Multiple Critical Vulnerabilities Patched in WP Job Portal Plugin
WP Job Portal Plugin Arbitrary File Download 8k CVSS 7.5 WP Job Portal Plugin SQL Injection 8k CVSS 9.3 This blog post is about an unauthenticated arbitrary file download and an SQL injection...
View ArticleSQL Injection Vulnerability Found in LifterLMS Plugin Affecting 10K+ Sites
LifterLMS Unauthenticated SQL Injection 10k CVSS 9.3 This blog post is about LifterLMS theme vulnerabilities. If you're a LifterLMS user, please update the plugin to version 8.0.7 or higher. ✌️ Our...
View ArticleHosting security tested: 87.8% of vulnerability exploits bypassed hosting...
.blocks-ps-vs-others__cell--green { background: var(--ps-primary-light) !important; } .blocks-ps-vs-others__cell--red { background: var(--ps-red-light) !important; } .wp-block-table { margin-inline:...
View ArticleSQL Injection Vulnerability Patched in Paid Membership Subscriptions Plugin
Paid Membership Subscriptions Plugin SQL Injection 10k CVSS 7.5 This blog post is about an unauthenticated SQL injection vulnerability in the Paid Membership Subscriptions plugin. If you're a Paid...
View ArticleUnpatched Privilege Escalation in Service Finder Bookings Plugin
Service Finder Bookings Unauthenticated Privilege Escalation 6k+ CVSS 9.8 This blog post is about an unauthenticated Privilege Escalation vulnerability in the Service Finder Bookings plugin. If you're...
View ArticleUnauthenticated Broken Authentication Vulnerability in WordPress Jobmonster...
Jobmonster Broken Authentication 5k+ CVSS 9.8 This blog post is about an unauthenticated Broken Authentication vulnerability in the Jobmonster theme. If you're a Jobmonster theme user, please update...
View ArticleCritical Vulnerabilities Found in Fancy Product Designer Plugin
Fancy Product Designer Unauthenticated Arbitrary File Upload 20k CVSS 9.0 Fancy Product Designer Unauthenticated SQL Injection 20k CVSS 9.3 This blog post is about Fancy Product Designer plugin...
View ArticleCritical Vulnerability Patched in GiveWP Plugin
GiveWP Unauthenticated PHP Object Injection 100k CVSS 9.8 The vulnerability in the GiveWP plugin was originally reported by Patchstack Alliance community member Edisc from Zalopay Security to the...
View ArticleUnauthenticated Privilege Escalation Vulnerability in RH - Real Estate Theme
RealHomes Theme Unauthenticated Privilege Escalation 32K CVSS 9.8 Easy Real Estate Plugin Unauthenticated Privilege Escalation 32K CVSS 9.8 This blog post discusses about the findings on the RealHome...
View ArticlePrivilege Escalation Vulnerability Patched in Better Find and Replace Plugin
Better Find and Replace Privilege Escalation Vulnerability 50k CVSS 8.8 This blog post is about the Better Find and Replace plugin vulnerability. If you're a Better Find and Replace user, please...
View ArticleRare Case of Privilege Escalation in ASE Plugin Affecting 100k+ Sites
Admin and Site Enhancements (ASE) Privilege Escalation 100k CVSS 7.5 Admin and Site Enhancements (ASE) Pro Privilege Escalation 100k CVSS 7.5 This blog post is about the Admin and Site Enhancements...
View ArticleCritical Privilege Escalation Patched in KLEO Theme's Plugin
K Elements Privilege Escalation 23k CVSS 9.8 This blog post is about the K Elements plugin vulnerability. If you're a KLEO theme user who is using the K Elements plugin, please update the plugin to at...
View ArticleReflected XSS Patched in Essential Addons for Elementor Affecting 2+ Million...
Essential Addons for Elementor Reflected Cross Site Scripting 2M CVSS 7.1 This blog post is about the Essential Addons for Elementor plugin vulnerability. If you're an Essential Addons for Elementor...
View ArticleUnauthenticated Arbitrary File Upload Vulnerability in Chaty Pro Plugin
Chaty Pro Unauthenticated Arbitrary File Upload 18K CVSS 10.0 This blog post discusses about the findings on the Chaty Pro plugin. This vulnerability is fixed on version 3.3.4 and the vulnerable...
View ArticleCritical LFI to RCE Vulnerability in WP Ghost Plugin Affecting 200k+ Sites
WP Ghost Local File Inclusion to RCE 200k CVSS 9.6 This blog post is about the WP Ghost plugin vulnerability. If you're a WP Ghost user, please update the plugin to at least version 5.4.02. ✌️ Our...
View ArticleQ3 2025's Most Exploited WordPress Vulnerabilities and How Patchstack’s...
WordPress powers a huge portion of the web, and its extensibility (plugins, themes, and custom code) is both its strength and its greatest security risk. When vulnerabilities appear in popular plugins...
View ArticlePHP Object Injection Patched in Quiz and Survey Master Plugin Affecting 40k+...
Quiz and Survey Master PHP Object Injection 40k CVSS 9.8 This blog post is about an unauthenticated PHP object injection vulnerability in the Quiz and Survey Master plugin. If you're a Quiz and Survey...
View Article