Taskbuilder – WordPress Project & Task Management plugin <= 3.0.6 - Authenticated (Contributor+) Stored Cross-Site Scripting via wppm_tasks Shortcode 24 January 2025 · Trust & Safety (Threat Alert)~ #CyberAdvisory, #InfoSec, #ThreatIntelligenceStay updated on cybersecurity threats to safeguard your systems and data from... Read Full Article
Classic Addons – WPBakery Page Builder <= 3.0 - Authenticated (Editor+) Local File Inclusion 24 January 2025 · Trust & Safety (Threat Alert)~ #CyberAdvisory, #InfoSec, #ThreatIntelligenceStay updated on cybersecurity threats to safeguard your systems and data from... Read Full Article
Dynamics 365 Integration <= 1.3.23 - Authenticated (Contributor+) Remote Code Execution and Arbitrary File Read via Twig Server-Side Template Injection 24 January 2025 · Trust & Safety (Threat Alert)~ #CyberAdvisory, #InfoSec, #ThreatIntelligenceStay updated on cybersecurity threats to safeguard your systems and data from... Read Full Article
Astra Widgets <= 1.2.15 - Authenticated (Contributor+) Stored Cross-Site Scripting 24 January 2025 · Trust & Safety (Threat Alert)~ #CyberAdvisory, #InfoSec, #ThreatIntelligenceStay updated on cybersecurity threats to safeguard your systems and data from... Read Full Article
Store Commerce <= 1.2.3 - Authenticated (Contributor+) Stored Cross-Site Scripting 24 January 2025 · Trust & Safety (Threat Alert)~ #CyberAdvisory, #InfoSec, #ThreatIntelligenceStay updated on cybersecurity threats to safeguard your systems and data from... Read Full Article
JobBoard Job listing <= 1.2.6 - Unauthenticated Arbitrary File Upload 24 January 2025 · Trust & Safety (Threat Alert)~ #CyberAdvisory, #InfoSec, #ThreatIntelligenceStay updated on cybersecurity threats to safeguard your systems and data from... Read Full Article
Fancy Product Designer <= 6.4.3 - Unauthenticated SQL Injection 24 January 2025 · Trust & Safety (Threat Alert)~ #CyberAdvisory, #InfoSec, #ThreatIntelligenceStay updated on cybersecurity threats to safeguard your systems and data from... Read Full Article
Media Library Assistant <= 3.23 - Reflected Cross-Site Scripting via smc_settings_tab, unattachfixit-action, and woofixit-action Parameters 24 January 2025 · Trust & Safety (Threat Alert)~ #CyberAdvisory, #InfoSec, #ThreatIntelligenceStay updated on cybersecurity threats to safeguard your systems and data from... Read Full Article
PlainInventory <= 3.1.6 - Unauthenticated PHP Object Injection 24 January 2025 · Trust & Safety (Threat Alert)~ #CyberAdvisory, #InfoSec, #ThreatIntelligenceStay updated on cybersecurity threats to safeguard your systems and data from... Read Full Article
ARPrice <= 4.0.3 - Authenticated (Subscriber+) SQL Injection 24 January 2025 · Trust & Safety (Threat Alert)~ #CyberAdvisory, #InfoSec, #ThreatIntelligenceStay updated on cybersecurity threats to safeguard your systems and data from... Read Full Article