Articles
Newsflash
22 May 2025 Business and Enterprise Solutions
WordPress: Reflected XSS via Unsanitized Parameter in ClipArt Plugin

In ClipArt plugin for WordPress versions through 0.2 a high severity vulnerability CVE-2024-12726 was detected. This vulnerability allows attackers to perform Reflected Cross-Site Scripting (XSS) attacks, which could be exploited against high privilege users such as administrators. Currently, there is no fix version for this issue. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2024-12726.

Read more
CMS
22 May 2025 Business and Enterprise Solutions
WordPress: Path Traversal Allows Arbitrary Image Access in Hot Random Image Plugin

In Hot Random Image plugin for WordPress versions up to and including 1.9.2 a medium severity vulnerability CVE-2025-4419 was detected. This vulnerability allows authenticated attackers with Contributor-level access and above to exploit a path traversal flaw via the ‘path’ parameter to access arbitrary images with allowed extensions outside the intended directory. To address this issue, users should upgrade Hot Random Image plugin to versions 1.9.3 or later. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2025-4419.

Read more
CMS
22 May 2025 Business and Enterprise Solutions
WordPress: Stored XSS via ‘link’ Parameter in Hot Random Image Plugin

In Hot Random Image plugin for WordPress versions up to and including 1.9.2 a medium severity vulnerability CVE-2025-4405 was detected. This vulnerability allows authenticated attackers with Contributor-level access and above to inject arbitrary web scripts via the ‘link’ parameter due to insufficient input sanitization and output escaping. To address this issue, users should upgrade Hot Random Image plugin to versions 1.9.3 or later. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2025-4405.

Read more
CMS
22 May 2025 Business and Enterprise Solutions
WordPress: Stored XSS via SVG Uploads in MapSVG Plugin

In MapSVG plugin for WordPress versions up to and including 8.6.4 a medium severity vulnerability CVE-2024-9544 was detected. This vulnerability allows authenticated attackers with Contributor-level access and above to upload malicious SVG files that inject arbitrary web scripts, which execute whenever a user accesses the file. Currently, there is no fix version for this issue. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2024-9544.

Read more
CMS
22 May 2025 Business and Enterprise Solutions
WordPress: PostMessage-Based XSS via ‘customize-store’ Page in WooCommerce Plugin

In WooCommerce plugin for WordPress versions 9.3.2 and prior, 9.4 up to 9.4.2, 9.4.2 and prior a medium severity vulnerability CVE-2025-5062 was detected. This vulnerability allows unauthenticated attackers to inject arbitrary web scripts via the ‘customize-store’ page due to insufficient sanitization and escaping of PostMessage data. To address this issue, users should upgrade WooCommerce plugin to versions 9.3.4 or 9.4.3. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2025-5062.

Read more
CMS
22 May 2025 Business and Enterprise Solutions
WordPress: Stored XSS via Unescaped Post Titles in Blog2Social Plugin

In Blog2Social: Social Media Auto Post & Scheduler plugin for WordPress versions before 8.4.0 a medium severity vulnerability CVE-2025-4133 was detected. This vulnerability allows users with the Contributor role to perform Cross-Site Scripting (XSS) attacks by injecting malicious scripts into post titles, which are not properly escaped when displayed in the dashboard. To address this issue, users should upgrade Blog2Social: Social Media Auto Post & Scheduler plugin to versions 8.4.0 or later. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2025-4133.

Read more
CMS
Case Studies