wordpress security

Website Builder by SeedProd Vulnerability – Missing Authorization via seedprod_lite_new_lpage – CVE-2024-1072 | WordPress Plugin Vulnerability Report

By Your WP Guy / Jan 31, 2024

Plugin Name: Website Builder by SeedProd – Theme Builder, Landing Page Builder, Coming Soon Page, Maintenance Mode Key Information: Software Type: Plugin Software Slug: coming-soon Software Status: Active Software Author: seedprod Software Downloads: 23,816,722 Active Installs: 900,000 Last Updated: February 1, 2024 Patched Versions: 6.15.23 Affected Versions: <= 6.15.21 Vulnerability Details: Name: Website Builder by…

Database for Contact Form 7, WPforms, Elementor forms Vulnerability – Authenticated (Administrator+) Arbitrary File Upload – CVE-2024-1069 | WordPress Plugin Vulnerability Report

By Your WP Guy / Jan 30, 2024

Plugin Name: Database for Contact Form 7, WPforms, Elementor forms Key Information: Software Type: Plugin Software Slug: contact-form-entries Software Status: Active Software Author: crmperks Software Downloads: 502,953 Active Installs: 60,000 Last Updated: February 1, 2024 Patched Versions: 1.3.3 Affected Versions: <= 1.3.2 Vulnerability Details: Name: Contact Form Entries <= 1.3.2 Title: Authenticated (Administrator+) Arbitrary File…

Starbox Vulnerability – the Author Box for Humans – Insecure Direct Object Reference – CVE-2024-0366 | WordPress Plugin Vulnerability Report

By Your WP Guy / Jan 30, 2024

Plugin Name: Starbox – the Author Box for Humans Key Information: Software Type: Plugin Software Slug: starbox Software Status: Active Software Author: cifi Software Downloads: 441,960 Active Installs: 50,000 Last Updated: February 1, 2024 Patched Versions: 3.4.8 Affected Versions: <= 3.4.7 Vulnerability Details: Name: Starbox – the Author Box for Humans <= 3.4.7 Title: Insecure…

Cookie Information | Free GDPR Consent Solution Vulnerability – Authenticated (Subscriber+) Arbitrary Options Update – CVE-2023-6700 | WordPress Plugin Vulnerability Report

By Your WP Guy / Jan 29, 2024

Plugin Name: Cookie Information | Free GDPR Consent Solution Key Information: Software Type: Plugin Software Slug: wp-gdpr-compliance Software Status: Active Software Author: cookieinformation Software Downloads: 3,745,212 Active Installs: 100,000 Last Updated: February 2, 2024 Patched Versions: 2.0.23 Affected Versions: <= 2.0.22 Vulnerability Details: Name: Cookie Information | Free GDPR Consent Solution <= 2.0.22 Title: Authenticated…

Instant Images Vulnerability– One Click Image Uploads from Unsplash, Openverse, Pixabay, and Pexels – Authenticated (Author+) Arbitrary Options Update – CVE-2024-0869 |WordPress Plugin Vulnerability Report

By Your WP Guy / Jan 29, 2024

Plugin Name: Instant Images – One Click Image Uploads from Unsplash, Openverse, Pixabay, and Pexels Key Information: Software Type: Plugin Software Slug: instant-images Software Status: Active Software Author: connekthq Software Downloads: 1,803,436 Active Installs: 100,000 Last Updated: February 2, 2024 Patched Versions: 6.1.1 Affected Versions: <= 6.1.0 Vulnerability Details: Name: Instant Images <= 6.1.0 Title:…

MapPress Maps for WordPress Vulnerability- Authenticated (Contributor+) Stored Cross-Site Scripting – CVE-2023-7225 |WordPress Plugin Vulnerability Report

By Your WP Guy / Jan 29, 2024

Plugin Name: MapPress Maps for WordPress Key Information: Software Type: Plugin Software Slug: mappress-google-maps-for-wordpress Software Status: Active Software Author: chrisvrichardson Software Downloads: 4,193,183 Active Installs: 50,000 Last Updated: February 2, 2024 Patched Versions: 2.88.17 Affected Versions: <= 2.88.16 Vulnerability Details: Name: MapPress <= 2.88.16 Title: Authenticated (Contributor+) Stored Cross-Site Scripting via Map Settings Type: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N…

SEO Plugin by Squirrly SEO Vulnerability- Authenticated (Administrator+) Stored Cross-Site Scripting – CVE-2024-0597 |WordPress Plugin Vulnerability Report

By Your WP Guy / Jan 29, 2024

Plugin Name: SEO Plugin by Squirrly SEO Key Information: Software Type: Plugin Software Slug: squirrly-seo Software Status: Active Software Author: cifi Software Downloads: 4,689,778 Active Installs: 200,000 Last Updated: February 2, 2024 Patched Versions: 12.3.16 Affected Versions: <= 12.3.15 Vulnerability Details: Name: SEO Plugin by Squirrly SEO <= 12.3.15 Title: Authenticated (Administrator+) Stored Cross-Site Scripting…

Formidable Forms Vulnerability– Contact Form, Survey, Quiz, Payment, Calculator Form & Custom Form Builder – Cross-Site Request Forgery to Stored Cross-Site Scripting – CVE-2024-0660 |WordPress Plugin Vulnerability Report

By Your WP Guy / Jan 26, 2024

Plugin Name: Formidable Forms – Contact Form, Survey, Quiz, Payment, Calculator Form & Custom Form Builder Key Information: Software Type: Plugin Software Slug: formidable Software Status: Active Software Author: strategy11team Software Downloads: 19,521,336 Active Installs: 300,000 Last Updated: January 30, 2024 Patched Versions: 6.8 Affected Versions: <= 6.7.2 Vulnerability Details: Name: Formidable Forms <= 6.7.2…

WP Dashboard Notes Vulnerability- Missing Authorization to Arbitrary Private Notes Update – CVE-2023-7239 |WordPress Plugin Vulnerability Report

By Your WP Guy / Jan 26, 2024

Plugin Name: WP Dashboard Notes Key Information: Software Type: Plugin Software Slug: wp-dashboard-notes Software Status: Active Software Author: sormano Software Downloads: 176,276 Active Installs: 30,000 Last Updated: January 30, 2024 Patched Versions: 1.0.10 Affected Versions: <= 1.0.10 Vulnerability Details: Name: WP Dashboard Notes <= 1.0.10 Title: Missing Authorization to Arbitrary Private Notes Update Type: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N…

SiteOrigin Widgets Bundle Vulnerability- Authenticated (Contributor+) Stored Cross-Site Scripting – CVE-2024-0961 |WordPress Plugin Vulnerability Report

By Your WP Guy / Jan 26, 2024

Plugin Name: SiteOrigin Widgets Bundle Key Information: Software Type: Plugin Software Slug: so-widgets-bundle Software Status: Active Software Author: gpriday Software Downloads: 37,152,267 Active Installs: 600,000 Last Updated: February 1, 2024 Patched Versions: 1.58.2 Affected Versions: <= 1.58.1 Vulnerability Details: Name: SiteOrigin Widgets Bundle <= 1.58.1 Title: Authenticated (Contributor+) Stored Cross-Site Scripting Type: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N CVE: CVE-2024-0961…