Latest Articles
Plugin Security Certification: “Simple Author Box” Version 6.3.1: Security at the Forefront
Security
In the world of WordPress, there are hundreds of thousands of plugins, and security plays a crucial role in ensuring…
CVE-2023-4827 – File Manager Pro < 1.8 - Remote Code Execution via CSRF
Security
During testing of the plugin, a CSRF vulnerability was discovered in action=rename, which can lead to denial of service and…
Plugin Security Certification: “File Manager Pro” — Filester Version 1.8.1: Enhanced Security
Security
Security is paramount in the world of WordPress plugins, and we are excited to bring you the latest on the…
Plugin Security Certification: “WP Reset” – Version 1.97: Fortifying WordPress Security
Security
In the realm of WordPress development, security is paramount. Enter the “WP Reset” plugin, specifically version 1.97, which stands as…
Improving Security on WordPress with CleanTalk HTTP Response Headers
CleanTalk
Securing your WordPress website is a critical aspect of website maintenance. In this article, we will explore how using the…
CVE-2023-4933 – WP Job Openings < 3.4.3 – Sensitive Data Exposure via Directory Listing
Security
During testing, a critical vulnerability was discovered in the plugin, namely a vulnerability in the Directory Listings system, which allows…
CVE-2023-4289 – WP Matterport Shortcode < 2.1.8 - Contributor+ Stored XSS via shortcode
Security
In the process of testing the plugin, a vulnerability was found that allows you to implement Stored XSS on behalf…
CVE-2023-4798 – User Avatar – Reloaded < 1.2.2 - Contributor+ Stored XSS
Security
During the plugin’s testing phase, a vulnerability was identified that enables the execution of Stored XSS by an attacker who…
CVE-2023-4646 – Simple Posts Ticker < 1.1.6 - Contributor + Stored XSS via shortcode
Security
While examining the plugin during the testing phase, we uncovered a vulnerability that enables the execution of Stored Cross-Site Scripting…
CVE-2023-4725 – Simple Posts Ticker < 1.1.6 - Admin+ Stored XSS
Security
During testing, a vulnerability was found that allows, through changing the settings, to implement Stored XSS on all pages where…