I went for coffee and came back with 6 vulnerabilities in WordPress plugins

This title could be clearer and more informative.Try out Clickbait Shieldfor free (5 uses left this month).

A security researcher discovered six vulnerabilities across popular WordPress plugins and components during a short break. The findings include an unauthenticated arbitrary file upload in Royal Elementor Addons via an exposed AJAX nonce, CSS injection in Appointment Hour Booking allowing site defacement, error-based SQL

3m read timeFrom infosecwriteups.com
Post cover image
Table of contents
1. Royal Elementor Addons — Arbirary File Upload2. Appointment Hour Booking — CSS Injection3. Tutor LMS — SQL InjectionGet Miguel Méndez Z. ’s stories in your inbox4. Better WP Security — SSRF5. SAML SSO — SSRF6. WooCommerce — Open Redirect

Sort: