I went for coffee and came back with 6 vulnerabilities in WordPress plugins
This title could be clearer and more informative.Try out Clickbait Shieldfor free (5 uses left this month).
A security researcher discovered six vulnerabilities across popular WordPress plugins and components during a short break. The findings include an unauthenticated arbitrary file upload in Royal Elementor Addons via an exposed AJAX nonce, CSS injection in Appointment Hour Booking allowing site defacement, error-based SQL injection in Tutor LMS due to improper use of sanitize_text_field(), SSRF in Better WP Security and SAML SSO plugins enabling internal network scanning and cloud metadata theft, and an open redirect in WooCommerce's REST API auth flow caused by using wp_redirect() instead of wp_safe_redirect(). The common root cause across all findings is blind trust in user input and missing input validation.
Table of contents
1. Royal Elementor Addons — Arbirary File Upload2. Appointment Hour Booking — CSS Injection3. Tutor LMS — SQL InjectionGet Miguel Méndez Z. ’s stories in your inbox4. Better WP Security — SSRF5. SAML SSO — SSRF6. WooCommerce — Open RedirectSort: