CVE-2024-8492 – Hustle – Stored XSS to backdoor creation – POC

CVE-2024-8492 – Hustle – Stored XSS to backdoor creation – POC

CVE-2024-8492 exposes a critical Stored Cross-Site Scripting (XSS) vulnerability in the Hustle plugin, which is used by over 100,000 WordPress installations to create popups, email opt-ins, and other marketing tools. This vulnerability allows attackers to inject malicious JavaScript (JS) code through the plugin’s settings, particularly in the “Error Message” field of the Email Field settings. If exploited, this vulnerability can lead to admin account takeover and the creation of persistent backdoors, giving attackers long-term control over the site.

CVE-2024-8187 – Smart Post Show – Stored XSS to backdoor creation – POC

CVE-2024-8187 – Smart Post Show – Stored XSS to backdoor creation – POC

CVE-2024-8187 reveals a critical Stored Cross-Site Scripting (XSS) vulnerability in the Smart Post Show plugin, a popular WordPress plugin with over 30,000 installations. This vulnerability allows attackers with editor-level access to inject malicious JavaScript (JS) into the plugin’s settings. If exploited, the vulnerability enables account takeover, backdoor creation, and long-term control over the WordPress site. The issue stems from improper input validation, particularly in the post grid settings.

Plugin Security Certification (PSC-2024-64529): “One User Avatar” – Version 2.5.0: Use Avatars with Enhanced Security

Plugin Security Certification (PSC-2024-64529): “One User Avatar” – Version 2.5.0: Use Avatars with Enhanced Security

The One User Avatar plugin offers a highly flexible way to manage custom user avatars on your WordPress site. Unlike WordPress’s default behavior, which limits custom avatars to those uploaded through Gravatar, One User Avatar allows you to use any image from your Media Library as a custom avatar. The simplicity and efficiency of this plugin have made it a go-to solution for users seeking more control over their avatar management.

And now, with the Plugin Security Certification (PSC-2024-64529) from CleanTalk, you can use One User Avatar with the assurance of enhanced security. This certification confirms that One User Avatar has passed rigorous security checks, making it a trusted option for managing user avatars without introducing vulnerabilities to your WordPress site.

CVE-2024-7762 – Simple Job Board – Unauthenticated Resumes Download – POC

CVE-2024-7762 – Simple Job Board – Unauthenticated Resumes Download – POC

CVE-2024-7762 highlights a critical security flaw in the Simple Job Board plugin, a popular WordPress plugin with over 30,000 installations. This vulnerability allows unauthorized users to access and download confidential resumes and other files uploaded by job applicants. The flaw lies within the plugin’s directory listings system, which fails to implement proper access controls. If exploited, this vulnerability can expose sensitive data, leading to severe privacy breaches and security risks.

CVE-2024-8239 – Starbox – the Author Box for Humans – Stored XSS to Admin Creation – POC

CVE-2024-8239 – Starbox – the Author Box for Humans – Stored XSS to Admin Creation – POC

CVE-2024-8239 uncovers a serious Stored Cross-Site Scripting (XSS) vulnerability in the Starbox – The Author Box for Humans plugin, used by over 40,000 WordPress sites to display author profiles and bios. This vulnerability allows contributors to inject malicious JavaScript (JS) into their profile settings, specifically through the “Twitter URL” field, which can lead to admin account creation and backdoor access. If exploited, attackers can hijack the WordPress site’s admin functionality and maintain persistent control.

CVE-2024-8283 – Slider by 10Web – Stored XSS to Backdoor Creation – POC

CVE-2024-8283 – Slider by 10Web – Stored XSS to Backdoor Creation – POC

CVE-2024-8283 exposes a serious vulnerability in the Slider by 10Web plugin, a widely used WordPress plugin with over 30,000 active installations. This Stored Cross-Site Scripting (XSS) vulnerability allows attackers, particularly users with contributor-level access, to inject malicious JavaScript (JS) code through the plugin’s slider settings. When exploited, this vulnerability enables attackers to take over admin accounts and create backdoors, allowing them to maintain long-term access to the site.

CVE-2024-3635 – The Post Grid – Stored XSS to Backdoor Creation – POC

CVE-2024-3635 – The Post Grid – Stored XSS to Backdoor Creation – POC

CVE-2024-3635 represents a critical Stored Cross-Site Scripting (XSS) vulnerability in The Post Grid plugin, a popular tool for creating custom grid layouts in WordPress. With over 100,000 installations, this vulnerability poses a serious threat as it allows attackers with editor-level permissions to inject malicious JavaScript (JS) code into grid settings. Once exploited, the vulnerability can lead to account takeover, enabling attackers to create persistent backdoors and take control of the WordPress site.

CVE-2024-8536 – Ultimate Blocks – Stored XSS to Admin Account Creation – POC

CVE-2024-8536 – Ultimate Blocks – Stored XSS to Admin Account Creation – POC

CVE-2024-8536 presents a serious security risk in the Ultimate Blocks plugin, used by over 70,000 WordPress sites to enhance post content with custom blocks. This vulnerability allows attackers, specifically users with contributor-level access, to inject malicious JavaScript (JS) into a new post using the plugin’s “Expand” block feature. If exploited, this can lead to admin account creation and full site takeover, putting the entire WordPress installation at risk.

CVE-2024-7133 – My Sticky Bar (myStickymenu) – Stored XSS to JS Backdoor Creation – POC

CVE-2024-7133 – My Sticky Bar (myStickymenu) – Stored XSS to JS Backdoor Creation – POC

CVE-2024-7133 reveals a critical vulnerability in the My Sticky Bar (myStickymenu) WordPress plugin, which has over 100,000 active installations. This Stored Cross-Site Scripting (XSS) vulnerability allows attackers to inject malicious JavaScript (JS) code through the plugin’s settings. Once exploited, the attacker can take over administrator accounts, create persistent backdoors, and control the entire WordPress site. The issue arises due to improper sanitization of user input, specifically in the “Font size” field when creating a sticky bar.

Plugin Security Certification (PSC-2024-64528): “SiteOrigin CSS” – Version 1.6.5: Use CSS with Enhanced Security

Plugin Security Certification (PSC-2024-64528): “SiteOrigin CSS” – Version 1.6.5: Use CSS with Enhanced Security

SiteOrigin CSS is an advanced, feature-rich CSS editor that empowers WordPress users to customize their website’s design in real time, without needing to master complex coding. Trusted by thousands of users, this powerful plugin simplifies the process of modifying the visual aspects of your WordPress site, offering ease of use for both beginners and advanced users. With Plugin Security Certification (PSC-2024-64528) by CleanTalk, you can now confidently use SiteOrigin CSS with the assurance of enhanced security and protection against vulnerabilities.