CVE-2023-4209 – POEditor < 0.9.8 - Settings Reset via CSRF

CVE-2023-4209 – POEditor < 0.9.8 - Settings Reset via CSRF

In our quest for a secure WordPress environment, a significant discovery has emerged. The POEditor plugin, a powerful translation tool, harbors a critical vulnerability. Prior to version 0.9.8, the absence of Cross-Site Request Forgery (CSRF) protection has exposed the plugin to potential manipulation by attackers. Main info: CVE CVE-2023-4209 Plugin POEditor Critical Medium Publicly Published

CVE-2023-4023 – All Users Messenger <= 1.24 - Subscriber + Message Deletion via IDOR

CVE-2023-4023 – All Users Messenger <= 1.24 - Subscriber + Message Deletion via IDOR

In a recent round of intensive plugin testing, a concerning security flaw has come to light. The All Users Messenger plugin, a widely used communication tool for WordPress, harbors a significant Insecure Direct Object Reference (IDOR) vulnerability. Main info: CVE CVE-2023-4023 Plugin All Users Messenger Critical Medium Publicly Published August 7, 2023 Last Updated August

CVE-2023-4035 – Simple Blog Card < 1.31 - Contributor+ Stored XSS via Shortcode

CVE-2023-4035 – Simple Blog Card < 1.31 - Contributor+ Stored XSS via Shortcode

In our recent in-depth security analysis of the widely used Simple Blog Card plugin for WordPress, a concerning vulnerability has come to light. Versions prior to 1.31 have a critical flaw, leaving your website exposed to potential Stored Cross-Site Scripting (XSS) attacks! Main info: CVE CVE-2023-4035 Plugin Simple Blog Card Critical High Publicly Published August

Our Investigation of the Hack of One Website (OR: How We Investigated a Hack of One Website)

Our Investigation of the Hack of One Website (OR: How We Investigated a Hack of One Website)

We were contacted by one WordPress website owner with the issue of a website hack. Consequences of the hack were that their whole website content was deleted, meaning articles, pictures, plugins and themes were gone and visiting the website displayed a blank page. What was left in the folder «wp-content» was a single folder «uploads»,

CleanTalk is Ending Support of the Anti-Spam Service for Shopify

CleanTalk is Ending Support of the Anti-Spam Service for Shopify

The CleanTalk company informs you, our clients, that starting on December 12, 2022, we will stop providing and supporting the Anti-Spam service for Shopify. The CleanTalk Anti-Spam service for Shopify was launched for testing the anti-spam protection features for free. To our regret we can not provide our full protection because of technical limitations. The Shopify

Checking your WordPress files and folders permissions with Website Security

Checking your WordPress files and folders permissions with Website Security

Website Security plugin now automatically scans your WordPress files and folders for unsafe permissions and recommends how to change them if necessary. What are WordPress File Permissions WordPress file permissions protect your site’s files and directories from unauthorized access by hackers. Securing the proper permissions adds security to your site and makes it less vulnerable. There