Sucuri Blog
  • Products
    • Website Security Platform
    • Website Firewall (WAF)
    • Multi-Site plans
    • Custom & Enterprise Plans
    • Partnerships
  • Features
    • Detection
      Website Monitoring & Alerts
    • Protection
      Future Website Hacks
    • Performance
      Speed Up Your Website
    • Response
      Help For Hacked Websites
    • Backups
      Disaster Recovery Plan
  • Resources
    • Guides
    • Webinars
    • Infographics
    • Blog
    • SiteCheck
    • Reports
    • Email Courses
  • Pricing
  • Immediate Help
  • Login
Sucuri Blog
  • Products
    • Website Security Platform
    • Website Firewall (WAF)
    • Multi-Site plans
    • Custom & Enterprise Plans
    • Partnerships
  • Features
    • Detection
      Website Monitoring & Alerts
    • Protection
      Future Website Hacks
    • Performance
      Speed Up Your Website
    • Response
      Help For Hacked Websites
    • Backups
      Disaster Recovery Plan
  • Resources
    • Guides
    • Webinars
    • Infographics
    • Blog
    • SiteCheck
    • Reports
    • Email Courses
  • Pricing
  • Immediate Help
  • Login
  • Immediate Help
Login
Login

New Customer?

Sign up now.
  • Submit a ticket
  • Knowledge base
  • Chat now

Browsing Category

Vulnerability Disclosure

254 posts

MailPoet Vulnerability Exploited in the Wild – Breaking Thousands of WordPress Sites

  • Daniel Cid
  • July 23, 2014
A few weeks ago we found and disclosed a serious vulnerability on the MailPoet WordPress Plugin. We urged everyone to upgrade their sites immediately due…
Read the Post

SQL Injection Vulnerability – vBulletin 5.x

  • Daniel Cid
  • July 17, 2014
The vBulletin team just released a security patch for vBulletin 5.0.4, 5.0.5, 5.1.0, 5.1.1, and 5.1.2 to address a SQL injection vulnerability on the member…
Read the Post

Disclosure: Insecure Nonce Generation in WPtouch

  • Marc-Alexandre Montpas
  • July 14, 2014
If you use the popular WPtouch plugin (5M+ downloads) on your WordPress website, you should update it immediately. During a routine audit for our WAF,…
Read the Post

Remote File Upload Vulnerability in WordPress MailPoet Plugin (wysija-newsletters)

  • Daniel Cid
  • July 1, 2014
Marc-Alexandre Montpas, from our research team, found a serious security vulnerability in the MailPoet WordPress plugin. This bug allows an attacker to upload any file…
Read the Post

TimThumb WebShot Code Execution Exploit (Zeroday)

  • Daniel Cid
  • June 25, 2014
If you are still using Timthumb after the serious vulnerability that was found on it last year, you have one more reason to be concerned.…
Read the Post

Disclosure: Remote Code Execution Vuln in Disqus

  • Marc-Alexandre Montpas
  • June 20, 2014
We recently found a security vulnerability in the Disqus Comment System plugin for WordPress. It could, under very specific conditions, allow an attacker to perform…
Read the Post

Vulnerability found in the All in One SEO Pack WordPress Plugin

  • Marc-Alexandre Montpas
  • May 31, 2014
The team behind the All in One SEO Pack just released a new version of their popular WordPress plugin. It is a security release patching…
Read the Post

Critical Update for JetPack WordPress Plugin

  • Daniel Cid
  • April 10, 2014
The Jetpack team just released a critical security update to fix a security vulnerability in the Jetpack WordPress plugin. The vulnerability allows an attacker to…
Read the Post

JCE Joomla Extension Attacks in the Wild

  • Daniel Cid
  • March 26, 2014
Our friends from SpiderLabs, issued a warning today on their blog about increased activity on their honeypots looking to exploit the old JCE (Joomla Content…
Read the Post

Security Exploit Patched on vBulletin – PHP Object Injection

  • Daniel Cid
  • March 14, 2014
The vBulletin team just issued a warning, and released patches for a security exploit that affected all versions of vBulletin including 3.5, 3.6, 3.7, 3.8,…
Read the Post

Joomla Security Updates – Version 2.5.19 and 3.2.3 Released

  • Daniel Cid
  • March 7, 2014
The Joomla team just released two security updates and pushed out the stable versions for Joomla 2.5.19 and 3.2.3. If you run your site on…
Read the Post
Search
Sucuri Sidebar Malware Removal to Signup Page
Sucuri Logo

Let’s Connect

Products
Website Firewall Website Security Platform WordPress Security Website Backups Hack Assistance Pricing
Solutions
DDoS Protection Malware Detection Malware Removal Malware Prevention Blacklist Removal SEO Spam Removal
USE CASES
Developers Ecommerce Agency Plans Enterprise Services HTTPS/2 Virtual Patching
Support
Knowledge Base SiteCheck Guides Research Labs Report Abuse Status Report
Company
About Sucuri Contact Blog Referral Partners Testimonials
Terms of Use Privacy Policy Do Not Sell My Personal Information Frequently Asked Questions

© 2025 GoDaddy Mediatemple, Inc., d/b/a Sucuri. All rights reserved.

back to top

'