Watch Out Wednesday – June 26, 2024
Plugin: User Profile Picture Vulnerability: Authenticated (Author+) Insecure Direct Object Reference to Profile Picture UpdatePatched Version: 2.6.2Recommended Action: Update to version 2.6.2, or a newer patched version Plugin: ContentLock Vulnerability: Cross-Site Request Forgery to Group/Email DeletionPatched Version: n/aRecommended Action: No known patch available. Please review the vulnerability’s details in depth and employ mitigations based on […]