In the ever-changing world of web security, WordPress plugins often find themselves at the forefront of both innovation and vulnerabilities. The latest discovery, CVE-2024-5442, reveals a critical flaw in the popular NextGen Gallery WordPress plugin gallery. This vulnerability makes a stored cross-site scripting (XSS) attack possible, allowing attackers to inject malicious JavaScript code and potentially create a backdoor to hijack accounts.
CVE-2024-4627 – Rank Math SEO – Stored XSS to backdoor creation – POC
WordPress is a popular content management system used by millions of websites worldwide. Its extensive plugin ecosystem allows users to add a wide range of functionalities to their sites. However, this flexibility can also introduce security vulnerabilities if plugins are not adequately secured. One such vulnerability, identified as CVE-2024-4627, was found in the widely used Rank Math SEO plugin, which has over 2 million active installations.
CVE-2024-3963 – RafflePress Lite – Stored XSS – POC
RafflePress Lite is WordPress plugin designed to help users drive traffic, grow their email lists, and boost social media engagement through viral giveaways and contests. Its intuitive drag-and-drop interface and pre-built actions, such as sharing on Facebook and Twitter, make it an easy-to-use tool for marketers and anyone looking to enhance audience engagement. However, a significant security flaw was discovered in versions prior to 1.12.14, allowing users with Editor+ rights to exploit a stored cross-site scripting (XSS) vulnerability. This flaw poses a serious risk as it can lead to the theft of user and administrator credentials.
CVE-2024-3111 – Interactive Content – H5P – Stored XSS to backdoor creation – POC
The WordPress ecosystem continues to be a focal point for web administrators due to its flexibility and extensive plugin ecosystem. However, this flexibility sometimes comes at the cost of security. A recent discovery (CVE-2024-3111) highlights a critical vulnerability in the Interactive Content – H5P plugin, which is actively installed on over 40,000 websites. This vulnerability allows for Stored Cross-Site Scripting (XSS) attacks, enabling attackers to create backdoors and potentially take over admin accounts.
CVE-2024-6138 – Secure Copy Content Protection – Stored XSS – POC
The Secure Copy Content Protection plugin for WordPress is designed to prevent unauthorized copying of website content. However, during a recent security audit, a severe vulnerability—CVE-2024-6138—was discovered. This vulnerability allows Editor-level users to execute Stored Cross-Site Scripting (XSS) attacks, potentially leading to the creation of backdoors.
Plugin Security Certification: “Classic Editor” – Version 1.6.7: Use Classic Interfaces with Enhanced Security
The “Classic Editor” plugin, version 1.6.7, has proudly achieved the Plugin Security Certification (PSC) from CleanTalk. This certification emphasizes the plugin’s commitment to maintaining a secure, reliable, and user-friendly experience for WordPress users who prefer the traditional editing interface.
Plugin Security Certification: “Simple Share Buttons Adder” – Version 8.5.1: Securely Add Social Share Buttons with Confidence
The “Simple Share Buttons Adder” plugin, version 8.5.1, has earned the esteemed Plugin Security Certification (PSC) from CleanTalk, guaranteeing superior security for its users. This certification represents a crucial achievement in the plugin’s dedication to offering a secure, reliable, and user-friendly solution for adding customizable social share buttons to WordPress websites.
CVE-2024-5573 – Easy Table of Contents – Stored XSS to backdoor creation – POC
In the ever-evolving landscape of web security, WordPress plugins frequently find themselves at the forefront of both innovation and vulnerability. The latest discovery, CVE-2024-5573, exposes a critical flaw in the popular WordPress plugin Easy Table of Contents. This vulnerability allows for a Stored Cross-Site Scripting (XSS) attack, enabling malicious actors to embed harmful JavaScript code and potentially create a backdoor for account takeovers. With over 500,000 active installations, the implications of this vulnerability are significant, warranting immediate attention and action.
Plugin Security Certification: “Responsive Lightbox & Gallery” – Version 2.4.9: Use Galleries and Lightboxes with Enhanced Security
The “Responsive Lightbox & Gallery” plugin, version 2.4.9, has achieved the prestigious Plugin Security Certification (PSC) from CleanTalk, ensuring enhanced security for all its users. This certification marks a significant milestone in the plugin’s commitment to providing a secure, robust, and user-friendly solution for creating and managing galleries and lightboxes on WordPress websites.
CVE-2024-4900 – SEOPress – On-site SEO – Malicious Redirect via HTTP-EQUIV Injection – POC
In the ever-evolving landscape of cybersecurity, staying vigilant about potential vulnerabilities in widely-used plugins is crucial. Recently, a critical vulnerability, identified as CVE-2024-4900, was discovered in the SEOPress plugin for WordPress, which has over 300,000 active installations. This vulnerability allows an attacker to execute a malicious redirect by injecting code through a field meant for SEO settings, posing a significant risk to websites using this plugin.