-
Vulnerability Watch No48
WordPress Frontend Admin Flaw Enables Administrator Takeover • Royal Elementor Addons SSRF Exposes Internal Services • Podlove File Deletion Flaw Can Lead to Remote Code Execution • ProSolution WP Client Upload Bug Enables Unauthenticated RCE • Autopay WordPress Plugin Allows Unauthenticated Stored XSS…
-
Vulnerability Watch No43
Biagiotti Core Vulnerable to Unauthenticated Local File Inclusion • Reviewer Subscriber Accounts Can Trigger SQL Injection • Multicluster Engine Tenant Isolation Flaw Enables Cross-Tenant Access • WP Directory Kit Hit by Unauthenticated SQL Injection • Critical Unauthenticated SQL Injection Affects WP Directory Kit…
-
Vulnerability Watch No34
lollms Path Traversal Exposes Arbitrary Server Files • MSI Radix AXE6600 OpenVPN Flaw Enables Root Command Execution • MSI Radix AXE6600 Mac Filter Bug Allows Root Commands • MSI Router Telnet Configuration Flaw Leads to Root Access • MSI Router SSH Configuration Flaw Enables Root Command Injection…