Critical Account Takeover Vulnerability Patched in LiteSpeed Cache Plugin
LiteSpeed Cache Unauthenticated Account Takeover This blog post is about the LiteSpeed plugin vulnerability. If you’re a LiteSpeed user, please update the plugin to at least version 6.5.0.1. Sign up...
View ArticleThe Best WordPress Security Plugins (+ Do You Really Need One?)
There are thousands of “WordPress security plugins” listed on the official WordPress plugin repository, which claim to offer some security-related functionality and serve some purpose related to...
View ArticleIntroducing the Patchstack VDP platform
Our mission to provide the fastest mitigation to security vulnerabilities is core to our long-term vision of becoming a global cyber-security leader with the biggest impact on open-source security....
View ArticleSQL Injection Vulnerabilities Found in ListingPro Theme and Plugin
ListingPro Theme Unauthenticated SQL Injection ListingPro Plugin Subscriber+ SQL Injection ListingPro Plugin Unauthenticated SQL Injection This blog post is about ListingPro theme vulnerabilities. If...
View ArticlePrivilege Escalation Vulnerability Patched in Houzez Theme
Houzez Theme Authenticated Privilege Escalation 46K CVSS 8.8 Houzez Login Register Plugin Authenticated Privilege Escalation 46K CVSS 8.8 This blog post discusses about the findings on the Houzez...
View ArticleUnpatched SQL Injection Vulnerability in TI WooCommerce Wishlist Plugin
TI WooCommerce Wishlist Unauthenticated SQL Injection 100k CVSS 9.3 This blog post is about an unauthenticated SQL injection vulnerability on the TI WooCommerce Wishlist plugin. If you’re a TI...
View ArticleUnauthenticated Stored XSS Vulnerability in LiteSpeed Cache Plugin Affecting...
Litespeed Cache Unauthenticated Stored XSS 6M+ CVSS 7.1 This blog post is about the LiteSpeed Cache plugin vulnerability which is originally reported by TaiYou to the Patchstack bug bounty program for...
View ArticleCritical Vulnerabilities in Ultimate Membership Pro Plugin
Ultimate Membership Pro Unauthenticated Privilege Escalation 40k CVSS 9.4 Ultimate Membership Pro Unauthenticated PHP Object Injection 40k CVSS 9.0 This blog post is about Ultimate Membership Pro...
View ArticleSecurity implications of WordPress repository access restrictions and plugin...
Over the past couple of weeks, we’ve noticed an increasing number of plugins not receiving updates through WordPress.org. Some have been banned and others cannot log in to their WordPress.org accounts...
View ArticleRare Case of Privilege Escalation Patched in LiteSpeed Cache Plugin
LiteSpeed Cache Unauthenticated Privilege Escalation 6+ million CVSS 8.1 The vulnerability in the LiteSpeed Cache plugin was originally reported by Patchstack Alliance community member TaiYou to the...
View ArticleNearly 1000 Plugins Closed During WordPress Security Cleanup
Patchstack is always looking for new ways to make the WordPress ecosystem safer by organizing various events for ethical hackers and security researchers. Our experiments sometimes lead to unexpected...
View ArticleCritical Account Takeover Patched in Really Simple Security Plugin
Really Simple Security Free Unauthenticated Account Takeover 4+ million CVSS 9.8 Really Simple Security Pro Unauthenticated Account Takeover Unknown CVSS 9.8 Really Simple Security Pro Multisite...
View ArticleUnauthenticated Arbitrary File Read Vulnerability in Jobify Theme
Jobify Theme Unauthenticated Arbitrary File Read 14k CVSS 7.5 This blog post is about an unauthenticated arbitrary file read vulnerability on the Jobify theme. If you’re a Jobify user, please delete...
View ArticleAuthenticated RCE Patched in Rank Math SEO plugin
Rank Math SEO plugin .htaccess File Overwrite 3+ million CVSS 7.2 This blog post is about an arbitrary .htaccess file overwrite vulnerability on the Rank Matho SEO plugin. If you’re a Rank Math SEO...
View ArticleUnauthenticated Privilege Escalation Vulnerability Patched in Sweet Date Theme
Sweet Date Theme Unauthenticated Privilege Escalation 10K CVSS 9.8 This blog post discusses about the findings on the Sweet Date theme. If you’re a Sweet Date user, please update the theme to version...
View ArticleMultiple Critical Vulnerabilities Patched in Woffice Theme
Woffice Theme Unauthenticated Privilege Escalation 15k CVSS 9.8 Woffice Theme Unauthenticated Broken Authentication 15k CVSS 9.8 This blog post is about the Woffice theme vulnerabilities. If you’re a...
View ArticleVirtual Patches vs. Hackers: Q4 2024’s Most Exploited WordPress Threats
Introduction WordPress has grown into the world’s most popular content management system (CMS), empowering individuals and businesses to create websites with ease. Its open-source nature has led to...
View ArticleNEW: Announcing Patchstack API for Endless Automations
We are excited to announce that the entire Patchstack App is now accessible completely as an API and as of today – all Patchstack Developer accounts can use the API without any extra charge. With more...
View ArticleMultiple Critical Vulnerabilities Patched in WPLMS and VibeBP Plugins
WPLMS Unauthenticated Arbitrary File Upload 28k CVSS 10.0 WPLMS Subscriber+ Arbitrary File Upload 28k CVSS 9.9 WPLMS Sutedent+ Arbitrary File Upload 28k CVSS 9.9 WPLMS Unauthenticated Privilege...
View ArticleCritical Vulnerabilities Found in Fancy Product Designer Plugin
Fancy Product Designer Unauthenticated Arbitrary File Upload 20k CVSS 9.0 Fancy Product Designer Unauthenticated SQL Injection 20k CVSS 9.3 This blog post is about Fancy Product Designer plugin...
View Article