Sucuri Blog
  • Products
    • Website Security Platform
    • Website Firewall (WAF)
    • Multi-Site plans
    • Custom & Enterprise Plans
    • Partnerships
  • Features
    • Detection
      Website Monitoring & Alerts
    • Protection
      Future Website Hacks
    • Performance
      Speed Up Your Website
    • Response
      Help For Hacked Websites
    • Backups
      Disaster Recovery Plan
  • Resources
    • Guides
    • Webinars
    • Infographics
    • Blog
    • SiteCheck
    • Reports
    • Email Courses
  • Pricing
  • Immediate Help
  • Login
Sucuri Blog
  • Products
    • Website Security Platform
    • Website Firewall (WAF)
    • Multi-Site plans
    • Custom & Enterprise Plans
    • Partnerships
  • Features
    • Detection
      Website Monitoring & Alerts
    • Protection
      Future Website Hacks
    • Performance
      Speed Up Your Website
    • Response
      Help For Hacked Websites
    • Backups
      Disaster Recovery Plan
  • Resources
    • Guides
    • Webinars
    • Infographics
    • Blog
    • SiteCheck
    • Reports
    • Email Courses
  • Pricing
  • Immediate Help
  • Login
  • Immediate Help
Login
Login

New Customer?

Sign up now.
  • Submit a ticket
  • Knowledge base
  • Chat now

Browsing Category

Vulnerability Disclosure

254 posts
  • Ecommerce Security
  • Magento Security
  • Security Advisory
  • Vulnerability Disclosure
  • Website Security

Adobe Patches Critical RCE Vulnerability in Magento2

  • Ben Martin
  • February 16, 2022
On Sunday, February 13th, Adobe pushed an emergency update to their Magento2 ecommerce software patching a critical unauthenticated remote code execution vulnerability. It is marked…
Read the Post
  • Vulnerability Disclosure
  • Website Security
  • WordPress Security

Critical Vulnerabilities in All in One SEO Plugin Affects Millions of WordPress Websites

  • Ben Martin
  • December 21, 2021
Security Risk: High Exploitation Level: Easy CVSS Score: 9.9 / 7.7 Vulnerability: Privilege Escalation, SQL Injection Patched Version: 4.1.5.3 Last week, security researcher at Automattic…
Read the Post
  • Security Advisory
  • Vulnerability Disclosure
  • Website Security

What is the Log4j Vulnerability?

  • Ben Martin
  • December 14, 2021
Editorial: This post was last updated October 17th, 2022. What is the Log4j vulnerability? Originally found on the popular game Minecraft, this critical server security…
Read the Post
Vulnerability in Magento
  • Magento Security
  • Security Advisory
  • Vulnerability Disclosure
  • Website Security

Adobe Patches Critical Magento Vulnerabilities in Recent Update

  • Ben Martin
  • August 13, 2021
Adobe has recently released several critical security patches for both their open source and commercial versions of their ecommerce platform. There are a total of…
Read the Post
WordPress Vulnerablity Disclosre
  • Sucuri Labs
  • Vulnerability Disclosure
  • Website Malware Infections
  • WordPress Security

Object Injection Vulnerability Affects WordPress Versions 3.7 to 5.7.1

  • Ben Martin
  • May 17, 2021
If you haven’t updated your WordPress website since October 2013, this wouldn’t affect you, but we strongly hope that is not the case! There’s a…
Read the Post
PHP repository exploited by hackers
  • Security Advisory
  • Vulnerability Disclosure
  • Web Pros

PHP Repository Exploited by Hackers

  • Antony Garand
  • March 29, 2021
The official PHP git repository, http://git.php.net/, was compromised this Sunday, March 28. An attacker was able to modify the PHP source code twice and inject…
Read the Post
WordPress Vulnerability
  • Security Education
  • Sucuri Labs
  • Vulnerability Disclosure
  • Website Security

Critical Vulnerabilities in 123contactform-for-wordpress WordPress Plugin

  • Rodrigo Escobar
  • January 19, 2021
In mass infection scenarios, our Malware Research team often looks for attack vectors to find patterns and other similarities among compromised websites. The identification of…
Read the Post
WordPress Vulnerability Detail
  • Sucuri Labs
  • Vulnerability Disclosure
  • Website Security
  • WordPress Security

Reflected XSS in WordPress v5.5.1 and Lower

  • Marc-Alexandre Montpas
  • October 30, 2020
WordPress released version 5.5.2 yesterday, which fixed a reflected XSS vulnerability we reported earlier this year. The root cause of this issue is a bug…
Read the Post
WordPress Vulnerability
  • Vulnerability Disclosure

Insufficient Privilege Validation in NextScripts: Social Networks Auto-Poster

  • John Castro
  • September 4, 2020
NextScripts: Social Networks Auto-Poster is a plugin that  automatically publishes posts from your blog to your Social Media accounts such as Facebook, Twitter, Google+, Blogger,…
Read the Post
WordPress Vulnerability
  • Vulnerability Disclosure
  • WordPress Security

Critical Vulnerability in File Manager Plugin Affecting 700k WordPress Websites

  • Antony Garand
  • September 2, 2020
Yesterday, the WordPress plugin File Manager was updated, fixing a critical vulnerability allowing any website visitor to gain complete access to the website. Users of…
Read the Post
Trojan Spyware and BEC Attacks
  • Security Advisory
  • Security Education
  • Sucuri Labs
  • Vulnerability Disclosure

Vulnerabilities Digest: June 2020

  • John Castro
  • July 6, 2020
Highlights for June 2020 Cross site scripting is still the most common vulnerability in WordPress Plugins. Bad actors are taking advantage of the lack of…
Read the Post
Search
Cross-Site Scripting Guide Sidebar
Sucuri Sidebar Malware Removal to Signup Page
Sucuri Logo

Let’s Connect

Products
Website Firewall Website Security Platform WordPress Security Website Backups Hack Assistance Pricing
Solutions
DDoS Protection Malware Detection Malware Removal Malware Prevention Blacklist Removal SEO Spam Removal
USE CASES
Developers Ecommerce Agency Plans Enterprise Services HTTPS/2 Virtual Patching
Support
Knowledge Base SiteCheck Guides Research Labs Report Abuse Status Report
Company
About Sucuri Contact Blog Referral Partners Testimonials
Terms of Use Privacy Policy Do Not Sell My Personal Information Frequently Asked Questions

© 2025 GoDaddy Mediatemple, Inc., d/b/a Sucuri. All rights reserved.

back to top

'