active Installs: 40,000 Last Updated: November 16, 2023 Patched Versions: 3.5.12 Affected Versions: <= 3.5.11 Vulnerability Details: Name: Ultimate Responsive Image Slider <= 3.5.11 – Missing Authorization via AJAX action Title: Missing Authorization via AJAX action Type: Missing Authorization CVSS Score: 4.3 (Medium)…

Read More
business executive overloaded with work 2021 08 26 22 39 44 utc - Avoiding Information Overload: Filtering Reliable WordPress Advice - wordpress plugins

Avoiding Information Overload: Filtering Reliable WordPress Advice

By Your WP Guy / Nov 14, 2023

With over 40% of websites using WordPress as their CMS, there is plenty of information out there when you need advice. But with such high volumes, there are bound to be a few bad eggs. The internet is saturated with so-called “WordPress experts” offering contradicting advice. So, how do you know who to trust? As…

Read More
hand of a businessman shaking hands with a android 2022 02 02 03 49 01 utc 1024x683 1 - How to Choose Between Manual and Automated WordPress Maintenance - wordpress plugins

How to Choose Between Manual and Automated WordPress Maintenance

By Your WP Guy / Oct 31, 2023

If you’re running a small business owner, you’re likely wearing many hats and juggling countless tasks. And if you’re using WordPress for your website (which, let’s be honest, is pretty likely considering WordPress powers over 40% of the web), that’s another hat to add to your collection: The WordPress maintenance hat! Before you start panicking…

Read More
WP Plugin Vulnerabilities Image - WordPress Plugin Vulnerability Report - WP Customer Reviews - Authenticated (Subscriber+) Sensitive Information Exposure - CVE-2023-4686 - wordpress plugins

WordPress Plugin Vulnerability Report – WP Customer Reviews – Authenticated (Subscriber+) Sensitive Information Exposure – CVE-2023-4686

By Your WP Guy / Oct 31, 2023

Plugin Name: WP Customer Reviews Key Information: Software Type: Plugin Software Slug: wp-customer-reviews Software Status: Active Software Author: bompus Software Downloads: 1,108,443 Active Installs: 30,000 Last Updated: October 31, 2023 Patched Versions: No Patched Version Affected Versions: <= 3.6.8 Vulnerability Details: Name: WP Customer Reviews <= 3.6.8 – Authenticated (Subscriber+) Sensitive Information Exposure Title: Authenticated (Subscriber+) Sensitive Information Exposure Type: Missing Authorization CVE: CVE-2023-4686 CVSS Score: 4.3 (Medium) Publicly…

Read More
WP Plugin Vulnerabilities Image - WordPress Plugin Vulnerability Report - Embed Calendly - Authenticated Stored Cross-Site Scripting - CVE-2023-4995 - wordpress plugins

WordPress Plugin Vulnerability Report – Embed Calendly – Authenticated Stored Cross-Site Scripting – CVE-2023-4995

By Your WP Guy / Oct 13, 2023

Plugin Name: Embed Calendly Key Information: Software Type: Plugin Software Slug: embed-calendly-scheduling Software Status: Active Software Author: turn2honey Software Downloads: 165,873 Active Installs: 20,000 Last Updated: October 13th, 2023 Patched Versions: 3.7 Affected Versions: <= 3.6 Vulnerability Details: Name: Embed Calendly <= 3.6 – Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode Type: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N CVE: CVE-2023-4995…

Read More
WP Plugin Vulnerabilities Image - WordPress Plugin Vulnerability Report - POST SMTP Mailer - Authenticated (Administrator+) SQL Injection - wordpress plugins

WordPress Plugin Vulnerability Report – POST SMTP Mailer – Authenticated (Administrator+) SQL Injection

By Your WP Guy / Oct 3, 2023

Plugin Name: POST SMTP Mailer Key Information: Software Type: PluginSoftware Slug: post-smtpSoftware Status: ActiveSoftware Author: wpexpertsioSoftware Downloads: 9,128,571Active Installs: 300,000Last Updated: October 3, 2023Patched Versions: 2.6.1Affected Versions: <=2.6.0 Vulnerability Details: Name: Post SMTP <= 2.6.0 – Authenticated (Administrator+) SQL InjectionType: Improper Neutralization of Special Elements used in an SQL Command (‘SQL Injection’)CVE: NACVSS Score: 7.2…

Read More
WP Plugin Vulnerabilities Image - WordPress Plugin Vulnerability Report - Comments – wpDiscuz - Unauthenticated SQL Injection - wordpress plugins

WordPress Plugin Vulnerability Report – Comments – wpDiscuz – Unauthenticated SQL Injection

By Your WP Guy / Sep 18, 2023

Plugin Name: Comments – wpDiscuz Key Information: Software Type: Plugin Software Slug: wpdiscuz Software Status: Active Software Author: advancedcoding Software Downloads: 2,865,421 Active Installs: 80,000 Last Updated: September 18, 2023 Patched Versions: 7.6.6 Affected Versions: <=7.6.5 Vulnerability Details: Name: wpDiscuz <= 7.6.5 – Unauthenticated SQL Injection Type: Improper Neutralization of Special Elements used in an…

Read More
WP Plugin Vulnerabilities Image - WordPress Plugin Vulnerability Report - Essential Addons for Elementor - Authenticated (Contributor+) Privilege Escalation - wordpress plugins

WordPress Plugin Vulnerability Report – Essential Addons for Elementor – Authenticated (Contributor+) Privilege Escalation

By Your WP Guy / Sep 14, 2023

Plugin Name: Essential Addons for Elementor Key Information: Software Type: Plugin Software Slug: essential-addons-for-elementor-lite Software Status: Active Software Author: wpdevteam Software Downloads: 55,164,924 Active Installs: 1,000,000 Last Updated: September 14, 2023 Patched Versions: 5.8.9 Affected Versions: <=5.8.8 Vulnerability Details: Name: Essential Addons for Elementor <= 5.8.8 – Authenticated (Contributor+) Privilege Escalation Type: Missing Authorization CVSS…

Read More
WP Plugin Vulnerabilities Image - WordPress Plugin Vulnerability Report - Migration, Backup, Staging – WPvivid - Missing Authorization & Stored Cross-Site Scripting - wordpress plugins

WordPress Plugin Vulnerability Report – Migration, Backup, Staging – WPvivid – Missing Authorization & Stored Cross-Site Scripting

By Your WP Guy / Sep 12, 2023

Plugin Name: Migration, Backup, Staging – WPvivid Key Information: Software Type: Plugin Software Slug: wpvivid-backuprestore Software Status: Active Software Author: wpvividplugins Software Downloads: 5,141,419 Active Installs: 300,000 Last Updated: September 12, 2023 Patched Versions: 0.9.91 Affected Versions: <=0.9.90 First Vulnerability: Vulnerability Details: Name: WPvivid Backup Plugin <= 0.9.90 – Missing Authorization via ‘start_staging’ and ‘get_staging_progress’…

Read More