An advisory has been issued about a high-severity WordPress vulnerability that makes it possible for attackers to inject arbitrary shortcodes into sites using the WordPress Popular Posts plugin. Attackers do not need a user account …
Continue readingTag: Affects
WordPress Backup Plugin Vulnerability Affects 3+ Million Sites
A high severity vulnerability in a popular WordPress backup plugin allows unauthenticated attackers to exploit the flaw. The vulnerability is rated 8.8 on a scale of 0.0 to 10. UpdraftPlus: WP Backup & Migration Plugin …
Continue readingWPForms Plugin Vulnerability Affects Up To 6 Million Sites
The WPForms plugin for WordPress exposes websites to a vulnerability that allows attackers to update subscriptions and issue refunds. This flaw enables attackers to modify data they normally should not have access to. Missing Capability …
Continue readingWordPress Translation Plugin Vulnerability Affects +1 Million Sites
A critical vulnerability was discovered in the WPML WordPress plugin, affecting over a million installations. The vulnerability allows an authenticated attacker to perform remote code execution, potentially leading to a total site takeover. It is …
Continue readingWordPress Cache Plugin Vulnerability Affects +5 Million Websites
Up to 5 million installations of the LiteSpeed Cache WordPress plugin are vulnerable to an exploit that allows hackers to gain administrator rights and upload malicious files and plugins The vulnerability was first reported to …
Continue reading