A security flaw has been identified in the Link Library plugin for WordPress, a tool many sites use to organize and display lists of external links. The issue impacts all versions of the plugin up to and including 7.9.4, and is caused by poor validation of file paths when the plugin deletes files tied to links.If a specific optional setting for ...
Continue reading
A security vulnerability has been found in the Pods – Custom Content Types and Fields plugin for WordPress, affecting all versions up to and including 3.3.9.
Normally, this plugin has built-in checks to block unapproved users from accessing sensitive site admin functions. A coding bug causes these checks to fail for visitors who do not have a ...
Continue reading
A security flaw has been found in the TrueBooker plugin for WordPress, affecting all versions up to and including 1.2.6. This vulnerability lets unauthenticated users (people who do not have a login for your site) take over any user account on your WordPress site, including administrator accounts.The plugin has a feature meant to let users update ...
Continue reading
A security vulnerability exists in the User Profile Builder plugin for WordPress, affecting all versions of the plugin up to and including version 3.16.4. This flaw lets unapproved users who are not logged into your site bypass standard login protections to access your site’s main administrator account, which grants them full control over all ...
Continue reading