Sucuri Blog
  • Products
    • Website Security Platform
    • Website Firewall (WAF)
    • Multi-Site plans
    • Custom & Enterprise Plans
    • Partnerships
  • Features
    • Detection
      Website Monitoring & Alerts
    • Protection
      Future Website Hacks
    • Performance
      Speed Up Your Website
    • Response
      Help For Hacked Websites
    • Backups
      Disaster Recovery Plan
  • Resources
    • Guides
    • Webinars
    • Infographics
    • Blog
    • SiteCheck
    • Reports
    • Email Courses
  • Pricing
  • Immediate Help
  • Login
Sucuri Blog
  • Products
    • Website Security Platform
    • Website Firewall (WAF)
    • Multi-Site plans
    • Custom & Enterprise Plans
    • Partnerships
  • Features
    • Detection
      Website Monitoring & Alerts
    • Protection
      Future Website Hacks
    • Performance
      Speed Up Your Website
    • Response
      Help For Hacked Websites
    • Backups
      Disaster Recovery Plan
  • Resources
    • Guides
    • Webinars
    • Infographics
    • Blog
    • SiteCheck
    • Reports
    • Email Courses
  • Pricing
  • Immediate Help
  • Login
  • Immediate Help
Login
Login

New Customer?

Sign up now.
  • Submit a ticket
  • Knowledge base
  • Chat now

Browsing Category

Vulnerability Disclosure

254 posts
WordPress Vulnerability
  • Vulnerability Disclosure

Cross Site Scripting in YITH WooCommerce Ajax Product Filter

  • John Castro
  • June 22, 2020
During a routine research audit for our Sucuri Web Application Firewall, we discovered a cross-site scripting (XSS) vulnerability affecting 100,000+ users of the YITH WooCommerce…
Read the Post
Labs Note
  • Security Advisory
  • Vulnerability Disclosure

Vulnerable Plugins: June 2020 Update

  • John Castro
  • June 19, 2020
This is a mid-month update to our regular Monthly Vulnerability Digest, which reveals a number of new patches for disclosed vulnerabilities. Plugin Vulnerability Patched Version…
Read the Post
Labs Note
  • Security Education
  • Sucuri Labs
  • Vulnerability Disclosure
  • Website Malware Infections

Vulnerabilities Digest: May 2020

  • John Castro
  • May 29, 2020
Relevant Plugins and Vulnerabilities: Plugin Vulnerability Patched Version Installs WP Product Review Unauthenticated Stored XSS 3.7.6 40000 Form Maker by 10Web Authenticated SQL Injection —…
Read the Post
Labs Note
  • Sucuri Labs
  • Vulnerability Disclosure
  • WordPress Security

Unauthenticated Stored Cross Site Scripting in WP Product Review

  • John Castro
  • May 14, 2020
During a routine research audit for our Sucuri Firewall, we discovered an Unauthenticated Persistent Cross-Site Scripting (XSS) affecting 40,000+ users of the WP Product Review…
Read the Post
Labs Note
  • Ecommerce Security
  • Magento Security
  • Sucuri Labs
  • Vulnerability Disclosure
  • Website Malware Infections
  • Website Security

Vulnerabilities Digest: April 2020

  • John Castro
  • May 1, 2020
Relevant Plugins and Vulnerabilities: Plugin Vulnerability Patched Version Installs Widget Settings Importer/Exporter Stored XSS Closed 40000 Accordion Stored/Reflected XSS 2.2.9 30000 Support Ticket System By…
Read the Post
  • Vulnerability Disclosure
  • Website Malware Infections
  • Website Security
  • WordPress Security

OneTone Vulnerability Leads to JavaScript Cookie Hijacking

  • Luke Leal
  • April 15, 2020
A vulnerability in the discontinued WordPress theme OneTone has been added to an ongoing campaign that is targeting vulnerable WordPress websites and causes malicious redirects…
Read the Post
Labs Note
  • Sucuri Labs
  • Vulnerability Disclosure
  • Website Security
  • WordPress Security

Vulnerabilities Digest: March 2020

  • John Castro
  • March 27, 2020
Fixed Plugins and Vulnerabilities Plugin Vulnerability Patched Version Installs Cookiebot Reflected Cross-Site Scripting 3.6.1 40000 Data Tables Generator By Supsystic Authenticated Stored XSS 1.9.92 30000…
Read the Post
Labs Note
  • Sucuri Labs
  • Vulnerability Disclosure
  • Website Malware Infections
  • Website Security
  • WordPress Security

Vulnerabilities Digest: February 2020

  • John Castro
  • March 2, 2020
Fixed Plugins and Vulnerabilities Plugin Vulnerability Patched Version Installs Duplicator Arbitrary File Download 1.3.28 1000000 Modula Image Gallery Authenticated Stored XSS 2.2.5 70000 Easy Property…
Read the Post
Labs Note
  • Joomla Security
  • Sucuri Labs
  • Vulnerability Disclosure
  • Website Malware Infections
  • Website Security

Stored XSS in Elementor

  • Marc-Alexandre Montpas
  • January 29, 2020
During a routine audit of WordPress plugins last december, we discovered a Stored XSS vulnerability in the very popular Elementor Page Builder plugin, which powers…
Read the Post
WordPress Vulnerability Detail
  • Security Advisory
  • Vulnerability Disclosure
  • Website Security
  • WordPress Security

Authentication Bypass Vulnerability in InfiniteWP Client <= 1.9.4.4 

  • Marc-Alexandre Montpas
  • January 16, 2020
An authentication bypass vulnerability affecting more than 300,000 InfiniteWP Client plugin users has recently been disclosed to the public. This plugin allows site owners to…
Read the Post
Zero-Day RCE in vBulletin v5.0.0-v5.5.4
  • Security Advisory
  • Vulnerability Disclosure
  • Website Security

Zero-Day RCE in vBulletin v5.0.0-v5.5.4

  • Marc-Alexandre Montpas
  • September 25, 2019
A new remote code execution (RCE) zero-day vulnerability has been disclosed by an anonymous researcher on the full disclosure mailing list this past Monday. This…
Read the Post
Search
Sucuri Sidebar Malware Removal to Signup Page
Sucuri Logo

Let’s Connect

Products
Website Firewall Website Security Platform WordPress Security Website Backups Hack Assistance Pricing
Solutions
DDoS Protection Malware Detection Malware Removal Malware Prevention Blacklist Removal SEO Spam Removal
USE CASES
Developers Ecommerce Agency Plans Enterprise Services HTTPS/2 Virtual Patching
Support
Knowledge Base SiteCheck Guides Research Labs Report Abuse Status Report
Company
About Sucuri Contact Blog Referral Partners Testimonials
Terms of Use Privacy Policy Do Not Sell My Personal Information Frequently Asked Questions

© 2025 GoDaddy Mediatemple, Inc., d/b/a Sucuri. All rights reserved.

back to top

'