Plugin Vulnerabilities Updates – Week of 7/8/2016
Here is what we have been doing to keep your website secure from WordPress plugin vulnerabilities this week:
Plugin Vulnerabilities We Discovered and Publicly Disclosed This Week
- Authenticated information disclosure vulnerability in Email Log
- Authenticated information disclosure vulnerability in Log Emails
- Arbitrary file upload vulnerability in Advanced AJAX Page Loader
- Authenticated information disclosure in Activity Log
- Authenticated persistent cross-site scripting (XSS) vulnerability in WooCommerce Products Filter
- Arbitrary file upload vulnerability in WooCommerce Products Filter
Plugin Vulnerabilities We Helped Get Fixed This Week
- Arbitrary file upload vulnerability in Jssor Slider, discovered by us
- Authenticated information disclosure vulnerability in Email Log, discovered by us
- Authenticated information disclosure vulnerability in Log Emails, discovered by us
- Arbitrary file upload vulnerability in Advanced AJAX Page Loader, discovered by us
- Arbitrary file upload vulnerability in BePro Listings, discovered by us
- Authenticated information disclosure in Activity Log, discovered by us
- Post deletion vulnerability in BePro Listings, discovered by us
- Authenticated persistent cross-site scripting (XSS) vulnerability in WooCommerce Products Filter, discovered by us
- Arbitrary file upload vulnerability in WooCommerce Products Filter, discovered by us
Vulnerabilities Added This Week
- Authenticated information disclosure vulnerability in Email Log, discovered by us
- Authenticated information disclosure vulnerability in Log Emails, discovered by us
- Authenticated privilege escalation vulnerability in Ultimate Member, discovered by James Golovich
- Arbitrary file upload vulnerability in Advanced AJAX Page Loader, discovered by us
- Authenticated information disclosure in Activity Log, discovered by us
- Authenticated persistent cross-site scripting (XSS) vulnerability in WooCommerce Products Filter, discovered by us
- Arbitrary file upload vulnerability in WooCommerce Products Filter, discovered by us