CVE-2024-12739 – Mobile Contact Bar < 3.0.5 – Stored XSS to JS Backdoor Creation – POC

CVE-2024-12739 – Mobile Contact Bar < 3.0.5 – Stored XSS to JS Backdoor Creation – POC

The Mobile Contact Bar plugin for WordPress provides website owners with an intuitive way to create customizable contact options for their visitors. However, a critical Stored Cross-Site Scripting (XSS) vulnerability has been identified in versions below 3.0.5, which can lead to JavaScript backdoor creation and potential full site compromise. This article explores the discovery, exploitation, risks, and mitigation strategies for this vulnerability

CVE-2024-11503 – WP Tabs < 2.2.7 – Stored XSS to JS Backdoor Creation – POC

CVE-2024-11503 – WP Tabs < 2.2.7 – Stored XSS to JS Backdoor Creation – POC

WP Tabs is a widely used WordPress plugin designed to help users create and manage tabbed navigation on their websites. With its user-friendly interface and extensive customization options, WP Tabs has gained popularity among WordPress site owners. However, a security vulnerability (CVE-2024-111503) was discovered in versions below 2.2.7, exposing websites to a Stored Cross-Site Scripting (XSS) attack. This article delves into the discovery, exploitation, risks, and remediation of this vulnerability.

Plugin Security Certification (PSC-2025-64560): “Disable Comments – Remove Comments & Stop Spam” – Version 2.4.7: Use Comments plugin with Enhanced Security

Plugin Security Certification (PSC-2025-64560): “Disable Comments – Remove Comments & Stop Spam” – Version 2.4.7: Use Comments plugin with Enhanced Security

Disable Comments – Remove Comments & Stop Spam [Multi-Site Support] is a powerful plugin designed to give WordPress site owners complete control over comment functionality. By allowing users to globally enable or disable comments on posts, pages, and media, this plugin is an effective tool to prevent spam and unwanted discussions. It provides seamless integration with WP-CLI, XML-RPC, and REST-API, ensuring a streamlined approach to managing comments.

This plugin enhances website security by eliminating potential spam injection points and preventing unauthorized comment-based interactions. It has successfully undergone rigorous security testing and has received the prestigious Plugin Security Certification (PSC-2025-64560) from CleanTalk, ensuring robust protection against spam-related vulnerabilities.

CVE-2024-10475 – Lead Form Builder – Stored XSS to JS Backdoor Creation – POC

CVE-2024-10475 – Lead Form Builder – Stored XSS to JS Backdoor Creation – POC

Lead Form Builder is a popular WordPress plugin designed to create and manage contact forms. It offers an easy-to-use drag-and-drop interface and integration with page builders like Elementor, Brizy, SiteOrigin, and Gutenberg. However, a security vulnerability (CVE-2024-10475) was discovered in versions prior to 1.9.8, which allows attackers to inject and execute malicious JavaScript code through Stored Cross-Site Scripting (XSS). This article explores the vulnerability, its risks, exploitation, and best practices to mitigate the issue.

Plugin Security Certification (PSC-2025-64559): “W3 Total Cache” – Version 2.8.6: Use Cache plugin with Enhanced Security

Plugin Security Certification (PSC-2025-64559): “W3 Total Cache” – Version 2.8.6: Use Cache plugin with Enhanced Security

W3 Total Cache (W3TC) is a powerful performance optimization plugin designed to enhance website speed, SEO rankings, and user experience. It achieves this by leveraging caching mechanisms, content delivery network (CDN) integration, and advanced web performance optimization (WPO) techniques. Trusted by over a million users, W3TC significantly reduces page load times, ensuring seamless website performance. The plugin has undergone rigorous security testing and has successfully obtained the Plugin Security Certification (PSC-2025-64559) from CleanTalk, guaranteeing a secure environment for WordPress websites.

CVE-2024-10703 – Registrations for Events Calendar – Stored XSS to JS Backdoor Creation – POC

CVE-2024-10703 – Registrations for Events Calendar – Stored XSS to JS Backdoor Creation – POC

Stored Cross-Site Scripting (Stored XSS) is a critical web security vulnerability that allows attackers to inject malicious scripts into a website, which are then executed in the browsers of unsuspecting users. This article focuses on CVE-2024-10703, a Stored XSS vulnerability found in versions below 2.13.4 of the “Registrations for The Events Calendar” plugin for WordPress. This vulnerability can be exploited by an attacker with administrator privileges to inject harmful scripts that execute when users interact with certain elements of the website.

CVE-2024-10472 – Stylish Price List < 7.1.12 – Stored XSS to Admin Creation – POC

CVE-2024-10472 – Stylish Price List < 7.1.12 – Stored XSS to Admin Creation – POC

WordPress plugins play a crucial role in extending the functionality of websites. However, vulnerabilities in these plugins can introduce significant security risks. One such vulnerability has been discovered in the Stylish Price List plugin (versions below 7.1.12), which enables users to create visually appealing price lists and pricing tables. The vulnerability allows a malicious actor to inject and store JavaScript code, leading to a Stored Cross-Site Scripting (XSS) attack that can compromise an administrator’s session.

CVE-2024-9390 – RegistrationMagic < 6.0.2.1 – Stored XSS to Admin Creation – POC

CVE-2024-9390 – RegistrationMagic < 6.0.2.1 – Stored XSS to Admin Creation – POC

In the ever-evolving landscape of cybersecurity, vulnerabilities in WordPress plugins remain a persistent threat. One such recent discovery is CVE-2024-9390, a Stored Cross-Site Scripting (XSS) vulnerability affecting versions of the RegistrationMagic plugin prior to 6.0.2.1. This flaw allows attackers with certain privileges to inject malicious scripts, which can execute arbitrary JavaScript in the administrator’s session, potentially leading to account hijacking or further exploitation of the system.

CVE-2024-10143 – MB Custom Post Types & Custom Taxonomies – Stored XSS to Admin Creation – POC

CVE-2024-10143 – MB Custom Post Types & Custom Taxonomies – Stored XSS to Admin Creation – POC

WordPress plugins are essential tools that enhance the functionality of websites, allowing users to extend features without modifying core code. However, security vulnerabilities in plugins can expose websites to serious threats, including Cross-Site Scripting (XSS) attacks. One such vulnerability has been identified in the “MB Custom Post Types & Custom Taxonomies” plugin (CVE-2024-10143), allowing stored XSS exploitation that could lead to administrative account creation and malicious script execution.

CVE-2024-10145 – Hubbub Lite – Stored XSS to Admin Creation – POC

CVE-2024-10145 – Hubbub Lite – Stored XSS to Admin Creation – POC

Hubbub Lite, a popular WordPress plugin for social sharing, allows users to integrate share buttons for major social networks such as Facebook, Twitter (X), Pinterest, and LinkedIn. However, a recently discovered vulnerability (CVE-2024-10145) exposes websites to stored cross-site scripting (XSS) attacks. This flaw could allow malicious actors to inject harmful scripts, leading to account hijacking and unauthorized actions within the site.