Category: Security Advisories

Ninja Forms Plugin Object Injection Security Bug Gets Patched

Published on June 17, 2022

TL;DR A critical security bug in Ninja Forms (1+ million installations) was patched by the plugin’s developers this week. The security bug posed a high risk, as it could result in unauthenticated object injection. Successful attacks could create arbitrary Classes within WordPress (and execute a function or method defined within). The WordPress.org plugins team took […]

Read more →

Critical Vulnerability Fixed In Elementor Plugin Version 3.6.3

Published on April 13, 2022

A critical vulnerability was fixed in the WordPress plugin Elementor. Do you want to be the first to be alerted about such vulnerabilities? Sign up for Patchstack. For plugin developers, we have security audit services and Threat Intelligence Feed API for hosting companies. Note: we are still gathering more information on this vulnerability, such as the requirements to exploit this vulnerability […]

Read more →

Critical Vulnerability Fixed In Responsive Menu Plugin

Published on February 8, 2022

The plugin Responsive Menu – Create Mobile-Friendly Menu (versions 4.1.7 and below), which has over 100.000 active installations, suffers from a critical vulnerability. This vulnerability allows any authenticated user, regardless of their authorization, to execute nearly all of the actions that only administrators are supposed to be able to execute. Do you want to be […]

Read more →

Critical Vulnerability Fixed In Essential Addons for Elementor Plugin

Published on January 27, 2022

A critical vulnerability was fixed in the WordPress plugin Essential Addons for Elementor. Do you want to be the first to be alerted about such vulnerabilities? Sign up for Patchstack. For plugin developers, we have security audit services and Threat Intelligence Feed API for hosting companies. Update February 1st, 2022: we would like to make clear that we did not originally […]

Read more →

Technical Advisory: WordPress Core 5.8.3 Security Update

Published on January 7, 2022

On the 6th of January 2022, WordPress.org released a security update and recommended users to “update your sites immediately”. This WordPress core 5.8.3 security update addresses 4 different security vulnerabilities which affect WordPress core versions between 3.7 and 5.8. For many, WordPress automatically updates the core to the latest version. Check if your WordPress version […]

Read more →

Extremely Critical Vulnerability In The Apache Log4j Logging Library

Published on December 13, 2021

Recently, an extremely critical remote code execution vulnerability was made public for the Apache Log4j logging library. If an organization or software made use of Apache Log4j logging library and the vulnerable version was running, it made it possible for malicious people to remotely execute commands which in many cases required no pre-requisites. A comprehensive […]

Read more →

An In-Depth Analysis Of The WP-VCD Malware

Published on December 2, 2021

The WP-VCD malware for WordPress has existed for many years. It mainly spreads by injecting itself into legitimate plugins and themes after which it will spread itself on sites that offer downloads to (nulled) WordPress plugins and themes. We noticed that during the corona-virus pandemic, the WP-VCD malware has also started injecting itself into plugins that can […]

Read more →

Multiple Security Vulnerabilities Fixed In Hide My WP by wpWave

Published on November 24, 2021

There were multiple security vulnerabilities fixed in the Hide My WP plugin by wpWave which allowed unauthenticated SQL injection and allowed unauthenticated users to retrieve a token to deactivate the plugin. Do you want to be the first to be alerted about such vulnerabilities? Sign up for Patchstack. For plugin developers, we have security audit services and Threat Intelligence Feed […]

Read more →

Critical Security Vulnerability Fixed In WP Reset PRO

Published on November 10, 2021

There was a critical security vulnerability in the WP Reset PRO plugin which allowed any authenticated user to wipe the database. Do you want to be the first to be alerted about such vulnerabilities? Sign up for Patchstack. For plugin developers, we have security audit services and Threat Intelligence Feed API for hosting companies. The PRO version of the WP Reset […]

Read more →
Previous Page 10 of 12 Next