Remove tag wordpress
article thumbnail

XSS flaw in WordPress WP-Members Plugin can lead to script injection

Security Affairs

A cross-site scripting vulnerability (XXS) in the WordPress WP-Members Membership plugin can lead to malicious script injection. Researchers from Defiant’s Wordfence research team disclosed a cross-site scripting vulnerability (XXS) in the WordPress WP-Members Membership plugin that can lead to malicious script injection.

article thumbnail

Critical flaw in Ninja Forms WordPress Plugin actively exploited in the wild

Security Affairs

A critical vulnerability in Ninja Forms plugin potentially impacted more than one million WordPress websites. In middle June, the Wordfence Threat Intelligence team noticed a back-ported security update in the popular WordPress plugin Ninja Forms, which has over one million active installations. SecurityAffairs – hacking, WordPress).

Hacking 113
Insiders

Sign Up for our Newsletter

This site is protected by reCAPTCHA and the Google Privacy Policy and Terms of Service apply.

article thumbnail

Millions of sites could be hacked due to flaws in popular WordPress plugins

Security Affairs

Experts found vulnerabilities in two WordPress plugins that could be exploited to run arbitrary code and potentially take over a website. Security researchers disclosed vulnerabilities in Elementor and WP Super Cache WordPress plugins that could be exploited to run arbitrary code and take over a website under certain circumstances.

Hacking 134
article thumbnail

100k+ WordPress sites exposed to hack due to a bug in Real-Time Find and Replace plugin

Security Affairs

A bug in the Real-Time Find and Replace WordPress plugin could allow hackers to hackers to create rogue admin accounts on over 100,000 sites. A vulnerability in the Real-Time Find and Replace WordPress plugin could be exploited by attackers to create rogue admin accounts. ” reads the analysis published by WordFence.

Hacking 120
article thumbnail

BackupBuddy WordPress plugin vulnerable to exploitation, update now!

Malwarebytes

Users of WordPress may need to perform an urgent update related to the popular BackupBuddy plugin. Traversing a WordPress installation. The developers make the following observations: Using this vulnerability, attackers can view the contents of any file on your server which is readable by the WordPress installation.

Backups 76
article thumbnail

Mar 27 – Apr 02 Ukraine – Russia the silent cyber conflict

Security Affairs

Mar 31 – Google TAG details cyber activity with regard to the invasion of Ukraine. The Google TAG uses uncovered phishing attacks targeting Eastern European and NATO countries, including Ukraine. Mar 29 – Compromised WordPress sites launch DDoS on Ukrainian websites.

DDOS 98
article thumbnail

CSRF flaw in WordPress potentially allowed the hack of websites

Security Affairs

Security researcher Simon Scannell from RIPS Technologies, has discovered a new CSRF vulnerability in WordPress, that could potentially lead to remote code execution attacks. Scannell demonstrated the attack that relies on multiple flaws, including: WordPress doesn’t implement CSRF validation when a user posts a new comment.

Hacking 85