CVE-2024-13615 – SocialSnap – Stored XSS to JS Backdoor Creation – POC

CVE-2024-13615 – SocialSnap – Stored XSS to JS Backdoor Creation – POC

The Social Media Plugin by Social Snap is widely used to add social sharing functionalities to WordPress websites. This plugin allows website administrators to add social sharing buttons, follow icons, and “Click to Tweet” features. However, a critical vulnerability, Stored Cross-Site Scripting (Stored XSS), has been identified in versions <= 1.3.6 of the plugin. This vulnerability allows an attacker to inject malicious JavaScript payloads, which can be executed when an admin user views the vulnerable settings page.

Plugin Security Certification (PSC-2025-64556): “TablePress” – Version 3.1.1: Use Tables with Enhanced Security

Plugin Security Certification (PSC-2025-64556): “TablePress” – Version 3.1.1: Use Tables with Enhanced Security

TablePress is a powerful and user-friendly WordPress plugin designed to help users create and manage tables effortlessly. Whether you need to display data, create interactive tables, or import/export information, TablePress offers a comprehensive set of features without requiring any coding knowledge.

Beyond its functional advantages, TablePress prioritizes security, ensuring that data handling remains safe and reliable. After undergoing a rigorous security audit, TablePress has earned the prestigious Plugin Security Certification (PSC) from CleanTalk, confirming its compliance with modern security standards.

Plugin Security Certification (PSC-2025-64555): “Safe SVG” – Version 3.2.8: Use SVG files with Enhanced Security

Plugin Security Certification (PSC-2025-64555): “Safe SVG” – Version 3.2.8: Use SVG files with Enhanced Security

Safe SVG is the most reliable WordPress plugin for securely allowing SVG file uploads while ensuring robust security measures. Unlike native WordPress behavior, which restricts SVG uploads due to potential security vulnerabilities, Safe SVG sanitizes and optimizes uploaded SVG files, protecting websites from XML-based threats and malicious code injection. With over 1 million downloads, Safe SVG is a trusted solution for safely handling scalable vector graphics within WordPress. The plugin has undergone extensive security testing and has been awarded the Plugin Security Certification (PSC) from CleanTalk, verifying its adherence to the highest security standards.

Plugin Security Certification (PSC-2025-64554): “CookieYes – Cookie Banner for Cookie Consent” – Version 3.2.9: Use Cookie with Enhanced Security

Plugin Security Certification (PSC-2025-64554): “CookieYes – Cookie Banner for Cookie Consent” – Version 3.2.9: Use Cookie with Enhanced Security

CookieYes – Cookie Banner for Cookie Consent is a powerful WordPress plugin designed to help website owners comply with global privacy regulations, including GDPR, CCPA/CPRA, LGPD, and more. By integrating a customizable cookie banner, CookieYes simplifies the process of obtaining user consent and managing cookies efficiently. This plugin ensures full compliance with privacy laws while maintaining a seamless user experience. Additionally, CookieYes has successfully passed a rigorous security audit and has obtained the Plugin Security Certification (PSC) from CleanTalk, reinforcing its commitment to robust security measures.

Plugin Security Certification (PSC-2025-64553): “Gwolle Guestbook” – Version 4.8.0: Use Guestbook with Enhanced Security

Plugin Security Certification (PSC-2025-64553): “Gwolle Guestbook” – Version 4.8.0: Use Guestbook with Enhanced Security

Gwolle Guestbook is a feature-rich and user-friendly WordPress guestbook plugin that allows website owners to integrate a secure and customizable guestbook system effortlessly. Unlike using the comment section as an alternative, this plugin provides a dedicated guestbook with built-in moderation, anti-spam measures, and user interaction tools. With a clean and intuitive interface, Gwolle Guestbook ensures seamless guestbook management while maintaining high security standards.

To guarantee the protection of user data and site integrity, Gwolle Guestbook undergoes rigorous security audits. The plugin has successfully passed CleanTalk’s security testing and has been awarded the Plugin Security Certification (PSC), confirming its adherence to industry best practices for security and reliability.

Malicious PHP snippets in WPCode

Malicious PHP snippets in WPCode

During the analysis and treatment of the infected site, malicious code was found embedded in the Code Snippets plugin. The main function of the malicious code was to redirect users once upon their first visit to the site, as well as to hide the plugin’s management form in the WordPress admin panel. This makes it difficult to detect the threat and increases the likelihood of a long-term presence of malicious code on a web resource.

This type of infection is quite common in the WordPress environment and causes a lot of inconvenience to website owners. Its main functionality is related to hiding malicious code and redirects on the website.

Plugin Security Certification (PSC-2025-64552): “Breadcrumb NavXT” – Version 7.4.1: Use Breadcrumb with Enhanced Security

Plugin Security Certification (PSC-2025-64552): “Breadcrumb NavXT” – Version 7.4.1: Use  Breadcrumb with Enhanced Security

Breadcrumb NavXT is a powerful WordPress plugin designed to generate breadcrumb trails for websites, providing users with a clear navigational structure. As the successor to Breadcrumb Navigation XT, it has been completely rebuilt to offer greater customization, performance, and compatibility with modern web standards. The plugin integrates seamlessly with WordPress themes, allowing both administrators and developers to configure breadcrumb settings effortlessly.

CVE-2024-13314 – Carousel, Slider, Gallery by WP Carousel – Stored XSS to JS Backdoor Creation – POC

CVE-2024-13314 – Carousel, Slider, Gallery by WP Carousel – Stored XSS to JS Backdoor Creation – POC

The WP Carousel plugin is a popular WordPress plugin that allows users to create beautiful image, post, and WooCommerce product carousels effortlessly. With its user-friendly interface and extensive features, it has become a preferred choice for many WordPress site owners. However, a vulnerability (CVE-2024-13314) has been discovered in versions below 2.7.4, allowing attackers to exploit Stored Cross-Site Scripting (XSS), posing a significant security risk.

Plugin Security Certification (PSC-2024-64551): “ManageWP Worker” – Version 4.9.20: Use Management tool with Enhanced Security

Plugin Security Certification (PSC-2024-64551): “ManageWP Worker” – Version 4.9.20: Use Management tool with Enhanced Security

The ManageWP Worker plugin, with over 1 million downloads, is a powerful tool for managing multiple WordPress websites from a single dashboard. It offers features such as automated backups, security monitoring, bulk updates, and website cloning. However, from a security standpoint, plugins with administrative control over multiple sites require strict scrutiny to ensure data integrity and prevent potential exploitation.

CVE-2024-13208 – WP Google Map – Stored XSS to JS Backdoor Creation – POC

CVE-2024-13208 – WP Google Map – Stored XSS to JS Backdoor Creation – POC

Google Maps is an essential feature for many websites, enabling businesses and organizations to display interactive maps for better user engagement. WP Google Map is a WordPress plugin designed to simplify the integration of Google Maps into websites. This user-friendly tool provides extensive customization options, making it a favorite among WordPress users. However, recent security research uncovered a critical stored Cross-Site Scripting (XSS) vulnerability in the plugin, identified as CVE-2024-13208. This vulnerability has the potential to compromise the security of websites using the plugin, highlighting the importance of robust security measures.