CVE-2024-2118 – Social Media Share Buttons – Stored XSS to JS backdoor creation – POC

CVE-2024-2118 – Social Media Share Buttons – Stored XSS to JS backdoor creation – POC

A critical vulnerability, CVE-2024-2118, threatens WordPress sites using Social Media Share Buttons. This flaw enables malicious actors to execute Stored XSS attacks, opening the door to account takeovers and backdoor creation. (if an attacker has previously hijacked an administrator or editor account, he can plant a backdoor to regain access back).

Plugin Security Certification: “WP External Links” – Version 2.61: Use links with Enhanced Security

Plugin Security Certification: “WP External Links” – Version 2.61: Use links with Enhanced Security

WP External Links, the comprehensive link management plugin, has undergone rigorous security testing and has successfully obtained the Plugin Security Certification (PSC) from CleanTalk. With enhanced security measures, this plugin allows users to manage both internal and external links on their WordPress websites with confidence.

CVE-2024-2309 – WP Staging – Stored XSS to JS backdoor creation – POC

CVE-2024-2309 – WP Staging – Stored XSS to JS backdoor creation – POC

A critical vulnerability, CVE-2024-2309, has been discovered in the WP Staging WordPress plugin, exposing websites to Stored Cross-Site Scripting (XSS) attacks. This flaw allows attackers to execute malicious scripts, potentially leading to the creation of JavaScript backdoors and compromising website integrity. Immediate action is advised to mitigate the risk. This vulnerability allows malicious actors to execute Stored XSS attacks, potentially leading to the creation of JavaScript backdoors, compromising website integrity. (if an attacker has previously hijacked an administrator or editor account, he can plant a backdoor to regain access back).

CVE-2024-3703 – Carousel Slider – Editor+ Stored XSS – POC

CVE-2024-3703 – Carousel Slider – Editor+ Stored XSS – POC

In the digital landscape, vulnerabilities in software can lead to significant security risks. One such vulnerability, CVE-2024-3703, has been discovered in the Carousel Slider plugin for WordPress. This particular vulnerability, categorized as a Stored XSS (Cross-Site Scripting), can enable malicious actors to execute arbitrary code on behalf of contributors, potentially leading to account takeover and other malicious activities. This article delves into the discovery, exploitation, potential risks, and recommendations associated with this vulnerability. (if an attacker has previously hijacked an administrator or editor account, he can plant a backdoor to regain access back)

CVE-2024-1664 – Responsive Gallery Grid – Stored XSS to JS backdoor creation – POC

CVE-2024-1664 – Responsive Gallery Grid – Stored XSS to JS backdoor creation – POC

A critical security flaw has been uncovered in Responsive Gallery Grid plugin, marked as CVE-2024-1664. This vulnerability enables attackers to execute Stored XSS attacks, potentially leading to the creation of JavaScript backdoors, thus endangering website integrity and security. This vulnerability allows malicious actors to execute Stored XSS attacks, potentially leading to the creation of JavaScript backdoors, compromising website integrity. (if an attacker has previously hijacked an administrator or editor account, he can plant a backdoor to regain access back).

Plugin Security Certification: “SEO SIMPLE PACK” – Version 3.4.0: Use SEO with Enhanced Security

Plugin Security Certification: “SEO SIMPLE PACK” – Version 3.4.0: Use SEO with Enhanced Security

The “SEO SIMPLE PACK” plugin prioritizes security to safeguard user data and ensure a secure SEO optimization process. With adherence to stringent security protocols and successful verification through the Plugin Security Certification (PSC) from CleanTalk, users can trust the plugin’s commitment to maintaining the highest security standards.

CVE-2024-2643 – My Sticky Bar – Stored XSS to JS backdoor creation – POC

CVE-2024-2643 – My Sticky Bar – Stored XSS to JS backdoor creation – POC

A critical vulnerability, CVE-2024-2643, has been unearthed in My Sticky Bar WordPress plugin, posing a significant threat to website security. Exploiting this flaw enables attackers to execute Stored XSS attacks and potentially implant JavaScript backdoors, jeopardizing website integrity. (if an attacker has previously hijacked an administrator or editor account, he can plant a backdoor to regain access back).

Plugin Security Certification: “WP Customer Reviews” – Version 3.7.2: Creating reviews with Enhanced Security

Plugin Security Certification: “WP Customer Reviews” – Version 3.7.2:  Creating reviews with Enhanced Security

WP Customer Reviews 3.7.2 is a WordPress plugin designed to facilitate user-generated reviews for businesses and products. It offers a dedicated page on your WordPress site where customers can submit testimonials or write reviews about your services or products. This plugin is tailored to meet the growing demand for user feedback, essential for businesses aiming to establish credibility and trustworthiness online.