Security News

WordPress Ninja Forms plugin flaw lets hackers steal submitted data
2023-07-27 17:00

Popular WordPress form-building plugin Ninja Forms contains three vulnerabilities that could allow attackers to achieve privilege escalation and steal user data. The second and third problems, tracked as CVE-2023-38393 and CVE-2023-38386, respectively, are broken access control issues on the plugin's form submissions export feature, allowing Subscribers and Contributors to export all of the data that users have submitted on the impacted WordPress site.

Hackers exploiting critical WordPress WooCommerce Payments bug
2023-07-17 21:08

Hackers are conducting widespread exploitation of a critical WooCommerce Payments plugin to gain the privileges of any users, including administrators, on vulnerable WordPress installation. WooCommerce Payments is a very popular WordPress plugin allowing websites to accept credit and debit cards as payment in WooCommerce stores.

WordPress AIOS plugin used by 1M sites logged plaintext passwords
2023-07-14 15:55

The All-In-One Security WordPress security plugin, used by over a million WordPress sites, was found to be logging plaintext passwords from user login attempts to the site's database, putting account security at risk. Roughly three weeks ago, a user reported that the AIOS v5.1.9 plugin was not only recording user login attempts to the aiowps audit log database table, used to track logins, logouts, and failed login events but also recording the inputted password.

AIOS WordPress Plugin Faces Backlash for Storing User Passwords in Plaintext
2023-07-14 11:07

All-In-One Security, a WordPress plugin installed on over one million sites, has issued a security update after a bug introduced in version 5.1.9 of the software caused users' passwords being added to the database in plaintext format. "This would be a problem if those site administrators were to try out those passwords on other services where your users might have used the same password. If those other services' logins are not protected by two-factor authentication, this could be a risk to the affected website."

Improve Your Security WordPress Spam Protection With CleanTalk Anti-Spam
2023-07-08 06:14

Every website owner or webmaster grapples with the issue of spam on their website forms. CleanTalk Anti-Spam is a cloud-based tool designed to block various types of spam that website administrators encounter daily.

WordPress plugin lets users become admins – Patch early, patch often!
2023-07-03 19:48

If you run a WordPress site with the Ultimate Members plugin installed, make sure you've updated it to the latest version. The plugin doesn't allow users to enter this value, but this filter turns out to be easy to bypass, making it possible to edit wp capabilities and become an admin.

Hackers Exploiting Unpatched WordPress Plugin Flaw to Create Secret Admin Accounts
2023-07-01 07:25

As many as 200,000 WordPress websites are at risk of ongoing attacks exploiting a critical unpatched security vulnerability in the Ultimate Member plugin. Ultimate Member is a popular plugin that facilitates the creation of user-profiles and communities on WordPress sites.

Hackers exploit zero-day in Ultimate Member WordPress plugin with 200K installs
2023-06-30 19:49

Hackers exploit a zero-day privilege escalation vulnerability in the 'Ultimate Member' WordPress plugin to compromise websites by bypassing security measures and registering rogue administrator accounts. Ultimate Member is a user profile and membership plugin that facilitates sign-ups and building communities on WordPress sites, and it currently has over 200,000 active installations.

Critical Security Flaw in Social Login Plugin for WordPress Exposes Users' Accounts
2023-06-29 07:24

A critical security flaw has been disclosed in miniOrange's Social Login and Register plugin for WordPress that could enable a malicious actor to log in as any user-provided information about email address is already known. Tracked as CVE-2023-2982, the authentication bypass flaw impacts all versions of the plugin, including and prior to 7.6.4.

Critical Flaw Found in WordPress Plugin for WooCommerce Used by 30,000 Websites
2023-06-22 10:17

A critical security flaw has been disclosed in the WordPress "Abandoned Cart Lite for WooCommerce" plugin that's installed on more than 30,000 websites. The problem, at its core, is a case of authentication bypass that arises as a result of insufficient encryption protections that are applied when customers are notified when they have abandoned their shopping carts on e-commerce sites without completing the purchase.