A security issue has been identified in the Ninja Tables Pro WordPress plugin, a tool many site owners use to create and manage tables on their websites. A tampered, unsafe version of the plugin (version 5.2.11) was distributed via a decommissioned, no-longer-active update server for the plugin, rather than the legitimate secure build.The hidden ...
Continue reading
A security flaw has been identified in version 6.2.7 of Fluent Forms Pro, a popular WordPress plugin used to add contact forms, surveys and other input fields to websites. This flaw comes from a tampered, malicious version of the plugin that was accidentally distributed to users via an old, no-longer-active update server.The malicious version of ...
Continue reading
AlanWeb SCADA does not enforce authorization for some directories. This allows an unauthorized attacker to read all files in these directories and even execute some of them. Critically the attacker could run PHP scripts directly on the connected database.This issue was fixed in AlanWeb SCADA version 9.8.5Source: NVD (National Vulnerability ...
Continue reading
A security flaw has been found in the Wishlist Member plugin for WordPress, affecting all versions up to and including 3.34.1. This flaw allows people who do not have any existing login access to your site to take over any existing WordPress account on your site, including administrator accounts that have full control over your site’s content ...
Continue reading