June 2023

Watch Out Wednesday – June 28, 2023

Plugin: Paid Membership Plugin, Ecommerce, Registration Form, Login Form, User Profile & Restrict Content – ProfilePress Vulnerability: Reflected Cross-Site Scripting via error messagePatched Version: 4.11.0Recommended Action: Update to version 4.11.0, or a newer patched version Plugin: Gravity Forms Vulnerability: Reflected Cross-Site ScriptingPatched Version: 2.7.5Recommended Action: Update to version 2.7.5, or a newer patched version Plugin: […]

Watch Out Wednesday – June 28, 2023 Read More »

Watch Out Wednesday – June 28, 2023

Plugin: Paid Membership Plugin, Ecommerce, Registration Form, Login Form, User Profile & Restrict Content – ProfilePress Vulnerability: Reflected Cross-Site Scripting via error messagePatched Version: 4.11.0Recommended Action: Update to version 4.11.0, or a newer patched version Plugin: Gravity Forms Vulnerability: Reflected Cross-Site ScriptingPatched Version: 2.7.5Recommended Action: Update to version 2.7.5, or a newer patched version Plugin:

Watch Out Wednesday – June 28, 2023 Read More »

Watch Out Wednesday – June 7, 2023

Plugin: JS Job Manager Vulnerability: Cross-Site Request Forgery via multiple functionsPatched Version: 2.0.1Recommended Action: Update to version 2.0.1, or a newer patched version Plugin: Directorist – WordPress Business Directory Plugin with Classified Ads Listings Vulnerability: Authenticated (Subscriber+) Arbitrary User Password Reset to Privilege EscalationPatched Version: 7.5.5Recommended Action: Update to version 7.5.5, or a newer patched

Watch Out Wednesday – June 7, 2023 Read More »