Articles
Newsflash
20 Jun 2025 Communication and Collaboration
Mattermost: Arbitrary File Write via Path Traversal in Mattermost Archive Extractor

In Mattermost versions 10.5.x ≤ 10.5.5, 9.11.x ≤ 9.11.15, 10.8.x ≤ 10.8.0, 10.7.x ≤ 10.7.2 and 10.6.x ≤ 10.6.5 a critical severity vulnerability CVE-2025-4981 was detected. This vulnerability allows authenticated users to write files to arbitrary locations on the filesystem by uploading archives containing path traversal sequences in filenames, potentially leading to remote code execution. This affects instances where file attachments and content extraction are enabled (default configuration). Currently, there is no fix version for this issue. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2025-4981.

Read more
Communication
20 Jun 2025 Business and Enterprise Solutions
WordPress: Stored XSS via Currency Shortcode in Euro FxRef Currency Converter Plugin

In Euro FxRef Currency Converter plugin for WordPress versions up to and including 2.0.2 a medium severity vulnerability CVE-2025-6257 was detected. This vulnerability allows authenticated attackers with Contributor-level access and above to inject arbitrary web scripts via the plugin’s currency shortcode due to insufficient input sanitization and output escaping. These scripts execute whenever a user accesses an injected page. To address this issue, users should upgrade Euro FxRef Currency Converter plugin to versions 2.0.3 or later. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2025-6257.

Read more
CMS
20 Jun 2025 Business and Enterprise Solutions
WordPress: Unauthorized Data Modification via Misconfigured Capability Checks in Opinion Stage Plugin

In Poll, Survey & Quiz Maker Plugin by Opinion Stage for WordPress versions up to and including 19.9.0 a medium severity vulnerability CVE-2025-3880 was detected. This vulnerability allows authenticated users with Contributor access and above to change plugin settings, including the account email or connection status, due to insufficient permission checks. To address this issue, users should upgrade Poll, Survey & Quiz Maker Plugin to versions 19.10.0 or later. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2025-3880.

Read more
CMS
20 Jun 2025 Business and Enterprise Solutions
WordPress: Arbitrary File Upload in Pixabay Images Plugin

In the Pixabay Images plugin for WordPress versions up to and including 3.4 a high severity vulnerability CVE-2025-4413 was detected. This vulnerability allows authenticated attackers with Author-level access and above to upload arbitrary files to the affected site’s server due to missing file type validation, which may lead to remote code execution. Currently, there is no fix version for this issue. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2025-4413.

Read more
CMS
20 Jun 2025 Business and Enterprise Solutions
WordPress: Arbitrary File Upload in Ultra Addons for Contact Form 7 Plugin

In the Ultra Addons for Contact Form 7 plugin for WordPress versions up to and including 3.5.12 a high severity vulnerability CVE-2025-6220 was detected. This vulnerability allows authenticated attackers with Administrator-level access and above to upload arbitrary files to the affected site’s server due to missing file type validation in the save_options function, potentially leading to remote code execution. To address this issue, users should upgrade the Ultra Addons for Contact Form 7 plugin to versions 3.5.13 or later. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2025-6220.

Read more
CMS
19 Jun 2025 Business and Enterprise Solutions
WordPress: Stored XSS via elementId Parameter in Gutenverse News Plugin

In Gutenverse News plugin for WordPress versions up to and including 1.0.4 a medium severity vulnerability CVE-2025-5234 was detected. This vulnerability allows authenticated attackers with Contributor-level access and above to perform Stored Cross-Site Scripting (XSS) attacks via the ‘elementId’ parameter due to insufficient input sanitization and output escaping. To address this issue, users should upgrade Gutenverse News plugin to versions 2.0.0 or later. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2025-5234.

Read more
CMS
Case Studies