Website Takeover Issue Fixed in WordPress' Most Popular Plugin

Website Takeover Issue Fixed in WordPress' Most Popular Plugin

All in One SEO Pack affected by stored XSS issue

Stored XSS in Jetpack Plugin Puts over One Million WordPress Sites at Risk

Stored XSS in Jetpack Plugin Puts over One Million WordPress Sites at Risk

Users should update to Jetpack 4.0.3 as soon as possible

Stored XSS in Jetpack Plugin Allows Attackers to Run Code in the WordPress Backend

Stored XSS in Jetpack Plugin Allows Attackers to Run Code in the WordPress Backend

XSS bug affected Jetpack's custom contact form module

  • Security
  • By Catalin Cimpanu
  • September 2nd, 2015
PayPal XSS Vulnerability Found, Fixed Before Being Exploited

PayPal XSS Vulnerability Found, Fixed Before Being Exploited

The stored XSS (fixed now) affected Firefox users only

Stored XSS Bug in eBay Messages Still Unpatched a Year After Reporting, PoC Available

Stored XSS Bug in eBay Messages Still Unpatched a Year After Reporting, PoC Available

Company refuses to offer the researcher info on glitch fix

WordPress 4.2.1 Patches Zero-Day Affecting All Previous Versions

WordPress 4.2.1 Patches Zero-Day Affecting All Previous Versions

Updating should be at the top of the priority list

Google Analytics by Yoast Security Patch Fixes Stored XSS

Google Analytics by Yoast Security Patch Fixes Stored XSS

Yoast downplays severity of its Google Analytics update

Stored XSS Glitch in WP-Super-Cache May Affect over 1 Million WordPress Sites

Stored XSS Glitch in WP-Super-Cache May Affect over 1 Million WordPress Sites

Attackers can gain complete control of the website

Stored XSS Found in Yoast’s Google Analytics for WordPress

Stored XSS Found in Yoast’s Google Analytics for WordPress

Non-severe issues, can be exploited via targeted attacks