-
Vulnerability Watch No52
WordPress WPAdverts Authorization Bypass Exposes Site Configuration • COMFAST Router Flaw Enables Remote OS Command Injection • PHPGurukul Complaint System Hit by Remote SQL Injection • SourceCodester Timetabling System Exposes SQL Injection Flaw • Second SourceCodester Timetabling Endpoint Vulnerable to SQL Injection…
-
Vulnerability Watch No46
Unauthenticated Stored XSS Hits Invisible Anti-Spam WordPress Plugin • Cookie Consent Plugin Exposes WordPress Sites to Stored XSS • MaxUpload Flaw Enables Unauthenticated File Upload and Possible RCE • User Session Synchronizer Bug Allows Full WordPress Account Takeover • Propovoice Manager Accounts Can Escalate to WordPress Administrator…