CVE-2024-10145 – Hubbub Lite – Stored XSS to Admin Creation – POC

CVE-2024-10145 – Hubbub Lite – Stored XSS to Admin Creation – POC

Hubbub Lite, a popular WordPress plugin for social sharing, allows users to integrate share buttons for major social networks such as Facebook, Twitter (X), Pinterest, and LinkedIn. However, a recently discovered vulnerability (CVE-2024-10145) exposes websites to stored cross-site scripting (XSS) attacks. This flaw could allow malicious actors to inject harmful scripts, leading to account hijacking and unauthorized actions within the site.

CVE-2024-9227 – PowerPress Podcasting < 11.9.18 – Author+ XSS – POC

CVE-2024-9227 – PowerPress Podcasting < 11.9.18 – Author+ XSS – POC

PowerPress Podcasting, a widely-used WordPress plugin developed by Blubrry Podcasting, facilitates podcast management and publishing directly from a WordPress website. It integrates with major platforms like Apple Podcasts, Spotify, and YouTube Music, making it an essential tool for podcasters. However, a vulnerability (CVE-2024-9227) has been discovered in versions below 11.9.18, allowing users with Author+ permissions to execute stored cross-site scripting (XSS) attacks. This article explores the discovery, impact, exploitation, and mitigation of this vulnerability.

Plugin Security Certification (PSC-2025-64558): “Maintenance” – Version 4.17: Use Maintenance plugin with Enhanced Security

Plugin Security Certification (PSC-2025-64558): “Maintenance” – Version 4.17: Use Maintenance plugin with Enhanced Security

Maintenance 4.17 is a powerful WordPress plugin designed to facilitate seamless maintenance mode activation. It allows website administrators to temporarily disable site access for visitors while displaying a custom maintenance page. The plugin supports the “503 Service Temporarily Unavailable” status, ensuring proper search engine handling during downtime.

With a highly customizable design, the plugin enables users to upload logos, set background images, customize colors, and add personalized text. It also integrates with Bunny Fonts to ensure GDPR compliance, making it a privacy-conscious choice.

Through rigorous security testing, Maintenance 4.1.7 has successfully obtained the Plugin Security Certification (PSC) from CleanTalk, confirming its adherence to best security practices and protection against potential threats

Plugin Security Certification (PSC-2025-64557): “Sucuri Security” – Version 1.9.9: Use Anti-malware plugin with Enhanced Security

Plugin Security Certification (PSC-2025-64557): “Sucuri Security” – Version 1.9.9: Use Anti-malware plugin with Enhanced Security

Sucuri Security is a powerful security plugin designed to protect WordPress websites from various cyber threats. Developed by Sucuri Inc., a globally recognized leader in website security, this plugin provides comprehensive protection through real-time monitoring, malware scanning, and security hardening.

Now owned by GoDaddy, Sucuri Security continues to offer robust security features for WordPress users, ensuring their websites remain protected against unauthorized access, malware infections, and other vulnerabilities. The plugin has successfully passed a rigorous security evaluation and has been awarded the Plugin Security Certification (PSC) from CleanTalk, guaranteeing compliance with the highest security standards.

CVE-2024-13602 – Poll Maker – Stored XSS to JS Backdoor Creation – POC

CVE-2024-13602 – Poll Maker – Stored XSS to JS Backdoor Creation – POC

Cross-Site Scripting (XSS) vulnerabilities remain one of the most persistent security threats in web applications, including WordPress plugins. The vulnerability CVE-2024-13602 was discovered in the “Poll Maker” WordPress plugin, allowing an attacker to inject malicious JavaScript code into the plugin’s redirect settings. This stored XSS vulnerability can be leveraged to execute arbitrary JavaScript, potentially leading to full account takeovers or JavaScript-based backdoor creation.

CVE-2024-13615 – SocialSnap – Stored XSS to JS Backdoor Creation – POC

CVE-2024-13615 – SocialSnap – Stored XSS to JS Backdoor Creation – POC

The Social Media Plugin by Social Snap is widely used to add social sharing functionalities to WordPress websites. This plugin allows website administrators to add social sharing buttons, follow icons, and “Click to Tweet” features. However, a critical vulnerability, Stored Cross-Site Scripting (Stored XSS), has been identified in versions <= 1.3.6 of the plugin. This vulnerability allows an attacker to inject malicious JavaScript payloads, which can be executed when an admin user views the vulnerable settings page.

Plugin Security Certification (PSC-2025-64556): “TablePress” – Version 3.0.4: Use Tables with Enhanced Security

Plugin Security Certification (PSC-2025-64556): “TablePress” – Version 3.0.4: Use Tables with Enhanced Security

TablePress is a powerful and user-friendly WordPress plugin designed to help users create and manage tables effortlessly. Whether you need to display data, create interactive tables, or import/export information, TablePress offers a comprehensive set of features without requiring any coding knowledge.

Beyond its functional advantages, TablePress prioritizes security, ensuring that data handling remains safe and reliable. After undergoing a rigorous security audit, TablePress has earned the prestigious Plugin Security Certification (PSC) from CleanTalk, confirming its compliance with modern security standards.

Plugin Security Certification (PSC-2025-64555): “Safe SVG” – Version 3.2.8: Use SVG files with Enhanced Security

Plugin Security Certification (PSC-2025-64555): “Safe SVG” – Version 3.2.8: Use SVG files with Enhanced Security

Safe SVG is the most reliable WordPress plugin for securely allowing SVG file uploads while ensuring robust security measures. Unlike native WordPress behavior, which restricts SVG uploads due to potential security vulnerabilities, Safe SVG sanitizes and optimizes uploaded SVG files, protecting websites from XML-based threats and malicious code injection. With over 1 million downloads, Safe SVG is a trusted solution for safely handling scalable vector graphics within WordPress. The plugin has undergone extensive security testing and has been awarded the Plugin Security Certification (PSC) from CleanTalk, verifying its adherence to the highest security standards.

Plugin Security Certification (PSC-2025-64554): “CookieYes – Cookie Banner for Cookie Consent” – Version 3.2.8: Use Cookie with Enhanced Security

Plugin Security Certification (PSC-2025-64554): “CookieYes – Cookie Banner for Cookie Consent” – Version 3.2.8: Use Cookie with Enhanced Security

CookieYes – Cookie Banner for Cookie Consent is a powerful WordPress plugin designed to help website owners comply with global privacy regulations, including GDPR, CCPA/CPRA, LGPD, and more. By integrating a customizable cookie banner, CookieYes simplifies the process of obtaining user consent and managing cookies efficiently. This plugin ensures full compliance with privacy laws while maintaining a seamless user experience. Additionally, CookieYes has successfully passed a rigorous security audit and has obtained the Plugin Security Certification (PSC) from CleanTalk, reinforcing its commitment to robust security measures.

Plugin Security Certification (PSC-2025-64553): “Gwolle Guestbook” – Version 4.8.0: Use Guestbook with Enhanced Security

Plugin Security Certification (PSC-2025-64553): “Gwolle Guestbook” – Version 4.8.0: Use Guestbook with Enhanced Security

Gwolle Guestbook is a feature-rich and user-friendly WordPress guestbook plugin that allows website owners to integrate a secure and customizable guestbook system effortlessly. Unlike using the comment section as an alternative, this plugin provides a dedicated guestbook with built-in moderation, anti-spam measures, and user interaction tools. With a clean and intuitive interface, Gwolle Guestbook ensures seamless guestbook management while maintaining high security standards.

To guarantee the protection of user data and site integrity, Gwolle Guestbook undergoes rigorous security audits. The plugin has successfully passed CleanTalk’s security testing and has been awarded the Plugin Security Certification (PSC), confirming its adherence to industry best practices for security and reliability.