Twenty five plugins for WordPress were found to be vulnerable to cross-site request forgery (CSRF) attacks.
With a proof of concept and a video, we explain in this post how hackers exploit XSS vulnerabilities in order to create administrator accounts on your blog.
Critical zero-day vulnerability fixed in WordPress File Manager (700,000+ installations). Update immediately.
The WordPress Kali Forms plugin (30,000+ active installations) fixed multiple vulnerabilities affecting version 2.1.2 and below.
The WordPress CMP – Coming Soon and Maintenance plugin (100k+ active installations) fixed multiple vulnerabilities.