Blog Posts

Unauthenticated Arbitrary File Upload Vulnerability in Chaty Pro Plugin

Published on March 5, 2025

This blog post discusses about the findings on the Chaty Pro plugin. This vulnerability is fixed on version 3.3.4 and the vulnerable function didn’t exist on free version (Chaty) of the plugin. If you are a Patchstack customer, you are protected from this vulnerability already, and no further action is required from you. For plugin […]

Read more →

The Best WooCommerce Security Plugins

Published on February 26, 2025

Is your WooCommerce store truly secure? If you cannot confidently say “Yes!” then it is vital to be aware that just one single security breach could easily cripple your business overnight. This can quickly lead to financial losses, reputational damage, and the loss of valuable customer data – which can, in turn, result in legal […]

Read more →

Critical Privilege Escalation Patched in KLEO Theme’s Plugin

Published on February 20, 2025

This blog post is about the K Elements plugin vulnerability. If you’re a KLEO theme user who is using the K Elements plugin, please update the plugin to at least version 5.4.0. If you are a Patchstack customer, you are protected from this vulnerability already, and no further action is required from you. For plugin […]

Read more →

Interview with Dhabaleshwar Das

Published on February 14, 2025

Today we present an interview with Dhabaleshwar Das. He’s a security professional with 3 years of experience across various domains, including web, network, API, and mobile VAPT, container, and cloud security, as well as red teaming. He also has a passion for traveling, writing, and photography. Why did you end up in security? Was this […]

Read more →

Rare Case of Privilege Escalation in ASE Plugin Affecting 100k+ Sites

Published on February 5, 2025

This blog post is about the Admin and Site Enhancements (ASE) free and pro plugin vulnerability. If you’re an Admin and Site Enhancements (ASE) user, please update the plugin to at least version 7.6.3. If you are a Patchstack customer, you are protected from this vulnerability already, and no further action is required from you. […]

Read more →

Privilege Escalation Vulnerability Patched in Better Find and Replace Plugin

Published on January 29, 2025

This blog post is about the Better Find and Replace plugin vulnerability. If you’re a Better Find and Replace user, please update the plugin to at least version 1.6.8. If you are a Patchstack customer, you are protected from this vulnerability already, and no further action is required from you. For plugin developers, we have security […]

Read more →

Interview with Kévin Mosbahi AKA Mika

Published on January 21, 2025

Today we present an interview with Kévin Mosbahi(most of you probably know him by his nickname – Mika). He lives in France and has been passionate about computers since he was a teenager. Over time he specialized in security, which is his current day job. He’s a fast learner and he loves learning new things from […]

Read more →

How & Why You Should Remove Unused WordPress Plugins

Published on January 14, 2025

As a seasoned WordPress developer, you might have spent countless hours perfecting your WordPress site by carefully selecting themes and plugins to create an outstanding experience. But did you stop and think about all the plugins that you no longer need? If you have numerous plugins installed on your WordPress site, you should consider removing […]

Read more →
Previous Page 4 of 40 (398 total posts) Next