Tag: arbitraryFileUpload

  • Vulnerability Watch No48

    WordPress Frontend Admin Flaw Enables Administrator Takeover • Royal Elementor Addons SSRF Exposes Internal Services • Podlove File Deletion Flaw Can Lead to Remote Code Execution • ProSolution WP Client Upload Bug Enables Unauthenticated RCE • Autopay WordPress Plugin Allows Unauthenticated Stored XSS…

  • Vulnerability Watch No46

    Unauthenticated Stored XSS Hits Invisible Anti-Spam WordPress Plugin • Cookie Consent Plugin Exposes WordPress Sites to Stored XSS • MaxUpload Flaw Enables Unauthenticated File Upload and Possible RCE • User Session Synchronizer Bug Allows Full WordPress Account Takeover • Propovoice Manager Accounts Can Escalate to WordPress Administrator…

  • Vulnerability Watch No21

    Hardcoded Backdoor Exposes WordPress Sites to Admin Takeover • Easy Digital Downloads Upload Flaw Could Enable Code Execution • WooCommerce Wholesale Plugin Lets Authors Become Administrators • Netty OCSP Race Can Leak Data to Revoked Servers • Netty Accepts Replayed Expired OCSP Responses…