# Trusti Security: Protect Your WordPress Site Generated by Yoast SEO v28.5, this is an llms.txt file, meant for consumption by LLMs. ## Pages - [Trusti Radar](https://trustiwp.com/trusti-radar/) - [Privacy Policy](https://trustiwp.com/privacy-policy/) - [Terms and Conditions](https://trustiwp.com/terms-and-conditions/) - [Home](https://trustiwp.com/) - [Blog](https://trustiwp.com/blog/) ## Posts - [Slider \& Popup Builder by Depicter CVE\-2025\-2011: Unauthenticated SQL Injection \(100,000\+ Sites, CVSS 9\.3\)](https://trustiwp.com/slider-popup-builder-depicter-cve-2025-2011-unauthenticated-sql-injection/): CVE\-2025\-2011 is a critical unauthenticated SQL injection in Slider \& Popup Builder by Depicter \(versions up to 3\.6\.1\) that lets anonymous attackers read your entire WordPress database\. Here's how the flaw works and how to fix it by updating to 3\.6\.2\. - [Email Subscribers by Icegram Express CVE\-2024\-2876: Unauthenticated SQL Injection \(CVSS 9\.8\)](https://trustiwp.com/email-subscribers-icegram-express-cve-2024-2876-unauthenticated-sql-injection/): CVE\-2024\-2876 is a critical unauthenticated SQL injection flaw in the popular Email Subscribers by Icegram Express plugin, scoring 9\.8 on CVSS\. It let anonymous attackers extract data from the WordPress database via the IG\_ES\_Subscribers\_Query class\. Update to version 5\.7\.15 or later to stay protected\. - [NotificationX CVE\-2024\-1698: Unauthenticated SQL Injection in a 30,000\-Site WordPress Plugin \(CVSS 9\.8\)](https://trustiwp.com/notificationx-cve-2024-1698-unauthenticated-sql-injection/): NotificationX, the popular FOMO and social\-proof plugin for WordPress, contained an unauthenticated SQL injection flaw \(CVE\-2024\-1698, CVSS 9\.8\) affecting all versions up to and including 2\.8\.2\. With no login required, a remote attacker could read usernames, password hashes, and other sensitive data straight from your database\. Here is how the vulnerability works, how to check whether you are exposed, and how to fix it\. - [Alone Theme CVE\-2025\-5394: Unauthenticated File Upload to RCE, Actively Exploited \(CVSS 9\.8\)](https://trustiwp.com/alone-theme-cve-2025-5394-unauthenticated-arbitrary-file-upload/): A critical flaw in the Alone – Charity Multipurpose Non\-profit WordPress theme \(CVE\-2025\-5394, CVSS 9\.8\) let unauthenticated attackers upload a webshell and seize full control of a site\. It was exploited as a zero\-day before public disclosure, with Wordfence blocking over 120,900 attacks\. Here is how the vulnerability works and how to fix it\. - [Profile Builder CVE\-2024\-6695: Unauthenticated Privilege Escalation to Admin \(CVSS 9\.8\)](https://trustiwp.com/profile-builder-cve-2024-6695-unauthenticated-privilege-escalation/): A critical flaw \(CVE\-2024\-6695, CVSS 9\.8\) in the Profile Builder plugin let unauthenticated attackers register their way into an administrator account on 50,000\+ WordPress sites\. Here's how the auto\-login flaw worked and why you must update to version 3\.11\.9\. ## Plugins - [Trusti Security](https://trustiwp.com/plugins/trusti-security/) - [Trusti Speed](https://trustiwp.com/plugins/trusti-speed/) ## Categories - [Security](https://trustiwp.com/category/security/) - [CVE](https://trustiwp.com/category/cve/) - [Guides](https://trustiwp.com/category/guides/) - [News](https://trustiwp.com/category/news/) - [Performance](https://trustiwp.com/category/performance/) ## Tags - [wordpress](https://trustiwp.com/tag/wordpress/) - [security](https://trustiwp.com/tag/security/) - [wordpress\-security](https://trustiwp.com/tag/wordpress-security/) - [unauthenticated](https://trustiwp.com/tag/unauthenticated/) - [critical vulnerability](https://trustiwp.com/tag/critical-vulnerability/) ## Optional - [Sitemap index](https://trustiwp.com/sitemap_index.xml)