Showing posts with label Marc-Alexandre Montpas. Show all posts
Showing posts with label Marc-Alexandre Montpas. Show all posts

Friday, November 24, 2017

Formidable Forms / Shortcodes Ultimate Exploits In The Wild

Formidable Forms / Shortcodes Ultimate Exploits In The Wild

On Monday, November 20th, we were notified about a vulnerability that poses a serious security risk when the Shortcodes Ultimate and Formidable Forms plugins are used together on a single WordPress installation.

Over the past couple of weeks, we’ve noticed a large influx in the number of malicious requests testing for the presence of the two popular WordPress plugins. Both of these plugins contain separate medium-risk vulnerabilities that, when combined, allow an attacker to remotely execute rogue code on the underlying server.

Continue reading Formidable Forms / Shortcodes Ultimate Exploits In The Wild at Sucuri Blog.

The post Formidable Forms / Shortcodes Ultimate Exploits In The Wild appeared first on Security Boulevard.



from Formidable Forms / Shortcodes Ultimate Exploits In The Wild

Monday, November 13, 2017

SQL Injection in bbPress

SQL Injection in bbPress

During regular audits of our Sucuri Firewall (WAF), one of our researchers at the time, Slavco Mihajloski, discovered an SQL Injection vulnerability affecting bbPress. If the proper conditions are met, this vulnerability is very easy to abuse by any visitors on the victim’s website.

Because details about this vulnerability have been made public today on a Hackerone report and updating to the latest version of WordPress fixes the root cause of the problem, we chose to disclose this bug and make the details public.

Continue reading SQL Injection in bbPress at Sucuri Blog.

The post SQL Injection in bbPress appeared first on Security Boulevard.



from SQL Injection in bbPress

Tuesday, March 14, 2017

Stored XSS in WordPress Core

Stored XSS in WordPress Core

As you might remember, we recently blogged about a critical Content Injection Vulnerability in WordPress which allowed attackers to deface vulnerable websites. While our original disclosure only described one vulnerability, we actually reported two to the WordPress team. As it turns out, it was possible to leverage the content injection issue to achieve a stored cross-site scripting attack. This issue was patched in WordPress 4.7.3.

Are You at Risk?

This vulnerability has been present in WordPress for quite a while, well before 4.7.

Continue reading Stored XSS in WordPress Core at Sucuri Blog.



from Stored XSS in WordPress Core