Category: Security Advisories

Unauthenticated PHP Object Injection in Gravity Forms Plugin <= 2.7.3

Published on May 30, 2023

This blog post is about the security vulnerability in Gravity Forms. If you’re a Gravity Forms user, please update the plugin to at least version 2.7.4. Patchstack users are protected from the vulnerability. For plugin developers, we have security audit services and Threat Intelligence Feed API for hosting companies. About the Gravity Forms WordPress plugin The plugin Gravity Forms […]

Read more →

CSRF to wp-admin Site Wide XSS in UpdraftPlus Plugin

Published on May 19, 2023

This blog post is about the UpdraftPlus plugin vulnerability. If you’re a UpdraftPlus user, please update the plugin to at least version 1.23.4. Patchstack users are protected from the vulnerability. For plugin developers, we have security audit services and Threat Intelligence Feed API for hosting companies. About the UpdraftPlus WordPress plugin The plugin UpdraftPlus (versions 1.23.3 and below, free […]

Read more →

WordPress Core 6.2.1 Security Update – Technical Advisory

Published on May 17, 2023

On the 16th of May 2023, the WordPress Core 6.2.1 version was released with a security update. It recommended users update their sites as soon as possible. This WordPress core 6.2.1 security release addresses 5 different security vulnerabilities that affect multiple WordPress core versions. For many, WordPress automatically updates the core to the latest version. […]

Read more →

Critical Privilege Escalation in Essential Addons for Elementor

Published on May 11, 2023

This blog post is about the Essential Addons for Elementor plugin vulnerability. If you’re an Essential Addons for Elementor user, please update the plugin to at least version 5.7.2. Patchstack paid plan users are protected from the vulnerability. For plugin developers, we have security audit services and Threat Intelligence Feed API for hosting companies. About the Essential Addons for […]

Read more →

Reflected XSS in Advanced Custom Fields Plugins Affecting 2+ Million Sites

Published on May 5, 2023

This blog post is about the Advanced Custom Fields free and pro plugin vulnerability. If you’re an Advanced Custom Fields free and pro user, please update the plugin to at least version 6.1.6. The security fix also backported on version 5.12.6. Patchstack users are protected from the vulnerability. For plugin developers, we have security audit services and Threat […]

Read more →

Critical Easy Digital Downloads Vulnerability

Published on May 2, 2023

This security advisory is written about a critical Easy Digital Downloads vulnerability originally discovered by Nguyen Anh Tien and reported to us through our bug bounty program. Patchstack users have received a vPatch to protect their site against this vulnerability. Patchstack users are protected from the vulnerability. For plugin developers, we have security audit services and Threat Intelligence […]

Read more →

Critical Unauthenticated SQL Injection in Quiz And Survey Master <= 8.1.4

Published on April 18, 2023

This blog post is about the Quiz And Survey Master plugin vulnerability. If you’re a Quiz And Survey Master user, please update the plugin to at least version 8.1.5. Patchstack users are protected from the vulnerability. For plugin developers, we have security audit services and Threat Intelligence Feed API for hosting companies. About the Quiz And Survey Master WordPress […]

Read more →

Critical Elementor Pro Vulnerability Exploited

Published on March 30, 2023

This security advisory is written about a critical Elementor Pro vulnerability originally disclosed by NinTechNet. Patchstack users have received a vPatch to protect their site against this vulnerability. Vulnerability information On March 22, 2023, Elementor Pro released version 3.11.7 of its plugin which fixes a critical Elementor Pro vulnerability that in combination with the WooCommerce […]

Read more →

User Registration Plugin Vulnerability

Published on March 24, 2023

This blog post is about the User Registration plugin vulnerability. If you’re a User Registration user, please update the plugin to at least version 2.3.3. Paid Patchstack users are protected from the vulnerability. For plugin developers, we have security audit services and Threat Intelligence Feed API for hosting companies. User Registration WordPress plugin The plugin User Registration (versions 2.3.2.1 […]

Read more →

Critical Vulnerability in WooCommerce Payments

Published on March 23, 2023

This security advisory is written about the critical vulnerability in WooCommerce Payments, which is a privilege escalation vulnerability. Patchstack users have received a vPatch to protect their site against this vulnerability. Update March 24th, 2023: WooCommerce has released a statement providing some information about this vulnerability. The critical vulnerability in WooCommerce payments was discovered and […]

Read more →
Previous Page 8 of 12 Next