A security flaw has been found in the TrueBooker plugin for WordPress, affecting all versions up to and including 1.2.6. This flaw allows anyone without an existing login for your site to change the email address tied to any user account on your WordPress site, including administrator accounts.Once an attacker changes a site administrator’s ...
Continue reading
A security vulnerability has been identified in the User Profile Builder plugin for WordPress, a common tool used to let visitors create accounts and manage their profiles on WordPress websites. The flaw impacts all versions of the plugin up to and including version 3.16.4.This vulnerability allows anyone who visits your site to log in as your ...
Continue reading
A security vulnerability has been identified in the User Session Synchronizer plugin for WordPress, impacting all versions of the plugin up to and including 1.4.0.
The flaw allows unauthenticated attackers (users who do not have valid login credentials for your site) to bypass all login checks and take full control of any account on your WordPress ...
Continue reading
The 6Storage Rentals plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 2.27.0. This is due to the six_storage_create_wp_user() AJAX handler being registered on wp_ajax_nopriv_six_storage_create_wp_user without any nonce, capability, credential, or ownership verification, while calling ...
Continue reading