Sucuri Blog
  • Products
    • Website Security Platform
    • Website Firewall (WAF)
    • Multi-Site plans
    • Custom & Enterprise Plans
    • Partnerships
  • Features
    • Detection
      Website Monitoring & Alerts
    • Protection
      Future Website Hacks
    • Performance
      Speed Up Your Website
    • Response
      Help For Hacked Websites
    • Backups
      Disaster Recovery Plan
  • Resources
    • Guides
    • Webinars
    • Infographics
    • Blog
    • SiteCheck
    • Reports
    • Email Courses
  • Pricing
  • Immediate Help
  • Login
Sucuri Blog
  • Products
    • Website Security Platform
    • Website Firewall (WAF)
    • Multi-Site plans
    • Custom & Enterprise Plans
    • Partnerships
  • Features
    • Detection
      Website Monitoring & Alerts
    • Protection
      Future Website Hacks
    • Performance
      Speed Up Your Website
    • Response
      Help For Hacked Websites
    • Backups
      Disaster Recovery Plan
  • Resources
    • Guides
    • Webinars
    • Infographics
    • Blog
    • SiteCheck
    • Reports
    • Email Courses
  • Pricing
  • Immediate Help
  • Login
  • Immediate Help
Login
Login

New Customer?

Sign up now.
  • Submit a ticket
  • Knowledge base
  • Chat now

Browsing Category

Vulnerability Disclosure

254 posts
WordPress Vulnerability Detail
  • Vulnerability Disclosure
  • Website Security
  • WordPress Security

Dissecting the WordPress 5.2.3 Update

  • Marc-Alexandre Montpas
  • September 13, 2019
Last week, WordPress released version 5.2.3 which was a security and maintenance update, and as such, contained many security fixes. Part of our day to…
Read the Post
WordPress Vulnerability Detail
  • Vulnerability Disclosure
  • WordPress Security

Icegram Persistent Cross-Site Scripting

  • John Castro
  • July 9, 2019
Icegram is a plugin that helps you collect email addresses for your newsletter. Other features include light-box popup offers, header action bars, toast notifications, and…
Read the Post
WordPress Vulnerability
  • Vulnerability Disclosure
  • Website Malware Infections
  • Website Security
  • WordPress Security

WordPress Plugin WP Statistics: Unauthenticated Stored XSS Under Certain Configurations

  • Antony Garand
  • July 3, 2019
The WordPress plugin WP Statistics, which has an active installation base of 500k users, has an unauthenticated stored XSS vulnerability on versions prior to 12.6.7.…
Read the Post
Stored XSS in MyBB
  • Vulnerability Disclosure
  • Website Malware Infections
  • Website Security

Stored XSS in MyBB <= 1.8.20

  • Marc-Alexandre Montpas
  • June 11, 2019
The open source PHP forum software myBB recently published a new update, version 1.8.21. This is a security release fixing a Stored XSS vulnerability in…
Read the Post
WordPress Vulnerability Detail
  • Vulnerability Disclosure
  • WordPress Security

OS Command Injection in WP-Database-Backup

  • Marc-Alexandre Montpas
  • June 4, 2019
On May 28th, a critical OS Command Injection vulnerability affecting the WP-Database-Backup plugin  was disclosed to the public by the Wordfence team. This is a…
Read the Post
WordPress Vulnerability
  • Vulnerability Disclosure
  • Website Security
  • WordPress Security

Slimstat: Stored XSS from Visitors

  • Antony Garand
  • May 21, 2019
The WordPress Slimstat plugin, which currently has over 100k installs, allows your website to gather analytics data for your WordPress website. It will track certain…
Read the Post
WordPress Vulnerability
  • Vulnerability Disclosure
  • Website Security
  • WordPress Security

Persistent Cross-site Scripting in WP Live Chat Support Plugin

  • John Castro
  • May 15, 2019
During a routine research audits for our Sucuri Firewall, we discovered an Unauthenticated Persistent Cross-Site Scripting (XSS) affecting 60,000+ users of the  WP Live Chat…
Read the Post
WordPress Vulnerability
  • Vulnerability Disclosure
  • Website Security
  • WordPress Security

WordPress Plugin Give – Stored XSS for Donors

  • Antony Garand
  • May 15, 2019
​​Give is a WordPress plugin which allows users to setup a donation page on a website. It currently has 60k installs. ​​During a recent audit…
Read the Post
WordPress Vulnerability
  • Vulnerability Disclosure
  • Website Security
  • WordPress Security

Multiple Vulnerabilities in the WordPress Ultimate Member Plugin

  • Antony Garand
  • May 13, 2019
The Ultimate member plugin version 2.0.45 and lower is affected by multiple vulnerabilities, among them is a critical vulnerability allowing malicious users to read and…
Read the Post
WordPress Vulnerability Detail
  • Vulnerability Disclosure
  • WordPress Security

Persistent XSS via CSRF in WP Meta and Date Remover

  • John Castro
  • May 7, 2019
During regular research audits for our Sucuri Firewall (WAF), we discovered a Cross Site Request Forgery (CSRF) leading to a persistent Cross Site Scripting vulnerability…
Read the Post
WordPress Vulnerability Detail
  • Vulnerability Disclosure
  • WordPress Security

Insufficient Privilege Validation in WooCommerce Checkout Manager

  • John Castro
  • April 29, 2019
Due to the poor handling of a vulnerability disclosure, a new attack vector has appeared for the WooCommerce Checkout Manager WordPress plugin and is affecting…
Read the Post
Search
Sucuri Sidebar Malware Removal to Signup Page
Sucuri Logo

Let’s Connect

Products
Website Firewall Website Security Platform WordPress Security Website Backups Hack Assistance Pricing
Solutions
DDoS Protection Malware Detection Malware Removal Malware Prevention Blacklist Removal SEO Spam Removal
USE CASES
Developers Ecommerce Agency Plans Enterprise Services HTTPS/2 Virtual Patching
Support
Knowledge Base SiteCheck Guides Research Labs Report Abuse Status Report
Company
About Sucuri Contact Blog Referral Partners Testimonials
Terms of Use Privacy Policy Do Not Sell My Personal Information Frequently Asked Questions

© 2025 GoDaddy Mediatemple, Inc., d/b/a Sucuri. All rights reserved.

back to top

'