WP-Polls <= 2.77.2 - Unauthenticated SQL Injection to Stored Cross-Site Scripting 21 January 2025 · Trust & Safety (Threat Alert)~ #CyberAdvisory, #InfoSec, #ThreatIntelligenceStay updated on cybersecurity threats to safeguard your systems and data from... Read Full Article
GamiPress <= 7.2.1 - Unauthenticated SQL Injection via orderby Parameter 21 January 2025 · Trust & Safety (Threat Alert)~ #CyberAdvisory, #InfoSec, #ThreatIntelligenceStay updated on cybersecurity threats to safeguard your systems and data from... Read Full Article
WPBot Pro WordPress Chatbot <= 13.5.5 - Missing Authorization to Authenticated (Subscriber+) Simple Text Response Creation 21 January 2025 · Trust & Safety (Threat Alert)~ #CyberAdvisory, #InfoSec, #ThreatIntelligenceStay updated on cybersecurity threats to safeguard your systems and data from... Read Full Article
Themify Builder <= 7.6.5 - Reflected Cross-Site Scripting 21 January 2025 · Trust & Safety (Threat Alert)~ #CyberAdvisory, #InfoSec, #ThreatIntelligenceStay updated on cybersecurity threats to safeguard your systems and data from... Read Full Article
Picture Gallery – Frontend Image Uploads, AJAX Photo List <= 1.5.19 - Authenticated (Contributor+) Stored Cross-Site Scripting 21 January 2025 · Trust & Safety (Threat Alert)~ #CyberAdvisory, #InfoSec, #ThreatIntelligenceStay updated on cybersecurity threats to safeguard your systems and data from... Read Full Article
aDirectory – WordPress Directory Listing Plugin <= 1.6.5 - Unauthenticated PHP Object Injection 20 January 2025 · Trust & Safety (Threat Alert)~ #CyberAdvisory, #InfoSec, #ThreatIntelligenceStay updated on cybersecurity threats to safeguard your systems and data from... Read Full Article
1003 Mortgage Application <= 1.87 - Unauthenticated Full Path Disclosure 20 January 2025 · Trust & Safety (Threat Alert)~ #CyberAdvisory, #InfoSec, #ThreatIntelligenceStay updated on cybersecurity threats to safeguard your systems and data from... Read Full Article
Visual Website Collaboration, Feedback & Project Management – Atarim <= 4.0.9 - Missing Authorization to Authenticated (Subscriber+) Project Page/File Deletion 20 January 2025 · Trust & Safety (Threat Alert)~ #CyberAdvisory, #InfoSec, #ThreatIntelligenceStay updated on cybersecurity threats to safeguard your systems and data from... Read Full Article
Jet Elements <= 2.7.2.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via Multiple Widgets 20 January 2025 · Trust & Safety (Threat Alert)~ #CyberAdvisory, #InfoSec, #ThreatIntelligenceStay updated on cybersecurity threats to safeguard your systems and data from... Read Full Article
Social Share, Social Login and Social Comments Plugin – Super Socializer <= 7.14 - Unauthenticated Limited SQL Injection via 'SuperSocializerKey' 20 January 2025 · Trust & Safety (Threat Alert)~ #CyberAdvisory, #InfoSec, #ThreatIntelligenceStay updated on cybersecurity threats to safeguard your systems and data from... Read Full Article