Blog

  • August 2020 Monthly Vulnerability Roundup

    WordPress Plugin Vulnerabilities Recall Products <= 0.8 – Authenticated Cross-Site ScriptingRecall Products <= 0.8 – Authenticated SQL InjectionWP Smart CRM & Invoices FREE <= 1.8.7 – Authenticated Stored Cross-Site ScriptingCeceppa Multilingua <= 1.5.17 – Authenticated Reflected Cross-Site ScriptingBulk Change <= 1.0 – Authenticated Reflected Cross-Site ScriptingWP Floating Menu < 1.4.1 – Authenticated Reflected Cross-Site ScriptingSubscribe…

  • July 2020 Monthly Vulnerability Roundup

    WordPress Plugin Vulnerabilities Quiz And Survey Master < 7.0.0 – Authenticated Stored Cross-Site Scripting (XSS)Gallery PhotoBlocks < 1.2.0 – Authenticated Cross-Site Scripting (XSS)Comments – wpDiscuz 7.0.0 – 7.0.4 – Unauthenticated Arbitrary File UploadWooCommerce Subscriptions < 2.6.3 – Unauthenticated Stored Cross-Site Scripting (XSS)JobSearch < 1.5.6 – Unauthenticated Reflected XSSSocial Sharing Plugin < 1.2.10 – Cross-Site Request…

  • Installing WPScan

    This is a copy of the WPScan User Documentation. Please refer to the Github Wiki version for the most up to date information. Introduction WPScan is a free, for non-commercial use, black box WordPress security scanner written for security professionals and blog maintainers to test the security of their sites. WPScan is written in the Ruby…