Category: Security Advisories

Unauthenticated PHP Object Injection in Flatsome Theme <= 3.17.5

Published on September 6, 2023

This blog post is about the Flatsome theme vulnerability. If you’re a Flatsome user, please update the plugin to at least version 3.17.6. Patchstack users are protected from the vulnerability. For plugin developers, we have security audit services and Threat Intelligence Feed API for hosting companies. About the Flatsome Theme The theme Flatsome (versions 3.17.5 and below, premium version), […]

Read more →

Critical Arbitrary File Upload Patched in Forminator Plugin

Published on August 31, 2023

This security advisory is written about a critical Forminator vulnerability initially disclosed by MEHMET KELEPÇE. Patchstack users have received a vPatch to protect their site against this vulnerability. This blog post is about the Forminator plugin vulnerability. If you’re a Forminator user, please update the plugin to at least version 1.25.0. Patchstack users are protected from the […]

Read more →

Pre-Auth Access Token Manipulation in All-in-One WP Migration Extensions

Published on August 30, 2023

This blog post is about the All-in-One WP Migration Extensions vulnerability. If you’re an All-in-One WP Migration Extensions user specified below, please update the plugin to the patched version mentioned in this article. Patchstack users are protected from the vulnerability. For plugin developers, we have security audit services and Threat Intelligence Feed API for hosting companies. About the All-in-One […]

Read more →

Critical Vulnerabilities Patched in Jupiter X Core Plugin

Published on August 24, 2023

This blog post is about the Jupiter X Core plugin vulnerability. If you’re a Jupiter X user, please update the plugin to at least version 3.4.3. Patchstack users are protected from the vulnerability. For plugin developers, we have security audit services and Threat Intelligence Feed API for hosting companies. About the Jupiter X Core Plugin The plugin Jupiter X […]

Read more →

Multiple High and Critical Vulnerabilities in Avada Theme and Plugin

Published on August 10, 2023

This blog post is about the Avada theme and plugin vulnerability. If you’re a Avada user, please update the Avada builder plugin to at least version 3.11.2 and Avada theme to at least version 7.11.2. Patchstack users are protected from the vulnerability. For plugin developers, we have security audit services and Threat Intelligence Feed API for hosting companies. About […]

Read more →

Authenticated RCE in JetElements For Elementor Plugin

Published on August 3, 2023

This blog post is about the JetElements For Elementor plugin vulnerability. If you’re a JetElements For Elementor user, please update the plugin to at least version 2.6.11. Patchstack users are protected from the vulnerability. For plugin developers, we have security audit services and Threat Intelligence Feed API for hosting companies. About the JetElements For Elementor Plugin The plugin JetElements […]

Read more →

Multiple High Severity Vulnerabilities in Ninja Forms Plugin

Published on July 27, 2023

This blog post is about vulnerabilities in Ninja Forms plugin vulnerabilities. If you’re a Ninja Forms user, please update the plugin to at least version 3.6.26. Patchstack users are protected from the vulnerability. For plugin developers, we have security audit services and Threat Intelligence Feed API for hosting companies. About the Ninja Forms plugin The plugin Ninja Forms versions […]

Read more →

Critical Privilege Escalation in HT Mega Plugin Affecting 100k+ Sites

Published on July 14, 2023

This blog post is about the HT Mega plugin critical vulnerability. If you’re a HT Mega user, please update the plugin to at least version 2.2.1. Patchstack users are protected from the vulnerability. For plugin developers, we have security audit services and Threat Intelligence Feed API for hosting companies. About the HT Mega plugin The plugin HT Mega (versions […]

Read more →

Unauthenticated IDOR to PII Disclosure in WooCommerce Stripe Gateway Plugin

Published on June 13, 2023

This blog post is about the WooCommerce Stripe Gateway plugin vulnerability. If you’re a WooCommerce Stripe Gateway user, please update the plugin to at least version 7.4.1. Patchstack users are protected from the vulnerability. For plugin developers, we have security audit services and Threat Intelligence Feed API for hosting companies. About the WooCommerce Stripe Gateway WordPress plugin The plugin […]

Read more →
Previous Page 7 of 12 Next