October 2024

Watch Out Wednesday – October 16, 2024

Plugin: WP Builder Vulnerability: Authenticated (Author+) Stored Cross-Site Scripting via SVG File UploadPatched Version: n/aRecommended Action: No known patch available. Please review the vulnerability’s details in depth and employ mitigations based on your organization’s risk tolerance. It may be best to uninstall the affected software and find a replacement. Plugin: GDPR-Extensions-com – Consent Manager Vulnerability: […]

Watch Out Wednesday – October 16, 2024 Read More »

Watch Out Wednesday – October 16, 2024

Plugin: WP Builder Vulnerability: Authenticated (Author+) Stored Cross-Site Scripting via SVG File UploadPatched Version: n/aRecommended Action: No known patch available. Please review the vulnerability’s details in depth and employ mitigations based on your organization’s risk tolerance. It may be best to uninstall the affected software and find a replacement. Plugin: GDPR-Extensions-com – Consent Manager Vulnerability:

Watch Out Wednesday – October 16, 2024 Read More »

Watch Out Wednesday – October 9, 2024

Plugin: Shortcodes and extra features for Phlox theme Vulnerability: Authenticated (Contributor+) Stored Cross-Site Scripting via Modern Heading and Icon Picker WidgetsPatched Version: 2.16.4Recommended Action: Update to version 2.16.4, or a newer patched version Plugin: Clio Grow Vulnerability: Reflected Cross-Site ScriptingPatched Version: n/aRecommended Action: No known patch available. Please review the vulnerability’s details in depth and

Watch Out Wednesday – October 9, 2024 Read More »

Watch Out Wednesday – October 2, 2024

Plugin: PWA — easy way to Progressive Web App Vulnerability: Authenticated (Author+) Stored Cross-Site Scripting via SVG File UploadPatched Version: 1.6.4Recommended Action: Update to version 1.6.4, or a newer patched version Plugin: BerqWP – Automated All-In-One PageSpeed Optimization for Core Web Vitals, Cache, CDN, Images, CSS, and JavaScript Vulnerability: Reflected Cross-Site ScriptingPatched Version: 2.1.2Recommended Action:

Watch Out Wednesday – October 2, 2024 Read More »

Watch Out Wednesday – October 2, 2024

Plugin: WP MultiTasking – WP Utilities Vulnerability: WP Utilities <= 0.1.17Patched Version: 0.1.18Recommended Action: Update to version 0.1.18, or a newer patched version Plugin: Absolute Reviews Vulnerability: Authenticated (Contributor+) Stored DOM-Based Cross-Site Scripting via Criteria NamePatched Version: 1.1.4Recommended Action: Update to version 1.1.4, or a newer patched version Plugin: Beaver Builder – WordPress Page Builder

Watch Out Wednesday – October 2, 2024 Read More »

Watch Out Wednesday – September 25, 2024

Plugin: LiteSpeed Cache Vulnerability: Authenticated (Administrator+) Stored Cross-Site ScriptingPatched Version: 6.5Recommended Action: Update to version 6.5, or a newer patched version Plugin: Backup Database Vulnerability: Authenticated (Admin+) Stored Cross-Site ScriptingPatched Version: n/aRecommended Action: No known patch available. Please review the vulnerability’s details in depth and employ mitigations based on your organization’s risk tolerance. It may

Watch Out Wednesday – September 25, 2024 Read More »