A security vulnerability impacts the Ninja Tables Pro WordPress plugin, specifically version 5.2.11. A tampered, malicious version of this plugin was distributed through a decommissioned (no longer active) update server, so sites that installed this specific plugin version may have unknowingly added harmful code to their websites.The compromised ...
Continue reading
A security vulnerability tracked as CVE-2024-13784 has been identified in the ARForms plugin for WordPress, a tool used to build contact forms, surveys, quizzes, and popups. The flaw affects all versions of the plugin up to 1.8.5, and allows unauthenticated attackers to inject harmful code into your site by sending specially crafted form ...
Continue reading
A security flaw has been found in the Solace Extra plugin for WordPress, affecting all versions up to and including 1.6.0. The plugin does not properly check if a user has the correct permissions to run its import function, which means even users with very basic access to your site's backend (such as Subscribers, the lowest-level role for ...
Continue reading
A security vulnerability has been found in the "Frontend Admin by DynamiApps" plugin for WordPress, affecting all versions up to and including 3.29.9. This is a privilege escalation flaw, which means an unauthorized user could gain full administrator access to your WordPress site, giving them control over all your site’s content, settings, and ...
Continue reading