June 2024

Watch Out Wednesday – June 26, 2024

Plugin: User Profile Picture Vulnerability: Authenticated (Author+) Insecure Direct Object Reference to Profile Picture UpdatePatched Version: 2.6.2Recommended Action: Update to version 2.6.2, or a newer patched version Plugin: ContentLock Vulnerability: Cross-Site Request Forgery to Group/Email DeletionPatched Version: n/aRecommended Action: No known patch available. Please review the vulnerability’s details in depth and employ mitigations based on […]

Watch Out Wednesday – June 26, 2024 Read More »

Watch Out Wednesday – June 26, 2024

Plugin: User Profile Picture Vulnerability: Authenticated (Author+) Insecure Direct Object Reference to Profile Picture UpdatePatched Version: 2.6.2Recommended Action: Update to version 2.6.2, or a newer patched version Plugin: ContentLock Vulnerability: Cross-Site Request Forgery to Group/Email DeletionPatched Version: n/aRecommended Action: No known patch available. Please review the vulnerability’s details in depth and employ mitigations based on

Watch Out Wednesday – June 26, 2024 Read More »

Watch Out Wednesday – June 26, 2024

Plugin: User Profile Picture Vulnerability: Authenticated (Author+) Insecure Direct Object Reference to Profile Picture UpdatePatched Version: 2.6.2Recommended Action: Update to version 2.6.2, or a newer patched version Plugin: ContentLock Vulnerability: Cross-Site Request Forgery to Group/Email DeletionPatched Version: n/aRecommended Action: No known patch available. Please review the vulnerability’s details in depth and employ mitigations based on

Watch Out Wednesday – June 26, 2024 Read More »

Watch Out Wednesday – June 26, 2024

Plugin: Pop ups, Exit intent popups, email popups, banners, bars, countdowns and cart savers – Promolayer Vulnerability: Missing AuthorizationPatched Version: n/aRecommended Action: No known patch available. Please review the vulnerability’s details in depth and employ mitigations based on your organization’s risk tolerance. It may be best to uninstall the affected software and find a replacement.

Watch Out Wednesday – June 26, 2024 Read More »

Watch Out Wednesday – June 19, 2024

Plugin: Popup Builder – Create highly converting, mobile friendly marketing popups. Vulnerability: Missing Authorization in Multiple AJAX ActionsPatched Version: 4.3.2Recommended Action: Update to version 4.3.2, or a newer patched version Plugin: FooEvents for WooCommerce Vulnerability: Improper Authorization to (Contributor+) Arbitrary File UploadPatched Version: 1.19.21Recommended Action: Update to version 1.19.21, or a newer patched version Plugin:

Watch Out Wednesday – June 19, 2024 Read More »

Watch Out Wednesday – June 5, 2024

Plugin: Page Builder Gutenberg Blocks – CoBlocks Vulnerability: Authenticated (Contributor+) Stored Cross-Site Scripting via Social ProfilesPatched Version: 3.1.10Recommended Action: Update to version 3.1.10, or a newer patched version Plugin: Responsive Owl Carousel for Elementor Vulnerability: Local File InclusionPatched Version: 1.2.1Recommended Action: Update to version 1.2.1, or a newer patched version Plugin: Simple Like Page Plugin

Watch Out Wednesday – June 5, 2024 Read More »