CVE-2024-3261 exposes a critical vulnerability within the Strong Testimonials plugin, allowing attackers to execute Stored XSS attacks, thereby compromising admin accounts. Understanding its implications and securing WordPress installations becomes paramount.
CVE-2024-2118 – Social Media Share Buttons – Stored XSS to JS backdoor creation – POC

A critical vulnerability, CVE-2024-2118, threatens WordPress sites using Social Media Share Buttons. This flaw enables malicious actors to execute Stored XSS attacks, opening the door to account takeovers and backdoor creation. (if an attacker has previously hijacked an administrator or editor account, he can plant a backdoor to regain access back).
Plugin Security Certification: “WP External Links” – Version 2.63: Use links with Enhanced Security

WP External Links, the comprehensive link management plugin, has undergone rigorous security testing and has successfully obtained the Plugin Security Certification (PSC) from CleanTalk. With enhanced security measures, this plugin allows users to manage both internal and external links on their WordPress websites with confidence.
CVE-2024-2309 – WP Staging – Stored XSS to JS backdoor creation – POC

A critical vulnerability, CVE-2024-2309, has been discovered in the WP Staging WordPress plugin, exposing websites to Stored Cross-Site Scripting (XSS) attacks. This flaw allows attackers to execute malicious scripts, potentially leading to the creation of JavaScript backdoors and compromising website integrity. Immediate action is advised to mitigate the risk. This vulnerability allows malicious actors to execute Stored XSS attacks, potentially leading to the creation of JavaScript backdoors, compromising website integrity. (if an attacker has previously hijacked an administrator or editor account, he can plant a backdoor to regain access back).
CVE-2024-1219 – Easy Social Feed – Stored XSS to Admin Account Creation (Contributor+) – POC
CVE-2024-1664 – Responsive Gallery Grid – Stored XSS to JS backdoor creation – POC

A critical security flaw has been uncovered in Responsive Gallery Grid plugin, marked as CVE-2024-1664. This vulnerability enables attackers to execute Stored XSS attacks, potentially leading to the creation of JavaScript backdoors, thus endangering website integrity and security. This vulnerability allows malicious actors to execute Stored XSS attacks, potentially leading to the creation of JavaScript backdoors, compromising website integrity. (if an attacker has previously hijacked an administrator or editor account, he can plant a backdoor to regain access back).
Plugin Security Certification: “SEO SIMPLE PACK” – Version 3.4.0: Use SEO with Enhanced Security

The “SEO SIMPLE PACK” plugin prioritizes security to safeguard user data and ensure a secure SEO optimization process. With adherence to stringent security protocols and successful verification through the Plugin Security Certification (PSC) from CleanTalk, users can trust the plugin’s commitment to maintaining the highest security standards.
CVE-2024-2643 – My Sticky Bar – Stored XSS to JS backdoor creation – POC

A critical vulnerability, CVE-2024-2643, has been unearthed in My Sticky Bar WordPress plugin, posing a significant threat to website security. Exploiting this flaw enables attackers to execute Stored XSS attacks and potentially implant JavaScript backdoors, jeopardizing website integrity. (if an attacker has previously hijacked an administrator or editor account, he can plant a backdoor to regain access back).
CVE-2024-1849 – WP Customer Reviews – Malicious Redirect via HTTP-EQUIV Injection – POC
Plugin Security Certification: “GTM4WP – A Google Tag Manager (GTM)” – Version 1.21.1: Manage and deploy analytics with Enhanced Security

GTM4WP – A Google Tag Manager (GTM) is a robust tool designed to manage and deploy analytics and marketing tags effortlessly on your WordPress website. With its intuitive web UI, users can seamlessly integrate code snippets and track valuable data without manual intervention. This plugin enhances security measures, ensuring safe analytics deployment, and has successfully obtained the Plugin Security Certification (PSC) from CleanTalk, guaranteeing a secure environment for your website.