Contact Form to Any API < 1.1.9 – Authenticated (Subscriber+) SQL Injection

Description The Contact Form to Any API plugin for WordPress is vulnerable to SQL Injection in all versions up to, and including, 1.1.8 due to insufficient escaping on the user supplied parameter and ...

Continue Reading
Best API Security Product: Wallarm wins 2024 Cybersecurity Excellence Award

We are thrilled to announce that Wallarm has clinched the sought-after 2024 Cybersecurity Excellence Award, under the category Best API Security Product. Our unwavering commitment to pioneering soluti ...

Continue Reading
Masteriyo – LMS < 1.7.4 – Insecure Direct Object Reference

Description The Masteriyo LMS – eLearning and Online Course Builder for WordPress plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 1.7.3 v ...

Continue Reading
WP Migration Plugin DB & Files – WP Synchro < 1.11.3 – Cross-Site Request Forgery

Description The WP Migration Plugin DB &amp; Files – WP Synchro plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.11.2. This is due to missing ...

Continue Reading
iPanorama 360 WordPress Virtual Tour Builder < 1.8.2 – Missing Authorization

Description The iPanorama 360 WordPress Virtual Tour Builder plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on a REST API endpoint in versions up t ...

Continue Reading
iPages Flipbook < 1.5.2 – Missing Authorization

Description The iPages Flipbook plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on a REST API endpoint in versions up to, and including, 1.5.1. This ...

Continue Reading
K000139532 : Node.js vulnerability CVE-2024-27983

Security Advisory Description An attacker can make the Node.js HTTP/2 server completely unavailable by sending a small amount of HTTP/2 frames packets with a few HTTP/2 frames inside. It is possible t ...

Continue Reading
Litestar and Starlite vulnerable to Path Traversal

Summary Local File Inclusion via Path Traversal in LiteStar Static File Serving A Local File Inclusion (LFI) vulnerability has been discovered in the static file serving component of LiteStar. This vu ...

Continue Reading

Back to Main

Subscribe for the latest news: