CVE-2024-1071: Critical Unauthenticated SQL Injection in Ultimate Member (200,000+ Sites)
CVE-2024-1071 is a critical (CVSS 9.8) unauthenticated SQL injection in the Ultimate Member plugin affecting versions 2.1.3 through…
CVE-2024-1071 is a critical (CVSS 9.8) unauthenticated SQL injection in the Ultimate Member plugin affecting versions 2.1.3 through…
A critical flaw (CVSS 9.8) in the CleanTalk Anti-Spam plugin let unauthenticated attackers bypass authorization through DNS spoofing…
A critical SQL injection flaw (CVSS 9.8) in the LayerSlider plugin let unauthenticated attackers extract data straight from…
GiveWP, the WordPress donation plugin running on 100,000+ sites, had a CVSS 10.0 flaw (CVE-2024-5932) that let unauthenticated…
A critical flaw (CVSS 9.8) in the Bricks Builder theme let unauthenticated attackers run arbitrary PHP code on…
A flaw in Really Simple Security let unauthenticated attackers log in as any user, including administrators, on more…
CVE-2024-28000 is a critical (CVSS 9.8) unauthenticated privilege escalation flaw in LiteSpeed Cache, a plugin on 5,000,000+ WordPress…
A CVSS 10.0 arbitrary file upload flaw in TI WooCommerce Wishlist let unauthenticated attackers upload PHP files and…
A supply chain attack on a popular caching plugin silently compromised over 100,000 WordPress sites in 48 hours.…
WordPress file permissions are the foundation of your site’s security. Even the strongest login protection and the most…