Category: Security Advisories

Critical Privilege Escalation in LiteSpeed Cache Plugin Affecting 5+ Million Sites

Published on August 21, 2024

The vulnerability in the LiteSpeed Cache plugin was originally reported by Patchstack Alliance community member John Blackbourn to the Patchstack Zero Day bug bounty program for WordPress. We are collaborating with the researcher to release the content of this security advisory article. This vulnerability has been rewarded the highest bounty in the history of WordPress […]

Read more →

Critical Vulnerability Patched in Backup and Staging by WP Time Capsule Plugin

Published on July 13, 2024

This blog post is about the WP Time Capsule plugin vulnerability. If you’re a WP Time Capsule plugin user, please update to at least version 1.22.21. Patchstack users are protected from this vulnerability. For plugin developers, we have security audit services and Enterprise API for hosting companies. About the Backup and Staging by WP Time CapsulePlugin Backup and Staging […]

Read more →

WordPress Core 6.5.5 Security Update – Technical Advisory

Published on July 1, 2024

On the 24th of June 2024, WordPress.org released a security update and recommended users update their sites as soon as possible. This WordPress core 6.5.5 security release addresses 3 different security vulnerabilities that affect multiple WordPress core versions. For many, WordPress automatically updates the core to the latest version. Check if your WordPress version is […]

Read more →

Multiple Vulnerabilities in WooCommerce Amazon Affiliates Plugin

Published on June 6, 2024

This blog post is about WooCommerce Amazon Affiliates (WZone) plugin vulnerabilities. If you’re a WooCommerce Amazon Affiliates (WZone) user, please deactivate and delete the plugin since there is still no known patched version. Patchstack users are protected from this vulnerability. For plugin developers, we have security audit services and Enterprise API for hosting companies. About the WZone Plugin The […]

Read more →

Critical Vulnerability Patched in UserPro Plugin

Published on May 22, 2024

This blog post is about the UserPro plugin vulnerabilities. If you’re a UserPro user, please update the plugin to at least version 5.1.9. Patchstack users are protected from this vulnerability. For plugin developers, we have security audit services and Enterprise API for hosting companies. About the UserPro Plugin The plugin UserPro (premium version), which has over 20,000 sales, is […]

Read more →

Critical Vulnerabilities Found in XStore Theme and Plugin

Published on May 14, 2024

This blog post is about the XStore theme and plugin vulnerabilities. If you’re an XStore user, please update the theme to at least version 9.3.9 and the plugin to at least version 5.3.9. Patchstack users are protected from this vulnerability. For plugin developers, we have security audit services and Enterprise API for hosting companies. About the XStore Theme and […]

Read more →

High Priority Vulnerabilities Patched in Uncode Core Plugin

Published on May 7, 2024

This blog post is about the Uncode Core plugin vulnerabilities. If you’re a Uncode user, please update the core plugin to at least version 2.8.9. Patchstack users are protected from this vulnerability. For plugin developers, we have security audit services and Enterprise API for hosting companies. About the Uncode Core Plugin The plugin Uncode Core (premium version) is a […]

Read more →
Previous Page 4 of 12 Next