# Trusti Security: Protect Your WordPress Site Generated by Yoast SEO v27.7, this is an llms.txt file, meant for consumption by LLMs. ## Pages - [Trusti Radar](https://trustiwp.com/trusti-radar/) - [Privacy Policy](https://trustiwp.com/privacy-policy/) - [Terms and Conditions](https://trustiwp.com/terms-and-conditions/) - [Home](https://trustiwp.com/) - [Blog](https://trustiwp.com/blog/) ## Posts - [CVE\-2024\-11972: Unauthenticated Plugin Installation in Hunk Companion Let Attackers Hijack WordPress Sites \(10,000\+ Installs, CVSS 9\.8\)](https://trustiwp.com/hunk-companion-cve-2024-11972-unauthenticated-plugin-installation/): A critical flaw \(CVSS 9\.8\) in the Hunk Companion plugin let unauthenticated attackers install and activate any plugin from WordPress\.org, then chain outdated plugins into remote code execution\. Exploited in the wild against 10,000\+ sites, it was fixed in version 1\.9\.0\. - [CVE\-2025\-1661: Unauthenticated Local File Inclusion in HUSKY Products Filter for WooCommerce \(CVSS 9\.8\)](https://trustiwp.com/husky-products-filter-woocommerce-cve-2025-1661-local-file-inclusion/): A critical unauthenticated Local File Inclusion flaw \(CVE\-2025\-1661, CVSS 9\.8\) in the popular HUSKY \- Products Filter Professional for WooCommerce plugin let attackers execute arbitrary PHP on the server via the woof\_text\_search AJAX action\. Here's how the flaw works, what it could do to your store, and why you must update to version 1\.3\.6\.6\. - [W3 Total Cache CVE\-2024\-12365: Subscriber\-Level SSRF in 1 Million WordPress Sites](https://trustiwp.com/w3-total-cache-cve-2024-12365-subscriber-ssrf/): A missing capability check in W3 Total Cache \(all versions up to 2\.8\.1\) let any logged\-in user — including a Subscriber — steal the plugin's admin nonce and force the server into making arbitrary outbound requests\. CVE\-2024\-12365 carries a CVSS score of 8\.5 and can be used to reach cloud metadata endpoints and internal services\. The fix is version 2\.8\.2\. - [CVE\-2024\-28890: Unauthenticated Arbitrary File Upload in Forminator Exposed 500,000\+ WordPress Sites \(CVSS 9\.8\)](https://trustiwp.com/forminator-cve-2024-28890-unauthenticated-arbitrary-file-upload/): CVE\-2024\-28890 is a critical \(CVSS 9\.8\) unauthenticated arbitrary file upload vulnerability in the Forminator form builder plugin, installed on 500,000\+ WordPress sites\. Attackers could upload PHP web shells and fully take over vulnerable sites\. Here is how the flaw works, how to check if you were exposed, and how to fix it\. - [CVE\-2025\-1128: Critical Unauthenticated Arbitrary File Upload in Everest Forms \(100,000\+ Sites, CVSS 9\.8\)](https://trustiwp.com/everest-forms-cve-2025-1128-unauthenticated-arbitrary-file-upload/): A critical flaw in the Everest Forms WordPress plugin \(100,000\+ installs\) let unauthenticated attackers upload, read, and delete arbitrary files on the server\. Rated CVSS 9\.8, CVE\-2025\-1128 affects all versions up to 3\.0\.9\.4 and could lead to remote code execution and full site takeover\. Here is how it works and how to fix it\. ## Plugins - [Trusti Security](https://trustiwp.com/plugins/trusti-security/) - [Trusti Speed](https://trustiwp.com/plugins/trusti-speed/) ## Categories - [Security](https://trustiwp.com/category/security/) - [CVE](https://trustiwp.com/category/cve/) - [Guides](https://trustiwp.com/category/guides/) - [News](https://trustiwp.com/category/news/) - [Performance](https://trustiwp.com/category/performance/) ## Tags - [wordpress](https://trustiwp.com/tag/wordpress/) - [security](https://trustiwp.com/tag/security/) - [wordpress\-security](https://trustiwp.com/tag/wordpress-security/) - [unauthenticated](https://trustiwp.com/tag/unauthenticated/) - [critical vulnerability](https://trustiwp.com/tag/critical-vulnerability/) ## Optional - [Sitemap index](https://trustiwp.com/sitemap_index.xml)