The WordPress GDPR CCPA Compliance Support plugin (1,000+ active installations) fixed an insecure deserialization vulnerability affecting version 2.1 and below that could lead to unauthenticated PHP object injection.
The WordPress TI WooCommerce Wishlist plugin (70,000+ installations) fixed a critical Zero-Day vulnerability affecting version 1.21.11 and below that could allow an attacker to take over the blog and its database.
Very often, when we clean up a hacked WordPress website, we found hidden admin users created by the attackers. In this post, we will see how hackers manage to create and hide them.
Fifteen WordPress themes were prone to critical unauthenticated function injection and privilege escalation vulnerabilities.
Additional WordPress plugins and themes were found to be vulnerable to CSRF attacks.