Simple Local Avatars is a user-friendly plugin designed to streamline avatar management on WordPress websites. By seamlessly integrating an avatar upload field into user profiles, this lightweight plugin empowers users with media permissions to personalize their online presence effortlessly. In this article, we explore the features of Simple Local Avatars, emphasizing its commitment to security and recognition through the esteemed “Plugin Security Certification” (PSC) from CleanTalk.
CVE-2023-6067 – WP User Profile Avatar – Stored XSS via shortcode (Contributor+) – POC
CVE-2024-2729 – Otter Blocks – Stored XSS to Admin Account Creation (Contributor+) – POC
CVE-2024-2428 – The Ultimate Video Player For WordPress – by Presto Player – Stored XSS to Admin Account Creation (Contributor+) – POC

A critical security flaw has been uncovered in “The Ultimate Video Player For WordPress” plugin, tagged as CVE-2024-2428. This vulnerability jeopardizes over 100,000 WordPress installations, enabling attackers to execute Stored Cross-Site Scripting (XSS) attacks, potentially leading to Admin Account Creation.
CVE-2024-2444 – Inline Related Posts – Stored XSS to JS backdoor creation – POC

CVE-2024-2444 poses a significant threat to WordPress sites utilizing Inline Related Posts plugin, with over 100,000 installations. This vulnerability allows malicious actors to execute Stored XSS attacks, potentially leading to the creation of JavaScript backdoors, compromising website integrity. (if an attacker has previously hijacked an administrator or editor account, he can plant a backdoor to regain access back).
CVE-2024-2369 – Page Builder Gutenberg Blocks – CoBlocks – Stored XSS to Admin Account Creation (Contributor+) – POC

A critical security flaw, identified as CVE-2024-2369, threatens the integrity of over 400,000 WordPress sites leveraging the Page Builder Gutenberg Blocks plugin. This vulnerability, allowing Stored XSS to Admin Account Creation, poses an imminent risk of unauthorized access and control over administrative privileges.
CVE-2024-2583 – Shortcodes Ultimate – Stored XSS to Admin Account Creation (Contributor+) – POC
CVE-2023-7164 – BackWPup – Sensitive Data Exposure to Account Takeover – POC
CVE-2024-2509 – Gutenberg Blocks by Kadence Blocks – Stored XSS to Admin Account Creation (Contributor+) – POC

A critical vulnerability, CVE-2024-2509, has been uncovered in the popular Gutenberg Blocks by Kadence Blocks plugin, boasting over 400,000 active installations. This flaw opens the door to malicious attackers, allowing them to execute Stored XSS attacks and potentially create admin accounts, posing a significant threat to WordPress sites.
CVE-2024-0673 – Pz-LinkCard – Stored XSS to JS backdoor creation – POC

A critical vulnerability, CVE-2024-0673, has been uncovered in the Pz-LinkCard plugin for WordPress. This flaw allows for the execution of Stored Cross-Site Scripting (XSS) attacks, enabling malicious actors to create JavaScript backdoors and potentially compromise admin accounts. As a result, high privilege users such as administrators can exploit this flaw to execute malicious scripts, potentially leading to account takeover (if an attacker has previously hijacked an administrator or editor account, he can plant a backdoor to regain access back).
