Security
Headlines
HeadlinesLatestCVEs

Tag

#wordpress

CVE-2023-22700: WordPress PixelYourSite – Your smart PIXEL (TAG) Manager plugin <= 9.3.0 - Cross Site Request Forgery (CSRF) vulnerability - Patchstack

Cross-Site Request Forgery (CSRF) vulnerability in PixelYourSite PixelYourSite – Your smart PIXEL (TAG) Manager plugin <= 9.3.0 versions.

CVE
#csrf#vulnerability#wordpress#auth
CVE-2023-25973: WordPress Auto Affiliate Links plugin <= 6.3.0.2 - Cross Site Request Forgery (CSRF) vulnerability - Patchstack

Cross-Site Request Forgery (CSRF) vulnerability in Lucian Apostol Auto Affiliate Links plugin <= 6.3.0.2 versions.

5 Lessons Learned From Hundreds of Penetration Tests

Developers must balance creativity with security frameworks to keep applications safe. Correlating business logic with security logic will pay in safety dividends.

CVE-2023-1374: Solidres <= 0.9.4 - Authenticated (Admin+) Stored Cross-Site Scripting — Wordfence Intelligence

The Solidres plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'currency_name' parameter in versions up to, and including, 0.9.4 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers with administrator privileges to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

CVE-2023-1372: WH Testimonials <= 3.0.0 - Unauthenticated Stored Cross-Site Scripting — Wordfence Intelligence

The WH Testimonials plugin for WordPress is vulnerable to Stored Cross-Site Scripting via several parameters such as wh_homepage, wh_text_short, wh_text_full and in versions up to, and including, 3.0.0 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

CVE-2022-47166: WordPress Void Contact Form 7 Widget For Elementor Page Builder plugin <= 2.1.1 - Cross Site Request Forgery (CSRF) - Patchstack

Cross-Site Request Forgery (CSRF) vulnerability in voidCoders Void Contact Form 7 Widget For Elementor Page Builder plugin <= 2.1.1 versions.