April 2024

Watch Out Wednesday – April 17, 2024

Plugin: Language Translate Widget for WordPress – ConveyThis Vulnerability: Unauthenticated Stored Cross-Site Scripting via api_keyPatched Version: 224Recommended Action: Update to version 224, or a newer patched version Plugin: Slider, Gallery, and Carousel by MetaSlider – Responsive WordPress Slideshows Vulnerability: Authenticated (Contributor+) Stored Cross-Site Scripting via metaslider ShortcodePatched Version: 3.70.1Recommended Action: Update to version 3.70.1, or

Watch Out Wednesday – April 17, 2024 Read More »

Watch Out Wednesday – April 10, 2024

Plugin: BookingPress – Appointment Booking Calendar Plugin and Online Scheduling Plugin Vulnerability: Authenticated (Admin+) Arbitrary File UploadPatched Version: 1.0.88Recommended Action: Update to version 1.0.88, or a newer patched version Plugin: Easy Digital Downloads – Sell Digital Files & Subscriptions (eCommerce Store + Payments Made Easy) Vulnerability: Sensitive Information ExposurePatched Version: 3.2.10Recommended Action: Update to version

Watch Out Wednesday – April 10, 2024 Read More »