Category: Security Advisories

Critical Vulnerability Patched in GiveWP Plugin

Published on January 10, 2025

The vulnerability in the GiveWP plugin was originally reported by Patchstack Alliance community member Edisc from Zalopay Security to the Patchstack Zero Day bug bounty program for WordPress. Patchstack Zero Day program has awarded the researcher a bounty of $2,600 USD. If you wish to participate in the program, you can join the community here. […]

Read more →

Multiple Critical Vulnerabilities Patched in WPLMS and VibeBP Plugins

Published on December 23, 2024

This blog post is about the WPLMS and VibeBP vulnerabilities. If you’re a WPLMS and VibeBP user, please update the plugin to at least version 1.9.9.5.3 and 1.9.9.7.7 respectively. If you are a Patchstack customer, you are protected from this vulnerability already, and no further action is required from you. For plugin developers, we have security […]

Read more →

Multiple Critical Vulnerabilities Patched in Woffice Theme

Published on December 12, 2024

This blog post is about the Woffice theme vulnerabilities. If you’re a Woffice user, please update the theme to at least version 5.4.15. Patchstack customers are protected from this vulnerability, and no immediate action is needed from you. For plugin developers, we have security audit services and Enterprise API for hosting companies. About the Woffice Theme The theme Woffice, […]

Read more →

Unauthenticated Privilege Escalation Vulnerability Patched in Sweet Date Theme

Published on December 5, 2024

This blog post discusses about the findings on the Sweet Date theme. If you’re a Sweet Date user, please update the theme to version 3.8.0 or higher. If you are a Patchstack customer, you are protected from this vulnerability already, and no further action is required from you. For plugin developers, we have security audit services and Enterprise […]

Read more →
Previous Page 2 of 12 Next