โผ CVE-2023-41561 โผ
๐ Read
via "National Vulnerability Database".
Tenda AC9 V3.0 V15.03.06.42_multi and Tenda AC5 US_AC5V1.0RTL_V15.03.06.28 were discovered to contain a stack overflow via parameter startIp and endIp at url /goform/SetPptpServerCfg.๐ Read
via "National Vulnerability Database".
โผ CVE-2023-32802 โผ
๐ Read
via "National Vulnerability Database".
Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in WooCommerce WooCommerce Pre-Orders plugin <=ร 1.9.0 versions.๐ Read
via "National Vulnerability Database".
โผ CVE-2023-33320 โผ
๐ Read
via "National Vulnerability Database".
Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Mohammad I. Okfie WP-Hijri plugin <=ร 1.5.1 versions.๐ Read
via "National Vulnerability Database".
โผ CVE-2023-41555 โผ
๐ Read
via "National Vulnerability Database".
Tenda AC7 V1.0 V15.03.06.44 was discovered to contain a stack overflow via parameter security_5g at url /goform/WifiBasicSet.๐ Read
via "National Vulnerability Database".
โผ CVE-2023-25019 โผ
๐ Read
via "National Vulnerability Database".
Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Premio Chaty plugin <=ร 3.0.9 versions๐ Read
via "National Vulnerability Database".
โผ CVE-2023-32962 โผ
๐ Read
via "National Vulnerability Database".
Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in HasTheme WishSuite รขโฌโ Wishlist for WooCommerce plugin <=ร 1.3.4 versions.๐ Read
via "National Vulnerability Database".
๐ด Should Senior IT Professionals Be Accountable for Professional Decisions? ๐ด
๐ Read
via "Dark Reading".
Everyone makes mistakes โ but what if your mistakes risk the security of millions of people?๐ Read
via "Dark Reading".
Dark Reading
Should Senior IT Professionals Be Accountable for Professional Decisions?
Everyone makes mistakes โ but what if your mistakes risk the security of millions of people?
๐ฆฟ iOS 16 Cheat Sheet: Complete Guide for 2023 ๐ฆฟ
๐ Read
via "Tech Republic".
Learn about the features available with iOS 16 and how to download and install the latest version of Apple's mobile operating system.๐ Read
via "Tech Republic".
TechRepublic
iOS 16 Cheat Sheet: Complete Guide for 2023
Learn about the features available with iOS 16 and how to download and install the latest version of Apple's mobile operating system.
โค1
โผ CVE-2023-34176 โผ
๐ Read
via "National Vulnerability Database".
Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Chilexpress Chilexpress woo oficial plugin <=ร 1.2.9 versions.๐ Read
via "National Vulnerability Database".
โผ CVE-2023-3992 โผ
๐ Read
via "National Vulnerability Database".
The PostX WordPress plugin before 3.0.6 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin๐ Read
via "National Vulnerability Database".
โผ CVE-2023-34172 โผ
๐ Read
via "National Vulnerability Database".
Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Miled WordPress Social Login plugin <=ร 3.0.4 versions.๐ Read
via "National Vulnerability Database".
โผ CVE-2023-4013 โผ
๐ Read
via "National Vulnerability Database".
The GDPR Cookie Compliance (CCPA, DSGVO, Cookie Consent) WordPress plugin before 4.12.5 does not have proper CSRF checks when managing its license, which could allow attackers to make logged in admins update and deactivate the plugin's license via CSRF attacks๐ Read
via "National Vulnerability Database".
โผ CVE-2023-34032 โผ
๐ Read
via "National Vulnerability Database".
Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Pascal Casier bbPress Toolkit plugin <=ร 1.0.12 versions.๐ Read
via "National Vulnerability Database".
โผ CVE-2023-34023 โผ
๐ Read
via "National Vulnerability Database".
Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Miled WordPress Social Login plugin <=ร 3.0.4 versions.๐ Read
via "National Vulnerability Database".
โผ CVE-2022-1601 โผ
๐ Read
via "National Vulnerability Database".
The User Access Manager WordPress plugin before 2.2.18 prioritizes getting a visitor's IP from certain HTTP headers over PHP's REMOTE_ADDR, which makes it possible for attackers to access restricted content in certain situations.๐ Read
via "National Vulnerability Database".
โผ CVE-2023-1982 โผ
๐ Read
via "National Vulnerability Database".
The Front Editor WordPress plugin through 4.0.4 does not sanitize and escape some of its form settings, which could allow high-privilege users to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)๐ Read
via "National Vulnerability Database".
โผ CVE-2023-34184 โผ
๐ Read
via "National Vulnerability Database".
Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Bhavik Patel Woocommerce Order address Print plugin <=ร 3.2 versions.๐ Read
via "National Vulnerability Database".
โผ CVE-2023-3356 โผ
๐ Read
via "National Vulnerability Database".
The Subscribers Text Counter WordPress plugin before 1.7.1 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack, which also lead to Stored Cross-Site Scripting due to the lack of sanitisation and escaping๐ Read
via "National Vulnerability Database".
โผ CVE-2023-4209 โผ
๐ Read
via "National Vulnerability Database".
The POEditor WordPress plugin before 0.9.8 does not have CSRF checks in various places, which could allow attackers to make logged in admins perform unwanted actions, such as reset the plugin's settings and update its API key via CSRF attacks.๐ Read
via "National Vulnerability Database".
โผ CVE-2023-3720 โผ
๐ Read
via "National Vulnerability Database".
The Upload Media By URL WordPress plugin before 1.0.8 does not have CSRF check when uploading files, which could allow attackers to make logged in admins upload files (including HTML containing JS code for users with the unfiltered_html capability) on their behalf.๐ Read
via "National Vulnerability Database".
โผ CVE-2023-4036 โผ
๐ Read
via "National Vulnerability Database".
The Simple Blog Card WordPress plugin before 1.32 does not ensure that posts to be displayed via a shortcode are public, allowing any authenticated users, such as subscriber, to retrieve arbitrary post title and their content such as draft, private and password protected ones๐ Read
via "National Vulnerability Database".