A security vulnerability has been found in the Pods – Custom Content Types and Fields plugin for WordPress, affecting all versions up to and including 3.3.9.
Normally, this plugin has built-in checks to block unapproved users from accessing sensitive site admin functions. A coding bug causes these checks to fail for visitors who do not have a ...
Continue reading
A security flaw has been found in the TrueBooker plugin for WordPress, affecting all versions up to and including 1.2.6. This vulnerability lets unauthenticated users (people who do not have a login for your site) take over any user account on your WordPress site, including administrator accounts.The plugin has a feature meant to let users update ...
Continue reading
A security vulnerability exists in the User Profile Builder plugin for WordPress, affecting all versions of the plugin up to and including version 3.16.4. This flaw lets unapproved users who are not logged into your site bypass standard login protections to access your site’s main administrator account, which grants them full control over all ...
Continue reading
A security vulnerability has been identified in the User Session Synchronizer plugin for WordPress, affecting all versions up to and including 1.4.0. This flaw allows people who are not logged into your site to take over any user account on the site, including administrator accounts, without needing to know any passwords or access your site’s ...
Continue reading