Online Safety Alerts by WebSifu
20 subscribers
46 links
Stay up to date on software vulnerability so you can patch your website in time
Download Telegram
XO Event Calendar < 2.3.7 πŸ‘ˆ Do you have this plugin installed on your website? Check now if it's at the latest version, else you want to update it immediately.

Reported vulnerability:
Reflected Cross-Site Scripting

More information:
https://websifu.sg/alert/xo-event-calendar-2-3-7/
Watu Quizz < 3.1.2.6 πŸ‘ˆ Do you have this plugin installed on your website? Check now if it's at the latest version, else you want to update it immediately.

Reported vulnerability:
Reflected XSS via question-form.html.php

More information:
https://websifu.sg/alert/watu-quizz-3-1-2-6/
Gutenberg Template Library & Redux Framework < 4.2.13 πŸ‘ˆ Do you have this plugin installed on your website? Check now if it's at the latest version, else you want to update it immediately.

Reported vulnerability:
Contributor+ Arbitrary Plugin Installation and Post Deletion

More information:
https://websifu.sg/alert/gutenberg-template-library-redux-framework-4-2-13/
ELEX WooCommerce Google Shopping < 1.2.4 πŸ‘ˆ Do you have this plugin installed on your website? Check now if it's at the latest version, else you want to update it immediately.

Reported vulnerability:
Reflected Cross-Site Scripting (XSS)

More information:
https://websifu.sg/alert/elex-woocommerce-google-shopping-1-2-4/
PublishPress Editorial Calendar < 3.5.1 πŸ‘ˆ Do you have this plugin installed on your website? Check now if it's at the latest version, else you want to update it immediately.

Reported vulnerability:


More information:
https://websifu.sg/alert/publishpress-editorial-calendar-3-5-1/
PublishPress Editorial Calendar < 3.5.1 πŸ‘ˆ Do you have this plugin installed on your website? Check now if it's at the latest version, else you want to update it immediately.

Reported vulnerability:


More information:
https://websifu.sg/alert/publishpress-editorial-calendar-3-5-1/
Better Find and Replace < 1.2.9 πŸ‘ˆ Do you have this plugin installed on your website? Check now if it's at the latest version, else you want to update it immediately.

Reported vulnerability:


More information:
https://websifu.sg/alert/better-find-and-replace-1-2-9/
Better Find and Replace < 1.2.9 πŸ‘ˆ Do you have this plugin installed on your website? Check now if it's at the latest version, else you want to update it immediately.

Reported vulnerability:
Reflected Cross-Site Scripting

More information:
https://websifu.sg/alert/better-find-and-replace-1-2-9/
uListing < 2.0.9 πŸ‘ˆ Do you have this plugin installed on your website? Check now if it's at the latest version, else you want to update it immediately.

Reported vulnerability:
Arbitrary Blog Option Update via CSRF

More information:
https://websifu.sg/alert/ulisting-2-0-9/
Bitcoin / AltCoin Payment Gateway for WooCommerce < 1.6.1 πŸ‘ˆ Do you have this plugin installed on your website? Check now if it's at the latest version, else you want to update it immediately.

Reported vulnerability:
Reflected Cross-Site Scripting

More information:
https://websifu.sg/alert/bitcoin-altcoin-payment-gateway-for-woocommerce-1-6-1/
My Chatbot πŸ‘ˆ Do you have this plugin installed on your website? Check now if it's at the latest version, else you want to update it immediately.

Reported vulnerability:
Reflected Cross-Site Scripting (XSS)

More information:
https://websifu.sg/alert/my-chatbot/
Weather Effect < 1.3.6 πŸ‘ˆ Do you have this plugin installed on your website? Check now if it's at the latest version, else you want to update it immediately.

Reported vulnerability:
Admin+ Stored Cross-Site Scripting

More information:
https://websifu.sg/alert/weather-effect-1-3-6/
SP Rental Manager πŸ‘ˆ Do you have this plugin installed on your website? Check now if it's at the latest version, else you want to update it immediately.

Reported vulnerability:
Unauthenticated SQL Injection. This vulnerability has NOT been patched. Uninstall and delete the theme until a patch is released.

More information:
https://websifu.sg/alert/sp-rental-manager/
User Activation Email πŸ‘ˆ Do you have this plugin installed on your website? Check now if it's at the latest version, else you want to update it immediately.

Reported vulnerability:
Reflected Cross-Site Scripting. This vulnerability has NOT been patched. Uninstall and delete the theme until a patch is released.

More information:
https://websifu.sg/alert/user-activation-email/
wp-publications πŸ‘ˆ Do you have this plugin installed on your website? Check now if it's at the latest version, else you want to update it immediately.

Reported vulnerability:
Local File Inclusion. This vulnerability has NOT been patched. Uninstall and delete the theme until a patch is released.

More information:
https://websifu.sg/alert/wp-publications/
Easy PayPal Buy Now Button < 1.7.3 πŸ‘ˆ Do you have this plugin installed on your website? Check now if it's at the latest version, else you want to update it immediately.

Reported vulnerability:


More information:
https://websifu.sg/alert/easy-paypal-buy-now-button-1-7-3/
BP Better Messages < 1.9.9.41 πŸ‘ˆ Do you have this plugin installed on your website? Check now if it's at the latest version, else you want to update it immediately.

Reported vulnerability:
Reflected Cross-Site Scripting

More information:
https://websifu.sg/alert/bp-better-messages-1-9-9-41/
Paypal Donation < 1.3.1 πŸ‘ˆ Do you have this plugin installed on your website? Check now if it's at the latest version, else you want to update it immediately!

Reported vulnerability:
CSRF to Stored Cross-Site Scripting

More information:
https://websifu.sg/alert/paypal-donation-1-3-1/
Channel name was changed to Β«Online Safety Alerts by WebSifuΒ»
User Registration – Custom Registration Form, Login Form And User Profile For WordPress πŸ‘ˆ Do you have this plugin installed on your website? Check now if it's at the latest version, else you want to update it immediately.

Reported vulnerability:
A critical vulnerability has been addressed in the User Registration plugin for WordPress. This security flaw allowed attackers to perform arbitrary file uploads due to insufficient validation checks. The impacted versions are those earlier than 3.0.2.1.

Action has been taken by the plugin development team to fix this vulnerability, if your website uses this…

More information:
https://websifu.sg/alert/user-registration-custom-registration-form-login-form-and-user-profile-for-wordpress/