Cross Site Scripting (XSS) – Attackers can inject malicious scripts into the site that steal visitor data or hijack their accounts.
Every day our team monitors threats that put your website at risk. We proactively patch vulnerabilities to protect your users, data, and your reputation.
19 vulnerabilities patched in the last 30 days
Page last updated:
Type
Affected Software
Latest Version
Description
Severity
Date
Plugin
<=
4.0.7
Cross Site Scripting (XSS) – Attackers can inject malicious scripts into the site that steal visitor data or hijack their accounts.
6.5
0 days ago
Type
Plugin
6.5
Affected Software
Latest Version
<=
4.0.7
Description
pulse_description
0 days ago
Plugin
<=
6.2.15
Broken Access Control – Users can access pages or perform actions they shouldn’t be allowed to, like viewing other people’s data.
5.3
0 days ago
Type
Plugin
5.3
Affected Software
Latest Version
<=
6.2.15
Description
pulse_description
0 days ago
Plugin
<=
6.17.5.1
Broken Access Control – Users can access pages or perform actions they shouldn’t be allowed to, like viewing other people’s data.
5.4
1 day ago
Type
Plugin
5.4
Affected Software
Latest Version
<=
6.17.5.1
Description
pulse_description
1 day ago
Plugin
<=
2.1.4
Broken Access Control – Users can access pages or perform actions they shouldn’t be allowed to, like viewing other people’s data.
2.7
1 day ago
Type
Plugin
2.7
Affected Software
Latest Version
<=
2.1.4
Description
pulse_description
1 day ago
Plugin
<=
1.67
PHP Object Injection – Attackers can manipulate how the site processes data to run harmful actions on the server.
8.8
1 day ago
Type
Plugin
8.8
Affected Software
Latest Version
<=
1.67
Description
pulse_description
1 day ago
Plugin
<=
7.4.3
Sensitive Data Exposure – Private information like passwords, emails, or payment details can be exposed and stolen by unauthorized parties.
5.3
1 day ago
Type
Plugin
5.3
Affected Software
Latest Version
<=
7.4.3
Description
pulse_description
1 day ago
Plugin
<=
1.8.47
PHP Object Injection – Attackers can manipulate how the site processes data to run harmful actions on the server.
8.8
1 day ago
Type
Plugin
8.8
Affected Software
Latest Version
<=
1.8.47
Description
pulse_description
1 day ago
Plugin
<=
6.3
Insecure Direct Object References (IDOR) – Changing an ID in the URL can expose other people’s data.
5.3
3 days ago
Type
Plugin
5.3
Affected Software
Latest Version
<=
6.3
Description
pulse_description
3 days ago
Plugin
<=
4.3.2
Cross Site Request Forgery (CSRF) – Logged-in users can be tricked into performing actions they didn’t intend, like changing passwords or making purchases.
8.8
6 days ago
Type
Plugin
8.8
Affected Software
Latest Version
<=
4.3.2
Description
pulse_description
6 days ago
Plugin
<=
4.0.6
Cross Site Scripting (XSS) – Attackers can inject malicious scripts into the site that steal visitor data or hijack their accounts.
6.5
8 days ago
Type
Plugin
6.5
Affected Software
Latest Version
<=
4.0.6
Description
pulse_description
8 days ago
Plugin
<=
2.5.1
Cross Site Scripting (XSS) – Attackers can inject malicious scripts into the site that steal visitor data or hijack their accounts.
6.5
8 days ago
Type
Plugin
6.5
Affected Software
Latest Version
<=
2.5.1
Description
pulse_description
8 days ago
Plugin
<=
3.15.4
Cross Site Scripting (XSS) – Attackers can inject malicious scripts into the site that steal visitor data or hijack their accounts.
7.1
9 days ago
Type
Plugin
7.1
Affected Software
Latest Version
<=
3.15.4
Description
pulse_description
9 days ago
Plugin
<=
9.8.2
Broken Authentication – Attackers can bypass the login system or log in as other users without their password.
4.3
13 days ago
Type
Plugin
4.3
Affected Software
Latest Version
<=
9.8.2
Description
pulse_description
13 days ago
Plugin
<=
7.111
Broken Authentication – This can be abused by a malicious actor to perform action which normally should only be able to be executed by higher privileged users. These actions might allow the malicious actor to gain admin access to the website.
5.3
15 days ago
Type
Plugin
5.3
Affected Software
Latest Version
<=
7.111
Description
pulse_description
15 days ago
Plugin
<=
11.0
SQL Injection – This could allow a malicious actor to directly interact with your database, including but not limited to stealing information.
7.6
23 days ago
Type
Plugin
7.6
Affected Software
Latest Version
<=
11.0
Description
pulse_description
23 days ago
Plugin
<=
10.8.1
Broken Access Control – A broken access control issue refers to a missing authorization, authentication or nonce token check in a function that could lead to an unprivileged user to executing a certain higher privileged action.
4.3
23 days ago
Type
Plugin
4.3
Affected Software
Latest Version
<=
10.8.1
Description
pulse_description
23 days ago
Plugin
<=
1.42.3
Bypass Vulnerability – A bypass vulnerability could allow a malicious actor to bypass certain restrictions in the code.
5.6
23 days ago
Type
Plugin
5.6
Affected Software
Latest Version
<=
1.42.3
Description
pulse_description
23 days ago
Plugin
<=
3.1.1
Cross Site Scripting (XSS) – This could allow a malicious actor to inject malicious scripts, such as redirects, advertisements, and other HTML payloads into your website which will be executed when guests visit your site.
7.1
27 days ago
Type
Plugin
7.1
Affected Software
Latest Version
<=
3.1.1
Description
pulse_description
27 days ago
Plugin
<=
2.4.37
Cross Site Scripting (XSS) – This could allow a malicious actor to inject malicious scripts, such as redirects, advertisements, and other HTML payloads into your website which will be executed when guests visit your site.
6.5
27 days ago
Type
Plugin
6.5
Affected Software
Latest Version
<=
2.4.37
Description
pulse_description
27 days ago
Plugin
<=
5.0.2
Broken Authentication – This can be abused by a malicious actor to perform action which normally should only be able to be executed by higher privileged users. These actions might allow the malicious actor to gain admin access to the website.
9.8
34 days ago
Type
Plugin
9.8
Affected Software
Latest Version
<=
5.0.2
Description
pulse_description
34 days ago
Explore our comprehensive WordPress support plans designed to proactively patch vulnerabilities and safeguard your online presence.