Tag: PluginVulnerability

  • Vulnerability Watch No61

    NLTK XML Parser Weakness Causes Denial of Service • node-poppler Flaw Allows Remote Argument Injection • Critical OCPP Buffer Overflow Threatens EV Charging Clients • WordPress InfusedWoo Pro Bug Enables Account Takeover • NLTK Deserialization Flaw Enables Python Code Execution…

  • Vulnerability Watch No46

    Unauthenticated Stored XSS Hits Invisible Anti-Spam WordPress Plugin • Cookie Consent Plugin Exposes WordPress Sites to Stored XSS • MaxUpload Flaw Enables Unauthenticated File Upload and Possible RCE • User Session Synchronizer Bug Allows Full WordPress Account Takeover • Propovoice Manager Accounts Can Escalate to WordPress Administrator…

  • Vulnerability Watch No21

    Hardcoded Backdoor Exposes WordPress Sites to Admin Takeover • Easy Digital Downloads Upload Flaw Could Enable Code Execution • WooCommerce Wholesale Plugin Lets Authors Become Administrators • Netty OCSP Race Can Leak Data to Revoked Servers • Netty Accepts Replayed Expired OCSP Responses…

  • Vulnerability Watch No19

    Xendit Payment Access-Control Flaw Exposes Unauthenticated Attack Surface • Contest Gallery Hit by Unauthenticated XSS Vulnerability • Kali Forms Vulnerable to Unauthenticated Script Injection • BackWPup XSS Flaw Threatens WordPress Administrators • FormCraft SSRF Flaw Could Reach Internal Services…

  • Vulnerability Watch No16

    NoteGen Shell Permissions Enable Full Remote Code Execution • Unsanitized AI Responses Expose NoteGen Users to XSS • WordPress Membership Flaw Lets Visitors Claim Elevated Roles • Critical SQL Injection Hits WordPress Issue-Tracking Plugin • CAFEHAUS API Bug Enables Administrator Account Takeover…