Sucuri Blog
  • Products
    • Website Security Platform
    • Website Firewall (WAF)
    • Multi-Site plans
    • Custom & Enterprise Plans
    • Partnerships
  • Features
    • Detection
      Website Monitoring & Alerts
    • Protection
      Future Website Hacks
    • Performance
      Speed Up Your Website
    • Response
      Help For Hacked Websites
    • Backups
      Disaster Recovery Plan
  • Resources
    • Guides
    • Webinars
    • Infographics
    • Blog
    • SiteCheck
    • Reports
    • Email Courses
  • Pricing
  • Immediate Help
  • Login
Sucuri Blog
  • Products
    • Website Security Platform
    • Website Firewall (WAF)
    • Multi-Site plans
    • Custom & Enterprise Plans
    • Partnerships
  • Features
    • Detection
      Website Monitoring & Alerts
    • Protection
      Future Website Hacks
    • Performance
      Speed Up Your Website
    • Response
      Help For Hacked Websites
    • Backups
      Disaster Recovery Plan
  • Resources
    • Guides
    • Webinars
    • Infographics
    • Blog
    • SiteCheck
    • Reports
    • Email Courses
  • Pricing
  • Immediate Help
  • Login
  • Immediate Help
Login
Login

New Customer?

Sign up now.
  • Submit a ticket
  • Knowledge base
  • Chat now

Browsing Category

Security Advisory

239 posts
  • Security Advisory
  • Vulnerability Disclosure
  • WordPress Security

Security Advisory: Stored XSS in bbPress

  • Marc-Alexandre Montpas
  • May 3, 2016
During regular research audits of our Sucuri Firewall, we discovered a Stored XSS vulnerability affecting the bbPress plugin for WordPress which is currently installed on…
Read the Post
  • Security Advisory
  • Website Security
  • WordPress Security

Beware of Unverified TLS Certificates in PHP & Python

  • Peter Kankowski
  • March 31, 2016
Web developers today rely on various third-party APIs. For example, these APIs allow you to accept credit card payments, integrate a social network with your…
Read the Post
  • Magento Security
  • Security Advisory
  • Vulnerability Disclosure

Security Advisory: Stored XSS in Magento

  • Marc-Alexandre Montpas
  • January 22, 2016
During our regular research audits for our Cloud-based WAF, we discovered a Stored XSS vulnerability affecting the Magento platform that can be easily exploited remotely.…
Read the Post
  • Joomla Security
  • Security Advisory
  • Website Malware Infections
  • WordPress Security

jQuery.min.php Malware Affects Thousands of Websites

  • Denis Sinegubko
  • November 5, 2015
Nov 2016 Update: If your Joomla or WordPress website is infected, check out our new, free, DIY guides to clean your site and prevent reinfection.…
Read the Post
  • Security Advisory
  • Vulnerability Disclosure
  • WordPress Security

Security Advisory: Stored XSS in Akismet WordPress Plugin

  • Marc-Alexandre Montpas
  • October 14, 2015
During a routine audit for our WAF, we discovered a critical stored XSS vulnerability affecting Akismet, a popular WordPress plugin deployed by millions of installs.
Read the Post
  • Security Advisory
  • Vulnerability Disclosure
  • WordPress Security

Security Advisory: Stored XSS in Jetpack

  • Marc-Alexandre Montpas
  • October 1, 2015
During a routine audit for our WAF, we discovered a critical stored XSS affecting the Jetpack WordPress plugin, one of the most popular plugins in…
Read the Post
  • Security Advisory
  • Website Malware Infections
  • WordPress Security

WordPress Malware – Active VisitorTracker Campaign

  • Daniel Cid
  • September 18, 2015
We are seeing a large number of WordPress sites compromised with the “visitorTracker_isMob” malware code. This campaign started 15 days ago, but only in the…
Read the Post

Security Advisory: Object Injection Vulnerability in WooCommerce

  • Marc-Alexandre Montpas
  • June 10, 2015
During a routine audit for our WAF, we discovered a dangerous Object Injection vulnerability in WooCommerce which could, in certain contexts, be used by an…
Read the Post

Security Advisory: XSS Vulnerability Affecting Multiple WordPress Plugins

  • Daniel Cid
  • April 20, 2015
Multiple WordPress Plugins are vulnerable to Cross-site Scripting (XSS) due to the misuse of the add_query_arg() and remove_query_arg() functions. These are popular functions used by…
Read the Post
  • Security Advisory
  • WordPress Security

FBI Public Service Annoucement: Defacements Exploiting WordPress Vulnerabilities

  • Daniel Cid
  • April 7, 2015
The US Federal Bureau of Investigation (FBI) just released a public service announcement (PSA) to the public about a large number of websites being exploited…
Read the Post
  • Ecommerce Security
  • Security Advisory
  • Vulnerability Disclosure
  • WordPress Security

Security Advisory: Persistent XSS in WP-Super-Cache

  • Marc-Alexandre Montpas
  • April 7, 2015
During a routine audit for our Website Firewall (WAF), we discovered a dangerous persistent XSS vulnerability affecting the very popular WP-Super-Cache plugin (more than a…
Read the Post
Search
Cross-Site Scripting Guide Sidebar
Sucuri Sidebar Malware Removal to Signup Page
Sucuri Logo

Let’s Connect

Products
Website Firewall Website Security Platform WordPress Security Website Backups Hack Assistance Pricing
Solutions
DDoS Protection Malware Detection Malware Removal Malware Prevention Blacklist Removal SEO Spam Removal
USE CASES
Developers Ecommerce Agency Plans Enterprise Services HTTPS/2 Virtual Patching
Support
Knowledge Base SiteCheck Guides Research Labs Report Abuse Status Report
Company
About Sucuri Contact Blog Referral Partners Testimonials
Terms of Use Privacy Policy Do Not Sell My Personal Information Frequently Asked Questions

© 2025 GoDaddy Mediatemple, Inc., d/b/a Sucuri. All rights reserved.

back to top

'