WP Hotel Booking <= 2.1.6 - Missing Authorization to Authenticated (Subscriber+) User Email Retrieval 21 January 2025 · Trust & Safety (Threat Alert)~ #CyberAdvisory, #InfoSec, #ThreatIntelligenceStay updated on cybersecurity threats to safeguard your systems and data from... Read Full Article
AI Power: Complete AI Pack <= 1.8.96 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Shortcode Execution 21 January 2025 · Trust & Safety (Threat Alert)~ #CyberAdvisory, #InfoSec, #ThreatIntelligenceStay updated on cybersecurity threats to safeguard your systems and data from... Read Full Article
WP-BibTeX <= 3.0.1 - Cross-Site Request Forgery to Stored and Reflected Cross-Site Scripting 20 January 2025 · Trust & Safety (Threat Alert)~ #CyberAdvisory, #InfoSec, #ThreatIntelligenceStay updated on cybersecurity threats to safeguard your systems and data from... Read Full Article
aDirectory – WordPress Directory Listing Plugin <= 1.6.5 - Unauthenticated PHP Object Injection 20 January 2025 · Trust & Safety (Threat Alert)~ #CyberAdvisory, #InfoSec, #ThreatIntelligenceStay updated on cybersecurity threats to safeguard your systems and data from... Read Full Article
1003 Mortgage Application <= 1.87 - Unauthenticated Full Path Disclosure 20 January 2025 · Trust & Safety (Threat Alert)~ #CyberAdvisory, #InfoSec, #ThreatIntelligenceStay updated on cybersecurity threats to safeguard your systems and data from... Read Full Article
Visual Website Collaboration, Feedback & Project Management – Atarim <= 4.0.9 - Missing Authorization to Authenticated (Subscriber+) Project Page/File Deletion 20 January 2025 · Trust & Safety (Threat Alert)~ #CyberAdvisory, #InfoSec, #ThreatIntelligenceStay updated on cybersecurity threats to safeguard your systems and data from... Read Full Article
Jet Elements <= 2.7.2.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via Multiple Widgets 20 January 2025 · Trust & Safety (Threat Alert)~ #CyberAdvisory, #InfoSec, #ThreatIntelligenceStay updated on cybersecurity threats to safeguard your systems and data from... Read Full Article
Social Share, Social Login and Social Comments Plugin – Super Socializer <= 7.14 - Unauthenticated Limited SQL Injection via 'SuperSocializerKey' 20 January 2025 · Trust & Safety (Threat Alert)~ #CyberAdvisory, #InfoSec, #ThreatIntelligenceStay updated on cybersecurity threats to safeguard your systems and data from... Read Full Article
String Locator <= 2.6.6 - Unauthenticated PHP Object Injection 20 January 2025 · Trust & Safety (Threat Alert)~ #CyberAdvisory, #InfoSec, #ThreatIntelligenceStay updated on cybersecurity threats to safeguard your systems and data from... Read Full Article
Betheme <= 27.6.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via Custom JS 20 January 2025 · Trust & Safety (Threat Alert)~ #CyberAdvisory, #InfoSec, #ThreatIntelligenceStay updated on cybersecurity threats to safeguard your systems and data from... Read Full Article