A security flaw has been identified in AlanWeb SCADA, a tool some website operators use to manage site functions. The flaw means the system does not enforce proper access restrictions for certain folders, so unauthorized people can view every file stored in those unprotected folders, and even run some of the files stored there.
The most serious ...
Continue reading
The Link Library plugin for WordPress has a security flaw affecting all versions up to and including 7.9.4. This issue is caused by the plugin not properly validating file paths when processing link deletions, which could allow unauthenticated attackers to delete files stored on your web server.This risk only applies if you have turned on the ...
Continue reading
A security vulnerability has been identified in the Pods – Custom Content Types and Fields plugin for WordPress, impacting all versions up to and including 3.3.9. This plugin is commonly used to add custom content types and fields to WordPress sites, so it may be installed on your website if you use it for customized content management.The flaw ...
Continue reading
A security flaw has been identified in the TrueBooker plugin for WordPress, impacting all versions of the tool up to and including 1.2.6. The issue allows anyone who is not logged into your website to change the email address linked to any user account on your WordPress site, including administrator accounts.Once an attacker changes an ...
Continue reading