Our researchers found a Pre-Auth Object Injection vulnerability in the SEOPress plugin (300k+ active installs). It was fixed in the recent 7.9 update. Make sure to update now! #wordpress#security
https://t.co/Mor1Qwvc0V
Our researchers found a Pre-Auth Stored XSS vulnerability in the WP Go Maps plugin (formerly known as WP Google Maps, 400k+ active installs). It was fixed in the recent 9.0.28 update. Make sure to update now!
#wordpress#security
https://t.co/m0IWVsc7vs
Our researchers found a Pre-Auth Stored XSS vulnerability in the Popup Builder plugin (200k+ active installs). It was fixed in the recent 4.2.3 update. Make sure to update now!
#wordpress#security
https://t.co/h9O5MSOHXP
Our researchers found a serious SQL Injection vulnerability in the WP Fastest Cache plugin. It was fixed in the recent 1.2.2 update. Make sure to update now!
https://t.co/Dk6m1ciEGd
#wordpress#security
URGENT: Active Hacking Campaign Targeting WordPress Plugin 'Royal Elementor Addons' (200,000+ active installs).
Update to 1.3.79 ASAP!
For more info:
https://t.co/k5fpZrUHAb
#wordpress#security
Our researchers found a RCE gadget chain in WordPress Core. Fortunately, it was fixed on the recent 6.3.2 update. Here's how it worked:
https://t.co/CSvE72xbzM
#wordpress#security
URGENT: Active Hacking Campaign Targeting #WordPress Plugin 'Ultimate Member' (200,000+ active installs).
We strongly recommend disabling this plugin immediately until a patch is released that fixes the vulnerability.
For more info: https://t.co/XcDKsMk7tO
Are you attending WordCamp Europe in Athens? We'd love to see you and talk security! Please come find the WPScan team at the Jetpack booth at WCEU.
#WCEU#WordPress#security