Critical Vulnerability Patched in GiveWP Plugin
GiveWP Unauthenticated PHP Object Injection 100k CVSS 9.8 The vulnerability in the GiveWP plugin was originally reported by Patchstack Alliance community member Edisc from Zalopay Security to the...
View ArticleUnauthenticated Privilege Escalation Vulnerability in RH – Real Estate Theme
RealHomes Theme Unauthenticated Privilege Escalation 32K CVSS 9.8 Easy Real Estate Plugin Unauthenticated Privilege Escalation 32K CVSS 9.8 This blog post discusses about the findings on the RealHome...
View ArticlePrivilege Escalation Vulnerability Patched in Better Find and Replace Plugin
Better Find and Replace Privilege Escalation Vulnerability 50k CVSS 8.8 This blog post is about the Better Find and Replace plugin vulnerability. If you’re a Better Find and Replace user, please...
View ArticleRare Case of Privilege Escalation in ASE Plugin Affecting 100k+ Sites
Admin and Site Enhancements (ASE) Privilege Escalation 100k CVSS 7.5 Admin and Site Enhancements (ASE) Pro Privilege Escalation 100k CVSS 7.5 This blog post is about the Admin and Site Enhancements...
View ArticleCritical Privilege Escalation Patched in KLEO Theme’s Plugin
K Elements Privilege Escalation 23k CVSS 9.8 This blog post is about the K Elements plugin vulnerability. If you’re a KLEO theme user who is using the K Elements plugin, please update the plugin to at...
View ArticleReflected XSS Patched in Essential Addons for Elementor Affecting 2+ Million...
Essential Addons for Elementor Reflected Cross Site Scripting 2M CVSS 7.1 This blog post is about the Essential Addons for Elementor plugin vulnerability. If you’re an Essential Addons for Elementor...
View ArticleUnauthenticated Arbitrary File Upload Vulnerability in Chaty Pro Plugin
Chaty Pro Unauthenticated Arbitrary File Upload 18K CVSS 10.0 This blog post discusses about the findings on the Chaty Pro plugin. This vulnerability is fixed on version 3.3.4 and the vulnerable...
View ArticleCritical LFI to RCE Vulnerability in WP Ghost Plugin Affecting 200k+ Sites
WP Ghost Local File Inclusion to RCE 200k CVSS 9.6 This blog post is about the WP Ghost plugin vulnerability. If you’re a WP Ghost user, please update the plugin to at least version 5.4.02. If you are...
View ArticleNew Year, New Threats: Q1 2025’s Most Exploited WordPress Vulnerabilities
Introduction WordPress remains the backbone of millions of websites, offering flexibility and scalability through its extensive library of plugins and themes. However, this same openness also makes it...
View ArticleCritical SureTriggers Plugin Vulnerability Exploited within 4 hours
If you are a Patchstack customer, you are protected from this vulnerability already, and no further action is required from you. Vulnerability Information On April 10, 2025, a critical vulnerability...
View ArticleCritical RomethemeKit For Elementor Plugin Vulnerability Patched
RomethemeKit For Elementor Arbitrary Plugin Installation/Activation to RCE 30k CVSS 9.9 This blog post is about the RomethemeKit For Elementor plugin vulnerability. If you're a RomethemeKit For...
View ArticleUnpatched Critical Vulnerability in TI WooCommerce Wishlist Plugin
TI WooCommerce Wishlist Arbitrary File Upload 100k CVSS 10.0 This blog post is about an unauthenticated arbitrary file upload in the TI WooCommerce Wishlist plugin. If you're a TI WooCommerce Wishlist...
View ArticleNEW: Patchstack AI code review tool and Security Suite for plugin vendors
Today, we are super excited to launch the new version of the Patchstack mVDP platform, which now comes with an AI-based code review tool, team management features and a discussion board that helps...
View ArticleUnpatched Account Takeover Vulnerability in PayU CommercePro Plugin
PayU CommercePro Plugin Account Takeover 5k CVSS 9.8 This blog post is about an unauthenticated account takeover vulnerability in the PayU CommercePro plugin. If you're a PayU CommercePro user, please...
View ArticlePatchstack managed VDP report forwarding
As the leading threat intelligence provider in the WordPress ecosystem, Patchstack has more experience with validating reports and coordinating vulnerability disclosures than anyone else. Because of...
View ArticleAccount Takeover Vulnerability Patched in Password Policy Manager Plugin
Password Policy Manager Plugin Account Takeover 5k CVSS 8.8 This blog post is about an unauthenticated account takeover vulnerability in the Password Policy Manager plugin. If you're a Password Policy...
View ArticleAccount Takeover Vulnerability Affecting Over 400K Installations Patched in...
Post SMTP Subscriber+ Account Takeover 400K CVSS 8.8 This blog post is about a Subscriber+ account takeover (broken authentication) vulnerability in the Post SMTP plugin. If you're a Post SMTP user,...
View ArticleUnauthenticated Arbitrary File Deletion Vulnerability in Litho Theme
Litho Theme Unauthenticated Arbitrary File Deletion 5K CVSS 8.6 This blog post is about an Unauthenticated Arbitrary File Deletion vulnerability in the Litho theme. If you're a Litho theme user,...
View ArticleRapidMitigate: Next-gen vulnerability mitigation for websites
For years, Patchstack has pushed the boundaries of virtual patching. Over the past two years we have relentlessly innovated to deliver the fastest, most accurate vulnerability-mitigation solution for...
View ArticleCritical Vulnerability Impacting Over 100K Sites Patched in Everest Forms Plugin
Everest Forms PHP Object Injection 100K CVSS 9.8 This blog post is about an unauthenticated PHP object injection vulnerability in the Everest Forms plugin. If you're an Everest Forms user, please...
View Article