ATENTIONβΌ New - CVE-2015-9425
π Read
via "National Vulnerability Database".
The social-locker plugin before 4.2.5 for WordPress has CSRF with resultant XSS via the wp-admin/edit.php?post_type=opanda-item&page=license-manager-sociallocker-next licensekey parameter.π Read
via "National Vulnerability Database".
ATENTIONβΌ New - CVE-2015-9424
π Read
via "National Vulnerability Database".
The multicons plugin before 3.0 for WordPress has CSRF with resultant XSS via the wp-admin/options-general.php?page=multicons%2Fmulticons.php global_url or admin_url parameter.π Read
via "National Vulnerability Database".
ATENTIONβΌ New - CVE-2015-9423
π Read
via "National Vulnerability Database".
The PlugNedit Adaptive Editor plugin before 6.2.0 for WordPress has XSS via wp-admin/admin-ajax.php?action=simple_fields_field_type_post_dialog_load PlugneditBGColor, PlugneditEditorMargin, plugnedit_width, pnemedcount, or plugneditcontent parameters.π Read
via "National Vulnerability Database".
ATENTIONβΌ New - CVE-2015-9422
π Read
via "National Vulnerability Database".
The PlugNedit Adaptive Editor plugin before 6.2.0 for WordPress has CSRF with resultant XSS via wp-admin/admin-ajax.php?action=simple_fields_field_type_post_dialog_load plugnedit_width, pnemedcount, PlugneditBGColor, PlugneditEditorMargin, or plugneditcontent parameters.π Read
via "National Vulnerability Database".
ATENTIONβΌ New - CVE-2015-9421
π Read
via "National Vulnerability Database".
The olevmedia-shortcodes plugin before 1.1.9 for WordPress has CSRF with resultant XSS via the wp-admin/admin-ajax.php?action=omsc_popup id parameter.π Read
via "National Vulnerability Database".
ATENTIONβΌ New - CVE-2015-9420
π Read
via "National Vulnerability Database".
The soundcloud-is-gold plugin before 2.3.2 for WordPress has XSS via the wp-admin/admin-ajax.php?action=get_soundcloud_player id parameter.π Read
via "National Vulnerability Database".
ATENTIONβΌ New - CVE-2015-9419
π Read
via "National Vulnerability Database".
The captain-slider plugin 1.0.6 for WordPress has XSS via a Title or Caption section.π Read
via "National Vulnerability Database".
ATENTIONβΌ New - CVE-2015-9418
π Read
via "National Vulnerability Database".
The Watu Pro plugin before 4.9.0.8 for WordPress has CSRF that allows an attacker to delete quizzes.π Read
via "National Vulnerability Database".
ATENTIONβΌ New - CVE-2015-9417
π Read
via "National Vulnerability Database".
The testimonial-slider plugin through 1.2.1 for WordPress has CSRF with resultant XSS.π Read
via "National Vulnerability Database".
ATENTIONβΌ New - CVE-2015-9416
π Read
via "National Vulnerability Database".
The sitepress-multilingual-cms (WPML) plugin 2.9.3 to 3.2.6 for WordPress has XSS via the Accept-Language HTTP header.π Read
via "National Vulnerability Database".
ATENTIONβΌ New - CVE-2015-9415
π Read
via "National Vulnerability Database".
The bj-lazy-load plugin before 1.0 for WordPress has Remote File Inclusion.π Read
via "National Vulnerability Database".
ATENTIONβΌ New - CVE-2015-9414
π Read
via "National Vulnerability Database".
The wp-symposium plugin through 15.8.1 for WordPress has XSS via the wp-content/plugins/wp-symposium/get_album_item.php?size parameter.π Read
via "National Vulnerability Database".
ATENTIONβΌ New - CVE-2015-9413
π Read
via "National Vulnerability Database".
The eshop plugin through 6.3.13 for WordPress has CSRF with resultant XSS via the wp-admin/admin.php?page=eshop-downloads.php title parameter.π Read
via "National Vulnerability Database".
ATENTIONβΌ New - CVE-2015-9412
π Read
via "National Vulnerability Database".
The Royal-Slider plugin before 3.2.7 for WordPress has XSS via the rstype parameter.π Read
via "National Vulnerability Database".
ATENTIONβΌ New - CVE-2015-9411
π Read
via "National Vulnerability Database".
The Postmatic plugin before 1.4.6 for WordPress has XSS.π Read
via "National Vulnerability Database".
ATENTIONβΌ New - CVE-2015-9411
π Read
via "National Vulnerability Database".
The Postmatic plugin before 1.4.6 for WordPress has XSS.π Read
via "National Vulnerability Database".
ATENTIONβΌ New - CVE-2015-9410
π Read
via "National Vulnerability Database".
The Blubrry PowerPress Podcasting plugin 6.0.4 for WordPress has XSS via the tab parameter.π Read
via "National Vulnerability Database".
β Vimeo sued for storing faceprints of people without their say-so β
π Read
via "Naked Security".
The suit was filed under BIPA, the Illinois law that requires written consent to grab people's faceprints - the same law Facebook's battling.π Read
via "Naked Security".
Naked Security
Vimeo sued for storing faceprints of people without their say-so
The suit was filed under BIPA, the Illinois law that requires written consent to grab peopleβs faceprints β the same law Facebookβs battling.
β Update ColdFusion now! Emergency patch for critical flaws β
π Read
via "Naked Security".
Adobe has rushed out fixes for three vulnerabilities in its ColdFusion web development platform, two of which have been given the top billing of βcriticalβ.π Read
via "Naked Security".
Naked Security
Update ColdFusion now! Emergency patch for critical flaws
Adobe has rushed out fixes for three vulnerabilities in its ColdFusion web development platform, two of which have been given the top billing of βcriticalβ.
β Russian pleads guilty in massive JPMorgan hacking scheme β
π Read
via "Naked Security".
Andrei Tyurin is the first to be convicted in one of the largest thefts of customer data from a single US financial institution in history.π Read
via "Naked Security".
Naked Security
Russian pleads guilty in massive JPMorgan hacking scheme
Andrei Tyurin is the first to be convicted in one of the largest thefts of customer data from a single US financial institution in history.
β Hackers are infecting WordPress sites via a defunct plug-in β
π Read
via "Naked Security".
If you're a Wordpress admin using a plug-in called Rich Reviews, you'll want to uninstall it. Now. The now-defunct plug-in has a major vulnerability that allows malvertisers to infect sites running Wordpress and redirect visitors to other sites.π Read
via "Naked Security".
Naked Security
Hackers are infecting WordPress sites via a defunct plug-in
If youβre a Wordpress admin using a plug-in called Rich Reviews, youβll want to uninstall it. Now.