Podcast Episode 17: 3 Severe WordPress Plugin Vulnerabilities
Podcast Episode 17: 3 Severe WordPress Plugin Vulnerabilities Mikey Veenstra joins us to talk about three WordPress plugins with severe vulnerabilities affecting well over 150,000 WordPress installations. Two plugins have been patched, one has not. With Mark under...
Critical Vulnerability Patched in Popular Convert Plus Plugin
Critical Vulnerability Patched in Popular Convert Plus Plugin Description: Unauthenticated Administrator CreationCVSS v3.0 Score: 10.0 (Critical)CVSS Vector String: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:HAffected Plugin: Convert PlusPlugin Slug:...Event Management Tickets Booking By Event Monster <= 1.0.5 – Stored XSS
https://wpvulndb.com/vulnerabilities/9290 Source: Security FeedHostel Plugin <= 1.1.3 – Unauthenticated Stored XSS
https://wpvulndb.com/vulnerabilities/9289 Source: Security FeedPrivilege Escalation Flaw Present In Slick Popup Plugin
Privilege Escalation Flaw Present In Slick Popup Plugin In April, our Threat Intelligence team identified a privilege escalation flaw present in the latest version of Slick Popup, a WordPress plugin with approximately 7,000 active installs. We notified the developers,...indeed-membership-pro (Ultimate Membership Pro) <=7.5 arbitrary media upload
https://wpvulndb.com/vulnerabilities/9293 Source: Security Feed